NIS2 enforcement and penalties in France — regulatory compliance concept

What France’s NIS2 Fines Actually Look Like: €10M Essential / €7M Important, Q4 2026 ANSSI Supervision, and How Appeals Work

France missed the EU’s 17 October 2024 NIS2 transposition deadline. The Loi Résilience — France’s national implementation bill — is still working through the National Assembly, with plenary debate scheduled for summer 2026. For organisations waiting on the law before taking action, this gap creates a specific risk that most guidance overlooks: enforcement is already underway.

Under its existing supervisory powers, ANSSI issued 23 remediation orders to entities in the energy and transport sectors for inadequate cybersecurity risk management before the new legislation passed [7]. When the Loi Résilience is promulgated — expected summer 2026 — full NIS2 fine exposure begins, and entities that have not prepared face a materially harder conversation with ANSSI’s auditors than those that have. This guide covers France’s NIS2 framework from the enforcement side: what the fines are, when they can be imposed, how they are calculated, who bears personal accountability, and how to challenge a decision.

To determine whether your organisation falls within NIS2’s scope as an essential or important entity, start with the sector and size thresholds. This article assumes you have already confirmed your classification and focuses on what happens once ANSSI turns its attention to you.

The Fine Amounts Under NIS2 Directive Article 34

The penalty ceiling for France will match the framework set directly in Article 34 of Directive (EU) 2022/2555, which the Loi Résilience implements without modification [1]:

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Entity type Maximum fine (fixed) Turnover cap Which applies
Essential entity (EE) €10,000,000 2% of worldwide annual turnover Whichever is higher
Important entity (IE) €7,000,000 1.4% of worldwide annual turnover Whichever is higher

The turnover cap means the nominal ceiling often understates the real exposure for larger organisations. A French essential entity with €500 million in global revenue faces a theoretical maximum of €10 million under the fixed cap — but 2% of €500 million is €10 million, exactly at the cap. One with €1 billion in global turnover faces €20 million, well above the fixed figure. The calculation uses worldwide turnover, not France-specific revenue [1].

Two categories of violation trigger these fines: failures under Article 21 (the ten cybersecurity risk-management measures, including risk analysis, incident handling, business continuity, supply chain security, network security, cryptography, access control, multi-factor authentication, staff training, and vulnerability management) and failures under Article 23 (incident reporting obligations, including the 24-hour early warning, 72-hour notification, and one-month final report) [1]. For a detailed breakdown of Article 23 incident notification requirements, including what constitutes a ‘significant incident’, see the dedicated guide.

Beyond one-off fines, Article 34 also authorises periodic penalty payments — daily or weekly amounts that accumulate while a violation continues. An entity that receives a binding compliance order and fails to act may face both: a one-off fine for the original violation and compounding periodic payments for every day of continued non-compliance [1].

One provision that most France-focused guides omit: Article 35 of the Directive establishes a GDPR coordination rule. If the CNIL (France’s GDPR supervisory authority) imposes an administrative fine for a personal data breach, ANSSI cannot additionally impose a NIS2 fine for the same conduct [1]. Non-monetary enforcement measures — warnings, binding instructions, public disclosure orders — remain available, but the financial double-jeopardy protection is real. Organisations that have already received a CNIL fine for a breach-related incident should factor this into any NIS2 enforcement response.

The Pre-Law Gap: What ANSSI Can Actually Enforce Right Now

The single most important distinction for French entities in 2026: NIS2 is a directive, not an EU regulation. That difference is not procedural — it is structural, and it affects what ANSSI can and cannot do today.

EU regulations — such as DORA for financial entities or the NIS2 Implementing Regulation CIR 2024/2690 for digital service providers — apply directly to entities without national implementation. Directives do not. They require member states to pass domestic legislation before authorities can enforce them against private organisations. The Directive itself does not create directly enforceable obligations for private entities under French law until the Loi Résilience is enacted [6].

That means ANSSI cannot currently issue a €10M or €7M NIS2 fine against a French entity. The legal basis does not yet exist at the national level. What ANSSI can do — and is doing — is enforce under the existing 2018 Law on Military Programming (LPM) framework, which grants supervisory powers over operators of essential services already regulated under NIS1. Under those powers, ANSSI issued 23 remediation orders to entities in energy and transport for inadequate risk management [7]. Those orders are binding under current law, and non-compliance carries consequences under the existing framework.

The risk for organisations delaying action is specific and measurable. When the Loi Résilience is promulgated — the current legislative calendar points to late summer 2026, following National Assembly plenary debate — ANSSI’s full NIS2 supervisory toolkit becomes active immediately [6]. Entities with risk assessments completed, Article 21 policies documented, and incident reporting procedures in place will face their first ANSSI interaction from a position of documented good faith. Entities ANSSI encounters without any of these will not. ANSSI has stated publicly that its approach prioritises remediation over punishment [7], but that approach applies more readily to entities that have demonstrably started.

A separate enforcement track runs in parallel but targets France as a state, not French entities. The EU Commission opened infringement proceedings against France for failing to transpose NIS2 by the October 2024 deadline. That proceeding creates political pressure on the legislative timeline and makes further delay increasingly difficult to sustain [6].

How ANSSI Builds a Case: The Enforcement Ladder Before Any Fine

No French entity will receive a fine as the first contact in an ANSSI enforcement interaction. The NIS2 Directive mandates a graduated escalation sequence, and France’s Loi Résilience will implement it in full [2].

For essential entities, Article 32 sets out the enforcement sequence ANSSI must follow [2]:

  1. Warning — ANSSI identifies a directive breach and formally notifies the entity
  2. Binding instruction — ANSSI specifies required remediation measures and a compliance deadline
  3. Cease and desist order — for ongoing violations, ANSSI orders the conduct stopped
  4. Compliance order — ANSSI mandates implementation of specific risk-management or incident reporting measures
  5. Public disclosure order — ANSSI may require the entity to inform affected users of ongoing cyber threats
  6. Audit recommendation implementation order — ANSSI sets a deadline for acting on specific audit findings
  7. Monitoring officer designation — in serious cases, ANSSI appoints a compliance monitor at the entity’s expense
  8. Administrative fine — the last step, reached only after prior measures have failed to compel compliance

One France-specific structural detail that competitors uniformly miss: under the Draft Resilience Bill, ANSSI does not impose fines directly. ANSSI investigates, builds the enforcement file, and refers the case to an independent sanctions committee operating under the Prime Minister’s authority. That committee holds sole authority to impose financial penalties [10]. This mirrors the CNIL’s restricted-formation architecture for GDPR fines. It means entities facing a fine have two distinct points of legal challenge: the ANSSI investigation and the sanctions committee’s referral decision — both of which can potentially be challenged in administrative court before a fine is actually imposed.

The enforcement regime differs substantially between entity types. Essential entities face proactive, ongoing supervision: on-site inspections, random checks, regular and targeted security audits, and security scans without any triggering incident [2]. Important entities face a fundamentally different, reactive regime: ANSSI’s supervisory tools activate primarily after an incident, a complaint, or information suggesting a violation [3]. For important entities, the practical implication is clear — a significant cyber incident that is not reported within 24 hours is the most likely trigger for an enforcement case, not a routine audit.

How the Fine Amount Is Calculated: Article 32(7)’s Eight Factors

The €10M and €7M figures are ceilings, not standard fines. Every penalty the sanctions committee imposes is determined by weighing the eight-factor framework set out in Article 32(7) of the Directive — which applies to important entities as well, by reference, under Article 33(5) [2][3]:

Factor (Art. 32(7)) What it covers How to demonstrate mitigation
(a) Seriousness Repeated violations, failure to notify incidents, obstruction of audits, false information provided First occurrence; transparent disclosure; no obstruction of investigation
(b) Duration How long the infringement lasted before remediation began Swift remediation following ANSSI’s initial contact
(c) Prior violations Previous enforcement history with ANSSI or other EU competent authorities Clean regulatory record; proactive historical compliance
(d) Damages Financial loss caused, number of users affected, impact on services Containment evidence; limited and documented impact scope
(e) Intent or negligence Whether the violation was deliberate or the result of failure to act Documented implementation effort, even if incomplete
(f) Remedial measures What corrective action the entity took to address the violation Prompt corrective action plan; documented remediation steps taken
(g) Certification adherence Compliance with NIS2-relevant codes of conduct or certifications ISO 27001 certification; alignment with ReCyF framework objectives
(h) Cooperation level Degree of cooperation with ANSSI throughout the investigation Full and timely disclosure; responsiveness to information requests

Factors (a), (f), and (h) — seriousness, remedial action, and cooperation — are the ones entities most directly control during an enforcement interaction. The enforcement ladder exists to correct the violation, not to maximise the penalty [7]: an entity that self-identifies a gap, documents remediation, and cooperates fully with ANSSI’s investigation is in a structurally different position at the sanctions committee stage than one that obstructs, delays, or provides incomplete information.

Factor (g) is increasingly relevant as France’s compliance ecosystem matures. ANSSI published the Référentiel Cyber France (ReCyF) on 17 March 2026 — a voluntary framework covering 20 security objectives across four domains [5]. ANSSI confirmed that entities applying ReCyF can rely on it during ANSSI audits. ISO 27001:2022 certification covers approximately two of the twenty objectives; ISO 27002 alignment covers closer to 80% [5]. Neither certification substitutes for full NIS2 compliance, but both provide documented evidence of good faith that feeds directly into factor (g) when the sanctions committee calculates the fine amount.

Management Liability: What France’s NIS2 Framework Means for Directors

NIS2 penalties do not stop at the organisation. Board members and senior leadership carry direct obligations under Article 20 of the Directive, and France’s implementing legislation does not soften them [4].

Article 20(1) requires that management bodies approve the cybersecurity risk-management measures and oversee their implementation. Approval is an operative word: passive endorsement of a CISO’s quarterly summary does not satisfy the obligation. The management body is expected to understand the measures, formally approve them, and actively monitor that implementation happens. Minutes of board meetings where Article 21 measures are reviewed and approved are not optional bureaucracy — they are the evidence Article 20 requires [4].

Article 20(2) adds a mandatory training requirement: management body members must receive cybersecurity training regularly — enough to identify risks and assess the organisation’s risk-management practices. The Directive does not prescribe hours or accreditation, but the standard is ‘sufficient knowledge’ to make informed oversight decisions. ANSSI will look for documented training completion when reviewing governance compliance [4].

Personal accountability reaches its sharpest form under Article 32(5) for essential entities. If an essential entity repeatedly violates NIS2 obligations and other enforcement measures have failed, ANSSI can refer the case to the sanctions committee for a temporary prohibition on the responsible manager or legal representative exercising management functions [2]. This is not a theoretical provision. France’s implementation of financial sector regulation includes equivalent management prohibition powers, and the NIS2 framework reflects a deliberate policy choice to make leadership personally exposed to enforcement outcomes [10].

France’s enforcement framework also includes public disclosure of violations — what the industry calls ‘name and shame’ [8]. An entity whose infringement is publicly disclosed by the sanctions committee faces reputational consequences that may exceed the financial penalty, particularly in regulated sectors where procurement authorities and enterprise clients consider cybersecurity compliance in contracting decisions.

The Appeals Route: Challenging an ANSSI Enforcement Decision

The two-stage structure of France’s NIS2 enforcement — ANSSI investigates, the independent sanctions committee decides — creates two distinct points at which an entity can mount a legal challenge [10].

Stage 1 — During the ANSSI investigation. ANSSI’s investigation produces the referral that the sanctions committee acts on. An entity can challenge the investigation itself — the legal basis, the scope, the evidence gathered — either directly with ANSSI or through an interim administrative court application before the sanctions committee receives the referral. The entity’s cooperation during this stage (factor (h)) and remedial action (factor (f)) also directly shape what the referral looks like, which is why legal representation during investigation is advisable for any entity facing a formal ANSSI inquiry.

Stage 2 — The sanctions committee decision. The committee hears the entity’s response before issuing any penalty. Its decision is a separate administrative act from ANSSI’s investigation, subject to its own challenge route under French administrative law [9].

For formal court challenges, French administrative law governs [9]. Decisions of national regulatory bodies in France are reviewed by the administrative court system. The appeals path for a sanctions committee decision operating under the Prime Minister’s authority will likely run to the Conseil d’État — France’s highest administrative court, which has first-instance jurisdiction over certain categories of decisions by national authorities. Before filing, French administrative procedure generally requires:

  1. Recours gracieux — a formal written request to the authority that issued the decision (ANSSI or the sanctions committee) to withdraw or modify it. This step is often procedurally required before a court will accept a challenge, and the deadline for the court filing often runs from the date of the contested decision, not from the date of ANSSI’s response to the recours.
  2. Court challenge — filed within the statutory deadline from the date of the contested decision. Filing within time is critical: late applications are automatically rejected [9]. For decisions of the Conseil d’État, legal representation is mandatory in most proceedings.

Two practical notes. First, whether an appeal suspends the fine while the court reviews it — the ‘suspensive effect’ question — will depend on France’s specific implementing legislation and the procedural rules the sanctions committee operates under. This is not yet settled. Second, because ANSSI investigates and then refers, a challenge to a flawed ANSSI investigation can potentially block the referral before the committee reaches a penalty decision at all. Specialist counsel in French administrative and regulatory law is essential for any sanctions committee challenge.

Key Takeaways for French Entities

The enforcement calendar works as follows:

Period Status Priority action
Now — Summer 2026 Loi Résilience pending; ANSSI enforcing under NIS1 powers Register via MonEspaceNIS2; begin Article 21 gap assessment; document Article 20 governance (board approval + training records)
Summer 2026 Loi Résilience promulgated; full NIS2 framework active Confirm entity classification (EE or IE); finalise risk management documentation; implement 24/72-hour incident reporting procedures
Q4 2026 onward ANSSI formal NIS2 audits begin for essential entities Essential entities: prepare for proactive on-site audits; align with ReCyF; document ISO 27001 and training evidence
Ongoing — Important entities Reactive enforcement; triggered by incidents or complaints Focus on incident detection speed and 24-hour reporting; an unreported significant incident is the primary enforcement trigger

The Article 34 ceilings are calibrated to be felt. The fine calculation under Article 32(7)’s eight factors means early remediation, cooperation, and documented compliance consistently reduce the final amount — sometimes significantly. But that reduction requires preparation that begins before ANSSI’s first contact, not after. A NIS2 compliance checklist covering Article 21’s ten domains is the starting point for that preparation.

  • Essential entities face fines up to €10M or 2% of worldwide turnover (whichever is higher); important entities face up to €7M or 1.4%. The cap applies to global revenue, not France-specific turnover.
  • ANSSI cannot currently impose NIS2-scale fines — the Loi Résilience must first be enacted. Full fine exposure begins at promulgation, expected summer 2026.
  • ANSSI is already enforcing under existing NIS1 powers: 23 remediation orders issued in energy and transport before the new law passed.
  • No fine arrives without a warning first. The graduated enforcement ladder runs from warnings to binding orders to monitoring officer designation to sanctions committee referral. Cooperation and documented remediation reduce the final amount across all eight Article 32(7) criteria.
  • France’s structure separates ANSSI (investigates and refers) from the independent sanctions committee (decides on fines). Both the investigation and the committee’s decision can be challenged in the administrative court system.
  • Management bodies are personally accountable under Article 20. Training records, documented approval of Article 21 measures, and oversight minutes are not optional — they are the evidence base that determines personal liability exposure.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. “Article 34: General Conditions for Imposing Administrative Fines on Essential and Important Entities” — NIS-2-Directive.com
  2. “Article 32: Supervisory and Enforcement Measures for Essential Entities” — NIS-2-Directive.com
  3. “Article 33: Supervisory Measures for Important Entities” — NIS-2-Directive.com
  4. “Article 20: Governance” — NIS-2-Directive.com
  5. “La directive NIS 2” — ANSSI (Agence nationale de la sécurité des systèmes d’information)
  6. “France NIS2 Transposition” — NIS-2-Directive.com: https://www.nis-2-directive.com/Transposition/France.html
  7. “NIS2 France Implementation: Timelines, Fines & Roadmap for 2026” — Copla: https://copla.com/blog/compliance-regulations/nis2-directive-regulations-and-implementation-in-france/
  8. “Sanctions en cas de non-respect de la directive NIS2” — Factorial: https://factorial.fr/blog/sanctions-nis2/
  9. “Recours devant le juge administratif” — Service-Public.gouv.fr
  10. “Cybersecurity 2026 — France” — Chambers and Partners: https://practiceguides.chambers.com/practice-guides/cybersecurity-2026/france
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: