Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

Compliance obligations for CTPPs CTPPs must adhere to a comprehensive set of resil - ience obligations, compliance with which is monitored by the LO. Key requirements include the following. • Robust ICT risk management: Implementing and documenting a comprehensive framework with strict security controls, continuous system monitor - ing, and effective risk mitigation strategies. • Advanced resilience testing: CTPPs must undergo regular, advanced security assessments, including TLPT, to proactively identify and remediate vul - nerabilities. The results of these assessments are subject to review by the LO. • Incident management and co-operation: processes are established to manage and report incidents to their financial entity clients without delay. CTPPs must also co-operate fully with the lead overseer during any investigation into an incident. • Business continuity and disaster recovery: main - taining robust business continuity policies and disaster recovery plans that are regularly tested to ensure the rapid restoration of services after a disruption. • Unrestricted regulatory audit rights: granting the LO and, by extension, the national authorities, full rights to conduct audits and on-site inspections, and to access all relevant information and prem - ises. Enforcement Measures and Sanctions The LO has a powerful toolkit to enforce compliance. If a CTPP fails to meet its obligations, the following measures can be applied. Supervisory audits and on-site inspections The LO can conduct investigations and inspections at any time. These activities are used to verify compli - ance with DORA and may involve forensic reviews of systems and procedures, particularly where vulner - abilities have been identified. Recommendations and corrective measures If deficiencies are discovered, the LO will issue formal recommendations for corrective action. These recom - mendations are not mere suggestions; the CTPP is legally required to notify the LO of the measures it will

and corrective actions must be submitted within one month of the incident being fully resolved. Obligations for Third-Party Service Providers Indirect reporting obligation DORA does not impose a direct reporting timeline on third-party providers to regulators. However, their contracts must stipulate that they report any ICT inci - dent impacting the services provided to a financial entity without undue delay. This contractual obligation is critical, as it enables the financial entity to meet its For providers designated as CTPPs, the lead supervi - sor can request all the information needed to assess the impact of an incident independently of the finan - cial entity’s reporting channel. 3.4 Operational Resilience Enforcement Responsible Regulatory Authorities own strict reporting deadlines. Direct information requests Under DORA, the enforcement framework is multi- layered, combining EU-level direct supervision with the support of national authorities. The lead overseer (LO) The LO is either the EBA, EIOPA or ESMA. This is the central enforcement authority. One of the ESAs is appointed as the LO for each designated CTPP and has primary responsibility for direct supervision, investigation and sanctioning, regardless of where the CTPP is headquartered. National competent authorities (NCAs) The ACPR and the French Financial Markets Authority (AMF) act in a supporting role. They assist the LO dur - ing on-site inspections in France and enforce DORA’s rules against the financial entities they supervise. The European Central Bank (ECB) For significant credit institutions within the eurozone, the ECB collaborates closely with the LO to ensure that supervisory activities concerning CTPPs align with prudential oversight.

131 CHAMBERS.COM

Powered by