Law / France

Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2)

Article 14, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (mesures de gestion des risques)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

Proposed: draft date not recorded.

Before the second chamber, dated 10 September 2025, as of 12 September 2026.

A sector security regimes rule binding public and private bodies.

As of 12 September 2026.

Where it has got to

The text described here is Texte adopté n° 78 (2024-2025), adopted by the Sénat in first reading, 12 March 2025, published 12 March 2025.

Locally, this stage is special committee review (commission spéciale) at the Assemblée nationale, concluded 10 September 2025, before debate in public session (séance publique).

The stage above is recorded at www.assemblee-nationale.fr.

More on this stage

The Assemblée nationale's special committee (commission spéciale) produced its own committee text, n° 1779-A0, deposited 10 September 2025, which may amend the Sénat's first-reading provisions described here; that committee text was not read, so its content is not described here. No floor debate at the Assemblée nationale, second reading, or promulgation had been recorded on the official dossier as of 12 September 2026.

What it requires

  • This duty does not yet bind: as of September 2026 the bill has passed the Sénat in first reading (12 March 2025) and the Assemblée nationale's special committee (commission spéciale) concluded its review on 10 September 2025, but the bill has not been debated on the Assemblée nationale floor, has not had a second reading, and has not been promulgated.
  • Once enacted, expect it to reach you where you are an essential or important entity under the bill's own designation articles (Articles 8 to 10), which name a provider of an online marketplace, an online search engine or a social-networking-services platform among the digital infrastructure and digital providers it covers expressly, transposing NIS2 Article 21; the wider sector, critical-infrastructure and public-administration classes it also reaches are a designation and sector class no activity in this vocabulary expresses, and are not raised here on that account.
  • Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or services: have your management body approve and oversee the security measures and receive cybersecurity training, protect your networks and systems including where you use a subcontractor, put in place tools and procedures to defend your networks and handle incidents, and ensure the resilience of your activities.
  • Expect the Agence nationale de la sécurité des systèmes d'information (ANSSI) to be the national competent authority, with a dedicated sanctions commission (commission des sanctions, Code de la défense Article L. 1332-15) able to impose an administrative fine of up to EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity, or up to EUR 7,000,000 or 1.4 percent for an important entity, whichever is higher; the State, local authorities and their public administrative bodies are excluded from these fines.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 37 of the text the Sénat adopted frames the penalty as an amende administrative (administrative fine) imposed by the sanctions commission; no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Article 37.I.1° of the text the Sénat adopted in first reading sets the maximum administrative fine for an essential entity's infringement at the greater of EUR 10,000,000 or 2 percent of worldwide annual turnover, and 37.I.2° sets an important entity's maximum at the greater of EUR 7,000,000 or 1.4 percent, mirroring NIS2 Article 34(4) and (5). Proposed and not yet in force; the Assemblée nationale's special committee text (n° 1779-A0, 10 September 2025) may have amended these figures and has not been independently confirmed here.

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Agence nationale de la sécurité des systèmes d'information (ANSSI), as the national network and information system security authority, which would notify a controlled entity of the grievances found against it and refer the matter to the commission des sanctions (sanctions commission) that Code de la défense Article L. 1332-15 establishes.

Settledness

As of
12 September 2026
Guidance link
https://cyber.gouv.fr/
Guidance body
Agence nationale de la sécurité des systèmes d'information (ANSSI)
Open questions
Will the Assemblée nationale's floor text, and any second Sénat reading, preserve the Article 14 and Article 37 provisions described here from the Sénat's first-reading text, given the special committee at the Assemblée nationale had already adopted its own committee text (n° 1779-A0) by 10 September 2025 that has not been independently confirmed?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 14 of the text the Sénat adopted in first reading would require an essential entity, an important entity, and a list of named public bodies to take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems they use for their activities or services, covering management-body approval and cybersecurity training, protection of networks and systems (including where a subcontractor is used), incident-handling tools and procedures, and the resilience of activities, transposing NIS2 Article 21.

Articles 8 to 10 designate the essential and important entities this reaches, naming a provider of an online marketplace, an online search engine or a social-networking-services platform among the digital infrastructure and digital providers it covers expressly, a wider list than the predecessor NIS1 transposition's three digital-service categories.

The instrument the corpus previously carried as France's NIS2 transposition, loi n° 2025-391 du 30 avril 2025, is a different, unrelated European Union law adaptation act that does not mention resilience, cybersecurity or the NIS directives; this bill, not that loi, is the actual transposition vehicle.

It passed the Sénat in first reading on 12 March 2025 and had its special committee (commission spéciale) review at the Assemblée nationale conclude on 10 September 2025, without a floor debate, a second reading, or a promulgation recorded since.

When LexLint raises it

  • operates_social_platform

Read the law

Texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025
not yet enacted

Back to the example  ·  Lint your app