FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
(a) within 14 days after a corrective measure becomes available (for actively exploited vul - nerabilities); or (b) within one month for severe incidents. In France, the implementation of the CRA relies on several national authorities with distinct roles. The Agence Nationale des Fréquences (ANFR) is responsible for market surveillance. It ensures that products made available in France comply with the CRA’s requirements and may impose sanctions, including product withdrawal from the market or finan - cial penalties of up to EUR15 million or 2.5% of the manufacturer’s global annual turnover. ANSSI plays a key role in the practical implementation of the CRA, acting as the notifying authority responsi - ble for assessing, supervising and notifying conformity assessment bodies. It also provides technical sup - port to the ANFR for market‑surveillance activities and centralises reports of actively exploited vulner - abilities and major incidents, co-ordinating remedia - tion actions with manufacturers when necessary. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The French cybersecurity certification landscape com - bines European harmonisation efforts with national sovereignty imperatives. Certifications and qualifica - tions evaluate the security robustness of ICT products, services and processes. While historically utilised as voluntary markers of quality, these certifications are increasingly becoming mandatory prerequisites for market access and public procurement in France. The European Framework At EU level, the CSA established the European Cyber - security Certification Framework (ECCF) in 2019 to harmonise evaluation approaches across the internal market. In 2024, the European Commission adopted the first scheme under this framework: the Common Criteria-based European Cybersecurity Certification Scheme (EUCC).
The EUCC provides a unified assessment process specifically for certifying the security of ICT products, including software, hardware and technological com - ponents such as microchips and smartcards. The scheme classifies products under two defined assur - ance levels based on risk: • “substantial” assurance – for products designed to resist basic-to-moderate cyber-attack potential; and • “high” assurance – for products that must with - stand sophisticated, well-resourced threats. While obtaining an EUCC certificate is inherently vol - untary, it is increasingly important for demonstrating compliance with other mandatory frameworks, such as the NIS2 Directive and the CRA. Following a transi - tion period, ANSSI issued France’s first EUCC certifi - cates in 2025. The Proposed Cybersecurity Act 2 In January 2026, the European Commission proposed a comprehensive cybersecurity package including a Cybersecurity Act 2 (CSA2), alongside targeted amendments to the NIS2 Directive. This proposal shifts the regulatory focus towards systemic vulner - abilities by introducing the EU’s first horizontal frame - work for ICT supply chain security. It empowers the European Commission to identify “key ICT assets” and prohibit entities from utilising components from high-risk suppliers. Furthermore, the CSA2 broadens the scope of the certification framework beyond indi - vidual products to include managed security services and the overall “cyber posture” of an organisation. French National Framework: ANSSI Security Visas At the national level, ANSSI issues “Security Visas” to validate the trustworthiness of cybersecurity solu - tions, making a clear distinction between two mecha - nisms. • Certifications: these attest to the technical robust - ness of a product against predefined threats, based on independent laboratory testing. France utilises the internationally recognised Common Cri - teria (CC) alongside its specific First Level Security Certification (CSPN). The CSPN is an agile, two- month evaluation scheme that assesses resistance
135 CHAMBERS.COM
Powered by FlippingBook