France’s NIS2 Transport Rules: What SNCF, ADP, and the Marseille and Le Havre Ports Already Owe ANSSI Under the OIV Framework
A French rail infrastructure manager, an airport operator, and a port authority can each be legally required today to secure their most critical systems under ANSSI supervision — and none of it is NIS2. The Loi Résilience, the bill that will transpose Directive 2022/2555 into French law, was referred to the Court of Justice of the European Union on 8 July 2026 for still not being passed, with National Assembly review pushed to September 2026 at the earliest [1]. Meanwhile, the Loi de programmation militaire (LPM) of 2013 has bound France’s designated Opérateurs d’Importance Vitale (OIV) — a list that includes SNCF, Aéroports de Paris, and the Marseille and Le Havre port authorities — to a separate, enforceable cybersecurity regime since 2016 [2]. Most compliance content for French transport operators glosses over this and treats NIS2’s Article 21 as if it were already law. It isn’t yet. This guide separates what already binds French transport operators under the OIV framework from what NIS2 adds once it passes, and maps both onto SNCF’s signalling systems, ADP’s airports, and France’s two largest ports.
Does France’s NIS2 Transport Sector Apply to You?
NIS2 places transport among Annex I’s sectors of "high criticality," which means qualifying operators go through essential-entity screening first and important-entity screening second — there’s no soft-touch default for this sector. Annex I names the entity types directly: air carriers, airport managing bodies, and traffic management control operators for air transport; infrastructure managers and railway undertakings for rail; port managing bodies and inland, sea, and coastal passenger and freight companies for water transport; and traffic-management road authorities plus intelligent transport system operators for road [3]. For the full national scope estimate and essential-vs-important mechanics, see our guide to ANSSI’s regulatory role and our essential vs. important entity classification guide.
| Classification | Size threshold | French transport examples |
|---|---|---|
| Essential Entity | ≥250 employees, OR ≥€50M turnover AND ≥€43M balance sheet | SNCF Réseau (rail infrastructure manager), Groupe ADP (airport managing body), Grand Port Maritime authorities |
| Important Entity | ≥50 employees AND ≥€10M turnover | Smaller regional rail undertakings, secondary airports, inland waterway operators |
| Automatically essential regardless of size | — | None in transport specifically — the no-size-test tier is reserved for digital infrastructure (DNS, cloud, CDN, trust services), not transport Annex I categories |
The Framework Already in Force: LPM, OIV, and SIIV
France’s transport operators didn’t need to wait for NIS2 to acquire a binding cybersecurity obligation — they’ve had one since 2016. Under the LPM (Article 22 of Law 2013-1168), operators designated by the State as vital to the nation’s functioning — Opérateurs d’Importance Vitale — must identify their most critical information systems, called Systèmes d’Information d’Importance Vitale (SIIV): systems whose confirmed compromise would seriously harm the nation [2][4]. Transport (terrestrial, maritime and fluvial, and aviation) was designated an OIV sector under sector-specific decrees effective 1 October 2016 [2]. Around 250 OIV currently operate across 11 vital sectors nationwide [5] — a far narrower population than the roughly 10,000 entities NIS2 is expected to bring into scope once it passes [5].
ANSSI enforces the OIV framework through roughly 20 mandatory security rules published in sectoral decrees between 2016 and 2017: security policy, system homologation, IT mapping, authentication/identity management, network segmentation and filtering, remote-access controls, logging, incident detection and management, crisis procedures, and performance indicators [2][4]. Non-compliance is a criminal matter, not an administrative one — a meaningful difference from NIS2. Article L1332-7 of the Code de la défense fines an OIV’s director up to €150,000 per violation, with legal-entity liability via the Penal Code’s quintuple multiplier — up to €750,000 [6][4]. Compare that to NIS2’s administrative ceiling for essential entities — €10,000,000 or 2% of global turnover, whichever is higher — once the French law takes effect. See our France NIS2 penalties guide for the full breakdown.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Because the SIIV rules were written years before NIS2’s 2022 text, coverage isn’t uniform. Several map cleanly onto Article 21(2); others don’t exist in the SIIV rulebook at all.
| SIIV rule category | Closest NIS2 Article 21(2) measure | Gap notes |
|---|---|---|
| Security policy | (a) Risk analysis & IS security policy | Direct overlap |
| System homologation | (a) / (f) Effectiveness assessment | Partial — homologation evidences risk treatment but not NIS2’s explicit effectiveness-review cycle |
| System mapping, auth/ID management | (i) Asset management & access control | Direct overlap |
| Segmentation, filtering, remote access | (e) Network & information systems security | Direct overlap — this is the OT/signalling security measure |
| Logging, incident detection/management, crisis procedures | (b) Incident handling / (c) Business continuity | Direct overlap |
| Performance indicators | (f) Effectiveness assessment | Partial |
| Not present in the 2016-17 SIIV rules | (d) Supply chain security | Gap — NIS2’s direct-supplier vulnerability clause postdates the sectoral decrees; see our supply chain security guide |
SNCF and Rail: Signalling OT Security Under Article 21(2)(e)
SNCF Réseau, the infrastructure manager that owns and operates France’s rail network, sits inside Annex I’s rail transport category as an infrastructure manager [3]. Its cybersecurity posture has been "considerably reinforced… under the impetus of ANSSI," according to the Établissement Public de Sécurité Ferroviaire (EPSF), France’s rail safety authority [7]. In 2021, EPSF led a working group with ANSSI, SNCF Réseau, SNCF Voyageurs, and the European Railway Agency that published a doctrine document setting out how railway safety regulation and cybersecurity regulation interact — recognising, as rail digitalises, that the two disciplines increasingly govern the same systems from different angles [7]. As a general guideline, that overlap is precisely where operational technology in rail lives: signalling.
Rail signalling — interlocking systems, digital train-control platforms, the software that decides which section of track a train may occupy — is, in NIS2’s language, a "network and information system." Article 21(2)(e) requires entities to secure exactly this: the "acquisition, development and maintenance" of network and information systems, "including vulnerability handling and disclosure" [8]. For a signalling estate that mixes decades-old interlocking hardware with newer digital control layers, that translates into documented vendor patch cycles, a disclosed vulnerability-handling process for legacy equipment that can’t always be patched on a normal IT cadence, and evidence that new signalling procurement specifies security requirements before commissioning — not after. That is a materially different discipline from the physical and operational safety rules EPSF already regulates, which is exactly why the 2021 doctrine document exists: to stop the two regimes from silently overlapping or, worse, silently leaving gaps between them.
Aéroports de Paris: From OES to Essential Entity
Groupe ADP operates Charles de Gaulle, Orly, and Le Bourget, plus stakes in 28 airports worldwide, placing it inside Annex I’s air transport category as an airport managing body [3][9]. The transition is already acknowledged internally: Groupe ADP’s CISO has stated the company moved from "Operator of Essential Services" under the original NIS Directive to "Essential Entity" under NIS2, adding that the classification "applies to airports in general, and to Groupe ADP a fortiori" as France’s largest airport complex [9].
What stands out about ADP’s approach is that it treats compliance as a floor, not a ceiling. The company runs an ethical-hacker programme testing the hardware and firmware of airport equipment before deployment — physical attack resistance, firmware vulnerability assessment, Zero Trust principles applied to newly connected devices — feeding results into a published list of penetration-test requirements for future equipment tenders [9]. Its CISO has also proposed mutualising this testing across European airports via ACI Europe, so vendors face one shared bar instead of every airport re-testing the same hardware [9]. That’s a different posture from treating Article 21(2) as a documentation exercise: it uses the regulatory floor to justify security work airports weren’t previously funding.
Marseille and Le Havre: Ports Between LPM and NIS2
Water transport’s Annex I category covers port managing bodies directly [3], which puts France’s Grands Ports Maritimes — including Marseille-Fos and the HAROPA grouping that includes Le Havre — on the same essential-entity screening path as SNCF and ADP. Both have already lived through the older LPM regime: maritime and fluvial transport was classified SAIV under the LPM, with SIIV obligations applying from 2016, and a 14 September 2018 decree separately designated maritime operators as Operators of Essential Services under the original NIS Directive [10].
The threat these rules address isn’t theoretical. In March 2020, the Port of Marseille was caught up in the Mespinoza/Pysa ransomware attack — not a direct hit on port systems, but fallout from an attack on the wider Aix-Marseille-Provence metropolitan information systems the port was connected to [11]. ANSSI’s risk analysis found older, previously undetected malware on port systems, evidence of intrusions predating the ransomware incident, though the techniques involved were, in ANSSI’s own assessment, "not very advanced" [11]. Impact was contained through a joint response across the CISOs of every affected organisation, not any single port’s isolated defences [11] — a reminder that port cybersecurity is inseparable from the metropolitan networks a port sits inside.
HAROPA Le Havre has taken a more proactive route since. In 2019 it ran an ANSSI-backed simulation testing AIS (Automatic Identification System) spoofing scenarios and the response measures they’d trigger [10]. In 2020 it began building CYMPATI, a port/maritime/industrial cybersecurity platform built with Le Havre Seine Métropole, UMEP, Synerzip-LH, Airbus, SOGET, ANSSI, and the DGSI, aimed at the information-system interfaces where port, maritime, and industrial actors meet [12]. The scale of the risk is documented, not assumed: the ADMIRAL database recorded 195 maritime-domain cyberattacks between 2020 and early 2023, 140 of them ransomware, 60 hitting port, shipowner, or vessel infrastructure directly [10].
What Happens When NIS2 Finally Passes: The OIV-to-NIS2 Bridge
Available compliance guidance treats the transition as mechanical, not optional: an operator already designated OIV is expected to become an NIS2 essential entity automatically once the French law takes effect, with no separate qualification process described [4]. The SIIV layer underneath doesn’t disappear. An OIV transport operator will carry three simultaneous obligations once the Loi Résilience passes: the LPM’s SIIV rules under the Code de la défense, NIS2’s broader Article 21(2) measures, and GDPR Article 32 wherever personal data is involved [4]. None of the three retires the others — they stack.
The timing is still unsettled. The Commission referred France — with Ireland, Spain, and the Netherlands — to the CJEU on 8 July 2026, seeking a lump sum plus daily fines for the delay, amounts undetermined [1]. The bill passed the Senate in March 2025, but National Assembly debate now isn’t likely before the September 2026 parliamentary return [1]. The sticking point is Article 16 bis, a Senate-added provision barring encryption backdoors, which the DGSI opposes as a restriction on lawful-access capability [1]. None of this changes what a French transport OIV owes ANSSI today under the LPM — it only delays the second, larger obligation set.
What Each Role Should Prioritise Right Now
| Role | Priority today (LPM/OIV already binding) | Priority once NIS2 passes |
|---|---|---|
| CISO / IT Security Manager | Confirm which systems are formally declared SIIV and verify homologation status is current; map existing SIIV evidence against Article 21(2)(a)/(e)/(i) using the gap table above | Close the supply-chain (d) and effectiveness-assessment (f) gaps the SIIV rules never covered |
| Compliance Officer / Legal | Confirm OIV/SIIV status directly with ANSSI — do not assume; register affiliated entities separately if the group spans multiple sectors | Pre-register on MonEspaceNIS2 and track the statutory registration window once the law is published |
| Board / C-Suite | Understand that LPM non-compliance is a criminal exposure for named directors (€150,000 per violation), not just a corporate fine | Approve the broader NIS2 risk-management framework under the eventual French equivalent of Article 20 governance duties |
| SME Owner / Non-technical | Most SMEs sit outside the ~250-operator OIV list; confirm size/sector thresholds before assuming either regime applies | Use ANSSI’s scope simulator once formal NIS2 registration opens |
Frequently Asked Questions
Does OIV status automatically make an entity an NIS2 essential entity?
Available compliance guidance says yes — the transition is expected to be mechanical once the French law takes effect, with no separate NIS2 qualification process described for entities already holding OIV status [4]. Confirm your own entity’s position with ANSSI directly rather than assuming it. The SIIV-specific obligations under the Code de la défense continue to apply on top; NIS2 doesn’t replace them.
What’s actually binding law for a French transport operator today?
If your organisation is a designated OIV, the LPM’s SIIV rules under the Code de la défense are binding now, enforced by ANSSI, with criminal sanctions for non-compliance [2][6]. NIS2’s Article 21 measures become binding only once the Loi Résilience is enacted — not before.
Does the 8 July 2026 CJEU referral create new obligations for my organisation?
No. The referral is a dispute between the European Commission and the French state over the transposition delay [1]. It creates political and financial pressure on France; it does not itself impose any requirement on a private or public transport operator. Your obligations still flow from French national law — the LPM today, and the Loi Résilience once it passes.
Are SNCF Voyageurs, regional TER operators, or private freight companies also OIV, or just SNCF Réseau?
OIV designation is made sector-by-sector, operator-by-operator, by government decree, and the full list is not fully public. SNCF Réseau’s status as the rail infrastructure manager is well documented through its ANSSI-reinforced security posture [7]; the OIV status of any other specific rail operator should be confirmed directly with ANSSI rather than assumed from SNCF Réseau’s example.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS 2: France Referred to EU Court. IT-Connect.
- Le dispositif SAIV. ANSSI (cyber.gouv.fr).
- NIS2 Annex I.2 — Transport Sector. AuditFront.
- LPM et OIV : les obligations cyber des Opérateurs d’Importance Vitale (2026). Legiscope.
- Homologation ANSSI 2026. Ayi Nedjimi Consultants.
- "Article L1332-7" (Code de la défense, legifrance.gouv.fr).
- Prise en compte des enjeux de cybersécurité au sein de la sécurité ferroviaire. Établissement Public de Sécurité Ferroviaire (EPSF).
- Article 21 — Cybersecurity risk-management measures. NIS 2 Directive (EU) 2022/2555.
- Groupe ADP airport cybersecurity. Yogosha.
- Le domaine maritime : zone de risques cyber. LeMagIT.
- Cybermarétique : petite histoire des cyberattaques contre le secteur portuaire. Stormshield.
- La cybersécurité portuaire, au cœur de l’innovation. HAROPA PORT.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
