Back to blog
Compliance & Regulation7 min read

NIS2: the law finally reaches Parliament
Here's what to do, whether it passes on October 7 or not

NIS2ReCyFAssemblée nationaleDORAANSSI

On Wednesday, October 7, 2026, the French Parliament finally debates the NIS2 transposition bill — two years after the European deadline. Whether or not it passes that day, the question for SME and mid-market CISOs isn't the parliamentary calendar. It's what to do starting this week.

Key takeaways

  • On October 7, 2026, Parliament finally debates the NIS2 transposition bill — two years behind the European deadline.
  • The holdup isn't about business obligations, but about Article 16 bis (end-to-end encryption and a possible backdoor requirement for intelligence services).
  • ANSSI's ReCyF framework, meanwhile, has been published since March 2026 and is already contractually required by some major procurement chains.
  • The DORA track record at the ACPR shows that even well-equipped, compliance-mature organizations struggle to meet deadlines once the law is in force.
2 ans

behind the transposition deadline (October 17, 2024)

4

member states targeted by the Commission's infringement procedure (France, Ireland, Spain, Netherlands)

7 mois

head start of the ReCyF framework (published March 2026) over the law's vote

63 %

of major DORA incidents already closed by the time they were reported to the ACPR (H1 2026)

October 7: NIS2 finally reaches debate

On Wednesday, October 7, 2026, the French Parliament finally examines the transposition bill for NIS2 — the European directive on the cybersecurity of essential infrastructures and important entities. With, it must be said, a serious delay: the European deadline to transpose NIS2 into French law was set at October 17, 2024. Two years late, then, and France is not in a strong position on this file: the European Commission referred France to the Court of Justice of the European Union (CJEU) on July 8, 2026 for failure to transpose, alongside Ireland, Spain and the Netherlands.

If the text is dragging, it isn't for lack of interest: a specific sticking point is slowing its adoption, Article 16 bis, which deals with end-to-end encryption and a possible backdoor requirement for intelligence services. A genuine substantive debate — but one that has nothing to do with what the directive expects from the businesses concerned.

For many SMEs and mid-market companies, this calendar uncertainty has had a simple effect: waiting for the law to pass before starting to care. That is exactly the mistake to avoid.

Waiting for the final vote is a risky bet

It's tempting to think: as long as the law isn't enacted, there's no rush. Three reasons show why that reasoning doesn't hold.

First, ANSSI's technical framework, the ReCyF (Référentiel Cyber France), has been published since March 2026 — well before the law itself. This framework already serves as a contractual basis for some large procurers toward their suppliers: companies are already being asked to comply with it in tenders or framework agreements, independently of any legal obligation. The technical framework already exists and already circulates on the ground, whether the law passes on October 7 or is postponed once again.

Second, the European Commission's infringement procedure changes the equation: France is under pressure to transpose quickly, which reduces the room for yet another postponement. The political calendar, even if uncertain in its details, points in a single direction.

Finally, and this is perhaps the most telling point: look at what is happening with DORA, the equivalent European regulation for the financial sector, which came into force in January 2025.

"The track record drawn up by the Autorité de contrôle prudentiel et de résolution (ACPR) is telling: among major incidents in the first half of 2026, 63% were already closed by the time they were reported, and notification deadlines (4h then 24h) remain, in the ACPR's own words, “still rarely met” — in a sector that is nonetheless used to regulatory obligations and equipped with dedicated compliance teams."

If well-equipped financial institutions struggle to meet deadlines once the law is already in force, an SME or mid-market company that discovers NIS2 on the day the law is enacted would start with a far more serious handicap.

What you can start right now

No need to wait for the final text to move forward. Here is, in order, what an SME or mid-market company can start this week:

1

Qualify your scope

NIS2 distinguishes essential entities from important entities based on sector and size. Even without absolute certainty on the final text, most organizations can already estimate whether they are concerned, directly or indirectly (as a supplier to a covered entity).

2

Map your critical suppliers

NIS2 extends responsibility to the supply chain. If one of your major clients already applies ReCyF in its contracts, you have every interest in knowing now where you stand against that framework.

3

Appoint a clear owner

Not necessarily a new hire: within your existing team, designate who owns the NIS2 topic and who has the authority to prioritize the associated actions.

4

Rely on ReCyF now

Rather than waiting for a law that will spell out the details, the baseline measures of the ANSSI framework (multi-factor authentication, access mapping, incident management) are already a concrete, actionable starting point.

5

Set up minimal traceability

Even in a simple way, keep a record of what was done, when, and by whom — this is often what is missing most on the day proof of compliance is requested, far more than the measures themselves being absent.

In summary

October 7 marks a milestone, not a finish line: even if voted that day, the NIS2 law will still take time to produce its implementing decrees. But the ReCyF framework is already here, already used contractually by some major procurers — and the DORA track record shows what awaits those who haven't anticipated it.

At Eyako, we believe the right approach isn't to follow the parliamentary calendar day by day, but to start with the handful of concrete actions listed above, which stay useful regardless of how the October 7 debate turns out. That's exactly what we help SME and mid-market CISOs do: qualify their scope, track their critical suppliers and trace their ReCyF measures, without devoting a dedicated team they don't have.

Frequently asked questions

When will the NIS2 law be voted in France?+
The NIS2 transposition bill is examined by Parliament on October 7, 2026, two years behind the European deadline set for October 17, 2024. The text is held up by Article 16 bis, devoted to end-to-end encryption and a possible backdoor requirement for intelligence services — a debate unrelated to the obligations expected from businesses.
What is Article 16 bis, blocking the NIS2 vote?+
It is a provision of the bill dealing with end-to-end encryption and a possible backdoor requirement for intelligence services. It is this specific point, not businesses' cybersecurity obligations, that is holding back the text's adoption.
Should you wait for the NIS2 law to be voted before preparing?+
No. ANSSI's technical framework, ReCyF, has been published since March 2026 and is already contractually required by some major procurers. The European Commission's infringement procedure also reduces the room for another postponement. And the DORA track record at the ACPR shows that even well-equipped organizations struggle to meet their obligations once the law is in force.
What is ANSSI's ReCyF?+
ReCyF (Référentiel Cyber France) is the technical framework published by ANSSI that serves as the operational translation of NIS2. Published since March 2026, it is already used as a contractual basis by some major procurers toward their suppliers, independently of the legislative calendar.
What concrete actions can an SME or mid-market company start right now?+
Five actions: qualify your scope (essential entity, important entity, or supplier to a covered entity), map your critical suppliers, appoint a clear owner for the NIS2 topic, rely on ReCyF's baseline measures now, and set up minimal traceability of the actions taken.

See where your NIS2 readiness really stands

Eyako helps SME and mid-market CISOs qualify their scope, track critical suppliers and trace their ReCyF measures — without a dedicated team.

Request a demo
NIS2: France's Law Finally Reaches Parliament — What to Do, Whether It Passes on October 7 or Not | Eyako