Skip to main content
NIS2 · FRANCE

NIS2 in France — a law still waiting, a portal already open, and ANSSI ahead of the text.

France has not yet promulgated its NIS2 transposition. The Sénat adopted its version on 12 March 2025; the Assemblée nationale's committee reported on 10 September 2025; the floor vote slipped toward September 2026; and on 8 July 2026 the Court of Justice was seised in the Commission's action against France — alongside Spain and Ireland — over the delayed transposition. Until the law lands, ANSSI remains the national authority and the OIV regime under the Military Programming Law continues to carry critical-infrastructure obligations.

What makes France distinctive is that the preparation infrastructure arrived before the law. ANSSI opened the MonEspaceNIS2 pre-registration portal on 24 November 2025, and confirmed the ReCyF — the French cybersecurity framework entities will be measured against — on 17 March 2026. Around 15,000 entities are projected in scope. Teams waiting for promulgation to start are therefore late against the authority's own runway, not just the directive's.

Who it applies to

Entities in the NIS2 sectors that meet the size thresholds — around 15,000 projected, most new to the regime since the OIV list covers only a fraction of them. Entities already designated OIV keep their existing obligations and will find the NIS2 law extends rather than replaces them. Pre-registration is open now through ANSSI's MonEspaceNIS2 portal; pre-registering positions an entity ahead of the classification notices the law will trigger.

The clock

Competent authority: ANSSI. Transposition: Transposition bill (not yet promulgated).

NIS2 in France · timeline
WhenWhat happens
12 Mar 2025Sénat adopts its transposition text
10 Sep 2025Assemblée nationale committee reports · floor vote slips
24 Nov 2025ANSSI opens MonEspaceNIS2 pre-registration
17 Mar 2026ReCyF, the French cybersecurity framework, confirmed by ANSSI
8 Jul 2026Court of Justice seised in the transposition-delay action (with Spain and Ireland)

The authority moved before the legislator

Most late-transposing member states left their entities in a vacuum. France did the opposite: ANSSI built the on-ramp while the law waited — a pre-registration portal (MonEspaceNIS2, open since 24 November 2025) and the ReCyF framework (confirmed 17 March 2026) that tells entities what “good” will look like before the law says when it must exist. For OIV operators the continuity runs deeper: the LPM structures, the ANSSI relationship and the incident-reporting channels all carry into the future regime. TruSecure maps the OIV-to-NIS2 delta rather than treating this as a green-field program, and holds the legislative status — promulgation pending, Court of Justice action live — as a tracked fact on the entity, so the moment the law lands, the clocks compute from real dates.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the France transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

France requirements · how TruSecure answers them
What the law asksWhere it is answered
Pre-register through MonEspaceNIS2Entity profile · pre-registration facts held as records
Map the OIV-to-NIS2 delta if you are a designated operatorRisk register · existing LPM controls credited, gaps only
Prepare against the ReCyF frameworkControl library · ReCyF mapped onto the same control set as the EU baseline
Report significant incidents under the current regime — 24 h, 72 h, one monthIncident workflow · clocked from awareness, pre-built stages
Track the legislative status and classification noticesCompliance workspace · promulgation and Court of Justice status tracked as dated facts

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

France NIS2 readiness file · excerptSample data
Pre-registration
MonEspaceNIS2 · filed 14 Jan 2026
OIV status
designated under LPM · delta mapped, 9 gaps only
ReCyF alignment
controls mapped · evidence continuous
Controls evidenced
138/152 · 14 open, each with owner and deadline
Export
sealed · sha256:2e7b...8c4a

Where teams usually start

With a demo walked through by TruSecure — your position against the projected French scope, the OIV-to-NIS2 delta mapped if you are a designated operator, and your controls prepared against the ReCyF ahead of promulgation. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in France by ANSSI. TruSecure determines applicability against France's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

How does NIS2 interact with France's existing OIV/LPM critical-operator regime?
French entities already inside the OIV regime under the Military Programming Law (LPM) face a transposition that extends that known structure — TruSecure maps the specific delta between OIV obligations and the NIS2 baseline rather than treating it as a green-field program.