A bill aiming to implement the European NIS2 directive, which enhances cybersecurity requirements and expands the number of entities under regulation, was presented to the National Assembly on October 7. The bill, titled the resilience of critical infrastructure and the strengthening of cybersecurity, was approved by the Senate and incorporates provisions from three European directives adopted in 2022: the REC directive on the resilience of critical entities, NIS2 on cybersecurity, and the directive linked to the DORA regulation, which focuses on digital operational resilience in the financial sector. The NIS2 directive was originally due to be fully implemented in France by October 17, 2024, as set by the European Commission. This new bill increases the number of sectors subject to regulation from six to 18, including health, manufacturing, chemical production, research, postal services, and digital infrastructure. It also expands the French security device for vital activities (SAIV) to include new sub-sectors like heating and cooling networks, hydrogen, and sanitation. The bill also requires resilience plans from operators managing the approximately 1,500 vital points across the country. The bill is expected to impact about 15,000 entities, including around 1,500 local collectivities, with 300 of them being communes with more than 30,000 inhabitants. The special committee report also notes that the French National Cybersecurity Agency (ANSSI) will be responsible for monitoring and controlling 14,500 of these entities. Regulated entities will be required to report security incidents and submit information to ANSSI. Companies can expect more rigorous cybersecurity governance, risk management, and cooperation with the national authority. For IT departments and chief information security officers (CISOs), the immediate challenge will be determining whether their organization falls under the category of essential or important entities, the affected sector, size, dependencies on critical service providers, and their ability to detect and notify incidents within the required timeframes. Non-compliance with the bill’s requirements could result in fines of up to 10 million euros or 2% of a company's global turnover, in line with the NIS2 directive’s sanction regime. However, the State, local authorities, and their administrative public establishments will not face these fines, a clarification that is particularly relevant for public actors who will still have to comply with security and notification obligations. The Senate added an article, 16 bis, to the bill aimed at protecting encryption by prohibiting the installation of backdoors, master decryption keys, or other mechanisms that weaken the security of instant messaging services. Senators argued that such measures could create vulnerabilities that could be exploited by cybercriminals, hostile states, or private actors. This provision may become a key topic of discussion during the Assembly's examination of the bill. The bill, numbered 1112, was adopted by the Senate on March 12, 2025, with 181 votes in favor and 134 against, securing a relative majority. However, no public session vote has yet occurred in the National Assembly. The special committee unanimously approved the text in September 2025 after reviewing 472 amendments. However, the final vote in public session, starting on October 7, will determine the bill’s fate. The examination on October 7 does not immediately implement NIS2 in France, as the bill must go through the parliamentary process before it can be enacted. ANSSI also notes that NIS2 will only become effective in France once all the necessary transposition texts—law, decrees, and orders—are officially promulgated.