NIS2 forces companies to encrypt. CSAR prevents them from really doing it.

NIS2 forces encryption on businesses. CSAR wants to crack it. Same institution. Two incompatible texts. What it means for you.

NIS2 forces companies to encrypt. CSAR prevents them from really doing it.

July Update 2026. The calendar has shifted: on July 9, the European Parliament allowed the renewal of Chat Control 1.0 without the 361 votes needed to block it, despite the majority voting against it with end-to-end encryption explicitly excluded from the text. CSAR 2.0, the one that contradicts NIS2 and is described here, will resume trilogue talks in September: the “May 4” mentioned below is outdated. Details in the radar.

Brussels has a brilliant idea: forcing you to encrypt your data. They also have another idea, less brilliant but more totalitarian: being able to read it whenever they want.

These are not two policies from two different institutions. It’s the same European Commission, a few months apart, signing both texts (yes, it’s possible, I assure you: welcome to Absurdistan).

NIS2 forces you to secure yourself or face sanctions. CSAR 2.0 forces you to leave a backdoor open so they can spy on you cheaply.

And, like any good mess of texts cooked up by our dear European technocrats, under the pressure of our dear politicians, the right hand doesn’t seem to know what the left hand is doing.

Here’s what this means for your digital protection, and why this inconsistency isn’t an accident.


NIS2: The EU finally discovers cybersecurity

The NIS2 directive came into effect in January 2023. It was called NIS1 before, covering around 500 entities in France. NIS2 expands the scope to 15,000-18,000 French entities according to the ANSSI.

It’s no longer just operators of critical infrastructures; it’s any company with 50 employees and €10 million in turnover or assets in the covered sectors. Healthcare, energy, transport, digital, finance. The hospital sector is listed in Annex I as highly critical.

Article 21 is the heart of the matter. It lists ten mandatory measures, including encrypting data in transit and at rest, multifactor authentication (MFA), and setting up secure communications. In plain language: if you handle data in a sector covered by NIS2, encryption is no longer a recommendation, it’s a legal obligation.

The structural novelty of NIS2 is Article 20. Responsibility no longer lies solely with the company; it lies with the physical person in charge. No more scapegoating the CISO, no more “our provider handled it”. The board members are personally responsible for compliance (Doc, if you’re there, your office is going to be busy, I know some executives heading straight for the tranxene).

France, however, is lagging behind (Same as ever, huh?). The deadline for transposition set by the EU was October 17, 2024. We’re approaching May 2026 (try meeting one of your deadlines and we’ll talk), and the text still hasn’t been voted on in the National Assembly. This delay doesn’t exempt anyone: NIS2 obligations are coming, the question is when, not if.

And in the French bill, one article stands out. Article 16 bis of the bill explicitly prohibits imposing forced access in encryption tools. No provider of encryption solutions can be forced to allow imposed access to their tools.

That’s where things get interesting.


CSAR: The EU wants to read what it just told you to encrypt

CSAR, officially the Child Sexual Abuse Regulation, is the other text. For the full details of the mechanism and the political dossier, the article on Chat Control 2.0 explains it all.

You’ll see that while the goal is laudable and one we all share, the methods are more reminiscent of totalitarian practices of the past than of healthy democracy.

The short version:

CSAR would force messaging apps to scan the content of your messages on your device before they’re encrypted. The technical term is “client-side scanning”.

In practice: your message is read on your device before it’s encrypted and sent. In France, allowing a public agent to access the content of a correspondence without authorization is an aggravated offense. Apparently, when you’re the EU, you can do it, and it doesn’t bother you.

End-to-end encryption remains “technically intact” during transport but is circumvented before it applies. Scanning before encryption is encryption for show.

The status of the dossier at the time of publication: the EU Council adopted its position on November 26, 2025. Trilogue talks, the opaque negotiations between Parliament, Council, and Commission where the final text is cooked up, have begun. Next trilogue: May 4, 2026. Formal adoption targeted: July 2026.

The terms have evolved since the first version: “client-side scanning” is now called “risk mitigation measures” in official documents. The packaging is more presentable. The effect on your device remains the same.

The same European Commission that produced NIS2 is pushing CSAR. It’s not a metaphor.

Read: Chat Control 2.0: The EU wants to read your messages before you send them: mechanism, Signal, Proton, and what you can do.


The fundamental contradiction

Put the two texts side by side.

NIS2, Article 21: encrypt data in transit and at rest, MFA, secure communications. Legal obligation, personal responsibility of the director, sanctions for non-compliance.

CSAR: scanning messages before encryption on every device, no judicial warrant, no user notification, for all communications, not just suspicious ones.

The scan reads everything, and an AI decides your fate. False positives are going to be spectacular. Let’s bet that the dawn raid, with or without apologetic platitudes, will be too.

Why these two texts are physically incompatible: to scan content “before encryption”, it must be accessible, at some point, in plain text, by a third-party process. This process creates a mandatory access point: assumed and legalized in the case of CSAR. This provision is totally incompatible with the objectives of NIS2.

This is precisely what French law, in the NIS2 transposition bill, via its Article 16 bis, prohibits imposing on encryption providers.

The same Commission wrote both texts. The commissioner for cybersecurity oversees NIS2. The commissioner for home affairs pushes CSAR. They’re not enemy ministries. In France, it’s the same story: the ANSSI publishes security guidelines, the DGSI reports its needs to its minister, and once again, interests diverge.

The COM(2025)740 final (November 27, 2025), the Commission’s own evaluation report, admits that the system does not allow a demonstrable link to be established between generated reports and actual convictions, nor can it quantify the number of children actually identified through it.

This isn’t external criticism. It’s the institution behind the text acknowledging, in its own balance sheet, the methodological impossibility of validating the tool it wants to impose on 450 million Europeans.

We’re building infrastructure for mass surveillance.

Its pretext doesn’t hold up, given the implemented technique and the unproven results.


What this says about your protection

NIS2 remains a good text. The obligation to encrypt, take cybersecurity seriously, and hold directors accountable are real advances. If you’re in a covered entity, NIS2 will force you to do what you should have done ten years ago. That’s not the problem.

The problem is what this inconsistency reveals about the solidity of your protection.

Individual digital protection cannot rely on the regulatory coherence of institutions. They structurally contradict each other. NIS2 forces you to encrypt today. CSAR wants to make encryption circumventable tomorrow. The law protecting you and the law spying on you can coexist in the same legal corpus with equal formal legitimacy.

What really protects you is technical design, not legal compliance.

Signal can’t implement client-side scanning without breaking its architectural model. That’s why Meredith Whittaker said she’d rather leave the European market than do it. It’s not a stance; it’s a technical impossibility disguised as a political position. Proton works on the same principle.

A tool whose architectural design prevents scanning is protected differently from one that “respects the law in force”. The law can change. Architecture remains. That’s your guarantee.

For entities covered by NIS2, a caveat is in order: this compliance remains mandatory and necessary. Encrypting your data in transit and at rest, implementing MFA, securing internal communications are real obligations with real sanctions if not met.

Implementing them with tools whose design is solid, whose code is audited, whose jurisdiction is favorable, is stacking two layers of protection instead of one. NIS2 and prudent architectural design are not opposed. They should complement each other.

What doesn’t hold up is believing that “NIS2 compliance = complete protection” if CSAR passes. Legal compliance becomes an insufficient safety net when another law creates a breach in what the first one demanded be built.

The French bill’s Article 16 bis, which prohibits scanning in encryption tools, is a real line of defense. The fact that it coexists in the same bill as NIS2 obligations is encouraging. The fact that it’s in political friction with CSAR, pushed by the same Commission, gives an idea of the terrain on which this tension will play out in the coming months.


In summary

Two texts, one institution, two opposing directions. NIS2 forces you to encrypt, holds directors accountable, and in the French bill, explicitly prohibits scanning in encryption tools. CSAR wants to scan before encryption, i.e., circumvent encryption by design, without a judicial warrant, for all your communications.

This isn’t a contradiction that can be overcome with an amendment. It’s a structural incoherence between two institutional priorities that are incompatible: securing and surveilling.

Concretely, the points to watch:

1. If you’re covered by NIS2, get a head start on compliance without waiting for the French vote. Obligations are coming, transposition delay or not.

2. Choose tools whose technical design makes forced access impossible, not just tools that “respect current regulations”. Regulations change. Architecture less so.

3. Follow CSAR trilogue talks: May 4, 2026, is the next turning point. Public pressure worked on Chat Control 1.0.

For a deeper dive into end-to-end encryption and why it remains the only solid bulwark, the upcoming article on the subject will explain.

Read: Chat Control 2.0: The EU wants to read your messages before you send them

If digital sovereignty concerns you beyond just the regulatory framework, the concept is laid out in the foundational article.

Read: Digital sovereignty: What is it, really?

The ANSSI’s dedicated NIS2 page lists the covered sectors and obligations in detail.