Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

• if they have been specifically designated by a member state due to their critical role. National specificities of the Draft Resilience Bill compared with the NIS2 Directive While the Draft Resilience Bill faithfully transposes the NIS2 Directive’s overall scope, its most significant departure lies in its treatment of public administra - tion entities. Indeed, the NIS2 Directive leaves the inclusion of regional and local bodies to a member state’s discretionary, risk-based assessment. There - fore, under the Draft Resilience Bill, the EE category includes regions, departments and municipalities with a population over 30,000, as well as major metropoli - tan and urban communities. Conversely, the IE cat - egory covers other local bodies, notably communities of municipalities ( communautés de communes ). To ensure a clear separation of powers, the latest version of the Draft Resilience Bill establishes a new and independent sanctions committee. Instituted under the Prime Minister, this committee will have the sole authority to impose penalties, upon referral from ANSSI after an investigation has revealed a persistent infringement. Operators of Vital Importance (OIVs) The notion of OIVs was introduced by Law No 2013‑1168 of 18 December 2013 on military program - ming for the years 2014–2019, which notably required operators of vital infrastructures to implement specific measures to strengthen their protection against cyber- risks. OIVs are defined in the French Defence Code as public or private operators running establishments or using facilities and structures whose unavailability could sig - nificantly reduce the nation’s war or economic poten - tial, security or survivability. While the specific list of entities designated as OIVs is classified for national security reasons, the over - arching “sectors of activities of vital importance” are publicly defined and include (for instance) energy, transport, banking, financial market infrastructures, health and digital infrastructure.

The Draft Resilience Bill plans to replace and rewrite the entire chapter of the French Defence Code relative to OIVs, redefining its core concepts to align with the new NIS2 Directive framework. It provides that an OIV is automatically classified as an EE if its activities also qualify as an “essential service” under the framework of the CER Directive. For completeness, it should be noted that the Draft Resilience Bill also transposes the CER Directive. This directive strengthens the physical resilience of critical entities against a wide range of threats. These obliga - tions are not detailed further here, as they concern physical – rather than cybersecurity – requirements. 2.2 Critical Infrastructure Cybersecurity Requirements Essential and Important Entities The requirements under the Draft Resilience Bill are substantially more demanding than those established by the 2018 Security Law and its implementing texts. Governance While OESs are required to adopt a security policy approved by their management, the 2018 Security Law does not impose specific obligations on man - agement training. The NIS2 Directive takes a differ - ent approach. Management bodies of EEs and IEs must now approve their organisation’s cybersecu - rity risk-management measures and oversee their implementation. They are also required to receive dedicated cybersecurity training to ensure informed decision-making. In addition, NIS2 encourages them to promote regular cybersecurity training across their workforce. The 2018 Security Law provides for personal liability for the managers of OESs. However, this liability is limited to financial penalties – up to EUR125,000 – for failing to comply with security rules or obstructing supervisory controls. By contrast, the NIS2 Directive allows member states to go further by temporarily prohibiting individuals with managerial responsibili - ties from exercising those functions. It also introduc - es sanctions targeting the entity itself (fines of up to EUR10 million or 2% of total worldwide annual turno - ver for EEs, and up to EUR7 million or 1.4% of total worldwide annual turnover for IEs).

126 CHAMBERS.COM

Powered by