Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — France

Command of the French regulatory framework — ANSSI, CNIL, NIS2, LPM — for companies and operators subject to enhanced security requirements.

Last updatedAugust 22, 2026

The local regulatory framework

France's cybersecurity framework is overseen by the Agence nationale de la sécurité des systèmes d'information (ANSSI) for information systems security, and by the Commission nationale de l'informatique et des libertés (CNIL) for personal data protection. The Loi de programmation militaire (LPM) governs the obligations of operators of vital importance (OIV), while the Référentiel général de sécurité (RGS) structures the requirements applicable to government online services. The NIS2 directive, currently being transposed, extends the scope of regulated entities well beyond the historical OIV category. The EBIOS Risk Manager method, issued by ANSSI, is the national reference for cyber risk analysis. Audit providers may also hold PASSI qualification from ANSSI to operate on sensitive systems. Financial entities subject to the EU DORA regulation face additional digital operational resilience requirements.

Concrete obligations

Application of the EBIOS Risk Manager method for cyber risk analysis and management, aligned with ANSSI's expectations

GDPR compliance for any processing of personal data, under CNIL oversight

Compliance with Loi de programmation militaire requirements for operators of vital importance (OIV) and essential service operators

Anticipation of obligations arising from the NIS2 transposition, which broadens the scope of regulated entities

Compliance with the DORA regulation for financial entities and their critical ICT providers

Priority sectors

FinanceIndustryPublic sector

Delivery modalities

Engagement model

Direct engagement

Methodology

Risk analysis conducted per EBIOS Risk Manager

Language

French

Local FAQ

What are the reference cybersecurity authorities in France?

ANSSI for information systems security, and CNIL for personal data protection.

What is the EBIOS Risk Manager method?

The cyber risk analysis method developed by ANSSI, used as a reference to structure risk assessment and prioritize security measures.

What is an operator of vital importance (OIV)?

An entity whose activity is deemed essential to the nation, and which is therefore subject to enhanced security obligations defined by the Loi de programmation militaire.

What is PASSI qualification?

A qualification issued by ANSSI to information systems security audit providers, certifying a level of competence and methodological rigor for engagements on sensitive scopes.

Does NIS2 apply to all French companies?

The directive broadens the scope of regulated entities beyond the historical OIV category; its precise scope depends on the size and sector of the organization, as defined by the national transposition. This topic has its own dedicated page on this site.

What is the DORA regulation and who is affected?

An EU regulation on digital operational resilience applicable to financial entities and their critical ICT providers. This topic has its own dedicated page on this site.

What services are most requested in France?

Security audits, penetration testing, GRC compliance and outsourced CISO support, particularly for entities affected by the LPM or the NIS2 transposition.

How does an engagement in France typically start?

With an initial scoping phase to identify the applicable regulatory regime (RGS, LPM, NIS2, DORA) and define the technical scope of the engagement.

Get in touch