Almost two years after it was first presented to the Council of Ministers, a bill aimed at strengthening France's cybersecurity measures has yet to be officially adopted by Parliament. The main obstacle is disagreement over encryption policies, which has slowed down the approval process in the National Assembly. As a result, France now faces legal action from the Court of Justice of the European Union. Last July, the European Commission announced it would take legal action against France for failing to implement the NIS 2 directive, a European cybersecurity law, and is requesting a fixed fine and daily penalties. France had until October 17, 2024, to align its laws with the directive.
This situation is not unexpected, as the bill, titled Bill relating to the resilience of critical infrastructures and the strengthening of cybersecurity, has been stalled in the legislative process for months. Deputy Philippe Latombe (Les Démocrates), a digital policy expert, warned in February that France was "under the sword of Damocles" due to potential sanctions from the European Commission. He also expressed concern over the rising number of data breaches. This warning proved prescient, as recent weeks revealed data leaks at two key French agencies: the interministerial digital direction (Dinum) and the national cybersecurity agency (Anssi).
The bill, which was already passed by the Senate, is now set to be reviewed by the National Assembly. Presented in the Council of Ministers on October 15, 2024, the legislation covers the implementation of three European cybersecurity directives, including NIS 2. It requires a larger number of companies and organizations—nearly 15,000—to adopt security measures and imposes strict obligations in the event of data breaches or cyberattacks. The bill also mandates the creation of a minimum security reference framework, which Anssi has already released in a beta version.
The bill was passed by the Senate in March 2025, but with amendments that caused a legislative deadlock. While the National Assembly debated the issue of access to encrypted messaging by intelligence services, the Senate introduced an article opposing the inclusion of "backdoors" in encrypted communications within the cybersecurity bill. This article, labeled 16 bis, was included in the version of the bill sent to the National Assembly. After a special committee approved the bill in September 2025—expanding article 16 bis—no further action has been taken in the National Assembly. Senator Olivier Cadic (Union centriste) and Philippe Latombe claim the delay is due to resistance from certain departments within the Ministry of the Interior, which want article 16 bis removed. They argue that encryption is essential for national security.
The bill is now scheduled to be discussed in the National Assembly on October 7 and 9, but its examination may be affected by the pace of debates on a separate bill addressing sexual and gender-based violence. Deputy Minister for Digital Affairs, Anne Le Hénanff, stated during an assembly session on October 1 that the government plans to remove article 16 bis, calling it a "legislative rider." In return, she assured that the government would not reintroduce provisions that weaken encryption by the end of the parliamentary session. This compromise aims to allow the cybersecurity bill to be adopted flexibly, two years after its initial presentation. For France, this is also about maintaining credibility with its European partners, as emphasized by senators Olivier Cadic and Philippe Latombe.
France's Cybersecurity Bill Faces Delays Over Encryption Disputes and EU Scrutiny
AI-rewritten from original reportingHow it works
cybersecurityencryptioneu-sanctionsfrancelegislationnis-2



