Skip to content
AEGRYN
← Back to Blog

Compliance

NIS2 in 2026: France's Transposition Delay Changes Nothing About Your Exposure

The directive is in force EU-wide. France is late on national transposition, and the European Commission has referred the country to the Court of Justice. Here is what that legal gap changes, and does not change, for organisations in scope.

September 15, 2026 9 min read

Directive (EU) 2022/2555, known as NIS2, has been in force since 16 January 2023. Member states had until 17 October 2024 to transpose it into national law. As of mid-September 2026, France still has not completed that transposition.

The French vehicle, a law on the resilience of critical infrastructure and the reinforcement of cybersecurity, bundles three European instruments into a single text: NIS2, the CER directive on the resilience of critical entities, and provisions tied to DORA for the financial sector. The Senate adopted it in March 2025. It has been stalled since a committee vote in September 2025, delayed repeatedly, and is now expected back before the National Assembly this autumn.

On 8 July 2026, the European Commission referred France to the Court of Justice of the EU, alongside Spain, Ireland and the Netherlands, for failure to transpose the directive. The Commission is seeking financial penalties.

This delay changes almost nothing for organisations in scope. Here is why.

The obligations are already operational at European level

NIS2 is a directive, meaning it requires national transposition to become directly binding on individual companies through French courts. But three things already hold true regardless of the French legislative calendar.

  • If your organisation operates in another EU member state, and twenty of the twenty-seven have already transposed it, you are already bound there.
  • ANSSI has published the Cyber France Reference Framework (ReCyF) since March 2026, and every serious organisation in scope is expected to align with it now, not once a decree formalises it.
  • Buyers, insurers, investors and enterprise customers are not waiting for the French statute. Cybersecurity clauses and security questionnaires are already circulating in supply chains, in automotive, logistics and industrial sectors, well ahead of any legal deadline.

The scope is large, and includes companies that do not think they are concerned

Energy, transport, banking, financial market infrastructure, health, digital infrastructure, ICT service management, public administration and space, plus every digital provider serving these sectors. ANSSI estimates between 15,000 and 18,000 entities will be affected in France, against roughly 500 under the original NIS1 regime. The shift in scale is the real story. NIS2 no longer targets only large critical operators. It reaches deep into the SME and mid-cap ecosystem, through the supply chain obligation alone.

15 000-18 000

entities estimated in scope in France, versus ~500 under NIS1

24h

to send early warning after detecting a significant incident

72h

to submit the full incident report to the authority

10 M€ / 2 %

maximum fine, or 2% of global turnover, whichever is higher

What is required once the law is fully in force

  • Documented risk management: written cybersecurity policies, incident handling procedures and business continuity plans, reviewed and approved by senior management. This is a board level governance obligation, not a task delegated to IT.
  • Incident reporting: early warning to the national competent authority within 24 hours of detecting a significant incident, and a full report within 72 hours. Almost no organisation has rehearsed this sequence under real conditions.
  • Supply chain security: an obligation to assess and document the cybersecurity posture of suppliers and subcontractors. A vendor's security gap becomes your compliance exposure, not in theory, in the text of the directive itself.
  • Management liability: senior executives can be held personally liable for non-compliance. Fines reach €10M or 2% of global turnover. This is not a hypothetical for the second half of 2026. It is the mechanism the directive was built around.

What French legal uncertainty actually means in practice

The absence of a promulgated French law does not mean absence of exposure. It means three specific things right now.

  • The timing of enforcement in France is uncertain. The exact date fines become legally enforceable through French courts is not fixed.
  • The substance of the obligations is not uncertain. The directive's content has been stable since December 2022, and the French law will not weaken it.
  • The market is not waiting for the law. Clauses, questionnaires and due diligence requirements tied to NIS2 readiness are already standard practice among buyers, insurers and larger counterparties.

Waiting for the French statute to be promulgated before starting compliance work is not a strategy. It is a bet that enforcement will arrive slower than your next transaction, your next enterprise contract or your next audit. For most organisations in scope, that bet does not hold.

Why this matters in a transaction context

Any organisation within NIS2 scope will be asked, at some point in a fundraising, acquisition or disposal process, to demonstrate compliance. Not describe it. Demonstrate it, with documentation, with evidence of governance, with proof that the risk management framework is more than a policy sitting in a drawer.

A buyer who cannot get a clear answer on NIS2 readiness will not necessarily walk away. They will price the uncertainty into the offer, make the deal conditional on remediation, or simply move to the next target where the answer is already documented.

This is precisely the gap the Security & Sovereignty dimension of the CIFSO certification protocol is built to close.

Aegryn

It does not ask whether your organisation has a cybersecurity policy. It verifies whether that policy reflects operational reality: incident response readiness, supply chain risk mapping, identity and access management, governance traceable to senior management sign-off.

The transposition delay in France is a legislative fact. It is not a compliance grace period. Organisations that treat it as one will find that out at the worst possible moment, during due diligence, when the answer is needed in days, not months.

Aegryn Advisory supports organisations across the NIS2 scope on risk management documentation, incident response readiness and supply chain security assessment, and certifies the outcome under the CIFSO Security & Sovereignty dimension, ahead of the moment a buyer, insurer or regulator asks for proof.

IA

This article was written with the assistance of artificial intelligence and reviewed under Aegryn editorial responsibility. In accordance with Article 50 of the EU AI Act, we assume editorial responsibility for this content.

Insights Aegryn

Recevez chaque semaine les analyses Aegryn — M&A, valorisation, tech, CIFSO.

Ready to submit your asset or access the catalogue?