France NIS2 Transposition (Résilience Bill)
French bill transposing NIS2, DORA and CER still in parliament as of August 2026; France is one of three member states referred to the Court of Justice for non-transposition. ANSSI is the designated authority.
| Jurisdiction | France |
|---|---|
| Category | Cybersecurity |
| Status | Proposed |
| Latest development |
Recent developments
- — An August 2026 practitioner guide stresses that, as of 10 August 2026, there is still **no French NIS2 law in force**, no application decrees and no enforceable registration or reporting duties under the Résilience Bill, underscoring a gap between EU transposition deadlines and the current French legal reality for cybersecurity operators and entities.[5] (source)
- — Analysis as of 2026-08-06 indicates that France has not yet completed the principal legislative transposition of NIS2; the main vehicle remains the *Projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité*, with final adoption still expected during 2026 following completion of the parliamentary process.[1] (source)
- — A July 2026 update reports that the so‑called Resilience law, intended to transpose NIS2, was not placed on the July parliamentary agenda and that its examination has slipped to the autumn session, further delaying legal certainty for covered entities.[6] (source)
- — French press in mid‑July 2026 notes that the National Assembly’s examination of the Résilience Bill, which transposes NIS2 into French law, has been postponed yet again, with debate now expected no earlier than the September 2026 parliamentary return, highlighting continued legislative slippage.[7] (source)
- — A July 2026 policy analysis explains that the Résilience Bill—covering NIS2, CER and REC—has been adopted by the Senate (March 2025) and in committee at the Assemblée nationale (September 2025), but its plenary examination remains pending due to disputes over encryption provisions, prolonging uncertainty on obligations and timelines.[10] (source)
- — A June 2026 calendar update states that the NIS2 transposition law (Résilience Bill) was initially expected to reach the National Assembly in July 2026 but has been rescheduled to September; the text simultaneously transposes NIS2, the CER Directive and DORA, with promulgation anticipated shortly after plenary examination if there is no extended shuttle between chambers.[8] (source)
- — A May 2026 regulatory overview describes France’s **combined transposition** approach via a single bill covering NIS2 and CER, and notes that ANSSI published the *Référentiel Cyber France (ReCyF)* on 17 March 2026 as a pre‑law compliance reference, with an estimated 15,000–18,000 entities expected to fall within scope, signaling significant impact across critical sectors.[12] (source)
- — An April 2026 specialist blog confirms that the Résilience Bill is the French legislative instrument transposing NIS2 and the CER Directive, currently under parliamentary examination in 2026, and stresses that it will redefine cybersecurity obligations for *entités essentielles et importantes* operating in France, expanding duties beyond the previous OIV framework.[15] (source)
- — A March 2026 industry advisory notes that the “cyber resilience bill” was adopted by the Senate in March 2025 and unanimously approved in a special National Assembly committee in September 2025, with floor debate initially scheduled for summer 2026, and highlights expected obligations, fines and enlarged scope affecting French SMEs once NIS2 is transposed.[9] (source)
- — A January 2026 compliance roadmap describes France as being in the “final stretch” of adopting the Résilience Bill, forecasting promulgation in Q1 2026 and technical decrees from ANSSI in Q2 2026, with full NIS2 regime entry into force in early to mid‑2026—though subsequent updates show this timeline slipping due to parliamentary delays.[4][6][7] (source)
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
- Belgium NIS2 Transposition — Belgium, Active, effective 2024-10-18
Put it into practice
- Generate the policy: NIS2 policy generator (generatepolicy.com)
- Buy the policy pack: NIS2 Compliance Policy (cyberpolicy.shop)
- Build it yourself: DORA + NIS2 EU Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates