NIS2 in France — a law still waiting, a portal already open, and ANSSI ahead of the text.
France has not yet promulgated its NIS2 transposition. The Sénat adopted its version on 12 March 2025; the Assemblée nationale's committee reported on 10 September 2025; the floor vote slipped toward September 2026; and on 8 July 2026 the Court of Justice was seised in the Commission's action against France — alongside Spain and Ireland — over the delayed transposition. Until the law lands, ANSSI remains the national authority and the OIV regime under the Military Programming Law continues to carry critical-infrastructure obligations.
What makes France distinctive is that the preparation infrastructure arrived before the law. ANSSI opened the MonEspaceNIS2 pre-registration portal on 24 November 2025, and confirmed the ReCyF — the French cybersecurity framework entities will be measured against — on 17 March 2026. Around 15,000 entities are projected in scope. Teams waiting for promulgation to start are therefore late against the authority's own runway, not just the directive's.
Who it applies to
Entities in the NIS2 sectors that meet the size thresholds — around 15,000 projected, most new to the regime since the OIV list covers only a fraction of them. Entities already designated OIV keep their existing obligations and will find the NIS2 law extends rather than replaces them. Pre-registration is open now through ANSSI's MonEspaceNIS2 portal; pre-registering positions an entity ahead of the classification notices the law will trigger.
The clock
Competent authority: ANSSI. Transposition: Transposition bill (not yet promulgated).
| When | What happens |
|---|---|
| 12 Mar 2025 | Sénat adopts its transposition text |
| 10 Sep 2025 | Assemblée nationale committee reports · floor vote slips |
| 24 Nov 2025 | ANSSI opens MonEspaceNIS2 pre-registration |
| 17 Mar 2026 | ReCyF, the French cybersecurity framework, confirmed by ANSSI |
| 8 Jul 2026 | Court of Justice seised in the transposition-delay action (with Spain and Ireland) |
The authority moved before the legislator
Most late-transposing member states left their entities in a vacuum. France did the opposite: ANSSI built the on-ramp while the law waited — a pre-registration portal (MonEspaceNIS2, open since 24 November 2025) and the ReCyF framework (confirmed 17 March 2026) that tells entities what “good” will look like before the law says when it must exist. For OIV operators the continuity runs deeper: the LPM structures, the ANSSI relationship and the incident-reporting channels all carry into the future regime. TruSecure maps the OIV-to-NIS2 delta rather than treating this as a green-field program, and holds the legislative status — promulgation pending, Court of Justice action live — as a tracked fact on the entity, so the moment the law lands, the clocks compute from real dates.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the France transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Pre-register through MonEspaceNIS2 | Entity profile · pre-registration facts held as records |
| Map the OIV-to-NIS2 delta if you are a designated operator | Risk register · existing LPM controls credited, gaps only |
| Prepare against the ReCyF framework | Control library · ReCyF mapped onto the same control set as the EU baseline |
| Report significant incidents under the current regime — 24 h, 72 h, one month | Incident workflow · clocked from awareness, pre-built stages |
| Track the legislative status and classification notices | Compliance workspace · promulgation and Court of Justice status tracked as dated facts |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Pre-registration
- MonEspaceNIS2 · filed 14 Jan 2026
- OIV status
- designated under LPM · delta mapped, 9 gaps only
- ReCyF alignment
- controls mapped · evidence continuous
- Controls evidenced
- 138/152 · 14 open, each with owner and deadline
- Export
- sealed · sha256:2e7b...8c4a
Where teams usually start
With a demo walked through by TruSecure — your position against the projected French scope, the OIV-to-NIS2 delta mapped if you are a designated operator, and your controls prepared against the ReCyF ahead of promulgation. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in France by ANSSI. TruSecure determines applicability against France's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.