NIS 2 in 2026: how to prepare for the Resilience bill ?

The NIS 2 directive came into force in January 2023, but France is lagging in its transposition with the Resilience bill, which merges the cyber (NIS 2) and physical (REC) components. Meanwhile, countries like Belgium are already applying their national framework (CyFun), imposing contractual requirements on French suppliers. Given this gap, a wait-and-see approach is a strategic risk: ANSSI’s ReCyF framework allows you to anticipate the 20 expected security objectives today, while convergence with GDPR and the AI Act encourages organizations to centralize risk management rather than handling it in silos.

By
Anne-Angélique de Tourtier
1
Min
Share this article
NIS 2 Resilience

The European NIS 2 directive officially entered into force on January 16, 2023. Its initial schedule aimed for implementation across all member states by October 18, 2024. However, in France, the legislative process has faced significant political and technical delays, leaving the country behind in its national transposition.

At Adequacy, as we support organizations daily in managing their governance workflows, we closely observe the operational challenges caused by this gap. While the French timeline is being adjusted, our European neighbors are moving forward. Belgium transposed the text as early as May 2024, making its companies immediately operational through the CyberFundamentals (CyFun) framework managed by the Centre for Cybersecurity Belgium (CCB).

For French management boards, regulatory wait-and-see is a strategic mistake. The requirements of your cross-border business partners are already active, and future French legislation will apply retroactively to many aspects of corporate governance. Where does the French legal framework stand, and how can you use existing European models to structure your action plan?

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The Resilience bill: what the future French law will contain

The French delay is due to the ambition of the chosen legislative vehicle: the bill regarding the resilience of critical infrastructure and the strengthening of cybersecurity. This text does not merely translate the NIS 2 directive (concerning measures for a high common level of cybersecurity across the Union); it merges this obligation with the European REC directive (concerning the resilience of critical entities).

The goal of this single law is to create a comprehensive shield for strategic companies. In practical terms, the French bill will be structured around two pillars:

  • The cyber component (NIS 2) : overseen by ANSSI (the French national cybersecurity authority), it mandates strict requirements for network and information system security, vulnerability management, and incident reporting.
  • The physical component (CER) : it requires the protection of physical infrastructure against climate risks, sabotage, or major supply chain disruptions.

Waiting for the final vote on this bill to begin your compliance projects is a risky strategy. The final text will inevitably align with the minimum European requirements, which are already set in stone.

Essential and important entities: who is affected by NIS 2?

The European directive introduces an automatic compliance framework based on company size, revenue, and the criticality of the business sector.

There are two levels of obligations and oversight:

  • Essential entities (EE) : large companies (more than 250 employees, or over €50 million in revenue, or a balance sheet total exceeding €43 million) operating in highly critical sectors (energy, transport, health, banking).
  • Important entities (IE) : medium and large companies (more than 50 employees, or over €10 million in revenue or balance sheet) operating in other critical sectors (waste management, postal services, manufacturing, digital service providers).

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The immediate impact on supply chain security

A key focus of NIS 2 is the requirement for entities to manage risks within their supply chain. Belgian companies, for instance, which have been subject to the CyFun framework since 2024, are already imposing strict cybersecurity contractual clauses on their business partners. If you are a subcontractor or a direct supplier, your European clients will demand compliance guarantees without waiting for the French law to be enacted.

Mapping and assessing third parties are common obligations under both GDPR and supply chain security. Using a structured GDPR compliance platform allows you to audit your subcontractors and centralize partner management starting today.

Anticipation strategy: the ANSSI ReCyF framework

To address legislative uncertainty and provide guidance to organizations, ANSSI has published the Référentiel Cyber France (ReCyF). This technical document serves as an official preparation guide for France and details the concrete measures to be implemented.

The ReCyF framework, much like the Belgian CyberFundamentals model, structures compliance around 20 security objectives organized into key pillars:

  • Governance and management : mandatory cybersecurity training for members of management bodies, and their direct involvement in the approval and oversight of risk management measures
  • Network and information system security : implementation of fundamental IT hygiene, including cryptography and sensitive data encryption, physical and logical access management, and secure network architecture
  • Defense and detection : continuous network monitoring, incident handling, and event log management
  • Business continuity and crisis management : drafting, updating, and testing business continuity plans (BCP) and disaster recovery plans (DRP) in the face of ransomware risks, combined with a multi-stage incident notification schedule (including an early warning within 24 hours of becoming aware of a significant incident)

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

NIS 2 sanctions: tightening the legal framework and accountability

The NIS 2 directive's sanction regime marks a paradigm shift by aligning with the severity of the GDPR.

  • Administrative fines : non-compliance can lead to administrative fines of up to 10 million euros or 2% of total annual global turnover for essential entities (7 million euros or 1.4% for important entities)
  • Liability of management members : this is the critical point of vigilance for legal directors. Management bodies can be held liable for failures to fulfill their obligations to implement and oversee security measures. French authorities will also be able to temporarily suspend management functions for legal representatives or individuals exercising management responsibilities at the executive level

The responsibility of executive committees is growing as technology regulations become more complex. Discover how to manage your AI Act project and coordinate your various obligations to avoid overloading your legal and technical teams.

Regulatory convergence: centralizing to streamline efforts

The proliferation of European regulations (GDPR for personal data, the AI Act for artificial intelligence, and NIS 2 for network security) exposes companies to the risk of operational fragmentation. Treating these texts in technical or legal silos creates costly duplication and organizational fatigue.

The consensus within the governance ecosystem is that compliance must be approached through unified risk management:

  • A security incident (NIS 2 scope) frequently leads to a personal data breach (GDPR scope), requiring dual notification to both the CNIL and ANSSI.
  • A high-risk artificial intelligence system must meet audit criteria (AI Act) while relying on highly secure network infrastructure (NIS 2).

By centralizing these processes, companies can pool asset inventories, harmonize risk assessments, and reuse existing governance frameworks.

To transform these regulatory obligations into a single management lever, centralization on a platform like Adequacy allows DPOs, CISOs, and General Counsels to collaborate within a shared workspace and optimize the organization's overall risk management.

FAQ - NIS 2, Resilience Bill, and anticipation

What is the difference between the entry into force and the entry into application of NIS 2?

The directive entered into force at the European level in January 2023, establishing the general framework. Its actual entry into application depends on the passing of national transposition legislation (the Resilience bill in France). However, French companies with business relationships in European countries that are already compliant are already feeling the impact of these obligations through contractual ripple effects.

What is the Belgian CyberFundamentals (CyFun) model and why should you use it as a guide?

It is the operational methodological framework deployed by Belgium upon the directive's transposition in May 2024. It offers progressive levels of cyber maturity. In the absence of a final French law, it serves, alongside ANSSI's ReCyF framework, as an excellent technical compass for structuring your roadmap.

How do incident notification requirements overlap between NIS 2 and GDPR?

In the event of a cyberattack that compromises personal data, an organization must take two distinct actions: send an initial early warning to ANSSI within 24 hours (a NIS 2 requirement) and report the data breach to the CNIL within 72 hours (a GDPR requirement).

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The latest news

They have trusted us for years

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.