C‑DRONE
Night aerial view of an illuminated urban area

C-DRONE GUIDE · 7 AUGUST 2026

The Resilience Act (NIS2) and drone services: what essential entities must check

Fifteen thousand French companies and public bodies are about to face a new requirement: proving their subcontractors are not the weak link in their cybersecurity. The Resilience Act, currently before Parliament to transpose the EU's NIS2 directive, extends information security well beyond an organisation's own IT system — all the way to any provider who accesses a site, including a drone pilot commissioned for a roof inspection, an industrial-site orthophoto, or a thermal survey of an electrical substation. Here is what the law actually changes, who it applies to, and what an informed client should check before commissioning a mission on a sensitive site.

Published on 7 August 2026, reviewed on 7 August 2026 — regulations in force as of August 2026.

Where the Resilience Act (NIS2) stands in France in 2026

The EU's NIS2 directive (text 2022/2555) has required a stronger level of cybersecurity from organisations deemed critical to the economy and society since late 2022. Its transposition into French law, due by October 2024, takes the form of the bill on the resilience of critical infrastructure and the strengthening of cybersecurity — the "loi Résilience", which transposes two other EU directives in the same text: the one on the resilience of critical entities (CER) and, for the financial sector, DORA. Adopted at first reading in the Senate on 12 March 2025, the text still needs to go through a public session at the National Assembly, now expected in September 2026; its promulgation, followed by implementing decrees, will follow according to the parliamentary calendar.

Once in force, the law will designate ANSSI as the national supervisory authority and will subject around 15,000 French entities to cyber-risk management duties, split into two categories depending on size and sector: "essential entities" (energy, transport, health, drinking water and wastewater, digital infrastructure, space, public administration…) and "important entities" (waste management, chemicals, food, manufacturing, postal services…). The penalties are severe — up to €10 million or 2% of worldwide turnover for an essential entity — and a significant incident will have to be reported on a strict timeline: early warning within 24 hours, formal notification within 72 hours, final report within one month.

Why this text concerns your drone providers too

The Resilience Act does not stop at an entity's own internal information system: its core risk-management article explicitly requires assessing the security of the supply chain — that is, of the suppliers and providers who access the entity's systems or data. A landmark 2014 study in Technovation by Scott Boyson did much to establish this idea in risk-management thinking: the author shows that an organisation's cyber risk depends as much on its own security as on that — often less controlled — of its IT and service subcontractors, and that ignoring this link leaves a backdoor open into the whole system (see the study on Google Scholar). A pilot flying over a power plant, an electrical substation, a hospital or a waste sorting centre for a photogrammetry or thermal survey mission falls squarely within that scope: they produce, carry and temporarily store data describing the site's layout, equipment and, at times, its physical vulnerabilities.

The drone itself adds a technical dimension to that risk. A 2020 review in the journal Internet of Things by Yaacoub, Noura, Salman and Chehab catalogues the attack surfaces specific to drone systems — the radio link between the drone and the ground station, onboard storage, the flight-control app, data transfer to the provider's cloud — and sets out recommendations for securing them (see the study on Google Scholar). A drone provider is generally not itself an entity subject to the Resilience Act — unless it separately falls under one of the 18 listed sectors — but its security practices effectively become something its essential or important client now has to document.

What a client should check before commissioning a mission

In practice, a company or public body in an essential or important sector does not need to wait for the text's final promulgation to start building these questions into its specifications — several clients in the energy and health sectors are already doing so ahead of time. A few points worth checking with a provider before commissioning a mission on a sensitive site:

This level of scrutiny adds to — without replacing — what the GDPR already requires whenever a mission captures identifiable people or property, detailed in our guide on GDPR for professional drone operators: the GDPR protects personal data, while the Resilience Act protects the availability and integrity of the entity's own systems and data, including data that concerns no individual at all — an HV/MV substation's layout or an industrial site's orthophoto falls into neither of the GDPR's categories, yet still sits squarely within the Resilience Act's scope if the client is a covered entity.

In-house fleet or outside provider: the angle changes, not the duty

Faced with these new requirements, some essential entities are asking whether it is worth bringing their drone fleet in-house rather than using an outside provider — a question, costs included, that we cover more broadly in our guide on building an in-house drone fleet versus outsourcing. On the Resilience Act alone, going in-house does not remove the duty: the data still needs securing, but its handling then falls directly under the entity's own information-security management system, already audited under its other obligations. Outsourcing shifts the burden: the entity has to formalise a risk assessment of the provider — the supply chain the text targets — and document it, which in practice looks like a contract clause and a security questionnaire rather than a full technical audit for a one-off mission.

For a classified site such as an HV/MV electrical substation, a healthcare facility or a waste sorting centre, this formalisation stays light compared with the security already in place on site: access badges, prevention plans, coordination with the site operator. It is one more item on that list, not a separate project of its own.

What it costs, and the questions worth asking

Since the Resilience Act had not yet been promulgated as of summer 2026, no serious provider currently charges extra to comply with it: the good practices described above — identified hosting, data deletion after delivery, encrypted transfer — are basic digital hygiene, not an add-on service. The sensible move is to put them in writing in the quote or purchase order, alongside the professional liability insurance cover already required for any mission. Request a quote and, if your organisation falls under an essential or important sector, state the data-security points you want written into the contract.

Is a drone provider directly subject to the Resilience Act? Generally not, unless it separately falls under one of the 18 covered sectors; but its security practices become something its covered client has to check and document.

When will the law take effect? The text still needs to go through a public session at the National Assembly, now expected in September 2026; its promulgation and implementing decrees will follow.

Isn't GDPR already enough? No: GDPR protects personal data, while the Resilience Act protects the availability and integrity of the entity's own systems and data, including data that concerns no individual at all.

What does an essential entity risk if it doesn't vet its subcontractors? The penalties target the entity itself, not the subcontractor: up to €10 million or 2% of worldwide turnover for a serious failure of its risk-management duties, including those tied to its supply chain.

Request a free quote

Put it into practice

Also worth reading