Cybersecurity 2026

FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields

have a proven track record in threat intelligence and penetration testing. For each test, at least one of the testing providers involved must be an independent, external entity. Cross-border recognition and reliance DORA establishes the crucial principle of mutual rec - ognition. If a financial group’s subsidiary in another EU member state conducts TLPT in compliance with DORA, the French authorities must recognise it as ful - filling the requirement for the group’s French opera - tions. Enforcement and non-compliance Failure to conduct a required TLPT or to adequately address the identified vulnerabilities constitutes a breach of DORA: • supervisory actions – the ACPR and AMF can issue binding orders requiring an entity to conduct a test or implement a remediation plan to address identi - fied weaknesses; and • sanctions – non-compliance can lead to admin - istrative sanctions, including significant financial penalties imposed by the national supervisor as part of DORA’s general sanctions regime. The CRA, which is directly applicable in France, establishes a horizontal regulatory framework for the security of digital products across the EU. It applies to all products with digital elements (PDEs), meaning any hardware or software – whether final products or components marketed separately – made available on the EU market. A central aspect of the CRA is that it imposes cyber - security obligations on manufacturers, importers and distributors from the design stage and throughout the entire life cycle of the product. Under the CRA, PDEs are classified into four catego - ries. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

• Default category: all digital products not consid - ered important or critical (eg, smartphones or computers). • Important Class I products: 19 categories, includ - ing cybersecurity products (eg, public key infra - structure (PKI) components, security information and event management (SIEM), password man - agers), core digital products (operating systems, routers, browsers) and sector‑specific items (smart home devices, toys). • Important Class II products: four categories – hypervisors, firewalls/Intrusion Detection System (IDS)/Intrusion Prevention System (IPS), micropro - cessors and microcontrollers. • Critical products: three categories – hardware security modules (HSMs), smart cards or similar devices, and gateways for smart meters. 4.2 Key Obligations Under Legislation The CRA places its main obligations on manufactur - ers, who must ensure that any product with digital elements they place on the market complies with the regulation’s essential cybersecurity requirements. To do so, manufacturers must conduct a cybersecurity risk assessment that guides security measures across all phases of the product’s life cycle, from planning and design to development, production, delivery and maintenance. Manufacturers must document their risk assessment and the technical measures or standards used to meet the essential requirements, keeping this techni - cal documentation available for market surveillance authorities upon request. Before placing a product on the market, they must complete the appropriate con - formity assessment, and then issue an EU declaration of conformity and apply the CE marking. Manufacturers must notify actively exploited vulner - abilities and severe security incidents affecting the security of their products with digital elements. They are required to submit the following. • An early warning within 24 hours of becoming aware of the issue.

• A full notification within 72 hours. • A final report which is required:

134 CHAMBERS.COM

Powered by