FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
systems must be operated by certified service provid - ers to ensure real-time detection of cyber-threats. Audits and compliance OIVs must regularly undergo security inspections and technical audits, often conducted at their own expense by ANSSI or State-certified auditors, to verify the resilience and compliance of their critical infra - structure. The Draft Resilience Bill seeks to harmonise the cyber - security obligations applicable to OIVs. It explicitly provides that the (current) former cyber-specific rules for OIVs under the French Defence Code are replaced by the new NIS2 Directive framework, so that OIVs will have to implement the same cybersecurity risk man - agement and incident-reporting obligations as EEs. 2.3 Incident Response and Notification Obligations Essential and Important Entities The framework under the 2018 Security Law, trans - posing the NIS Directive, is based on a general prin - ciple. OESs and DSPs are required to notify ANSSI of incidents having a “significant” impact “without delay”. The implementing orders specify the modali- ties of the declaration (ie, via a form) but do not pre - scribe a mandatory multi-stage reporting process with fixed, harmonised deadlines across all sectors. The NIS2 Directive alters this by mandating a uniform, multi-stage reporting process for any “significant incident” affecting both EEs and IEs. An incident is deemed to be significant if: • it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; or • it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. For entities such as cloud providers and MSPs, the NIS2 Implementing Regulation of 17 October 2024 provides directly applicable, concrete thresholds, such as a complete service unavailability of more than 30 minutes or a direct financial loss exceeding EUR500,000.
The reporting timeline is now highly structured. • Early warning: within 24 hours of becoming aware of an incident, an early alert to ANSSI. • Incident notification: within 72 hours, a more detailed incident notification. • Final report: no later than one month after the inci - dent notification, a final report including: (a) a detailed description of the incident, including its severity and impact; (b) the type of threat or root cause that is likely to have triggered the incident; (c) applied and ongoing mitigation measures; and (d) where applicable, the cross-border impact of the incident. In France, notifications are to be made to ANSSI. The latest version of the Draft Resilience Bill provides that the ANSSI will be required to inform the CNIL of any incident that may constitute a personal data breach. Operators of Vital Importance (OIVs) It is important to note that the OIV regime, codified in the French Defence Code, imposes stringent incident- reporting requirements that go beyond the general NIS Directive framework. This strict national regime is a key reason why OIVs’ core SIIVs were explicitly carved out of the 2018 Security Law’s scope. Key OIV obligations include the following. • Immediate notification: OIVs must notify ANSSI “without delay” of any incidents affecting the secu - rity or functioning of their SIIVs. • Iterative reporting: the process is dynamic, requir - ing OIVs to transmit all available information as they become aware of it and to supplement this report throughout the crisis. The specific data to be communicated is often detailed in classified, sector-specific rules. To avoid a dual-reporting structure, the Draft Resil - ience Bill plans to repeal these specific provisions. For cybersecurity incidents, OIVs will have to follow the same multi-stage notification process to ANSSI as EEs and IEs.
128 CHAMBERS.COM
Powered by FlippingBook