Parliament has never been your CISO
On 6 October 2026, the French National Assembly pulled from its agenda the bill that is meant to transpose NIS2, two years after the deadline set by Brussels. Within the hour, professional networks were calling it a disaster for small and medium businesses, abandoned by politicians who are not doing their job. Not one of the measures that law will require needs it in order to be applied on Monday morning.

On Tuesday 6 October, the conference of presidents of the French National Assembly struck from the agenda of 7 and 9 October the bill on the resilience of critical infrastructure and the strengthening of cybersecurity. The official reason fits on one line: the examination of the text on sexist and sexual violence is overrunning the planned timetable. The rapporteur, Éric Bothorel, said he hoped it would be rescheduled within a fortnight or three weeks. No date has been settled, and the next conference of presidents meets on 13 October.
That same evening, my LinkedIn feed sounded like a chorus. NIS2 delayed again, a disaster for SMEs, businesses left in limbo by elected officials who are not doing their job. I read those messages thinking of the directors I work with, and I looked for what the 6 October delay prevented them from doing. I found nothing.
The 6 October delay moves a sanction date
Once promulgated, the law will create three things nothing else creates: the obligation to register with ANSSI, the obligation to notify significant incidents, and inspection powers backed by sanctions that can reach 10 million euros or 2 % of worldwide turnover for an essential entity, 7 million or 1.4 % for an important entity. The press repeats the figure of around 15,000 entities, in eighteen sectors against six under NIS1, including close to 1,500 local authorities. I believe it is well below reality. Article 21 obliges every entity to manage the security of its supply chain, and the requirements will cascade down onto thousands of subcontractors, service providers and software vendors who will appear in no ANSSI register but will receive their clients' questionnaires. It is a considerable change of scale, and it is normal to await its effective date with impatience.
It helps to know which date is being discussed. In October 2024, at the Assises de la sécurité in Monaco, Vincent Strubel, director general of ANSSI, said: « We will give ourselves at least three years before requiring full compliance with the framework. » Do the arithmetic with a vote in November, a shuttle between the chambers, implementing decrees in the spring. The first possible sanction for missing security measures falls somewhere between 2029 and 2030. The 6 October delay moves by a few weeks a horizon that was already three years away.
What the comments are calling a disaster is therefore the slipping of a date from which you can be reproached for not having acted. Ransomware groups, for their part, do not consult the agenda of the conference of presidents. Your exposure began the day you plugged your first server into the internet, and it did not move a millimetre last Tuesday.
I criticised the ReCyF, and it has been on the table since 17 March
I do not like the ReCyF. I wrote what I thought of that framework in an earlier article, and I take none of it back. But the criticism I make of it assumes it exists, that it can be read, compared, contested measure by measure. Which has been the case since 17 March 2026, the date of its version 2.5.
ANSSI presents it as a working document until transposition, and as the framework referred to in Article 14 of the bill. It is not mandatory: an entity can meet the security objectives by other means. One that chooses to apply it will, on the other hand, be able to rely on it during an inspection. Vincent Strubel has publicly asked entities not to wait for the law before getting to work, and ANSSI's official page on NIS2 invites future essential and important entities to engage with it straight away. The agency even took the trouble to publish a mapping tool between the ReCyF and existing frameworks, so that nobody has to start from scratch.
An imperfect framework still describes the destination. You know, give or take some adjustments, what ANSSI will come and look at. And if you have doubts about the ReCyF, the directive itself has been published in the Official Journal of the Union since 27 December 2022. Its Article 21 lists ten families of measures: risk analysis and security policy, incident handling, business continuity with backups and crisis management, supply chain security, security in acquisition and maintenance of systems, assessment of the effectiveness of measures, cyber hygiene and training, cryptography, human resources security and access control, multifactor authentication. The list has been public for nearly four years. The uncertainty people complain about concerns the article of law that will set the sanction. What will have to have been done is known, published, translated into every language of the Union.
Why would you need a vote to turn on multifactor authentication?
Set the ReCyF aside, since it irritates. ANSSI's cyber hygiene guide and its 42 measures dates from 2017. The ISO/IEC 27001 standard in its current version dates from October 2022, and its first edition from 2005. NIST published version 2.0 of its Cybersecurity Framework in February 2024. The CIS Controls are freely available. With CyFun, the CyberFundamentals of the Centre for Cybersecurity Belgium, Belgium has built a framework calibrated on NIS2 and graded into assurance levels, Basic, Important and Essential, which the Belgian regulator recognises as a route to compliance. It is public, free, available in French, and a French SME can open it tomorrow morning to find out where it stands. The American defence industry works with CMMC. There are dozens of frameworks and collections of good practice, and they all converge on the same foundation. Asset inventory, management of accounts and privileged access, strong authentication, patching, isolated and tested backups, logging, incident response, supplier oversight.
None of those steps requires a voted text. Turning on multifactor authentication for your remote access takes an afternoon. Testing a backup restore takes a day, and often reveals that the backup existed only in the provider's spreadsheet. Running a crisis exercise with the executive committee takes a morning. The choice of framework is, in fact, the least important question in the whole file, and it is often the one people spend the most time on, because it gives the impression of working without committing to anything.
An SME that tells me it is waiting for the law to know what to do is really telling me it is waiting for someone to set it a deadline. That is an understandable request, and it is an admission: the organisation has not set for itself the level of risk it accepts.
Who answers for an SME's cybersecurity, if not its director?
The cruellest irony of this debate sits in Article 20 of the directive. It requires management bodies to approve risk management measures, to oversee their implementation, to follow training, and it provides that they may be held liable for failures. It is the article that makes the director the first person responsible for their company's cybersecurity, and it is precisely the one people await from the legislator as though awaiting permission.
For essential entities, Article 32 goes as far as allowing a temporary ban on holding management positions. The law will therefore sanction a responsibility that already exists, from the moment you run a business whose activity rests on information systems, which is to say every business. A director's responsibility that only applies once the law makes it enforceable is not one. The business owner who manages stock, cash flow and contracts without waiting for a decree knows perfectly well how to weigh a risk. They do it every day. What they refuse to do for cybersecurity, they do without difficulty for fire, fraud or the loss of a major client, because those risks are ones they have made their own.
The market, for that matter, has not waited for Parliament. The DORA regulation has applied directly since 17 January 2025, without transposition, and banks and insurers pass its requirements on to their IT providers by contract, SMEs included. Large buyers subject to NIS2 in other member states, where the law is in force, do the same with their supply chain. Cyber insurers make their cover conditional on multifactor authentication and offline backups. For many SMEs, the real effective date of NIS2 is that of the next client questionnaire, and it has often already passed.
What Belgium taught me about the companies that were waiting for the law
Belgium transposed NIS2 through a law of 26 April 2024, in force since 18 October 2024. The Centre for Cybersecurity Belgium set precise deadlines: by 18 April 2026, essential entities had to hold or be in the process of obtaining a CyFun verification at Basic or Important level, or submit the scope and statement of applicability of their ISO 27001 programme, with compliance at Essential level to be demonstrated by 18 April 2027. The regulator speaks of a binding obligation, backed by administrative measures and fines. In late August 2026, it nonetheless published a communication addressed to entities that will not be ready: those that do not reach the Essential level by 18 April 2027 may submit a remediation plan, provided they demonstrate the Important level, with an Essential target of 18 April 2028. The CCB specifies that this communication changes neither the obligations nor the deadlines set by the law. In practice, the last step slides by a year, and that is an admission: even with a law in force, the calendar ends up being negotiated with the latecomers.
I have overseen some fifty NIS2 engagements there, which lets you observe what happens once the law finally exists. It changed almost nothing. We are in October 2026, a few weeks from 2027, the first Belgian deadline passed six months ago, and I still see organisations only just starting their NIS2 roadmap. The text, voted, published and accompanied by a calendar, did not move by a month the point at which they decided to get going.
The organisations that had waited for the text to move produced, when it arrived, what you produce under deadline pressure: policies, registers, matrices, a presentable file. The law gave them a date and a format. It gave them neither maturity, nor the ability to restore a system in forty-eight hours, nor an executive committee capable of taking a decision in the middle of the night during an incident. I have called that phenomenon the illusion of compliance: the document stands in for resilience until the day an attacker checks.
Those that were ready were ready for reasons that had nothing to do with a fine. A competitor encrypted by ransomware, a client who had demanded an audit, a director who had worked out that three weeks of stopped production cost more than the entire security programme. The decision had been taken before the law, by someone with the authority to take it.
There is worse than the latecomers. With several organisations, under NIS2 as under DORA, I decided personally to stop working, for a simple reason: they did not even want the minimum. The legal framework sets a floor, the bare minimum, and the text never claimed to do more. Some management teams refused that floor with a law in force, a known deadline and a regulator that had published its calendar. A transposition attaches a sanction to a responsibility that existed before it, and the Belgian experience shows that the sanction itself is not enough for those who have decided to do nothing.
Compliance produces documentary proof at a date set by a third party. Resilience produces an operational state that depends on no calendar. A company waiting for the Assembly's vote to act is preparing its future compliance, and nothing else. It will find itself, when the day comes, three years behind the threat and right on time for the inspection.
« I do not have the budget »: what if the problem were you?
The most serious objection comes from CISOs themselves, and I have heard it in dozens of committees. No legal obligation, no budget. The security plan loses the arbitration against the commercial project, the hire, the hardware refresh, and the law would have served as leverage. Every delay deprives whoever was counting on it.
If you did not get your budget, the problem may well be you, and not necessarily your management. An executive committee pursues, in the end, the same objectives of success for the business and for cybersecurity: sell, deliver, meet commitments, last. Cybersecurity exists to serve that activity. When I coach CISOs, I very often find the opposite posture, that of a security lead waiting for the company to put itself at the service of their roadmap. They present a list of controls and an invoice, facing a sales director who presents revenue. They lose, and they conclude that they need a law.
A plan that speaks in exposed revenue, in lost contracts, in days of stopped production and in clauses that clients already demand defends itself without any text of law. A plan that speaks in measures and frameworks needs an external constraint in order to exist, which says a great deal about its ability to convince. The NIS2 fine is capped at 2 % of worldwide turnover. A stopped production line, published customer data, an order book that moves to a competitor have no cap at all, and that is the language in which the arbitration is won.
Management is not off the hook for all that. A management team that only funds its backups under threat of a fine has delegated its risk appetite to Parliament. I have argued several times that compliance is the entry ticket, and that the best are those who tick the boxes faster, more cheaply and with less pain. An SME starting today, three years ahead of the sanction, will have that luxury. One that waits for the vote will pay for the same compliance at emergency prices, with saturated consultancies and teams discovering the subject at the same time as the deadline.
The state has its share, and it does not cover yours
None of the above excuses the political class. The government tabled the text in the Senate on 15 October 2024, two days before the transposition deadline, under the accelerated procedure. The Senate adopted it on 12 March 2025. The Assembly's special committee adopted it in September 2025. Since then, nothing in the chamber, until this latest delay. On 8 July 2026, the European Commission referred France, Ireland, Spain and the Netherlands to the Court of Justice of the Union, asking for a lump sum and daily penalty payments until full transposition. A letter of formal notice had been sent on 28 November 2024, a reasoned opinion on 7 May 2025. The file has had two years to find a slot.
The sticking point, for that matter, has nothing to do with SMEs. It is called Article 16 bis, introduced in the Senate by Olivier Cadic, which prohibits requiring encryption providers to build in mechanisms that deliberately weaken security, of the master key kind. The DGSI wants it removed. The security timetable of 15,000 entities hangs on a quarrel over backdoors in messaging apps, and that is a failure of public governance I have no wish to play down.
Real uncertainty also hangs over the scope: members of parliament added software vendors in committee, and a company in that sector does not yet know, legally, whether it will be in scope. The MonEspaceNIS2 simulator gives an indicative answer, and that uncertainty concerns the question of who will be inspected. It says nothing about what has to be done in order not to be compromised.
Two failures can coexist. The state's delays the law. That of a director who has undertaken nothing in four years of a published directive belongs to them alone, and no agenda of the Assembly will take it away.
October, budget season: your 2027 roadmap awaits no vote
The law will change nothing for three years, and that is exactly why the moment matters. We are in October. In most companies, the 2027 budgets are being decided now, well before the Assembly has found a slot. Do not wait for the NIS2 law to implement NIS2: the roadmap you are planning in these very weeks is the one you will be inspected on in 2029 or 2030.
Between now and the next conference of presidents, on 13 October, an SME's management can have spent ten minutes on the « Am I concerned? » simulator on MonEspaceNIS2 and learned, indicatively, whether it falls in scope as an essential or important entity. If the answer is no, let it look at its client list: those in scope will pass their requirements on to it anyway. It can also have named someone responsible for the subject, with a written mandate, rather than a willing colleague who handles it between two emergencies.
Before the budget vote, it can have taken the framework it already applies, ISO 27001, CyFun, the hygiene guide or nothing at all, and matched it against the ReCyF using ANSSI's mapping tool, to obtain a prioritised and costed list of gaps. That is the document that should reach the budget committee, translated into risks to the business, with a 2027 line identified. The measures that cost almost nothing do not need to wait: multifactor authentication on all remote access and all administration accounts, a full restore of a critical system from an isolated backup, with a written record stating how long it actually took.
In the first quarter of 2027, its executive committee can have played a crisis exercise on a ransomware scenario, and recorded in minutes the approval of the risk management measures, exactly as Article 20 will require. The day the law is promulgated, that document will already exist, dated, signed, predating any obligation. It is the best proof of governance an inspector could read.
None of that depends on the Official Journal.
On 13 October, the conference of presidents may once again consider the place of the Resilience bill in the Assembly's agenda. Between now and then, thousands of executive committees will have begun deciding their 2027 budget, and not one of them needs a slot on the agenda to decide what it protects.
Further reading
- ReCyF, backdoors and USB sticks: France in cybersecurity, between clarity and anachronism
- NIS2 in 2026: France falls behind
- Cybersecurity must not become an election issue
- PECB Insights, « What the 50 Missions I Oversaw Taught Me About Europe's Biggest Cyber Bet », The Expert column
- etrecyber.fr: the practical steps, without the jargon
Sources
- French National Assembly, conference of presidents of 6 October 2026, withdrawal of the bill on the resilience of critical infrastructure and the strengthening of cybersecurity from the sittings of 7 and 9 October; reported by Next, « Caramba, encore raté : la transposition de NIS2 est de nouveau repoussée », updated 6 October 2026.
- Clubic, « La loi NIS2 encore reportée, nouveau camouflet pour la cybersécurité en France », 6 October 2026, for the scope (around 15,000 entities, 18 sectors, close to 1,500 local authorities) and Article 16 bis.
- Leto, « Transposition NIS 2 : le projet de loi Résilience de nouveau reporté », October 2026, for the parliamentary timeline (tabled 15 October 2024, adopted by the Senate 12 March 2025, special committee text of 10 September 2025).
- European Commission, Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose rules, statement of 8 July 2026 (infringement procedure: letter of formal notice 28 November 2024, reasoned opinion 7 May 2025).
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022, known as NIS2, OJEU L 333 of 27 December 2022, Articles 20, 21, 32 and 34.
- ANSSI, ReCyF, Référentiel Cyber France, version 2.5 of 17 March 2026, and the page La directive NIS 2 on cyber.gouv.fr, with the framework mapping tool and the MonEspaceNIS2 service; Next, « NIS 2 : l'ANSSI publie son ReCyF, la CSNP s'impatiente et le fait savoir », 19 March 2026.
- Banque des Territoires (Localtis), « L'Anssi se donne trois ans pour la pleine application de la directive NIS 2 », 14 October 2024, statement by Vincent Strubel at the Assises de la sécurité in Monaco.
- Regulation (EU) 2022/2554, known as DORA, applicable since 17 January 2025.
- Belgian law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security, in force since 18 October 2024; Centre for Cybersecurity Belgium, NIS2: 18 April 2026 deadline, what essential entities must have in place, inspection service communication À l'attention des entités essentielles NIS2 (August 2026) on remediation plans with an 18 April 2028 deadline, and the CyberFundamentals (CyFun) framework.
- ANSSI, Guide d'hygiène informatique, 42 measures, 2017; ISO/IEC 27001:2022; NIST, Cybersecurity Framework 2.0, February 2024.
Frequently asked questions
Is my SME covered by NIS2?
NIS2 in principle covers medium-sized and large companies, meaning from 50 employees or 10 million euros of annual turnover, in the eighteen sectors listed in the annex to the directive. Some entities are covered whatever their size. The « Am I concerned? » simulator on ANSSI's MonEspaceNIS2 service gives a first answer, indicative as long as the law is not promulgated, in particular for the software vendors added in committee.
When will the NIS2 law apply in France?
No date is set. After the sitting at the Assembly, the text will have to be reconciled with the Senate version, then completed by implementing decrees. ANSSI announced in October 2024 at least three years before requiring full compliance, which pushes the first sanctions for missing measures towards the end of the decade.
Is the ReCyF mandatory?
No. ANSSI presents it as a working document until transposition. An entity can meet the NIS2 security objectives by other means, but one that applies the ReCyF will be able to rely on it during an inspection. ANSSI provides a mapping tool to other frameworks.
If I am ISO 27001 certified, am I NIS2 compliant?
Not automatically. The overlap is very wide and a certified organisation starts with a considerable head start, but NIS2 adds obligations of its own, such as registering with ANSSI, notifying significant incidents within set deadlines and the explicit responsibility of management bodies. ANSSI's mapping tool makes it possible to identify the remaining gaps.
Can a French SME use the Belgian CyFun framework?
Yes. CyFun is published free of charge by the Centre for Cybersecurity Belgium, in several languages including French, and graded into assurance levels that let a small organisation start with the basics. It has no regulatory standing in France, but its measures overlap broadly with the NIS2 objectives, and ANSSI's mapping tool allows any existing framework to be matched against the ReCyF.
Is the delay not a real problem after all?
For the state, yes: France has been before the Court of Justice of the Union since 8 July 2026, with a request for a lump sum and penalty payments. For legal certainty too, in particular on the exact scope of the entities covered. The security measures themselves have been known since the directive was published in December 2022 and depend on no vote, and the delay only pushes back the date from which their absence can be sanctioned.
What sanctions does NIS2 provide for?
The directive provides for fines of up to 10 million euros or 2 % of annual worldwide turnover for essential entities, and 7 million euros or 1.4 % for important entities, whichever is higher. Directors can also be held liable for failures to meet risk management obligations.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
