NIS2: the law finally reaches Parliament
Here's what to do, whether it passes on October 7 or not
On Wednesday, October 7, 2026, the French Parliament finally debates the NIS2 transposition bill — two years after the European deadline. Whether or not it passes that day, the question for SME and mid-market CISOs isn't the parliamentary calendar. It's what to do starting this week.
Key takeaways
- On October 7, 2026, Parliament finally debates the NIS2 transposition bill — two years behind the European deadline.
- The holdup isn't about business obligations, but about Article 16 bis (end-to-end encryption and a possible backdoor requirement for intelligence services).
- ANSSI's ReCyF framework, meanwhile, has been published since March 2026 and is already contractually required by some major procurement chains.
- The DORA track record at the ACPR shows that even well-equipped, compliance-mature organizations struggle to meet deadlines once the law is in force.
behind the transposition deadline (October 17, 2024)
member states targeted by the Commission's infringement procedure (France, Ireland, Spain, Netherlands)
head start of the ReCyF framework (published March 2026) over the law's vote
of major DORA incidents already closed by the time they were reported to the ACPR (H1 2026)
October 7: NIS2 finally reaches debate
On Wednesday, October 7, 2026, the French Parliament finally examines the transposition bill for NIS2 — the European directive on the cybersecurity of essential infrastructures and important entities. With, it must be said, a serious delay: the European deadline to transpose NIS2 into French law was set at October 17, 2024. Two years late, then, and France is not in a strong position on this file: the European Commission referred France to the Court of Justice of the European Union (CJEU) on July 8, 2026 for failure to transpose, alongside Ireland, Spain and the Netherlands.
If the text is dragging, it isn't for lack of interest: a specific sticking point is slowing its adoption, Article 16 bis, which deals with end-to-end encryption and a possible backdoor requirement for intelligence services. A genuine substantive debate — but one that has nothing to do with what the directive expects from the businesses concerned.
For many SMEs and mid-market companies, this calendar uncertainty has had a simple effect: waiting for the law to pass before starting to care. That is exactly the mistake to avoid.
Waiting for the final vote is a risky bet
It's tempting to think: as long as the law isn't enacted, there's no rush. Three reasons show why that reasoning doesn't hold.
First, ANSSI's technical framework, the ReCyF (Référentiel Cyber France), has been published since March 2026 — well before the law itself. This framework already serves as a contractual basis for some large procurers toward their suppliers: companies are already being asked to comply with it in tenders or framework agreements, independently of any legal obligation. The technical framework already exists and already circulates on the ground, whether the law passes on October 7 or is postponed once again.
Second, the European Commission's infringement procedure changes the equation: France is under pressure to transpose quickly, which reduces the room for yet another postponement. The political calendar, even if uncertain in its details, points in a single direction.
Finally, and this is perhaps the most telling point: look at what is happening with DORA, the equivalent European regulation for the financial sector, which came into force in January 2025.
"The track record drawn up by the Autorité de contrôle prudentiel et de résolution (ACPR) is telling: among major incidents in the first half of 2026, 63% were already closed by the time they were reported, and notification deadlines (4h then 24h) remain, in the ACPR's own words, “still rarely met” — in a sector that is nonetheless used to regulatory obligations and equipped with dedicated compliance teams."
If well-equipped financial institutions struggle to meet deadlines once the law is already in force, an SME or mid-market company that discovers NIS2 on the day the law is enacted would start with a far more serious handicap.
What you can start right now
No need to wait for the final text to move forward. Here is, in order, what an SME or mid-market company can start this week:
Qualify your scope
NIS2 distinguishes essential entities from important entities based on sector and size. Even without absolute certainty on the final text, most organizations can already estimate whether they are concerned, directly or indirectly (as a supplier to a covered entity).
Map your critical suppliers
NIS2 extends responsibility to the supply chain. If one of your major clients already applies ReCyF in its contracts, you have every interest in knowing now where you stand against that framework.
Appoint a clear owner
Not necessarily a new hire: within your existing team, designate who owns the NIS2 topic and who has the authority to prioritize the associated actions.
Rely on ReCyF now
Rather than waiting for a law that will spell out the details, the baseline measures of the ANSSI framework (multi-factor authentication, access mapping, incident management) are already a concrete, actionable starting point.
Set up minimal traceability
Even in a simple way, keep a record of what was done, when, and by whom — this is often what is missing most on the day proof of compliance is requested, far more than the measures themselves being absent.
In summary
October 7 marks a milestone, not a finish line: even if voted that day, the NIS2 law will still take time to produce its implementing decrees. But the ReCyF framework is already here, already used contractually by some major procurers — and the DORA track record shows what awaits those who haven't anticipated it.
At Eyako, we believe the right approach isn't to follow the parliamentary calendar day by day, but to start with the handful of concrete actions listed above, which stay useful regardless of how the October 7 debate turns out. That's exactly what we help SME and mid-market CISOs do: qualify their scope, track their critical suppliers and trace their ReCyF measures, without devoting a dedicated team they don't have.
Frequently asked questions
When will the NIS2 law be voted in France?+
What is Article 16 bis, blocking the NIS2 vote?+
Should you wait for the NIS2 law to be voted before preparing?+
What is ANSSI's ReCyF?+
What concrete actions can an SME or mid-market company start right now?+
See where your NIS2 readiness really stands
Eyako helps SME and mid-market CISOs qualify their scope, track critical suppliers and trace their ReCyF measures — without a dedicated team.
Request a demo