Command of the French regulatory framework — ANSSI, CNIL, NIS2, LPM — for companies and operators subject to enhanced security requirements.
Last updated — August 22, 2026
France's cybersecurity framework is overseen by the Agence nationale de la sécurité des systèmes d'information (ANSSI) for information systems security, and by the Commission nationale de l'informatique et des libertés (CNIL) for personal data protection. The Loi de programmation militaire (LPM) governs the obligations of operators of vital importance (OIV), while the Référentiel général de sécurité (RGS) structures the requirements applicable to government online services. The NIS2 directive, currently being transposed, extends the scope of regulated entities well beyond the historical OIV category. The EBIOS Risk Manager method, issued by ANSSI, is the national reference for cyber risk analysis. Audit providers may also hold PASSI qualification from ANSSI to operate on sensitive systems. Financial entities subject to the EU DORA regulation face additional digital operational resilience requirements.
Engagement model
Direct engagement
Methodology
Risk analysis conducted per EBIOS Risk Manager
Language
French
ANSSI for information systems security, and CNIL for personal data protection.
The cyber risk analysis method developed by ANSSI, used as a reference to structure risk assessment and prioritize security measures.
An entity whose activity is deemed essential to the nation, and which is therefore subject to enhanced security obligations defined by the Loi de programmation militaire.
A qualification issued by ANSSI to information systems security audit providers, certifying a level of competence and methodological rigor for engagements on sensitive scopes.
The directive broadens the scope of regulated entities beyond the historical OIV category; its precise scope depends on the size and sector of the organization, as defined by the national transposition. This topic has its own dedicated page on this site.
An EU regulation on digital operational resilience applicable to financial entities and their critical ICT providers. This topic has its own dedicated page on this site.
Security audits, penetration testing, GRC compliance and outsourced CISO support, particularly for entities affected by the LPM or the NIS2 transposition.
With an initial scoping phase to identify the applicable regulatory regime (RGS, LPM, NIS2, DORA) and define the technical scope of the engagement.