Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements
Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 10 May 2018.
A sector security regimes rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds a fournisseur de service numérique (digital service provider) operating an online marketplace, an online search engine or a cloud computing service above the fifty-employee, EUR 10 million turnover threshold, and an opérateur de services essentiels (operator of essential services) the Premier ministre designates by sector; the operator-of-essential-services sector and designation class is a role no activity in this vocabulary expresses, so it is not separately flagged here.
- Identify the risks that threaten the security of the networks and information systems you use to provide your services in the European Union, and take the necessary and proportionate technical and organisational measures to manage those risks, prevent an incident from compromising your networks and systems, and minimise its impact, so as to guarantee the continuity of your services.
- Cover each of: the security of your systems and installations; incident management; business-continuity management; monitoring, audit and control; and compliance with international standards.
- Where you are instead designated as an operator of essential services, apply the security rules the Premier ministre sets under Article 6 at your own expense, covering governance, protection, defence and resilience of your networks and systems.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 9 (operator of essential services) and Article 15 (digital service provider) each punish a director's (dirigeant's) own non-compliance with the security-measures duty, after a formal notice (mise en demeure) under Article 8 or 14 has gone unheeded, as a criminal fine («est puni de ... d'amende») rather than an administrative penalty on the entity.
Penalty structure
Article 9 punishes a director of a designated operator of essential services who fails to comply with the Article 6 security rules, after the mise en demeure deadline under Article 8 has passed, by a fine of EUR 100,000. Article 15 punishes the equivalent failure by a director of a digital service provider, under Article 12 and after the Article 14 mise en demeure deadline, by a fine of EUR 75,000. These are personal criminal fines on a director, not a turnover-based penalty on the entity.
- Rule
- Fixed only
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 100,000
Who enforces it
Enforcement body
The Premier ministre (Prime Minister), acting through the Agence nationale de la sécurité des systèmes d'information (ANSSI), the national network and information system security authority under Code de la défense Article L. 2321-1, which the implementing décret names as the authority conducting or commissioning the compliance controls.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://cyber.gouv.fr/
- Guidance body
- Agence nationale de la sécurité des systèmes d'information (ANSSI)
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Chapitre II of Titre Ier binds an opérateur de services essentiels (operator of essential services, OSE), public or private, designated by the Premier ministre because it offers a service essential to the functioning of society or the economy whose continuity could be gravely affected by an incident touching the network or information systems it needs to provide that service (Article 5).
Article 6 has the Premier ministre set the applicable security rules, covering governance, protection, defence and resilience of the operator's networks and systems, which the operator applies at its own expense.
Chapitre III imposes the equivalent duty on a fournisseur de service numérique (digital service provider, FSN) operating an online marketplace, an online search engine or a cloud computing service (Article 10), excluding a business with fewer than fifty employees and no more than EUR 10 million in annual turnover (Article 11), and requiring it to identify risks and take technical and organisational measures across systems security, incident management, business continuity, monitoring and audit, and compliance with international standards (Article 12), transposing the original NIS Directive (Directive (EU) 2016/1148).
Titre Ier entered into force from a date fixed by décret en Conseil d'Etat, at the latest 10 May 2018 (Article 25); Décret n° 2018-384 du 23 mai 2018 sets out the security-rule content, the OSE-designation procedure and ANSSI's role implementing this chapter, and Article 25 separately gave the designation of the first OSEs until 9 November 2018.
When LexLint raises it
operates_social_platform
Read the law
Journal officiel de la République française n°0048 du 27 février 2018, Loi n° 2018-133