NIS2 Resilience Act: What Is the Current Status of the Bill in France?



As of July 21, 2026, the NIS2 Resilience Act has not been confirmed as having been definitively passed in the National Assembly’s official records. However, its impact is already being felt: approximately 15,000 French entities could fall under the NIS2 scope, subject to cybersecurity, governance, and incident reporting requirements. For an affected small or medium-sized business, waiting for the final vote would be a poor business decision.


NIS2 Resilience Act: What Is the Current Status of the Bill in France?

NIS2 Resilience Act: What Is the Current Status of the Bill?

The French bill is titled “on the resilience of critical infrastructure and the strengthening of cybersecurity.” In particular, it transposes the European NIS2 Directive, which was adopted by the European Union to raise the security level of networks and information systems.

The bill was introduced in the Senate on October 15, 2024, with the government initiating an expedited procedure. The Senate adopted it on first reading on March 12, 2025, and then forwarded it to the National Assembly on March 13, 2025, under number 1112. The National Assembly’s special committee submitted its report on September 10, 2025.

Point of contention: Some publications refer to a “Resilience Act passed in July 2026.” Institutional sources consulted as of July 21, 2026, do not confirm this. The official record currently shows the bill at the first-reading stage in the National Assembly, following committee deliberations in September 2025.

Another recent development: On July 8, 2026, the European Commission decided to refer France, Ireland, Spain, and the Netherlands to the Court of Justice of the European Union for failing to provide full notification of the transposition of NIS2. It is seeking financial penalties, calculated on a daily basis, until full notification is provided. This is therefore not a theoretical issue: regulatory pressure is very much a reality.

What changes does the Resilience Act bring for a business?

The underlying motivation for researching the NIS2 Resilience Act is often very pragmatic: “Does this apply to me, and what do I need to do?” ” The answer can be summarized in three key points: a broader scope covering more companies, better-defined security requirements, and higher administrative penalties for noncompliance.

NIS2 distinguishes between two main categories: essential entities and important entities. The classification depends on the criticality of the activity, the sector, the service provided, and the size of the organization. A company must therefore consider not only its revenue or headcount but also what it provides, to whom, and within which dependency chain.

According to the opinion of the Council of State and parliamentary proceedings, the scope of the French regulation would expand from approximately 500 to 600 entities under the previous regime to approximately 15,000 entities under NIS2. This represents a significant change in scale. Companies that were not previously subject to cybersecurity requirements may now be affected because they operate in the digital, healthcare, energy, transportation, water, manufacturing, financial services, or certain subcontracting sectors.

For a leader, the right question isn’t “Will I be audited tomorrow?” but rather “Can I demonstrate that my cybersecurity risks are identified, monitored, and addressed seriously?” ” The distinction is important. NIS2 does not require perfect cybersecurity. It promotes verifiable governance.

Is my company affected by NIS2?

The first criterion is the sector of activity. NIS2 targets sectors considered essential or important to the economy and society: energy, transportation, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, agri-food, the manufacturing of certain critical products, and digital service providers.

Read also  How to choose AI tools for your project: an expert guide for development teams and managers

The second criterion is size. The European thresholds for SMEs, mid-sized companies, and large enterprises generally serve as a starting point, but they are not always sufficient. A smaller entity may be included if it provides a critical service or if a sector-specific regulation so provides.

The third filter is dependency. A company that hosts customer data, maintains an e-commerce platform, operates a business application, or develops software used by a critical entity may be subject to contractual requirements based on NIS2, even if it is not directly classified. This is a common pitfall: the risk sometimes arises from contracts, not from a letter from an authority.

In the projects we undertake, we often see small and medium-sized enterprises (SMEs) discover their exposure when a contract is up for renewal, during a request for proposals, or as part of a supplier audit. At this stage, everything costs more because evidence must be produced quickly: backup policies, logging, access management, disaster recovery plans, incident logs, and hosting terms.

For WordPress sites, extranets, or commercial platforms, this issue also arises on the application side. Executives who want to explore this topic further can read our analysis dedicated to The Impact of NIS2 on a WordPress Site, because many risks stem from simple components: unmaintained extensions, shared administrator accounts, and untested backups.

Penalties, management, budget: Key Points to Watch Closely

The maximum penalties set forth in the legislative proceedings are high. For essential entities, the cap on administrative fines is 10 million euros or 2 % of the previous fiscal year’s global annual revenue hors taxes, whichever is higher. For significant entities, the cap is set at 7 million euros or 1.4 % of global annual revenue hors taxes.

These amounts do not mean that every incident will result in the maximum penalty. They set a cap. The real issue for an SME is its ability to demonstrate that it has taken appropriate measures: risk analysis, prioritization, budgeting, monitoring, documentation, and correction of known discrepancies.

The bill also provides for a sanctions commission to address violations of the obligations set forth in Title II, “Cybersecurity,” which transposes NIS2. A government amendment related to the temporary ban on natural persons serving as executives of critical entities was considered by the Senate and subsequently rejected. This ban should therefore not be taken for granted as it currently stands in the text, but the debate reveals a clear trend: cybersecurity is moving up to the governance level.

In terms of budget, costs vary significantly depending on the level of maturity. An initial risk and digital asset assessment can cost between €5,000 and €15,000 for an SME with a simple IT system, depending on the service provider and the scope of the project. A more comprehensive upgrade—including access controls, backups, monitoring, incident response procedures, and testing—can cost tens of thousands of euros over a period of 6 to 12 months.

Project Specific Objective Typical cost range in France Realistic timeline
Initial NIS2 Diagnosis Identify scope, gaps, and priorities €5,000 to €15,000 2 to 5 weeks
Stricter Access Controls MFA, registered accounts, limited rights €3,000 to €20,000 1 to 3 months
Backups and Recovery Recovering from ransomware or human error €5,000 to €30,000 1 to 4 months
Monitoring and Logging Detect incidents and preserve evidence €10,000 to €60,000 per year 2 to 6 months
Incident Response Plan Knowing who makes the decisions, what to cut, and who to notify €4,000 to €18,000 3 to 8 weeks
Read also  Agile methods for efficient project management

With this budget, it’s better to allocate funds to measures that truly reduce risk: multi-factor authentication (two-step verification), restorable backups, updates, access segmentation, and log monitoring. Purchasing a sophisticated tool without clear internal procedures rarely provides long-term peace of mind.

ANSSI’s “Cyber France” Framework: Useful, but Not a Magic Bullet

On March 17, 2026, ANSSI published the Cyber France Framework, also known as ReCyF. It is a working document that lists recommended measures for achieving the NIS2 security objectives. ANSSI notes that it is not mandatory by default at this stage.

This framework, however, has great practical value. It provides a basis for discussion among senior management, the CIO, the CISO (Chief Information Security Officer), service providers, and legal counsel. Instead of speaking vaguely about “security,” you can link each action to a specific objective: managing risks, protecting access, detecting threats, responding to incidents, and restoring systems.

Honestly, striving for perfect document compliance as early as the first quarter is justified only for organizations that are already very mature or highly exposed. For many small and medium-sized businesses, the best approach is to establish a credible process from the outset: risks classified, responsible parties designated, actions dated, and evidence retained.

This work overlaps with other texts. Companies that produce or distribute software will also need to monitor the The Cyber Resilience Act and Its Requirements for Software. Financial players, for their part, are already having to deal with DORA, effective as of January 2025 for financial services. The texts are not identical, but they all point toward the same goal: demonstrating mastery of digital risk.

Where should you start without stalling your digital projects?

The natural instinct is to ask for a checklist. It helps, but it doesn't replace setting the framework. A web platform, a mobile application, OVH hosting, Cloudflare protection, a back-office connected to an ERP system, and APIs (interfaces for exchanging data between software applications) do not pose the same risks.

A simple method works well for getting started without disrupting operations:

  1. List the digital services that would disrupt your business if they were down for 48 hours.
  2. Identify sensitive data: customer information, health information, payment information, trade secrets, login credentials, and contracts.
  3. Check administrator access, shared accounts, and multi-factor authentication.
  4. Test a backup restore—not just whether a backup exists.
  5. Document who makes decisions in the event of an incident: management, technical, legal, communications, and service providers.
  6. Classify the actions by impact, cost, and timeline, then make a decision as a management committee.

When the obvious solution is the wrong one: completely rebuilding a website or application to “start fresh.” Sometimes this is necessary, especially if the technical foundation is obsolete. But often, the quickest improvements come from targeted hardening: updates, removing dormant accounts, reviewing extensions, separating environments, and implementing real-time backups.

Read also  Developing a mobile application for Android

Visit mobile applications deserve special attention, as they expose APIs, access tokens, and sometimes local data. Before publishing or refactoring, a Mobile App Security Checklist avoids late cor calls. And if your application depends fortely on APIs, the Invisible vulnerabilities on the mobile API side are often more critical than the screen visible to the user.

From the agency’s perspective, the natural tendency is to link compliance with the actual lifecycle of the digital product: design, development, hosting, maintenance, and monitoring. A NIS2 requirement added after delivery costs more than one that is integrated into the specifications from the outset.

What the NIS2 Resilience Act Means for Your Contracts

The NIS2 Resilience Act doesn't just affect your internal organization. It changes the way you draft and manage contracts with your digital service providers: hosting providers, web agency, IT service provider, SaaS provider, maintenance provider, payment provider, support center.

The clauses to look for aren’t just legal ones. They must address operational questions: where is the data hosted, how quickly must an incident be reported, who has access to the logs, how are backups tested, what procedure applies in the event of a security breach, and how is the contract properly terminated.

Be wary of offers that are too vague. “Secure hosting” doesn’t tell you anything if you don’t know whether updates are included, whether an application firewall is enabled, whether backups are isolated, or whether logs are retained long enough to conduct an investigation. For an e-commerce project, for example, the choice between PrestaShop, WooCommerce, or Shopware must also take into account maintenance and the exposure of extensions; this topic is covered in detail in our comparison of e-commerce platforms in 2026.

Defining the scope of this type of project early on helps avoid most unpleasant surprises: vague scope, underestimated budgets, scattered responsibilities, and missing documentation. Above all, an outside perspective helps translate a regulatory requirement into a realistic action plan that is compatible with your deadlines and resources.

FAQ on the NIS2 Resilience Act

Has the NIS2 Resilience Act been passed in France?

As of July 21, 2026, the official National Assembly record consulted does not confirm a final vote or enactment. The bill passed the Senate in March 2025 and remained at the first-reading stage in the National Assembly following committee review.

How many French companies will be affected by NIS2?

Institutional sources estimate that there are approximately 15,000 French entities, compared with about 500 to 600 previously. The exact figure will depend on the final scope and the implementing regulations.

What penalties does NIS2 provide for?

The proposed caps are 10 million euros or 2.% of global revenue (excluding tax) for core entities, and 7 million euros or 1.4 % for non-core entities. The higher amount would apply.

Should we wait until the law is enacted to start preparing?

No, especially if your business relies heavily on digital technology or contracts with regulated entities. ANSSI is already urging future essential and critical entities to implement a security strategy consistent with NIS2.

Is ANSSI's ReCyF mandatory?

ANSSI states that the Cyber France Framework, published in March 2026, is not mandatory by default at this stage. It remains a useful working basis for structuring a compliance roadmap.

English