Abstract network of glowing blue nodes representing France's electricity grid cybersecurity

France’s NIS2 Energy Rules Aren’t Law Yet — What ANSSI, RTE, ENEDIS, and CRE Require Right Now

Who This Applies To: Scope at a Glance

France’s electricity sector runs on a small number of very large operators and a long tail of small ones, and NIS2’s Annex I treats them differently. Before anything else, here is where each type of French energy player sits — both under the NIS2 categories that will eventually apply, and under the legal regimes that actually bind them today.

Entity type NIS2 Annex I category What binds it today Likely classification once NIS2 is in force
RTE (Réseau de Transport d’Électricité) Transmission system operator (TSO) OIV sector rules (energy decree, 2016); ANSSI incident reporting Essential entity
Enedis Distribution system operator (DSO) Self-identifies today as an Opérateur de Services Essentiels (OSE) under NIS1 Essential entity
Regional ELDs (est. 130-160 local distribution companies — Strasbourg, Metz, Grenoble, etc.) Distribution system operator (DSO), smaller scale Mostly outside the OIV/OSE lists Important entity, unless designated “critical at regional level”
Independent generators and renewables operators Producer Some covered by the 2016 energy sector decree if OIV-designated Essential or important, by size
Aggregators, demand-response and storage operators Market participant Largely unregulated pre-NIS2 Important entity — a genuinely new compliance population
EV charge-point operators Operator of a recharging point Not previously in scope of any cyber-specific regime Important entity — also new

The last two rows matter more than they look. NIS2’s Annex I brought aggregation, demand-response, storage and EV-charging operators into cybersecurity regulation for the first time in France — none of them existed as a category under the old OIV or OSE lists.

The Law Isn’t in Force Yet — Here’s What That Actually Means

In plain terms: nothing in NIS2 is legally binding on French energy operators today, because France has not finished transposing the directive.

France missed the 17 October 2024 transposition deadline. The European Commission sent a formal notice on 28 November 2024, followed by a reasoned opinion on 7 May 2025 [5]. On 8 July 2026, as part of that month’s infringement package, the Commission referred France — together with Ireland, Spain and the Netherlands — to the Court of Justice of the EU for failing to notify complete transposition measures, and is asking the Court for a lump sum plus daily penalty payments until France notifies full transposition [5][11].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The transposition vehicle is a single bill, the loi relative à la résilience des infrastructures critiques et au renforcement de la cybersécurité, which bundles NIS2 together with the Critical Entities Resilience (REC) directive. The Senate adopted it at first reading on 12 March 2025, and the National Assembly’s special committee adopted it unanimously on 9 September 2025 [6][11]. As of this writing, no floor-vote date has been scheduled — the legislative calendar is congested with an AI/data bill, a 2030 Olympics surveillance law, budget texts, and a March 2026 recess for municipal elections, leaving what one specialist firm called “rare parliamentary time slots” [6]. Once it does reach the floor, it can move quickly; that is also the risk of treating “NIS2 isn’t law yet” as a reason to wait.

Three Overlapping Regimes Already Bind France’s Energy Operators

In plain terms: most guides describe French energy cybersecurity law as one thing — “the LPM” or “NIS2” — when it is actually three separate, currently-active legal layers, plus a fourth that is still pending.

Regime Legal basis What it requires today What changes once the loi Résilience passes
OIV / SAIV Code de la défense, Art. L.1332-1 et seq. (framework est. 2006; energy sector decree, 25 Aug 2016) SIIV information-system security rules, ANSSI technical checks, incident reporting to ANSSI Continues in parallel — the REC directive layers onto the same population rather than replacing it
OSE (NIS1) Ordonnance n°2018-1125 Security measures plus incident notification to ANSSI; Enedis self-identifies as OSE today [10] Re-designated “entité essentielle” — NIS2’s Article 21 measures replace NIS1’s, with no automatic carry-over of the old label
LPM n°2023-703, Arts. 64–68 Code de la défense L.2321-2-1 to -4-1; CPCE L.33-14/L.36-14 Cooperate with ANSSI technical markers on operator networks; software vendors must disclose significant vulnerabilities [7] Unaffected — this is a defence-focused detection-powers law, not a NIS2 transposition instrument, and stays in force regardless
NIS2 (pending) Loi Résilience (not yet in force) Nothing mandatory yet Article 21 risk-management measures, Article 23 incident reporting (24h/72h/1 month), Article 20 management liability, mandatory registration

The LPM row is the one worth double-checking against your own compliance brief: LPM n°2023-703 is frequently cited as France’s “NIS2 law,” but it does not transpose the directive — it gives ANSSI defence-oriented powers (domain-name blocking, vulnerability-disclosure duties for software publishers, network-level threat detection) that exist independently of whether or when the loi Résilience passes [7]. One more calibration point: the exact list of OIV-designated companies in France is legally classified information [12]. RTE and Enedis’s OIV status is understood from their role in the publicly-known energy SAIV sector, not confirmed by any published government register — a distinction that matters if you’re building an audit trail rather than a marketing claim.

RTE and ENEDIS Under NIS2’s Own Definitions

Annex I’s Energy/Electricity subsector names seven entity types verbatim: electricity undertakings, distribution system operators, transmission system operators, producers, nominated electricity market operators, market participants providing aggregation, demand response or energy storage, and operators of a recharging point [1]. RTE and Enedis map cleanly onto two of them.

RTE, as France’s sole transmission system operator, fits the TSO definition in Article 2(35) of Directive (EU) 2019/944 without ambiguity. That matters beyond labelling: NIS2’s Article 2(2) lets a member state bring an entity into essential-entity scope regardless of size where it is the sole provider of a service in that member state [2] — a ground RTE could meet independently of the standard large/medium size test, though the point is largely academic since RTE is unambiguously a large enterprise either way.

Enedis is a less clean case than most articles imply. It manages roughly 95% of the mainland French distribution grid, but not all of it — an estimated 130-160 entreprises locales de distribution (ELDs) cover the remaining 5%, in pockets including Strasbourg, Metz and Grenoble under historical municipal concessions [13]. Those smaller DSOs generally cannot claim Enedis’s near-monopoly position, so most will fall to NIS2’s ordinary Article 3 size test — landing as important, not essential, entities unless a specific French designation pulls them up.

CRE’s Real Role: Market Regulator, Not Cybersecurity Enforcer

In plain terms: the Commission de Régulation de l’Énergie (CRE) is France’s independent energy market regulator. It does not enforce NIS2, and it cannot fine an operator for a cybersecurity failure — that authority sits with ANSSI alone, both today under the OIV/OSE regimes and under the pending law.

Where CRE’s oversight genuinely intersects with compliance is economic, not technical. CRE approves the TURPE tariff — the regulated fee that funds RTE’s and Enedis’s network investment — and represents France in the development of EU-wide network codes, including the Network Code on Cybersecurity (NCCS, Commission Delegated Regulation (EU) 2024/1366) that will set harmonised cyber-risk rules for cross-border electricity flows. In practice, that means cybersecurity capital expenditure tied to NCCS or future NIS2 Article 21 measures has to be justified within RTE’s or Enedis’s regulated cost base before CRE will approve its recovery through tariffs — an economic gate that runs alongside ANSSI’s technical requirements, not inside them. Confusing the two — treating CRE as a cyber regulator, or ANSSI as a tariff-setter — is a common and avoidable framing error.

From Pre-Registration to Mandatory Filing: Where MonEspaceNIS2 Stands Today

One correction worth making explicitly: OSE designation is not, and has never been, a self-registration process. Under ordonnance n°2018-1125, the Prime Minister designates OSE by decree on a sectoral authority’s proposal — it is a closed administrative act, not a form an operator fills in.

What is open today is ANSSI’s self-assessment portal, MonEspaceNIS2 (monespacenis2.cyber.gouv.fr), which opened for voluntary pre-registration on 24 November 2025 after running as a pilot since 2024 [9]. Any organisation — RTE and Enedis included — can use it today to check likely essential/important status ahead of the mandatory registration NIS2’s own framework will require once the loi Résilience is promulgated. ANSSI also published the Référentiel Cyber France (ReCyF) on 17 March 2026: a four-pillar (Governance, Protection, Defence, Resilience) reference framework that is not itself mandatory, but previews the kind of Article 21 evidence ANSSI is expected to accept once enforcement begins [9]. With an estimated 15,000 French entities in NIS2’s eventual scope — against roughly 250 OIV and a far smaller, undisclosed number of OSE designated since 2018 under the current regimes [8][9] — energy operators sitting near the boundary (mid-sized generators, aggregators, ELDs) have the most reason to check their classification now rather than after enforcement starts.

What’s at Stake Once the Law Passes

Trigger Essential entity (e.g. RTE, Enedis) Important entity (e.g. most ELDs, aggregators)
Article 21/23 infringement, administrative fine Up to the higher of EUR 10,000,000 or 2% of total worldwide annual turnover [3] Up to the higher of EUR 7,000,000 or 1.4% of total worldwide annual turnover [3]
Management-body liability Board members “can be held liable for infringements by the entities” of Article 21 [4] — applies to both categories Same provision applies

None of this is enforceable in France yet, because the underlying law isn’t in force — but treat “no NIS2 fine yet” carefully. The OIV/SAIV and OSE regimes already carry their own, older sanctions and reporting duties today, independent of whether or when NIS2 arrives [8][10].

A Practical Gap-Closing Roadmap Before the Loi Résilience Passes

Step Owner Effort
Pre-register on MonEspaceNIS2 and confirm likely essential/important status Compliance officer / legal Low
Map current OIV/SIIV or OSE controls against ReCyF’s four pillars to surface gaps before Article 21 is binding CISO / IT security Medium
Cross-reference NCCS obligations with NIS2 Article 21(2) so grid-specific work (SCADA, IEC 61850, IEC 60870-5-104 segmentation) counts toward both frameworks CISO plus regulatory affairs / CRE liaison High
Brief the management body on Article 20(1) liability now, even though it isn’t binding yet Board / C-suite Low
Track the loi Résilience’s Assemblée nationale floor-vote date — it can move quickly once scheduled Compliance officer Low

Frequently Asked Questions

Is NIS2 already law in France?

No. The transposition bill has cleared the Senate and a National Assembly special committee, but has no scheduled floor vote as of this writing, and on 8 July 2026 the European Commission referred France to the Court of Justice of the EU for failing to notify full transposition [5].

If NIS2 isn’t in force, why would RTE or Enedis need to act now?

Because both already operate under the OIV/SAIV and OSE/NIS1 frameworks, which carry their own ANSSI reporting duties and sanctions regardless of NIS2’s legislative fate.

Does CRE enforce NIS2 in France?

No. ANSSI is the sole cybersecurity competent authority under both the current regimes and the pending law. CRE’s role is economic market regulation — including how energy operators recover cybersecurity investment through the TURPE tariff.

Is Enedis officially an “essential entity” under NIS2?

Not yet, since NIS2 isn’t transposed. Enedis currently self-identifies as an Opérateur de Services Essentiels under the NIS1-era ordonnance [10], and would be expected to become an entité essentielle once the loi Résilience takes effect — but NIS2 does not automatically carry the old OSE label forward.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive, Annex I — Sectors of High Criticality (Advisera)
  2. NIS2 Directive, Article 2 — Scope
  3. NIS2 Directive, Article 34 — Administrative Fines
  4. NIS2 Directive, Article 20 — Governance
  5. European Commission refers France to the CJEU over NIS2 (European Sting)
  6. Projet de loi résilience — legislative status (Entropy Law)
  7. LPM n°2023-703 — cybersecurity provisions (Ledieu-Avocats)
  8. Le dispositif SAIV (ANSSI)
  9. Transposition NIS2 en France (Legiscope)
  10. Enedis, la cybersécurité au cœur du réseau d’électricité (Enedis)
  11. NIS 2 Directive — Transposition in France
  12. OIV : c’est quoi un Opérateur d’Importance Vitale ? (Twist Conseil)
  13. ELD en France : Entreprise Locale de Distribution (Selectra)
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: