French Cybersecurity Authority (ANSSI)

The French Cybersecurity Authority

The Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI) is France’s national cybersecurity authority, established by Decree No. 2009-834 of 7 July 2009. Placed under the authority of the Prime Minister and reporting to the Secrétariat Général de la Défense et de la Sécurité Nationale (SGDSN), ANSSI is responsible for defending national information systems, providing expertise and technical assistance, and developing security standards and certification. Its mission has expanded considerably in response to the growing sophistication and frequency of cyber threats, and it now exercises both regulatory and operational functions.

Certification and Standards

ANSSI operates France’s cybersecurity certification framework. It issues certifications de sécurité for information technology products and services under the Schéma Français de Certification de la Sécurité des Technologies de l’Information. The agency evaluates products against defined security criteria, issuing Certificats de Sécurité de Premier Niveau (CSPN) and Profils de Protection (PP) aligned with the Common Criteria framework (ISO/IEC 15408). ANSSI also maintains the SecNumCloud certification for cloud service providers, which has become a de facto requirement for hosting sensitive public sector data under the loi de programmation militaire requirements.

The agency develops technical guides and security recommendations (guides ANSSI) covering network architecture, cryptographic protocols, authentication, incident response, and secure software development. These guides, while not always legally binding, establish the professional standard of care for cybersecurity in France and are frequently referenced by regulators and courts.

Incident Reporting Under NIS2

The transposition of the EU Network and Information Security Directive (NIS2, Directive 2022/2555) into French law has expanded and harmonised incident reporting obligations. Under the NIS2 framework, operators of essential services (Opérateurs de Services Essentiels, OSE), digital service providers, and other covered entities must notify ANSSI of significant cybersecurity incidents without undue delay, and in any event within 24 hours of becoming aware of the incident, followed by a detailed notification within 72 hours and a final report within one month.

Significant incidents are defined by criteria including the number of affected users, the duration of the service disruption, the geographic extent of the incident, and the economic impact. ANSSI serves as the national Computer Security Incident Response Team (CSIRT) and single point of contact for cybersecurity cooperation within the European Union. The agency coordinates incident response, facilitates information sharing among affected entities, and may issue warnings to the public or to specific sectors. The loi de programmation militaire (LPM) 2019-2025 reinforced ANSSI’s powers, including the authority to conduct inspections of critical infrastructure operators and to impose administrative sanctions for non-compliance.

Critical Infrastructure: Opérateurs d’Importance Vitale

France’s critical infrastructure protection regime is based on the concept of Opérateurs d’Importance Vitale (OIV). Designated by sectoral authorities under the Code de la défense, OIVs are operators whose activities are vital to the nation’s defence, economic security, or public health. The loi de programmation militaire 2013-2019 (Article 22) imposed mandatory cybersecurity obligations on OIVs, requiring them to implement security measures defined by ANSSI, to use certified security products for critical systems, and to submit to ANSSI inspections.

The OIV regime covers sectors including energy, transport, health, water supply, digital infrastructure, finance, food supply, and space operations. Operators must adopt a Politique de Sécurité des Systèmes d’Information (PSSIE) approved by ANSSI and must report significant security events. The regime has been progressively extended to local authorities and health establishments through the LPM 2019-2025.

State Cyber Defence

ANSSI works in close coordination with military cyber defence structures, particularly the Commandement de la Cyberdéfense (COMCYBER) under the Ministry of the Armed Forces. While ANSSI is responsible for the protection of civilian information systems and for national cybersecurity policy, COMCYBER conducts offensive cyber operations and defends military networks. The LPM 2019-2025 allocated significant resources to cyber defence, including the recruitment of additional ANSSI personnel and the development of a national cyber threat intelligence capability.

The Agence Nationale de la Sécurité des Systèmes d’Information also participates in European and international cybersecurity cooperation. It hosts the Centre Européen de Compétence en CyberSécurité (ECCC) regional hub and collaborates with national CSIRTs across the European Union. The agency’s annual report provides a comprehensive assessment of the threat landscape, including state-sponsored attacks, ransomware campaigns, and vulnerabilities affecting critical systems.