The 2026 Summit: NIS 2, Small Words, Big Changes in Cybersecurity

“Strengthened Authority for the ANSSI”… and “parliamentary logjam.” At the opening conference of the Security Assizes, that was about all there was to say on NIS 2.

Vincent Strubel had the chance to speak more broadly last week at the National Assembly. He appeared before the special committee charged with examining the bill that transposes this directive. The aim was to have public-session debates on October 7. In the end, nothing happened of the sort. The day before, the text was pulled from the agenda — with a sine die postponement — due to an overly crowded parliamentary calendar.

A text awaited by France’s cyber sector

Before the rapporteurs, the director-general of ANSSI urged not to “over-transpose” or overburden NIS 2. The deputy Philippe Latombe had just asked him whether, after months have passed (the Senate adopted the text in March 2025), it was necessary to update the bill.

“No thanks,” replied Vincent Strubel, who saw in it “a response adapted to the state of the threat and its anticipated evolutions.” A text “technologically neutral” and whose measures “would have been effective against the majority of data thefts observed in France in recent months.”

Also read: Directive NIS2: France faces the challenge of cyber maturity

The delays in transposition, he adds, have a deterrent effect on the preparation of the concerned entities, including on budget allocations. This is what French cybersecurity companies have reported…

Until the end of 2028 to achieve compliance?

In March, ANSSI published the ReCyF (French Cyber Reference Framework), subsequently rolled out in practical sheets. This foundation for NIS 2 compliance will be completed “in delta on a case-by-case basis for the specific frameworks.” Excluding however those outside ANSSI’s remit. The agency also invites, where appropriate, to use the comparator available on the MesServicesCyber platform.

During a prior hearing before this same committee, Vincent Strubel had spoken of a three-year timeline before requiring full compliance. In the circumstances we know, he now believes one cannot “stick to that timing.” End of 2028 for all entities is now being considered. Until the regulatory framework is applied, there will be “trial runs.” Both to support future obliged organizations and to allow ANSSI’s control mission to bed in.

The logic of sanctions, and of a binding power, should also help to “make cybersecurity less a matter for technicians and more a matter of governance: finance directors, legal affairs, boards, and the executive committee.”

State security: logging, another challenge

The transposition of NIS 2 is set against France’s national cybersecurity strategy published in January. In April, the state-security roadmap was added. “Not new, but a tighter calendar and governance,” to sum up Vincent Strubel’s words. Ministries have several actions to carry out by December 31, 2026. Among them:

  • Implement an audit and control policy for information systems
  • Endorse information systems supporting essential missions
  • Put in place procedures for installing security patches
  • Replace obsolete security components
  • Generalize ProConnect on high-stakes information systems
  • Implement multi-factor authentication for information system administrators
  • Deploy EDR or XDR on all workstations and servers

Under this regime, ANSSI has “seen projects that were planned to take three years culminate in three months.” Its director-general explained this a few weeks ago to deputy Éric Bothorel, the lead rapporteur of the special committee. He also warned that the broad rollout of strong or multifactor authentication would not be easy. On the menu, “thousands and thousands of digital services,” a large portion of which are outsourced, for which any evolution remains subject to the framework of public procurement. In short, “this is a question of months, not years; but not weeks either.” The DGFiP must, after all, account for 90,000 agents and potentially hundreds of thousands of external partners. Among them: notaries, municipal accountants… and surveyors (a profession highlighted by one of the compromises).

There will also be, among other tasks, a systematic generation and collection of logs across all state applications. Yet, “this is far from the case, and some remain not very modern or developed with exotic technologies.”

“Let’s dare” to think differently about AI

Vincent Strubel finds the consternation sparked by the DGFiP report “almost surprising.” The ANSSI, he explains, probably demonstrates “what every cybersecurity professional sees in their daily life.” Put differently: “Foundational vulnerabilities that are everywhere.”

Facing what he calls a “gap,” the agency head points to the transparency work it has been pursuing for several weeks. It materialized with the DGFiP report, the first milestone of the REACTIV framework… and, this week, a retrospective analysis that CERT-FR and CERT-Santé consolidated based on incidents they have handled in recent years. This document also highlights elementary security flaws (default passwords that cannot be changed, lack of access control…).

This transparency work “stings a bit,” admits Vincent Strubel. “We need to overcome misplaced modesty and tolerate some sensational treatment.” There are other issues not to overlook, he adds: “Do we talk to each other too much and not enough to others? Do we sometimes rely too much on buzzwords rather than on fundamentals? …”

Also read: NIS 2: Brussels takes France to task

That notwithstanding, there is room to “dare to think for oneself,” starting with AI. His premise: rather than basing thinking on the announcements of a few providers, begin by making them face their responsibilities. Attacks by AI agents, even in tests or without the designer’s knowledge, “are not a technical feat, they are a basic security flaw.” Elsewhere, they trigger urgent measures. It should be the same with AI. Otherwise we repeat the original sin: letting editors off the hook.”

Eyes on the CRA, NIS 2’s twin

The responsibility of publishers lies at the heart of the CRA (Cyber Resilience Act). As a regulation, it is not bound by the parliamentary calendar. Its entry into force will occur on December 11, 2027.

The National Assembly’s special committee decided to include this population “en bloc” in the transposition of NIS 2. ANSSI is not in favor. Its argument: that would create an obligation that would apply only to editors established in France.

For the management of subcontractors, the committee believes in “the right way to do things.” These actors are not subject to obligations in themselves, but are indirectly bound through their contractual relationships. “We could always do more, but at some point we must set the bar at a level of complexity and proportionality that is appropriate,” summarizes Strubel.

ANSSI says it is capable of carrying out its new NIS 2 missions because it has adapted its operating model through liaisons across state services, the private sector, and local authorities. Otherwise, with 670 full-time equivalents, “there is no fat,” as its director-general notes, adding that the German BSI has between 1800 and 2000 for the same missions.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.