No, quite the opposite. The Resilience Bill, which transposes the European NIS 2 directive into French law, is due to be debated in the National Assembly in July 2026, with the act expected to be signed into law over the summer. ANSSI, the French national cybersecurity agency, has already published its operational roadmap, the ReCyF, and is urging the 15,000 or so entities concerned not to wait for the vote before starting work on compliance. For an SMB, a mid-sized company or a public authority, the coming months are a window to use, not a waiting period.
Where French transposition stands
NIS 2 should have been transposed by every member state before October 2024. France fell behind: the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, which in fact transposes three European texts (CER, NIS 2 and DORA), was passed by the Senate in March 2025, then examined by a special committee in the National Assembly in September 2025. The debate in the chamber is now announced for July 2026, as part of an extraordinary session, and the Commission supérieure du numérique et des postes is pressing parliament to see it through without delay.
This legislative delay should not create a false impression of respite. Once the act is signed into law, the implementing decrees will follow quickly, and the obligations will apply to organisations that, in many cases, are starting from a long way back. Those that have done the work in advance will absorb the deadline calmly. The others will have to do everything at once, against the clock, in a cybersecurity market that is already heavily in demand.
Are you concerned? Probably more than you think
This is the major change of scale in NIS 2: France moves from around 500 regulated entities under NIS 1 to somewhere between 10,000 and 15,000, split into two categories (essential entities and important entities) across 18 sectors. In practice, a great many SMBs and mid-sized companies in manufacturing, food processing, transport, healthcare, digital services and waste management fall within scope without yet being aware of it.
Local and regional authorities are equally in the front line: France has chosen to include around 1,500 authorities, groupings and supervised bodies, with the threshold lowered to 30,000 inhabitants. For a town or an inter-municipal authority in the Var or the Bouches-du-Rhône, the question is no longer whether cybersecurity is a subject, but how to structure the work with IT teams that are often small.
A useful first step: check where you stand with the online test MonEspaceNIS2, provided by ANSSI. A few minutes are enough to find out whether your organisation falls under the rules, and in which category.
ReCyF: the roadmap ANSSI has already published
Since 17 March 2026, ANSSI has been publishing the Référentiel Cyber Français (ReCyF), as a working document pending the vote. It is the piece that was missing: an operational framework that turns the NIS 2 requirements into 20 concrete security objectives. Objectives 1 to 15 apply to every regulated entity; objectives 16 to 20 are reserved for essential entities, which are held to a higher level of protection.
Two points deserve the attention of directors and IT managers. First, proportionality: the effort expected is matched to the maturity and the means of each organisation, which puts the exercise within reach of an SMB as much as of a large city. Second, the content itself: it sets out the fundamentals our teams deploy day to day, governance and risk analysis, strong authentication, network segmentation, monitoring and logging, tested backups, incident management. In other words, preparing for NIS 2 is not about ticking administrative boxes, it is about raising the real security level of your information system.
Where to start, in practice
There is no need to wait for the decree to start the work that takes time. This is the order we recommend to our clients across the Provence-Alpes-Côte d’Azur region:
- Map your information system: you only protect well what you know about. An inventory of equipment, critical applications, remote access and third-party providers.
- Appoint someone to own the work and involve the leadership: NIS 2 makes cybersecurity a responsibility of the governing body, not only of the IT department.
- Close the gaps with the best return first: strong authentication on sensitive accounts, backups that follow the 3-2-1 rule with tested restores, updates on exposed equipment. We go into detail in our article on the 5 priority measures.
- Segment the network: partitioning, which we implement on Alcatel-Lucent OmniSwitch switches and Stormshield firewalls (French technology, certified by ANSSI), limits how far an attack can spread and answers several ReCyF objectives directly. Industrial sites have a dedicated range, such as the new SNi50.
- Put detection and monitoring in place: a supervised EDR, such as the Trend Micro solutions our teams deploy and watch, plus centralised logging, so that you can detect an incident and report it within the deadlines the law will set.
This work naturally spreads over several months. That is precisely why starting now, before the act is signed, makes the difference between compliance you control and a race against the clock.
Turning an obligation into an opportunity
NIS 2 arrives in a context where micro-businesses and SMBs already account for most of the attacks ANSSI handles. The directive only makes mandatory what the threat level already justified: for most organisations, the real benefit is not avoiding a penalty, it is not being shut down for three weeks after a ransomware attack.
IT1 Connect works with SMBs, mid-sized companies and public authorities across the Provence-Alpes-Côte d’Azur region on the whole exercise: a review of your exposure, gaps prioritised against the ReCyF, the right hardware deployed, and monitoring and managed services over the long term. If you want to know where you stand, or simply to check whether your organisation falls within scope, an engineer who knows the constraints of your area is on +33 4 22 14 04 63.
NIS 2 compliance
- A review of your exposure and of your gaps against the ReCyF
- A prioritised roadmap, matched to your size and your means
- Certified hardware deployed and configured: Stormshield, OmniSwitch, Trend Micro
- The monitoring and logging needed to detect and report incidents
- One point of contact who already knows your environment
