Abstract network shield illustrating French financial cybersecurity oversight

DORA-Only or Still NIS2? France’s ACPR/AMF Boundary for Banks and Investment Firms

Most French financial-services compliance teams have been told a simplified version of the DORA/NIS2 relationship: “DORA replaces NIS2 for finance.” That is true for a credit institution or a large insurer — but it is not true for every entity sitting inside France’s NIS2-scoped banking and finance sectors under NIS2 Annex I. The Digital Operational Resilience Act (DORA) only displaces NIS2 for entities that fall inside DORA’s own Article 2 scope. Fall outside it — a small alternative investment fund manager, a micro insurance intermediary, a fintech that isn’t a licensed payment institution — and you are back under NIS2, reporting to ANSSI, not ACPR or AMF. Getting this boundary wrong means either under-complying (missing a NIS2 obligation you assumed DORA covered) or over-building (duplicating controls a DORA-covered entity doesn’t need to document twice).

Which Authority Covers Your Financial Entity: ANSSI, ACPR, or AMF?

France splits financial-sector cyber-risk supervision three ways. The starting rule: ANSSI is France’s single NIS2 competent authority for every sector except the entities that DORA’s Article 2 pulls out of NIS2’s scope — those go to the ACPR (banking, insurance) or AMF (asset management, trading venues, crowdfunding) instead, under DORA rather than NIS2.

Entity type DORA-covered? Supervisor Governing framework
Credit institutions (banks) Yes ACPR DORA (NIS2 Art. 4 lex specialis)
Insurance & reinsurance undertakings Yes (with exemptions — see below) ACPR DORA
Investment firms, trading venues, crowdfunding platforms, management companies Yes AMF DORA
Micro/SME insurance intermediaries, small AIF managers, small IORPs (≤15 members) No — DORA Art. 2(3) exempted ANSSI NIS2 directly (if Annex I/II thresholds met)
Fintechs outside DORA’s 21 entity categories (e.g. unregulated software vendors to banks) No ANSSI NIS2 directly, or as a supplier under a bank’s Art. 21(2)(d) supply-chain obligations

The practical test is three questions, in order: (1) Does your entity type appear in one of DORA’s 21 categories under Article 2(1)? (2) If yes, does an Article 2(3) exemption pull you back out (size, member count, licensing status)? (3) If you land outside DORA at either step, do you meet NIS2’s own Annex I/II sector-plus-size thresholds? Only a “yes” at step 1, “no” at step 2 puts you fully under ACPR/AMF and DORA.

Why DORA, Not NIS2, Governs Most French Banks’ Cyber Risk

The legal mechanism sits in Article 4 of the NIS2 Directive, titled “Sector-specific Union legal acts” — not, despite a common mix-up, Article 2(3) (which is a separate, unrelated provision about critical entities under the CER Directive). Article 4 states that where a sector-specific EU law imposes cybersecurity risk-management and incident-notification obligations that are “at least equivalent in effect” to NIS2’s, the sector-specific law applies and NIS2’s own provisions do not. DORA was built to satisfy that equivalence test for financial entities: its ICT risk-management chapter and incident-classification-and-reporting regime cover the same ground as NIS2 Articles 21 and 23, in more granular, finance-specific form — see our general NIS2 vs DORA breakdown for the EU-wide mechanism outside the France-specific detail covered here. For a French credit institution, that means ACPR — not ANSSI — is the authority that actually inspects your ICT risk framework and receives your incident reports.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

This is a real handoff, not a formality. ANSSI does not co-supervise a fully DORA-covered bank’s cybersecurity programme. The bank’s compliance evidence, audit trail, and incident-reporting relationship run through the ACPR (or AMF, depending on entity type) under DORA’s own Articles 5-15 and 17-23 — a different rulebook, different templates, different supervisor, even though the underlying goal (resilient IT, fast incident disclosure) is the same one NIS2 pursues everywhere else.

The DORA Exemption That Pulls Entities Back Under NIS2

DORA’s own Article 2(3) lists categories the Regulation excludes from its 21-entity scope: managers of alternative investment funds under the small-AIFM regime (Article 3(2) AIFMD), certain insurance and reinsurance undertakings, occupational retirement institutions running schemes with 15 members or fewer, persons exempted under MiFID II, insurance intermediaries that are micro, small, or medium-sized enterprises, and post-office giro institutions. Article 2(4) additionally lets Member States exclude the smaller CRD-exempt credit institutions listed in Directive 2013/36/EU Article 2(5), points 4-23, from their territory.

None of these exemptions removes an entity from cybersecurity regulation altogether — they remove it from DORA. If the entity still meets NIS2’s Annex I banking or financial-market-infrastructure sector definition and its size thresholds, NIS2 applies in full, directly, with ANSSI as the competent authority. A micro-enterprise insurance broker that is DORA-exempt under Article 2(3) but large enough to clear NIS2’s Important Entity threshold does not get a lighter regime — it gets NIS2’s Article 21 measures and Article 23 incident timeline instead of DORA’s, administered by ANSSI instead of the ACPR.

Dual Reporting in Practice: ACPR’s Fast Clock vs NIS2’s Cascade

For DORA-covered entities, the reporting relationship runs to the ACPR or AMF, not ANSSI. Practitioner guidance drawn from DORA’s implementing technical standards (the Level 1 Regulation defers the exact hour-count to those standards under Article 19-20) puts the initial major-incident notification window at roughly 4 hours from the moment an incident is classified as “major,” and in any case within 24 hours of the entity becoming aware of it — followed by an intermediate report and a final root-cause report. That is a materially tighter first-notification clock than NIS2’s own cascade: a 24-hour early warning, a 72-hour incident notification, and a final report within one month, which still applies in full to any French financial entity that is NIS2-governed rather than DORA-governed.

The fragmentation shows up operationally. AMF’s own DORA notification page confirms it routes incident and cyberthreat reports through separate email inboxes by entity type (management companies, crowdfunding providers, trading-venue operators) using downloadable Excel templates — a different mechanic entirely from ANSSI’s NIS2 portal. A French banking group that experiences a ransomware incident touching customer data can end up notifying the CNIL under GDPR, the ACPR under DORA, and — for any group entity that is NIS2-governed rather than DORA-governed — ANSSI under NIS2, on three different clocks, through three different channels, with no shared intake portal between them as of this writing.

France’s Transposition Status: What’s Live, What’s Still Pending

DORA has applied directly and fully across the EU, including France, since 17 January 2025 — it is a Regulation, not a directive, so no national transposition step was needed for it to bind ACPR and AMF. NIS2 is a different story, and the gap is now a formal one: France missed the original 17 October 2024 EU transposition deadline, and the Loi Résilience that would activate NIS2 for its DORA-exempt financial entities is stalled in Parliament over an unrelated dispute.

Milestone Date
DORA applies directly (Regulation, no transposition needed) 17 January 2025 — already in force
NIS2 EU transposition deadline (missed by France) 17 October 2024
Commission reasoned opinion to France (2-month deadline) 7 May 2025
Loi Résilience adopted by the Senate, first reading 12 March 2025
National Assembly special-commission review concluded (Article 16 bis encryption/anti-backdoor clause added) 10 September 2025
Commission refers France (with Ireland, Spain, Netherlands) to the CJEU for non-notification, seeking a lump sum plus daily penalties 8 July 2026
National Assembly public-session examination (postponed, per the responsible deputy minister) Not before September 2026

The blocker is not technical. Article 16 bis, added in the Senate to bar encryption providers from being forced to build backdoors into messaging services, has drawn opposition from France’s domestic intelligence service (DGSI) — a fight that has nothing to do with financial-sector cybersecurity but is holding the whole bill, and with it every DORA-exempt French financial entity’s NIS2 activation date, hostage. DORA-covered entities feel none of this delay; their obligations have been live and enforced by the ACPR and AMF since January 2025 regardless of where the Loi Résilience stands. ANSSI’s pre-registration portal, MonEspaceNIS2, is open for entities anticipating NIS2 scope — including the DORA-exempt financial entities that will eventually register there, not with the ACPR or AMF — but pre-registration is not the same as an enforceable obligation.

Penalties: Why DORA Leaves France’s Number Undefined (While NIS2’s Is Already Set)

France’s NIS2 penalty structure is already documented and enforceable once the Loi Résilience takes effect — essential entities face fines up to €10 million or 2% of global turnover, important entities up to €7 million or 1.4%, detailed in our France NIS2 penalties guide. DORA’s side of the boundary is different. DORA Article 50 requires Member States to set their own “effective, proportionate and dissuasive” administrative penalties — it does not fix an EU-wide figure the way NIS2’s Article 34 does. As of the most recent comparative review (DLA Piper, dlapiper.com), France had not yet implemented a local penalty regime under DORA Article 50(3), leaving ACPR and AMF to draw on their existing Code monétaire et financier sanction powers (warnings, formal notice to comply, and pecuniary sanctions) rather than a DORA-specific ceiling. Other Member States that have legislated show how wide the range can get — Sweden allows penalties up to 10% of turnover, Italy caps at €20 million — which means a group with entities in multiple Member States cannot assume France’s eventual figure will match a sister subsidiary’s exposure elsewhere.

Compliance Checklist by Role

Role What to do now Effort
Compliance Officer / Legal Run the 3-step DORA/NIS2 test above for every entity in your group, including subsidiaries and joint ventures; document which regulator (ACPR, AMF, or ANSSI) each one reports to Medium
CISO / IT Security Lead Confirm which incident-reporting clock applies per entity (DORA’s 4h/24h classification window vs NIS2’s 24h/72h/1-month cascade) and build separate playbooks — do not assume one incident procedure covers both High
Board / C-Suite Ask which entities in the group are still pending NIS2 activation under the stalled Loi Résilience (CJEU referral 8 July 2026, floor debate not expected before September 2026) rather than treating DORA compliance as “finance sector, fully covered” Low
Procurement / Supply Chain Where a NIS2-governed financial entity buys ICT services from a DORA-covered bank (or vice versa), map the contractual security clauses each regime requires — they are not identical Medium

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Frequently Asked Questions

Does DORA completely replace NIS2 for every French financial institution?

No. It replaces NIS2 only for entities inside DORA’s own Article 2(1) scope. Entities that DORA’s Article 2(3) exempts — micro/SME insurance intermediaries, small AIF managers, small pension institutions, and similar — remain under NIS2 directly if they meet its Annex I/II thresholds, with ANSSI as their competent authority.

Which regulator do I report a cyber incident to — ACPR, AMF, or ANSSI?

It depends on your entity type, not your industry label. Banks and insurers report to the ACPR under DORA; investment firms, trading venues, crowdfunding platforms, and management companies report to the AMF under DORA; everyone outside DORA’s scope who still meets NIS2 thresholds reports to ANSSI under NIS2.

Is my fintech or crowdfunding platform covered by DORA or NIS2 in France?

Crowdfunding service providers are explicitly inside DORA’s 21 entity categories and report to the AMF. A fintech that is not a licensed, DORA-listed entity type — for example, a software vendor selling to banks rather than a regulated financial entity itself — sits outside DORA and is assessed under NIS2’s own sector-and-size rules, or as a supplier under a bank’s Article 21(2)(d) supply-chain obligations.

When does France’s NIS2 law actually take effect for the financial sector?

Not yet, and the delay is now formal: the European Commission referred France to the Court of Justice of the EU on 8 July 2026 for failing to notify NIS2 transposition, seeking a lump sum plus daily penalties. The Loi Résilience is stalled over Article 16 bis, an unrelated encryption/anti-backdoor clause opposed by the DGSI, with National Assembly floor debate not expected before September 2026. DORA, by contrast, has applied directly and fully since 17 January 2025 because it is an EU Regulation rather than a directive — so DORA-covered French financial entities have had zero delay.

Sources

  • NIS2 Directive (EU) 2022/2555, Article 4 — Sector-specific Union legal acts
  • DORA Regulation (EU) 2022/2554, Article 2 — Scope
  • DORA Regulation (EU) 2022/2554, Article 50 — Administrative penalties and remedial measures
  • AMF (Autorité des Marchés Financiers) — DORA incident and cyberthreat notification forms (linked above)
  • DLA Piper (dlapiper.com) — DORA Penalty Regimes: Overview of Divergence Among Member States, October 2025
  • nis-2-directive.com — France transposition tracker
  • Legiscope — Transposition NIS2 en France: loi, calendrier 2026 et obligations ANSSI
  • ComplyAdvantage — What is France’s ACPR?
  • MLex / European Commission — Referral of France, Ireland, Spain, and the Netherlands to the CJEU over NIS2 non-notification (8 July 2026)
  • IT SOCIAL — La transposition de NIS2 attendra au plus tôt la rentrée parlementaire de septembre (Article 16 bis encryption dispute)
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: