Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2)
Article 17, texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025 (notification des incidents)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Proposed: draft date not recorded.
Before the second chamber, dated 10 September 2025, as of 12 September 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
Where it has got to
The text described here is Texte adopté n° 78 (2024-2025), adopted by the Sénat in first reading, 12 March 2025, published 12 March 2025.
Locally, this stage is special committee review (commission spéciale) at the Assemblée nationale, concluded 10 September 2025, before debate in public session (séance publique).
The stage above is recorded at www.assemblee-nationale.fr.
The Assemblée nationale's special committee (commission spéciale) produced its own committee text, n° 1779-A0, deposited 10 September 2025, which may amend the Sénat's first-reading provisions described here; that committee text was not read, so its content is not described here. No floor debate at the Assemblée nationale, second reading, or promulgation had been recorded on the official dossier as of 12 September 2026.
What it requires
- This duty does not yet bind: as of September 2026 the bill has passed the Sénat in first reading (12 March 2025) and the Assemblée nationale's special committee (commission spéciale) concluded its review on 10 September 2025, but the bill has not been debated on the Assemblée nationale floor, has not had a second reading, and has not been promulgated.
- Once enacted, this binds the same essential and important entities as this jurisdiction's companion risk-management row, for the reason given there.
- Notify ANSSI without undue delay of any incident with an important impact on the provision of your services (one causing or liable to cause a severe operational disruption or financial loss for you, or considerable material, physical or non-material damage to another person), on a graduated clock: an initial notification within 24 hours of becoming aware of it, an intermediate notification within 72 hours updating the initial one and giving an initial assessment of severity and impact, a report on ANSSI's request, and a final report within one month (or, for an incident still being handled, a progress report at one month followed by a final report within one month of resolution).
- Where you are a trust-service provider or one of the domain-name and registry services Articles 8(4) and 9(3) name, notify within 24 hours rather than 72 for the intermediate notification.
- Expect ANSSI to respond within 24 hours of your initial notification where possible, and expect the same penalty tiers as this jurisdiction's companion risk-management row.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 37 of the text the Sénat adopted frames the penalty as an amende administrative (administrative fine) imposed by the sanctions commission; no provision reviewed here makes the infringement itself a criminal offence.
Penalty structure
Article 37.I.1° of the text the Sénat adopted in first reading sets the maximum administrative fine for an essential entity's infringement at the greater of EUR 10,000,000 or 2 percent of worldwide annual turnover, and 37.I.2° sets an important entity's maximum at the greater of EUR 7,000,000 or 1.4 percent, mirroring NIS2 Article 34(4) and (5). Proposed and not yet in force; the Assemblée nationale's special committee text (n° 1779-A0, 10 September 2025) may have amended these figures and has not been independently confirmed here.
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Agence nationale de la sécurité des systèmes d'information (ANSSI), as the national network and information system security authority, which would notify a controlled entity of the grievances found against it and refer the matter to the commission des sanctions (sanctions commission) that Code de la défense Article L. 1332-15 establishes.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://cyber.gouv.fr/
- Guidance body
- Agence nationale de la sécurité des systèmes d'information (ANSSI)
- Open questions
- Will the Assemblée nationale's floor text, and any second Sénat reading, preserve the Article 14 and Article 37 provisions described here from the Sénat's first-reading text, given the special committee at the Assemblée nationale had already adopted its own committee text (n° 1779-A0) by 10 September 2025 that has not been independently confirmed?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 17 of the text the Sénat adopted in first reading would require the same essential and important entities Article 14 covers to notify ANSSI without undue delay of any incident with an important impact on the provision of their services, on a graduated clock: an initial notification within 24 hours of becoming aware of it, an intermediate notification within 72 hours updating the initial one and giving an initial assessment of severity and impact, a report on ANSSI's request, and a final report within one month (or, for an incident still being handled, a progress report at one month followed by a final report within one month of resolution), transposing NIS2 Article 23.
A trust-service provider and certain domain-name and registry services named in Articles 8(4) and 9(3) notify within 24 hours rather than 72 for the intermediate notification. ANSSI in turn responds within 24 hours of the initial notification where possible.
When LexLint raises it
operates_social_platform
Read the law
Texte adopté n° 78 (2024-2025), Sénat, 12 mars 2025
not yet enacted