NIS2: What to Expect from the NIS2 Bill Under Review in …

Will France finally transpose the European NIS2 directive, two years after the date initially set in the European Commission’s schedule? Brussels had indeed set the transposition deadline into national law for 17 October 2024.

On the agenda for the extraordinary parliamentary session in July, the Bill relating to “the resilience of critical infrastructures and the strengthening of cybersecurity,” which carries the transposition of NIS 2, is ultimately to be examined in public session as bill no. 1112, concerning the resilience of critical infrastructures and the strengthening of cybersecurity.

The bill does not stop at NIS2. It also transposes three European directives adopted in 2022: the REC directive on the resilience of critical entities, NIS2 on cybersecurity, and the directive associated with the DORA regulation for the digital operational resilience of the financial sector.

Also read: { Expert Column } – NIS 2: a lever to strengthen the resilience of critical infrastructures

Its Title I modernises France’s security framework for the activities of vital importance (SAIV), created in 2006 and applicable to more than 300 operators. It expands this framework to new subsectors, including heating and cooling networks, hydrogen, and sanitation, and imposes resilience plans on operators and the roughly 1,500 points of vital importance.

The Title II, dedicated to cybersecurity, is the part directly linked to NIS2. It broadens the regulated scope from 6 to 18 sectors, notably including health, manufacturing industries, chemical production, research, postal services, and digital infrastructures.

Who is affected?

The transposition is expected to apply to essential entities and important entities, two categories whose obligations will be proportionate to their level of criticality.

Among the targets are supply-chain actors, central administrations, medium and large enterprises, and local authorities.

According to the elements presented during the parliamentary review, around 15,000 entities will be affected, including around 1,500 local authorities, among which 300 municipalities with more than 30,000 inhabitants.

The report from the special commission also mentions 14,500 entities that the ANSSI will be tasked with monitoring and supervising.

Before the text After transposition (expected)
Approximately 500 regulated entities Nearly 15,000 regulated entities
6 regulated sectors 18 regulated sectors
Approximately 300 vital operators Essential and important entities, public and private
Obligations focused on critical infrastructures Obligations extended to a broad portion of the economic and public fabric

The obligations expected

The regulated entities will notably be required to provide information to the ANSSI and to declare their security incidents.

Also read: Cybersecurity maturity in French companies: a gap between regulation and size

Concretely, companies should anticipate enhanced requirements in governance of cybersecurity, risk management, incident notification, and cooperation with the national authority.

For IT departments and CISOs, the immediate challenge will be to determine the status of the organisation: essential or important entity, the sector involved, size, dependencies on critical service providers, and the ability to detect and notify an incident within the prescribed timelines.

Significant sanctions

In case of non-compliance, the affected entities could face fines of up to €10 million or 2% of global turnover. This range is consistent with the sanction regime envisaged by NIS2.

However, the State, local authorities, and their public administrative establishments will not be subject to these fines. This clarification is important for public actors, who will nevertheless remain bound by security and notification obligations.

The encryption sticking point

The Senate’s examination introduced Article 16 bis aiming to “shield” encryption in the law. It would ban forcing instant messaging services to install backdoors, master decryption keys, or other mechanisms that deliberately weaken their security.

Senators justified this provision by the risk of creating vulnerabilities exploitable by cybercriminals, hostile states, or private actors. This point could remain one of the most sensitive topics of debate during the House’s discussion.

A uncertain vote in the Assembly

Adopted in first reading by the Senate on 12 March 2025 by 181 votes to 134, the bill no. 1112 holds a slim majority in the Senate, but with no abstentions among the 315 ballots cast.

In the National Assembly, however, no public vote has yet taken place. The special commission had unanimously approved the text in September 2025, but the examination in the chamber scheduled to begin on 7 October will determine the final majority.

In committee, deputies reviewed 472 amendments and adopted the commission’s text on 10 September 2025. This consensus in committee does not guarantee the absence of divisions during the final vote in a public session.

Nevertheless, the 7 October examination does not mark the immediate entry into force of NIS2 in France. The bill will need to go through the parliamentary shuttle before potential promulgation.

The ANSSI also notes that NIS2 will come into force in France only once all transposition texts (law, decrees, and orders) have been promulgated.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.