Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

side the specific LPM provisions codified in the French Defence Code. The 2018 framework is now undergoing a comprehen - sive overhaul to transpose the NIS2 Directive. Indeed, the French government introduced the Draft Resil - ience Bill in late 2024, which will serve as the vehicle for implementing the NIS2 Directive into national law. The legislative process at the French Parliament is still ongoing. Once enacted, this bill will repeal the 2018 framework and significantly broaden its scope. Material scope: a two-tier system The NIS Directive, as transposed by the 2018 Security Law, provides for a separate classification of “Opera - tors of Essential Services” (OESs) and “Digital Service Providers” (DSPs). OESs are entities designated by the State in tradi - tional sectors (eg, energy, transport, banking) and subject to proactive, ex ante supervision. This stricter regime also applies to a few key digital infrastructure providers, namely Internet Exchange Points (IXPs), Domain Name System (DNS) providers, and Top-Level Domain (TLD) registries – a detail specified not in the 2018 Security Law itself but in its key implementing decree. In contrast, DSPs are an exhaustively defined category comprising only online marketplaces, online search engines and cloud computing services. These entities benefit from a much lighter, reactive ex post supervisory regime. Notably, this framework leaves significant gaps, as some providers in the digital sup - ply chain – such as those qualified as managed ser - vice providers (MSPs) and managed security service providers (MSSPs) under the NIS2 Directive, as well as data centre service providers – are not explicitly covered at all. The new NIS2 Directive framework fundamentally alters this landscape. All regulated organisations are now integrated into a two-tier system of “Essential Entities” (EEs) and “Important Entities” (IEs), which applies to a much larger number of critical and highly critical sectors. EEs, operating in the “highly critical sectors” listed in Annex I of the NIS2 Directive, include “Digital Infra -

structure”, which encompasses cloud computing and data centre providers alongside TLD registries and DNS providers. Furthermore, a new highly critical activity, information and communication technology (ICT) service management (business-to-business), has been created to directly bring MSPs and MSSPs into scope. EEs are subject to a robust, proactive supervisory regime. IEs are entities operating in “other critical sectors” listed in Annex II of the NIS2 Directive. This second tier includes a diverse range of activities such as postal and courier services, waste management, food production and distribution, and the manufacturing of certain critical goods. It also covers other digital providers, namely online marketplaces, online search engines, and social networking service platforms. IE entities are subject to a lighter, ex post supervisory regime. Size thresholds and exemptions The outgoing NIS1 framework operates on a dual sys - tem for determining its scope. • OESs are designated by the Prime Minister by order based on their criticality, irrespective of their size; there is no automatic exemption for smaller entities if they were deemed critical. • For DSPs, a size-cap rule is applied, but only as an exemption. The law explicitly excludes DSPs that are micro or small enterprises (employing fewer than 50 people and with a turnover/balance sheet below EUR10 million). The upcoming NIS2 framework’s reliance on a size- cap rule marks a significant departure from the logic of the 2018 Security Law. In most cases, entities employing fewer than 50 people and whose annu - al turnover and/or annual balance sheet total does not exceed EUR10 million are exempt from the NIS2 Directive. However, some entities in various sectors fall under the NIS2 Directive regardless of their size – for instance: • if they provide public electronic communications networks (if they are at least medium-sized); • if they are qualified trust service providers; • if they provide domain name services; or

125 CHAMBERS.COM

Powered by