Abstract network security illustration representing NIS2 healthcare compliance in France

France’s NIS2 Law Is Stalled — Why ANSSI, PGSSI-S, and a Three-Tier System Already Shape Hospital Compliance

France missed the NIS2 transposition deadline by more than 20 months. On 8 July 2026, the European Commission referred France — along with Ireland, Spain, and the Netherlands — to the Court of Justice of the EU, asking for a lump sum plus daily penalties until the law is notified [1][2]. The bill carrying NIS2 into French law, the projet de loi résilience, has been stuck since a special National Assembly commission approved it in September 2025 — blocked, according to French tech press, by a single disputed clause (Article 16 bis, on encryption backdoors) that pits domestic intelligence services against the directive’s own security requirements [2]. France’s AI and digital minister, Anne Le Hénanff, has said the earliest realistic floor debate is September 2026 [2].

None of that suspends what French healthcare organisations already have to do. Hospitals have carried a mandatory IT-security-incident reporting duty to CERT Santé since well before NIS2 existed [3], and the Politique Générale de Sécurité des Systèmes d’Information de Santé (PGSSI-S) has set baseline security expectations for health IT since 2012 [4].

Does NIS2 Apply to Your French Healthcare Organisation?

In plain terms: if you’re a hospital, clinic, medical biology lab, or medico-social facility above roughly 50 staff (or €10M turnover/balance sheet), NIS2 almost certainly reaches you once the French law is in force — healthcare is one of the most broadly defined sectors in the directive.

NIS2 Annex I lists "Health" as a sector of high criticality, covering five categories: healthcare providers (hospitals, clinics, and other entities providing healthcare under Directive 2011/24/EU), EU reference laboratories, entities carrying out R&D of medicinal products, manufacturers of basic pharmaceutical products, and manufacturers of medical devices designated critical during a declared public-health emergency under Article 22 of Regulation (EU) 2022/123 [5]. That last category is narrow — it only pulls in devices on the EMA’s crisis list (ventilators, oxygen concentrators, certain diagnostics). Everyday medical device and IVD manufacturers instead sit in Annex II, which carries "important entity" status by default, not "essential" [5].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Your organisation NIS2 annex Size test Likely status
University hospital / large CHU Annex I 250+ staff or €50M+ turnover Essential (EE)
Mid-size public or private hospital Annex I 50–249 staff or €10–50M turnover Important (EI)
Small clinic below the medium-enterprise ceiling Annex I Below 50 staff and €10M Generally out of scope
Standard medical device / IVD manufacturer Annex II 50+ staff or €10M+ turnover Important (EI)
Manufacturer of an EMA crisis-listed device Annex I (upgraded) Same as above Essential (EE)

Article 3 sets the underlying test: Annex I entities that exceed the medium-enterprise ceilings in Recommendation 2003/361/EC become essential; those between the small and medium ceilings become important [6]. Four questions settle it fast: (1) Do you provide healthcare, run a reference lab, do medicinal-product R&D, or manufacture pharmaceuticals or devices? (2) Are you above 50 staff or €10M in turnover/balance sheet? (3) If yes to both, are you above 250 staff or €50M turnover — that’s essential; below it, important. (4) Separately: are you already designated an Opérateur d’Importance Vitale (OIV)? If so, none of the above replaces that obligation — see the next section.

France Hasn’t Passed Its NIS2 Law — Here’s What’s Actually True Right Now

As of this writing, the projet de loi résilience — which transposes NIS2 and the Critical Entities Resilience (CER) directive together — has not been promulgated. The Senate adopted its version in March 2025; a National Assembly special commission approved it in September 2025; floor debate has not happened and, per the responsible minister, is unlikely before September 2026 [2]. The sticking point reported in French tech press is Article 16 bis, a clause barring mandated encryption backdoors, which has drawn opposition from domestic security services and stalled the bill for months [2]. Separately, at least one deputy has publicly warned that the delay leaves roughly 15,000 organisations — explicitly including hospitals — unable to plan against a settled legal text, and that the state itself carries liability exposure if a covered entity is breached before the law exists [7] — on top of the penalty exposure that will apply once it does.

That legislative gap hasn’t stopped ANSSI from acting. The agency published version 2.5 of the Référentiel Cyber France (ReCyF) on 17 March 2026 — its own translation of Article 21’s ten measure categories into concrete security objectives. ANSSI describes ReCyF as non-binding by default, but notes it may be invoked during future compliance inspections [8]. Voluntary pre-registration has also been open through ANSSI’s MonEspaceNIS2 portal since late 2025, letting entities get ahead of the eventual mandatory registration window rather than scrambling once the law takes effect [8]. Nothing here is enforceable today — ANSSI can’t yet fine a hospital under NIS2 — but healthcare’s Annex I status makes it a sector ANSSI is expected to prioritise once it can.

The Real Structure Isn’t Two Tiers — It’s Three

Most NIS2 explainers describe French entities as split into two categories: essential (EE) and important (EI). For healthcare, that undercounts the picture. France runs three overlapping regimes, and a single hospital can be caught in more than one at once.

Tier 1 — Opérateurs d’Importance Vitale (OIV). Roughly 300 organisations nationally hold this pre-NIS2 designation under the 2013 Military Programming Law and the Defense Code, covering operators whose disruption would threaten the nation’s ability to function [9]. Some of France’s largest university hospitals (CHU) and regional referral centres are understood to carry OIV designation, alongside operators in energy, transport, and other sectors [9]. OIV obligations — securing designated "systems of vital importance," reporting to ANSSI, submitting to state-mandated audits — are separate from NIS2 and do not disappear once the new law passes [9].

Tier 2 — Essential Entities (EE) under NIS2. Large healthcare providers (250+ staff or €50M+ turnover) that aren’t already OIV-designated will become essential entities once the law is in force, facing ANSSI’s more intrusive, no-notice-required supervision model.

Tier 3 — Important Entities (EI) under NIS2. Mid-size hospitals, clinics, and standard medical device manufacturers land here, facing NIS2’s reactive supervision — audits triggered by evidence of non-compliance rather than routine inspection.

The overlap matters operationally: a CHU that is both OIV and, once the law passes, an essential entity doesn’t get to pick one compliance programme. It runs both, submits to both authorities’ expectations, and can’t point to LPM/OIV security work as automatic NIS2 coverage — the two frameworks share a regulator but not a single audit trail. For most French hospitals below OIV thresholds, the practical question is simpler: EE or EI, decided purely by the size test in the table above. See our France NIS2 overview for the full ANSSI registration and penalty picture beyond healthcare.

PGSSI-S Already Covers Part of Article 21 — Here’s the Exact Gap

Since 2012, the Agence du Numérique en Santé (ANS) has published the PGSSI-S — a reference framework built on the Public Health Code (Articles L1470-1 to L1470-6) that sets security expectations for hospitals, health-data hosts, and medico-social organisations, and helps them define the security levels their own information-system policy must meet [4]. It predates NIS2 by a decade, which raises the obvious question: does complying with PGSSI-S already satisfy Article 21? Partially — and unevenly.

The PGSSI-S corpus has four core reference documents — electronic identification of users, identification of legal-entity actors, identification of natural-person actors, and the evidentiary force of health documents — plus supporting guides on access management, continuity, incident response, backups, and phishing [10]. Mapped against Article 21(2)’s ten measure categories [11]:

Article 21(2) measure PGSSI-S coverage
(a) Risk analysis & IS security policy Partial — PGSSI-S sets baseline security-level expectations project leads must apply, but has no standalone risk-analysis methodology of its own
(b) Incident handling Partial — a dedicated incident-response guide exists and CERT Santé reporting is mandatory (see next section), but neither is structured against Article 23’s notification timeline
(c) Business continuity Partial — continuity and backup guides exist; no mandated business-impact-analysis methodology or tested disaster-recovery-plan requirement
(d) Supply chain security No dedicated coverage found in the current published corpus — no supplier classification or contractual security requirement
(e) Acquisition, development & maintenance No dedicated coverage found in the current published corpus — no secure-development-lifecycle or vulnerability-handling requirement
(f) Effectiveness assessment No dedicated coverage found in the current published corpus — no audit/scoring methodology equivalent
(g) Cyber hygiene & training Partial — a phishing-prevention guide exists but isn’t a full training programme
(h) Cryptography No dedicated cryptography-policy requirement found in the current published corpus
(i) HR security, access control & asset management Partial — the three identification référentiels plus the access-management guide give a real identity-assurance grounding
(j) MFA & secure communications No dedicated multi-factor or continuous-authentication requirement found — the identification référentiels address who a user is, not how they’re forced to prove it each session

The pattern: PGSSI-S gives hospitals a real head start on identity, documentation, and basic continuity habits — six of ten domains have something to build on. But four domains (supply chain security, secure development, effectiveness assessment, and cryptography policy) have no dedicated PGSSI-S equivalent in the published corpus, and none of the six partial domains reach Article 21’s documented, auditable standard on their own. Treat PGSSI-S as a foundation, not a finish line.

The Dual Incident-Reporting Trap: CERT Santé vs. ANSSI

French health establishments, medico-social facilities, medical biology labs, and radiotherapy centres already have a standing legal duty — under Public Health Code Article L1111-8-2 and its implementing decree — to report serious information-system security incidents to CERT Santé, the sector CSIRT run by ANS [3]. "Serious" means anything with a real or potential effect on patient-care safety, on the integrity or confidentiality of health data, or on normal facility operation [3].

Once the French NIS2 law takes effect, essential and important healthcare entities will separately owe ANSSI a notification within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month [12]. These are not the same obligation wearing two names. CERT Santé’s reporting duty is sector-specific, patient-safety-framed, and already in force; ANSSI’s Article 23 timeline is cross-sector, entity-status-framed, and not yet enforceable. Ambiguity around exactly how the two will reconcile once NIS2 lands is real — the CERT Santé portal itself notes that additional declarations to ANSSI, CNIL, or the Ministry of the Interior may apply depending on an entity’s status and the incident’s nature, without spelling out a single merged workflow [3]. Building one incident-triage runbook now — one that branches to CERT Santé today and adds an ANSSI/Article 23 branch when the law passes — beats improvising during an actual breach.

What to Do Before the Law Passes

Role Action now Effort
CISO / IT Security Manager Score existing PGSSI-S artefacts against the Article 21(2) gap map above; prioritise supply chain, secure development, effectiveness assessment, and cryptography — the four domains with no existing foundation Medium
Compliance Officer Complete voluntary pre-registration on MonEspaceNIS2; build the dual CERT Santé / future-ANSSI reporting runbook; track the September 2026 National Assembly session Low–Medium
Board / C-Suite Don’t treat the delay as a compliance pause — CERT Santé and GDPR/CNIL obligations already apply, and a breach before the law passes doesn’t erase the organisation’s exposure; budget now for the four uncovered Article 21 domains Low (decision), High (funding)

Frequently Asked Questions

Is NIS2 already legally in force in France?
No. As of this writing, the transposition law has not been promulgated; National Assembly floor debate isn’t expected before September 2026 at the earliest. Confirm the current status directly with ANSSI before acting on any deadline — this detail moves fast [2].

If my hospital already follows PGSSI-S, are we NIS2-compliant?
No. PGSSI-S gives partial coverage on six of Article 21’s ten measure categories and no dedicated coverage on supply chain security, secure development, effectiveness assessment, or cryptography policy — see the gap map above.

Does this apply to private clinics, or only public hospitals?
Annex I’s healthcare-provider category follows Directive 2011/24/EU’s definition, which does not distinguish public from private status — any entity providing healthcare above the size thresholds is in scope, public or private [5].

What happens if we’re breached before the law passes?
The NIS2-specific notification duty to ANSSI isn’t enforceable yet, but the existing CERT Santé reporting obligation and GDPR/CNIL breach-notification duties are already live and independent of NIS2’s timeline [3]. A legislative delay does not suspend those.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  • "Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity" — The European Sting
  • "NIS 2 Delayed Again: France Referred to the European Court of Justice" — IT-Connect
  • "Le cadre législatif et les déclarations" — Portail du CERT Santé, Agence du Numérique en Santé
  • "Politique générale de sécurité des systèmes d’information de santé" — Agence du Numérique en Santé
  • "Am I a medical device manufacturer under NIS2?" — NISD2.eu
  • NIS2 Directive, Article 3 — nis-2-directive.com
  • "La loi cybersécurité dort dans les tiroirs de l’Assemblée nationale" — Clubic
  • "The NIS 2 Directive" — ANSSI (cyber.gouv.fr)
  • "NIS 2 France : différences OIV, OSE, EE, EI" — Legiscope
  • "Corpus documentaire PGSSI-S" — Agence du Numérique en Santé
  • NIS2 Directive, Article 21 — nis-2-directive.com
  • NIS2 Directive, Article 23 — nis-2-directive.com
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: