NIS2 on Hold: CISOs and Market Await Clarity

The French bill to transpose the European NIS2 directive is still not on the agenda of the extraordinary session opened on July 1, 2026.

For CESIN, the leading association of CISOs in France, this gap is not merely a legal loophole—it is a practical brake on cybersecurity investment.

The parliamentary timetable is moving forward, but the text is not making it onto the agenda. It is worth recalling that the original transposition deadline was set for October 17, 2024.

Read also: Gamaredon: how the FSB reinvented its espionage arsenal

As the extraordinary session opens on July 1, 2026, the proposed law on the resilience of critical infrastructure and the strengthening of cybersecurity shines by its absence from the agenda.

CESIN is sounding the alarm about the very practical consequences of this delay.

Decisions Pending

Cybersecurity operates in long cycles, and cyber leaderships need a stable framework.

In the absence of a promulgated text, some projects are slowed down. Others are simply waiting.

“Regulatory uncertainty disrupts the cyber procurement and slows investment decisions,” summarizes Fabrice Bru, president of CESIN. “It affects all organizations, including those already subject to regulatory frameworks, insofar as NIS2 significantly broadens the scopes and the levels of requirements.”

The French delay is not happening in a vacuum. At the European level, some member states have already transposed the directive. Companies operating across multiple markets are gradually aligning with the more advanced frameworks, which mechanically widens the gap with French organizations kept in question by uncertainty.

The problem concerns both entities historically regulated, which see their coverage expanding, and those newly affected by NIS2, entering for the first time the regulatory cyberspace and needing to anticipate still-undecided requirements.

Read also: Suspension of Claude Mythos: experts call for lifting restrictions

Added to this is the matter of the supply chain. The directive’s requirements are intended to diffuse through suppliers and service providers, whose own positioning also depends on a visibility they do not yet have.

Three Specific Demands

CESIN lays out precise expectations.

The association is calling for a readable parliamentary and regulatory timetable, for a rapid confirmation of the main requirements to allow companies to prepare their action plans, and for particular attention to the implementation conditions, notably for newly regulated entities and their subcontractors.

It also notes, in passing, that many companies do not wait for the law to act. Compliance efforts are already underway.

“The market is ready. The framework must follow.” That line sums up the mindset of a sector that does not dispute the direction but grows impatient at not seeing the starting signal.

Europe is also impatient. After a formal notice to 23 member states at the end of 2024, followed by a reasoned opinion sent on May 7, 2025 to 19 reluctant countries, the European Commission is moving up a gear. A referral to the Court of Justice of the European Union (CJUE) would be imminent.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.