← All resources

NIS2 France: are hotels and tourism in scope?

Published October 7, 2026 · 7 min read · CyberNovaLabs.io

Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.

The short answer

No. NIS2 France does not cover hotels and tourism as a sector: accommodation, food service, travel agencies and holiday residences do not appear in Annex I or II of Directive (EU) 2022/2555[1]. A hotel, a campsite or a holiday village does not become an "essential" or "important" entity because of its hospitality business.

And in France, as of 7 October 2026, there is still nothing to comply with: the Senate adopted the transposition bill on 12 March 2025, the text has been with the National Assembly as no. 1112 since 13 March 2025, and the legislative file is still marked "under construction"[3].

Your property is not safe for all that. In May 2026, three French tourism operators lost their reservation databases within 72 hours. What exposes a French hotel today is the GDPR, the police registration form and your corporate clients — not NIS2.

Are you in scope? The tests, in order

The first "no" means you are not in scope for that activity.

  1. Is your activity listed in Annex I or II? The 18 listed sectors run from energy and transport to health, water, digital infrastructure, chemicals, food, manufacturing and digital providers[1]. Tourist accommodation is not among them.
  2. Does another activity of the group appear there? This is the common trap. A hotel group that generates or resells electricity, operates a water abstraction point, runs a spa with medical treatment, a central kitchen or its own passenger transport may be in scope for that activity. ANSSI stresses that you must look at the legal entity's actual activities, not the brand[2].
  3. Do you sell other providers' inventory? "Providers of online marketplaces" are in Annex II[1]. Your own website selling your own rooms is not a marketplace; a central reservation service distributing independent properties is a different question, one for your counsel.
  4. Do you meet the size thresholds? In the general case you must be at least a medium-sized enterprise under Recommendation 2003/361/EC: 50 staff, or EUR 10 million in both turnover and balance sheet[2].
  5. Are you designated a "critical entity" under the CER Directive (EU) 2022/2557? If so, you are automatically an essential entity under NIS2[2].

Nobody will tell you. ANSSI has confirmed there will be no individual notification: each entity must determine its own status and register itself through the MonEspaceNIS2 platform[2].

Where France stands on 7 October 2026

The official timeline, as published by the Senate[3]:

DateStep
15 October 2024Bill no. 33 tabled in the Senate, fast-track procedure
12 March 2025Text no. 78 adopted by the Senate
13 March 2025Text no. 1112 transmitted to the National Assembly
10 September 2025Special committee report no. 1779
7 October 2026File still "under construction": no promulgated act, therefore no decrees

In practice: no NIS2 penalty is enforceable in France today. For reference, the directive sets caps of EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important entities[1]; ANSSI, the national competent authority, expects thousands of entities and around 600 different entity types to be covered[2]. If you track several countries, our cybersecurity deadlines by country page keeps the calendar: Belgium, Luxembourg and the Netherlands are already applying their national rules.

Three doors through which NIS2 reaches a hotel anyway

You are not regulated, yet the obligations arrive — by contract.

  1. Your clients' supply chain. Article 21 requires regulated entities to manage risks arising from their direct suppliers[1]. A business hotel sells room nights and meeting space to hospitals, transport operators, manufacturers and public bodies: all regulated. The supplier security questionnaire therefore arrives with the tender, not after it. We have collected those questions on our supplier security questionnaire page.
  2. Your own suppliers. PMS, channel manager, booking engine, connected locks, guest Wi-Fi, hosting: several fall within listed sectors themselves (cloud computing, managed ICT services, digital infrastructure)[1]. They will tighten contracts, notification deadlines and authentication requirements. You absorb that upgrade without being in scope.
  3. The forgotten side business. Industrial laundry, a central kitchen delivering other sites, hot water resold, shuttles run in-house: every time a support function is industrialised and sold outside, go back to test no. 2.

The sector's real risk, in French numbers

In May 2026, three French tourism operators disclosed a data breach within 72 hours.

OperatorDateWhat was exposed
Pierre et Vacances - Center Parcs14 May 20261.6 million booking records[6]
Belambra16 May 2026Unauthorised access to digital infrastructure and customer data[8]
Gites de France16 May 2026Close to 400,000 customers, across several departments[7]

What they share is not size but the point of failure: not the lock on room 214, but the reservation database — names, addresses, phone numbers, email addresses and stay histories accumulated over years. The Pierre et Vacances data went back to 2005[6].

The one-question test. If your PMS became unreachable tonight at 7 p.m., how many minutes before you can no longer check a guest in, and who do you call — name, mobile, written response time? If the answer is not on paper at the front desk, you have your first action item.

What French law already requires of a hotel, without NIS2

The individual police form. Every accommodation provider must complete one for each foreign guest on arrival: identity, date and place of birth, nationality, usual address, phone and email details, expected arrival and departure dates. It is kept for six months, then handed over on request to the police or gendarmerie (Article R. 611-42 of the CESEDA, order of 1 October 2015)[4]. Read it through a security lens: for six months you hold a named file of foreign nationals with their contact details. In many properties it lives in a binder behind reception or a spreadsheet with no password. It is the hotel's most sensitive file and its least protected one.

Tourist tax. You declare the property's characteristics and rates to the municipality, then collect, declare and remit the tax on local deadlines; under the per-person regime you keep evidence of chargeable nights[9]. A second stay register, usually with no written retention period.

The GDPR. Purposes, minimisation, guest notices, retention periods, processor agreements, a record of processing. Where a breach poses a risk, notification to the CNIL is due within 72 hours of becoming aware of it, and individuals must be informed where the risk is high[5]. On card data, PCI DSS is not a GDPR obligation: it is a payment-card industry standard that binds you contractually through your acquirer. The sound line remains never to store a card number in clear text in the PMS.

A French accounting firm is in the same position: outside the annexes, yet caught by subcontracting. Our guide on NIS2 in France for accounting firms and fiduciaries sets out that reasoning, and the one on estate agents and letting agents in Belgium shows how a country already applying the rules handles an unlisted sector that houses people.

The first five actions

  1. Inventory every database that holds guests: PMS, channel manager, OTA extranets, captive Wi-Fi, email tool, front-desk spreadsheets, police forms, restaurant till. For each: who has access, from where, and how long since that account was last used. Half a day, and every other action depends on it.
  2. Turn on two-factor authentication on email, the PMS, the channel manager and every remote supplier access. The most ordinary intrusions in this sector use a valid credential, not an exploit.
  3. Write down retention periods, then purge. Police form: six months[4]. Bookings: a period you set and can justify. Cards: never in clear text. A 2005 database still online in 2026 is not an asset, it is a liability.
  4. Demand three things from your PMS vendor in writing: its incident notification deadline, its recovery plan with stated durations, and the country where your data is hosted. No answer within two weeks is itself information.
  5. Write and rehearse the breach procedure: who decides, who notifies the CNIL within 72 hours[5], who writes to guests, who speaks to local press. Run it once as a dry run, out of season. The three May 2026 brands were judged on their communication as much as on the breach.

At CyberNovaLabs.io

We work with SMEs and groups in France, Belgium, the Netherlands and Luxembourg. For hospitality, two free tools frame the subject in half an hour: the NIS2 check, which tells you in a few questions whether one of your activities brings you into scope, and the email security check, which tests SPF, DKIM and DMARC on your domain — the entry point for fake booking emails and fraudulent payment requests. Our reference material sits on the cybersecurity page.

For a specific case — a multi-site group, a side activity, a client questionnaire due on Friday — let's discuss your property in 20 minutes. We will tell you plainly whether NIS2 applies to you, and what actually does. Services quoted on request; best-efforts undertaking.

Sources

  1. Directive (UE) 2022/2555 (NIS2), annexes I et II - EUR-Lex
  2. ANSSI - FAQ MonEspaceNIS2, perimetre des entites
  3. Senat - dossier legislatif, projet de loi relatif a la resilience des infrastructures critiques et au renforcement de la cybersecurite
  4. Prefecture de police - La fiche individuelle de police (fiches conseils hotels)
  5. CNIL - Notifier une violation de donnees personnelles
  6. TF1 Info - Pierre et Vacances-Center Parcs : 1,6 million de reservations affectees par une fuite de donnees
  7. RTL - Pres de 400 000 clients concernes : le reseau Gites de France touche par une cyberattaque massive
  8. 20 Minutes - Belambra, Pierre et Vacances, Gites de France : le point sur la vague de piratage du secteur du tourisme
  9. economie.gouv.fr - Taxe de sejour : quelles sont les obligations des hebergeurs ?
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked