Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

Regional support network Complementing this central capability is a network of regional CSIRTs (CSIRT-Régions) and Cyber Resource Centres (CRCs), whose development is co-ordinated and supported by ANSSI as part of its national strat - egy. These regional bodies are not direct branches of ANSSI but are typically independent local structures designed to provide crucial “first-level” cybersecurity support. Their mission is to assist small and medium- sized enterprises (SMEs), local authorities and asso - ciations by offering free initial support in diagnosing incidents and by connecting them with nearby, trusted private-sector incident response providers. CNIL The CNIL is France’s national data protection authority. The CNIL’s mission consists of safeguarding individual rights while steering public and private organisations towards compliance, advising the government, and supporting innovation by anticipating the ethical impli - cations of emerging technologies. To fulfil this role, it holds broad supervisory and enforcement powers, including conducting on‑site or online inspections, issuing injunctions and imposing substantial fines. The CNIL is one of the regulators empowered with the enforcement of the AI Act in France. Section J3 of the Paris Criminal Prosecutor Office Section J3 has a national competence, alongside local criminal prosecutors, for the investigation and pros - ecution of all sorts of cyber infringements. It works with specialised investigators, mainly from the Central Office for Combating Crime Linked to Information and Communication Technologies (OCLCTIC), the Paris Cybercrime Unit (BL2C), the Gendarmerie Command in Cyberspace (COMCyberGend) and the General Directorate for Internal Security (DGSI). Arcep The Electronic Communications, Postal and Print Media Distribution Regulatory Authority (Arcep) is France’s national regulator for electronic communi - cations, postal services and print media distribution. It notably monitors the security obligations imposed on electronic communications operators. Such operators are legally required to ensure the continuity, availabil - ity and security of their networks under the European Electronic Communications Code (EECC) and the

publish practical guides and recommendations that set the standard for personal data security. The fol - lowing are a few examples: • CNIL, Data security guide, 2024; • CNIL, Deliberation No 2021-122 of 14 October 2021, adopting a recommendation on logging; • CNIL, Developer’s GDPR Guide of 27 January 2020; and • EDPB, Guidelines 9/2022 on personal data breach notification under the GDPR of 28 March 2023. The French cybersecurity agency (ANSSI) has also issued many technical recommendations that set out best practices for securing IT environments, including: • ANSSI, Securing multi-environment workstations (unclassified), 16 January 2026; • ANSSI, Managing the remediation of a cyber inci - dent, 16 January 2024; • ANSSI, Recommendations on digital nomadism, 2023; • ANSSI, Security recommendations for the architec - ture of a logging system, 28 January 2022; and • ANSSI, Recommendations regarding multi-factor authentication and passwords, 8 October 2021. 1.3 Cybersecurity Regulators ANSSI France’s public cybersecurity landscape is orchestrat - ed by ANSSI, which operates under the authority of the Secretary General for Defence and National Secu - rity (SGDSN). As the national cyber authority, ANSSI is responsible for proposing and implementing state cybersecurity policy, supervising regulated operators, and co-ordinating the operational response to cyber- threats. To deliver on these missions, its capabilities are structured in a tiered model. National-level operations Operating as an integral part of ANSSI, the national government Computer Emergency Response Team (CERT-FR) is the nation’s primary technical and opera - tional division for cyber defence. It is primarily respon - sible for handling incidents affecting the most critical entities, such as State ministries and operators of vital importance (OIVs).

123 CHAMBERS.COM

Powered by