Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

Cyber-risk management The 2018 Security Law requires designated OESs to comply with a detailed list of 23 security rules set out in a specific governmental order, such as conducting security accreditation, implementing network parti - tioning and establishing crisis management proce - dures. These stringent rules do not apply to DSPs, which are subject to a much more general and less prescriptive set of obligations defined directly in the law. The new framework under the NIS2 Directive and the Draft Resilience Bill eliminates this distinction and mandates a single, non-exhaustive baseline of at least ten security measure categories that all in-scope enti - ties – both EEs and IEs – must implement, including: • risk analysis and information system security poli - cies; • incident handling; • business continuity, disaster recovery and crisis management; • security in network and information systems acqui - sition, development and maintenance, including vulnerability handling and disclosure; • policies to assess the effectiveness of risk-man - agement measures; • basic cyber hygiene practices and cybersecurity training; • policies on the use of cryptography and encryp - tion; and • human resources security, access control policies and asset management. This new baseline is complemented by the NIS2 Implementing Regulation of 17 October 2024. This regulation is important as, for a specific list of entities, it moves beyond the high-level principles of the NIS2 Directive to define precise, legally binding require - ments. It applies specifically to DNS service providers, TLD registries, cloud computing providers, data centre service providers, content delivery network providers, MSPs, MSSPs, online marketplaces, online search engines, social networking platforms and trust service providers. For these entities, it details technical and methodological requirements, as well as significant incident thresholds (see 2.3 Incident Response and Notification Obligations ).

The implementation of the NIS2 Directive can be sup - ported by aligning with the ISO/IEC 27001 standard, which provides a robust framework for an Informa - tion Security Management System (ISMS). However, it should be noted that certification to ISO/IEC 27001 alone is not sufficient, as it does not automatically cover all the specific prescriptive measures required under NIS2. It should therefore be used as a valuable, complementary tool, while full compliance in France will ultimately need to be measured against ANSSI’s forthcoming national framework. Supply Chain Security Under the 2018 Security Law transposing the NIS Directive, supply chain security is not an explicit, stan - dalone requirement. It is only implicitly covered under the general risk management obligations for OESs. Under the NIS2 Directive, this will become a core, explicit obligation. Entities must manage risks aris - ing from their direct suppliers and service providers, including assessing the overall quality and cyberse - curity practices of third-party products and services. Operators of Vital Importance Once designated, OIVs are subject to a stringent regulatory framework codified in the French Defence Code. Their obligations include the following. Organisational measures OIVs must appoint a Delegate for Defence and Secu - rity ( Délégué pour la défense et la sécurité ), who acts as the primary point of contact for the State and over - sees the protection of the entity’s vital interests. Physical and strategic planning OIVs must identify their Points of Vital Importance (PIVs). They are required to draft an Operator Security Plan (PSO) and individual External Protection Plans to restrict access to sensitive facilities and systems to authorised personnel only. The Draft Resilience Bill updates this, now requiring an “Operator Resilience Plan” and, for each PIV, a “Specific Resilience Plan”. Cybersecurity and monitoring OIVs are specifically mandated to implement quali - fied detection systems (such as PDIS) to monitor their Information Systems of Vital Importance (SIIVs). These

127 CHAMBERS.COM

Powered by