Book a demoDemo Open menu Close menu

Regulation 4 min read

NIS2 transposition: the Resilience bill is expected to reach the National Assembly on 7 October.

A NIS2 plan that starts with email and forgets the PLC installed twenty years ago misses the point. In France, the obligations do not apply yet: the bill transposing the directive is expected to reach the National Assembly from 7 October 2026, two years late. The most useful job at an older site can start straight away, though: knowing what is running there, and which way its data flows.

A row of red gas cylinders under a canopy, in front of a thermal power plant building and its stack, under a blue sky.
A thermal power plant. Energy is one of the 18 sectors covered by NIS2.

Where the bill stands.

The bill “on the resilience of critical infrastructure and the strengthening of cybersecurity” (in French, the loi Résilience) was adopted by the Senate in March 2025, then by the National Assembly’s special committee on 10 September 20251. The plenary debate planned for July 2026 was postponed, for lack of agreement on an article dealing with encrypted messaging, according to the French IT publication IT Social2. On 8 July, the European Commission3 referred France and three other member states to the Court of Justice of the European Union for failing to transpose the directive on time. On 23 September, the French tech news site Next4 reported that the bill was scheduled for plenary debate from Wednesday 7 October.

The timetable has already slipped several times. No date of application is certain, and this article will be updated after the vote in the Assembly.

Who would be covered.

The directive covers 18 sectors, including energy and transport, the Commission points out. In France, according to the parliamentary channel LCP5, the number of regulated entities would rise from 500 to around 15,000, with chemicals manufacturing, the manufacturing industries and medium-sized and large companies among the newcomers. The bill distinguishes between “essential” and “important” entities, which would not be subject to the same requirements. If you operate a power generation site or a medium-sized plant, ask yourself the question now rather than the day after the vote.

What nobody has inventoried.

ANSSI, the French national cybersecurity agency, overhauled its “Mesures détaillées” (detailed measures) guide for industrial systems6 on 27 November 2025. The guide starts from something every operator knows: equipment is generally deployed for at least 20 years, and its obsolescence limits both updates and the addition of security functions. It also describes a “lack of mapping”: no inventory of equipment, generations of technology that coexist without anyone knowing, little information on the support manufacturers still provide. And it notes that entities rarely carry out this mapping. Yet on a site that has grown layer by layer, that is where everything starts.

In its Panorama de la cybermenace 20257 (cyber threat overview), published on 11 March 2026, ANSSI observes that sabotage attempts against critical infrastructure, particularly in energy, remain much favoured by state actors.

Does that mean older PLCs have to be replaced? The bill has not been passed. The guide recommends, first, knowing this equipment, managing its obsolescence and segregating its data flows.

The direction of data flows.

Every time a tool comes to fetch data from a PLC (monitoring, energy tracking, maintenance), a path opens towards the control system. The ANSSI guide recommends one-way flows between industrial systems of different security classes. A firewall may be enough for the least critical classes. For the most sensitive, one-way flow has to be enforced by a unidirectional gateway.

We came across the question at a thermal power plant operator we equip. Some of its turbines are run by Woodward Micronet controllers, whose native protocols give write access to their settings. So we read them through an OPC DA server, read-only: Mobapi sends no commands to the controller, and the control network stays cut off from the internet. At the same plant operator, the Siemens PLCs of the flue gas treatment unit are on a network separate from the gensets’ network. The two networks stay separate. They only come together on screen.

With every supplier that asks for access to a PLC, one question comes before all the others: which way does the data flow? A tool that can only read cannot, by that path, send a command to a machine. Our team can connect your equipment, legacy equipment included, on that principle: the BOX is read-only by design, it communicates only with Mobapi over an encrypted connection, and a built-in firewall blocks everything else. The data is hosted on AWS in the Paris region, or stays on your own servers. Compliance itself will be judged against the text as passed.

Sources.

  1. French National Assembly, projet de loi relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité, text adopted by the special committee, 10 September 2025.

    assemblee-nationale.frBack to text

  2. IT Social, on the postponement of the bill’s debate and the disagreement over Article 16 bis, 15 July 2026.

    itsocial.frBack to text

  3. European Commission, referral of Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union, 8 July 2026.

    digital-strategy.ec.europa.euBack to text

  4. Next, on the bill being placed on the National Assembly’s agenda, 23 September 2026.

    next.inkBack to text

  5. LCP, on the Resilience bill and the number of regulated entities, 20 July 2025.

    lcp.frBack to text

  6. ANSSI, guide “Mesures détaillées” for the cybersecurity of industrial systems, version 2.0, 27 November 2025.

    messervices.cyber.gouv.frBack to text

  7. ANSSI, Panorama de la cybermenace 2025, 11 March 2026.

    cyber.gouv.frBack to text

  8. ANSSI, overview page on the NIS 2 directive.

    cyber.gouv.frBack to text

  9. ANSSI, “NIS 2 : l’ANSSI poursuit et renforce sa dynamique d’accompagnement”, presentation of the ReCyF framework, 18 March 2026.

    cyber.gouv.frBack to text

First, know what is running. Nothing sent to the machines.

Tell us what you operate: we’ll show you a case similar to yours, then your own data.