It’s one of those Parisian bureaucratic delays that Paris is famous for, but it’s already starting to cost credibility and, soon, tens of millions of euros.
According to Politico, the European Commission is gradually hardening its stance against France, which remains sidelined on transposing the NIS 2 cybersecurity directive.
The issue has taken on a particularly sensitive dimension in Brussels since the Commission began issuing formal warnings with increasing frequency.
The initial transposition deadline was set for October 17, 2024. Almost two years later, France has still not completed the legislative process.
After a formal notice to 23 member states at the end of 2024, followed by a reasoned opinion sent on May 7, 2025 to 19 recalcitrant countries, the executive is accelerating. This would amount to a reference to the Court of Justice of the European Union (CJEU) in the near future.
A devastating political signal
For Brussels, this chronic delay is not merely an administrative hiccup. It directly undermines the coherence of the European cybersecurity framework at a moment when ransomware attacks and state-backed sabotage operations against critical infrastructures, digital services, and supply chains are reaching new heights.
By tolerating such misalignments among member states, the European Union risks fracturing its internal market, rendering it opaque to global business players.
The message sent to Paris sounds like a blunt political rebuke. France, which traditionally positions itself as a champion of “European strategic autonomy” and digital sovereignty, finds itself caught red-handed in contradiction with a foundational text.
This yawning gap between the rhetoric of the discourse and the inertia of execution feeds the administration’s embarrassment, especially since the dossier hits at the country’s sovereign core: energy, transport, health, and telecommunications.
The industry kept in the fog
The NIS 2 directive dramatically scales up compared to its first version. It massively broadens the scope of regulated entities and imposes stringent obligations in governance, risk management, incident notification, and subcontractor screening.
This broad regulatory grey area understandably unsettles industrial players and essential service operators (ESOs). They are compelled to design major cyber surveillance and detection capabilities without a national reference framework stabilized by the ANSSI.
The knock-on effect also touches the IT ecosystem and cybersecurity solution providers, who see NIS 2 as a catalyst for demand.
“The European Commission is about to, just before or just after the summer, and no later than the end of the year, bring France and Spain before the Union’s highest court, the CJEU, for failing to enact national laws transposing the EU rules on protecting critical infrastructure from cyberattacks,” warn Philippe Latombe (Deputy for Vendée, Chair of the National Assembly’s Special Committee) and Olivier Cadic (Senator for French citizens abroad, Chair of the Senate’s Special Committee).
Both lawmakers remind that on September 10 last year, the National Assembly’s Special Committee had indeed voted the bill unanimously. “Its examination on the floor seemed a mere formality… And then, nothing more! Despite our repeated warnings, this text keeps getting pushed back into the ether. Such a decision by the European Commission, rare in its history, should, moreover, be accompanied by a fine that could reach tens of millions of euros—a financial penalty our national budget can ill afford in these austere times. Finalizing this legislative path on protecting critical infrastructure from cyberattacks is an absolute urgency.”
Brussels’ method: no privilege
The doctrine championed by the European Commission is brutally straightforward. Without rapid and uniformly applied transposition, the effectiveness of a cross-border regulation collapses. Brussels stresses that in matters of network security, the vulnerability of any single national link instantly compromises the Union’s collective integrity. It is this stubborn stance that explains why the Commission refuses to grant the French executive any special treatment.
Admittedly, the bill on critical infrastructure resilience and the strengthening of cybersecurity is technically moving through Parliament. The Senate has advanced, and the National Assembly has convened its special committee.
But if Paris does not urgently get back on track before Brussels’ year-end deadlines, a ruling from the CJEU will follow.