FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
2.4 State Responsibilities and Obligations The French State, primarily through its national cyber - security authority, ANSSI, has extensive responsibili - ties for ensuring national cyber-resilience, managing threat intelligence and fostering co-operation. Under the current framework of the 2018 Security Law, the French State’s primary responsibility is to formally designate the OESs by order of the Prime Minister. By contrast, under the upcoming NIS2 Directive, an entity will be directly subject to the law as either EE or IE if it meets the new criteria of sector and size, placing the initial onus on the entity to self-assess and register with the national authority, ANSSI. Compliance is monitored by the national author - ity, ANSSI, which is empowered to conduct security audits and on-site inspections. In its support role, ANSSI centralises incident reports and disseminating threat intelligence to the ecosystem. This co-operative approach is anchored in concrete initiatives such as the Campus Cyber – a physical hub co-locating State experts with private companies – and practical tools such as the MonEspaceNIS2 digi - tal platform, designed to guide businesses in their compliance efforts with the upcoming framework. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation DORA is the primary legal framework that governs operational resilience. As a directly applicable EU legislation, DORA establishes a comprehensive and harmonised set of rules for managing ICT risks, super - seding prior national laws and covering both financial entities and their critical technology providers. Material Scope of Application Scope for supervised financial entities DORA applies to a wide range of financial entities operating in France. These include traditional entities such as: • credit institutions;
• investment firms; • insurance and reinsurance undertakings; and • payment institutions. It also covers newer participants, including crypto- asset service providers, crowdfunding platforms, and managers of alternative investment funds (AIFMs). A key feature is the principle of proportionality, where - by requirements are tailored to an entity’s size, busi - ness profile and complexity. Scope for critical third-party providers For technology providers, DORA introduces a direct oversight framework for critical ICT third-party provid - ers (CTPPs), such as cloud computing or data centre service providers, whose failure could cause systemic risk. CTPPs are designated by European Supervisory Authorities (ESAs) based on specific criteria, including the number of financial entities that rely on them and their systemic importance. Territorial scope of application The scope of application covers the following: • entities with registered offices in France; • EU operations of third-country financial institutions; and • third-country ICT providers – providers designated as “critical” to EU financial entities are required to establish a corporate presence within the EU. 3.2 ICT Service Provider Contractual Requirements DORA defines ICT service providers very broadly as any undertaking providing ICT services. This includes everything from cloud platforms and data centres to software vendors and managed service providers. DORA stipulates that contracts with ICT providers must include robust provisions covering the entire life cycle of the relationship. The key requirements are as follows. • For subcontracting, contracts must state whether it is permitted for critical functions, ensure the primary provider remains fully liable, and grant the
129 CHAMBERS.COM
Powered by FlippingBook