Aller au contenu

Regulation & compliance

NIS 2 in France: postponing the Resilience bill is not a pause

On 6 October 2026, the Resilience bill was pulled from the Assembly agenda again. For you, that changes less than you might think.

  • 11 OCTOBER 2026
  • 2 MIN READ
  • CITED SOURCES

The essentials

  • On 6 October 2026, the bill transposing NIS 2 was removed from the National Assembly agenda (sessions of 7 and 9 October), with no new date set.
  • The transposition deadline was 17 October 2024: NIS 2 obligations are still not enforceable under French law.
  • ANSSI already asks affected entities to prepare using the Référentiel Cyber France (ReCyF), published as a working document in March 2026.

A text awaited for two years

NIS 2 is the EU directive that imposes a minimum cybersecurity baseline on a large number of organisations deemed essential or important. Its transposition deadline was 17 October 2024. In France, the transposing text—the bill on critical infrastructure resilience and strengthened cybersecurity, which also transposes the REC and DORA directives—was introduced in the Senate on 15 October 2024, adopted by the Senate on 12 March 2025, then adopted by the Assembly special committee in September 2025. It has been waiting for plenary debate since.

It was due to be examined on 7 and 9 October 2026. On 6 October, the Assembly bureau removed it from the agenda, officially because of a crowded calendar, without setting a new date. Specialist press also cites a long-standing political fault line on encryption (Article 16 bis as amended by the Senate).

What the delay does not change

With no transposition law, no entity can today be sanctioned in France on the basis of NIS 2. But the content of the bill is known, and ANSSI is preparing the ground: on 17 March 2026 it presented the Référentiel Cyber France (ReCyF) as a working document, with a proportionality principle—the effort expected depends on the entity’s maturity and resources.

The directive’s obligations boil down to three: register the organisation with ANSSI, implement risk-management measures, and notify significant incidents. What you can start without waiting for the vote:

  • Know whether you are in scope: sector, size, place in the supply chain of a regulated entity.
  • Map: systems, flows, providers, and critical dependencies.
  • Check the basics: tested backups, multi-factor authentication, rapid patching on exposed equipment, logging.
  • Write the incident procedure: who decides, who notifies, within what timeframe—before the incident, not during it.

Sources

This note was drafted with AI tools from the cited sources, then reviewed and published under the responsibility of Jordan FOUASSIER, publication director. We summarise the facts and add our reading; source text and images are not reproduced. An error? Write to contact@aigyrosgroup.com.

Prendre contact

Does this affect your environment?

Describe your context. We reply with an analysis of what it means for you, not a catalogue.