Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

ICT Risk Management Framework Financial entities must implement a sound, compre - hensive and well-documented ICT risk management framework. This is the operational core of DORA and must include the following. • Strategies and policies: detailed policies for the protection, prevention and detection of anomalous activities, as well as response and recovery. • Asset management: identification, classification and mapping of all supporting ICT assets and criti - cal business functions. • Business continuity: development and annual testing of business continuity plans and disaster recovery plans. • Testing and review: the framework must be reviewed at least annually and after any major incident. It must be subject to regular, risk-based digital operational resilience testing, including, for significant entities, advanced TLPT at least every three years. Incident Management and Reporting DORA harmonises the reporting process. Internal incident management Financial entities must have a process in place for managing and classifying ICT-related incidents. Incident materiality criteria Reporting to national regulators (such as the ACPR or AMF) is mandatory for any “major ICT-related inci - dent”, where materiality is determined by factors including the number of clients affected, service dura - tion, geographical spread, loss of data confidentiality integrity, or availability, impact on critical services and functions, and direct and indirect costs and economic impact. Reporting timelines for financial entities The reporting timeline is multi-staged. It begins with an initial notification to the relevant national regulator. This must be submitted without undue delay, and no later than 24 hours after the incident has been clas - sified as major. This is followed by an intermediate report within 72 hours of the initial notification, provid - ing an update on the situation. Finally, a comprehen - sive final report detailing the root cause, overall impact

financial entity notification and termination rights to manage supply chain risk. • Regarding oversight, contracts must grant the financial entity, its auditors and regulators with unrestricted rights to access, inspect and audit the provider’s systems, records and premises. These rights are supplemented by the direct investiga - tory powers of the lead supervisor for CTPPs and include requirements for advanced security testing, such as threat-led penetration testing (TLPT). • To prevent vendor lock-in, financial entities must develop, maintain and test comprehensive exit strategies. Contracts must oblige providers to sup - port an orderly transition and ensure the secure, complete and cost-effective portability of data. • While DORA does not impose strict data locali - sation requirements, it does require contracts to specify all data processing and storage locations to guarantee unimpeded supervisory access. For non-EU CTPPs, the mandatory EU subsidiary serves as the legal anchor for these rights. • Finally, financial entities must actively manage concentration risk by assessing dependencies on single providers within their formal risk framework. ESAs monitor this risk at a macro, sector-wide level to identify potential systemic vulnerabilities. 3.3 Key Operational Resilience Obligations Financial entities are subject to a set of specific obli - gations designed to create a robust and consistent framework for managing technology-related risks. Governance and Internal Control Ultimate responsibility lies with the entity’s manage - ment body. Their obligations include: • defining and approving the digital operational resil - ience strategy; • setting risk tolerance levels for ICT risk; • allocating sufficient budget; • overseeing all arrangements with ICT third-party providers; and • maintaining adequate ICT risk knowledge. Financial entities must also establish control functions to ensure the proper implementation and monitoring of the risk framework.

130 CHAMBERS.COM

Powered by