France's transposition of the NIS2 Directive (Directive (EU) 2022/2555) has not been enacted.
Loi n° 2025-391 du 30 avril 2025, sometimes taken for the transposition, is a different, unrelated statute (Journal officiel n° 0101 du 1er mai 2025), portant diverses dispositions d'adaptation au droit de l'Union européenne en matière économique, financière, environnementale, énergétique, de transport, de santé et de circulation des personnes (an omnibus European Union law adaptation act covering economic, financial, environmental, energy, transport, health and immigration matters); its full text names neither resilience nor cybersecurity nor the NIS directives, and that citation is corrected here.
The actual transposition vehicle, the projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersecurité (transposing the Critical Entities Resilience Directive, NIS2 and the Digital Operational Resilience Act in three titles), passed the Sénat in first reading on 12 March 2025 and had its special committee (commission spéciale) review at the Assemblée nationale conclude on 10 September 2025; as of this writing it has not been debated on the Assemblée nationale floor, has not had a second reading, and has not been promulgated.
Pending its enactment, the predecessor NIS1 transposition, loi n° 2018-133 du 26 février 2018 (Titre Ier), remains in full effect and is the operative regime: it binds an opérateur de services essentiels (operator of essential services, OSE) designated by the Premier ministre in a sector whose continuity could be gravely affected by a network or information system incident, and a fournisseur de service numérique (digital service provider, FSN) operating an online marketplace, an online search engine or a cloud computing service above a small-business threshold, to security measures set by the Premier ministre and to an incident-declaration duty to the Agence nationale de la sécurité des systèmes d'information (ANSSI, the national network and information system security authority under Code de la défense Article L. 2321-1), enforced through criminal fines on a non-compliant operator's own directors rather than through an administrative penalty on the entity itself.
No French instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
France does hold one standalone security-baseline statute reaching a class of digital platform beyond General Data Protection Regulation (GDPR), NIS1 or the Cyber Resilience Act (CRA): loi n° 2022-309 du 3 mars 2022 (the cyberscore law), in force since 1 October 2023, requires a large online platform operator (Code de la consommation Article L. 111-7-3, covering the online marketplace, ranking and comparison operators Article L. 111-7 defines) and a large number-independent interpersonal communications service, above a visitor-count threshold set by decree, to undergo a cybersecurity audit by an ANSSI-qualified provider (a PASSI) and display the result to consumers on a coloured scale; press reporting found the decrees fixing the applicability thresholds and audit criteria delayed past the statute's own commencement date, so the practical reach of the duty as of this writing is not confirmed in the sources reviewed here even though the statute itself is in force.
Personal-data breach notification to the CNIL and to the affected person under GDPR Articles 33 and 34 and loi 78-17 is separate law, already documented in the privacy topic, and sits there rather than here even where one incident triggers both regimes. The French statutory texts here were read from public Internet Archive captures of Legifrance rather than from Legifrance itself, which refuses automated requests with an HTTP 403 at every tier.
A capture states the law as it stood when the copy was made, so a reader checking whether a provision has since been amended should consult Legifrance directly.