News
Published on
08.10.2026

NIS 2 delayed: what to do with your files right now

Cléa Fontaine

Quick reply

Resilience Act postponed: your files can't wait. External exchanges, traceability, access: 5 priorities to tackle right now.

In this article

La loi Résilience, qui doit transposer NIS 2 du droit européen au droit français, est de nouveau reportée. Le contenu de la directive, lui, est connu depuis 2022. Pour un DSI, le report est donc une fenêtre utile : cartographier les échanges de fichiers avec l'extérieur, poser la traçabilité et revoir les accès sont des chantiers qui servent, quelle que soit la version finale du texte.

‍

What is the current status of NIS 2 transposition in France?

As of October 7, 2026, NIS 2 has still not been transposed in France. The bill regarding the resilience of critical infrastructure is awaiting its floor debate at the National Assembly. No new date has been set. At the opening of the Assises, Vincent Strubel (ANSSI) urged lawmakers not to over-transpose NIS 2 and deemed the Senate's version sufficient. He believes the three-year deadline for full compliance is no longer tenable, suggesting late 2028 for all entities, with dry-run exercises to be conducted in the meantime.

Resilience Bill delayed again

The review of the bill, which covers NIS 2, CER, and DORA, was scheduled for October 7. It was postponed during the conference of presidents on October 6, officially due to a busy schedule. Rapporteur Éric Bothorel hopes for it to be rescheduled within two to three weeks, though no date is set at this stage. (Source: Next).

This delay is the latest in a long process. The transposition deadline was set for October 17, 2024. The text passed through the Senate in early 2025 and was adopted by a special committee in September 2025. In July 2026, the European Commission referred France to the Court of Justice of the European Union for failure to transpose, alongside Ireland, Spain, and the Netherlands.

What remains unchanged: the content of the directive

Directive (EU) 2022/2555, known as NIS 2, has been published since December 2022 (text on EUR-Lex). Article 21 sets out minimum risk management measures. Article 23 governs incident notification. Article 20 establishes the liability of management bodies.

French law will specify the scope of the entities concerned, control procedures, and implementation deadlines. It will not rewrite the nature of the measures: transposition adapts a directive; it does not replace it.

Why is this delay the right time to act on your files?

File-related projects do not depend on the details of the French text, and they take time. Waiting for the law means starting them at the same time as everyone else. While waiting for the final text may seem prudent, file-related projects benefit from an early start for two reasons.

They require time. Inventorying file exchanges involves communicating with every department, and access rights reviews must be conducted folder by folder. This work does not depend on the final text.

They are useful right now. Knowing where sensitive files are, who accesses them, and who they are shared with helps in responding to client audits, cyber insurance questionnaires, or GDPR requests. NIS 2 simply adds to these existing needs.

The delay therefore provides time to move forward with peace of mind.
‍

Which NIS 2 requirements directly affect files?

Four of the ten measures in Article 21 directly concern how an organization stores, shares, and protects its files. Furthermore, the obligation to notify incidents (Article 23) requires knowing precisely what has been affected.

Access control and asset management

Article 21 targets access control policies and asset management. For files, the question is concrete: who accesses which folder, under what authority, and since when? A sensitive file whose location is unknown is not a managed asset.

Supply chain security

The directive mandates addressing the security of relationships with direct suppliers and service providers. In practice, a large portion of these relationships involves files: contracts, plans, production data, and accounting documents. External exchange is one of the points where the supply chain touches the information system.

Continuité d'activité et sauvegarde

La gestion des sauvegardes et la reprise des activités figurent dans les mesures minimales. Elles supposent de savoir quels fichiers sont critiques et où ils vivent. Des fichiers dispersés sur des postes et des messageries ne se restaurent pas de façon fiable.

Cryptographie et chiffrement

La directive demande des politiques d'usage de la cryptographie et, le cas échéant, du chiffrement. Pour les fichiers, cela concerne leur stockage comme leur transit vers l'extérieur.

Que faire dès maintenant ? 5 chantiers pour mettre ses fichiers en ordre

1. Cartographier les échanges de fichiers avec l'extérieur

Le partage externe est souvent le flux le moins visible pour la DSI. Pièces jointes, liens de transfert grand public, plateformes imposées par les partenaires, supports amovibles : chaque métier a ses habitudes.

Commencez par les cinq services les plus exposés (juridique, RH, achats, finance, projets). Pour chacun, recensez :

  • les canaux utilisés pour envoyer et recevoir des fichiers ;
  • les destinataires réguliers (clients, fournisseurs, experts, administrations) ;
  • la nature des fichiers échangés et leur niveau de sensibilité ;
  • la fréquence et le volume.

Le livrable : une matrice des flux externes, première pièce de votre analyse de risques.

2. Rendre chaque échange traçable

Un échange traçable répond à quatre questions : qui a envoyé quoi, à qui, quand, et qui l'a ouvert ou téléchargé. Sans ces données, un incident ne se qualifie pas, et un délai de notification devient difficile à tenir.

Concrètement : centraliser les échanges sortants sur un canal journalisé, fixer une durée de vie aux liens de partage et rendre ces journaux consultables par la DSI et le RSSI.

3. Revoir les droits d'accès aux fichiers sensibles

Les habilitations s'accumulent : changements de poste, projets terminés, prestataires partis. Une revue part des dossiers sensibles identifiés au chantier 1 et applique le principe du moindre privilège.

Trois points à vérifier en priorité : les comptes de personnes parties, les accès accordés à des externes et les droits hérités par défaut sur les arborescences.

4. Réunir la donnée qui compte à un seul endroit

Il ne s'agit pas de tout déplacer. Il s'agit de réunir les fichiers sensibles dans un lieu où les droits, les versions et l'historique sont maîtrisés. Chaque dossier sensible a un propriétaire identifié, une règle d'accès et une règle de conservation.

C'est aussi ce qui rend la sauvegarde et la reprise fiables : on restaure ce qu'on sait localiser.

5. Documenter pour pouvoir prouver

Compliance must be demonstrated. Formalize as you go: a file-sharing policy, the external data flow register from project 1, the access review log, and the incident management procedure for files. These are the documents that auditors or inspectors will ask for first.

External sharing and file platforms: two solutions for these projects

The deciding factor is simple: does the data stay in your current tools, or does it move to a dedicated space?

For projects 1 and 2, the need is to exchange with external parties without opening up your IS. This is the role of Voltn Share, for external file sharing. It sits on top of your existing tools with no migration required, and every exchange is tracked. External users do not enter your directory and do not consume licenses. Nothing is stored: files are purged after 30 days. IT and security teams maintain visibility over data flows, and deployment takes only days.

For projects 3 through 5, the need is to bring essential data together in one place. This is the role of Voltn Workspace, the enterprise file platform. Store, co-edit, sign, validate, track, and search: the entire file lifecycle in one place, with granular permissions and full traceability. Your document management is compliant by design.

‍

{{cta-section}}

‍

{{faq-section}}

No items found.
No items found.

Definition

No items found.

FAQ

No questions found.

Best practices / Common pitfalls

No items found.

Key figures

No items found.

Key takeaways

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

You could keep all your documents on a floppy disk.
Vintage office chair with a pile of folders and a beige corded telephone, handset off the hook on red carpet.

But let's be honest, our cloud-based file storage and sharing solution is just easier.