NIS2 and the French Resilience bill: who is in scope, and for what
The topic is treated either as a distant formality or as an imminent disaster. Reality is simpler: a wide scope, obligations known since 2022, and a French timetable that has slipped without changing the work to be done.
European directive 2022/2555, known as NIS2, has been in force since January 2023 and was due to be transposed by member states by 17 October 2024 at the latest. France is behind.
Transposition runs through the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, known as the Resilience bill, which also transposes the critical entities resilience directive and adapts national law to the DORA regulation for the financial sector. Passed by the Senate in March 2025, its examination by the National Assembly was still expected at the September 2026 return of parliament.
ANSSI will be the supervisory authority for the vast majority of sectors. On 17 March 2026 it published the Référentiel Cyber France, which translates the NIS2 security objectives into concrete measures. It is circulated as a working document and remains non-binding until the legal framework is adopted, which takes nothing away from its usefulness: it is the best preparation grid available today.
The scope covers eighteen sectors, far beyond the vital-importance operators targeted by the previous scheme: energy, transport, health, water, banking, digital infrastructure, public administration, but also manufacturing, food, waste management, postal services and digital service providers.
Within those sectors the threshold starts at size: from fifty employees, or ten million euros of annual turnover or balance sheet. Entities are then classified essential or important, which changes the intensity of supervision and the penalty ceiling, not the nature of the obligations.
The most commonly missed point is the supply-chain effect. A company outside the scope that supplies an in-scope entity gets the requirements passed down by contract. In practice many companies discover NIS2 through a customer's security questionnaire, not through the official journal.
Manage risk. Risk analysis and security policy, incident handling, continuity and backups, supply-chain security, access control and multi-factor authentication, encryption, training. Nothing exotic: it is the baseline, written down and verifiable.
Notify fast. Early warning within 24 hours of becoming aware of a significant incident, a detailed notification within 72 hours, a final report within one month.
Own it at board level. The directive makes management bodies responsible for approving and overseeing the measures, and requires them to be trained. Security stops being a topic delegated to the technical team.
The cost of non-compliance. Up to ten million euros or two percent of worldwide turnover for an essential entity, seven million or one point four percent for an important entity, whichever is higher.
The timetable slipped, the useful work did not change, and it takes longer than the time left anyway. Four workstreams deliver most of the result.
Know what you have. An inventory of systems, accesses and the providers who come into your environment. You cannot protect what you do not know you own, and that inventory is also the first thing an inspection asks for.
Make backups restorable. Tested by real restoration, isolated from the domain, timed. In practice this is the measure that saves the most companies.
Close the accesses. Multi-factor authentication everywhere it is possible, privileged-account review, removal of leavers' accounts. Best effort-to-risk ratio of the lot.
Write the crisis plan. Who decides, who calls whom, in what order, and one rehearsal a year. Without it the other three workstreams only half pay off on the day.
Does NIS2 already apply in France?
The directive has been in force at European level since January 2023, but it takes effect in French law through the transposition act, the Resilience bill, whose examination by the National Assembly was still expected at the September 2026 return of parliament. Inspections and penalties will follow a compliance period. Waiting for the text before starting means compressing several years of work into a few months.
How do we know whether we are an essential or an important entity?
It depends on your sector and your size, and the boundary is finer than the comparison tables circulating online suggest. The classification changes the supervision regime, ex ante for essential entities and ex post for important ones, and the penalty ceiling. A gap analysis settles it in a few days.
Should we aim for ISO 27001 certification?
Not necessarily. NIS2 mandates risk-management measures, not a certificate. An ISO 27001 programme is an excellent vehicle if you need the certification commercially anyway, but it costs more and takes longer than the text requires. The Référentiel Cyber France published by ANSSI is a more direct preparation grid.
This maps to our Cybersecurity and resilience offer, or talk it through with the founder.
Let's talk about your situation.
A 30-minute call with the founder, no strings attached. Reply within 24 business hours.
Your details are used only to answer your enquiry: never sold, never used for cold outreach. Privacy policy.