Data protection: How can you comply with ANSSI’s recommendations?
© Ercom-Illustrator
Cyberattacks are growing more sophisticated, costing French businesses billions each year. Protecting sensitive data is now a top priority, and leading agencies like ANSSI are setting new standards for cybersecurity. Explore key recommendations and practical steps to keep your organisation safe and compliant in this evolving digital landscape.
47% of European businesses suffered at least one cyberattack in 2024. In France, the annual cost of cybercrime is estimated at over €100 billion. Year on year, cyber threats are evolving. Attacks on businesses are now meticulously targeted and planned to steal their most sensitive data.
As France’s leading authority on cybersecurity, ANSSI (the National Cybersecurity Agency) plays a central role in protecting organisations against digital threats. The agency fulfils several roles: it provides updates on the evolution of cyber threats, awards certifications to cybersecurity providers that meet its requirements… and develops regulations to enhance the level of cybersecurity within businesses.
What are ANSSI’s key recommendations for protecting your business and your data? How can you comply with the various regulatory frameworks developed by the agency?
ANSSI’s key recommendations
ANSSI breaks down cyber risk management into four main pillars.
1. Risk assessment: your organisation must map all its assets (software, applications, devices, data, etc.) to determine the digital scope that needs protecting. This phase also involves modelling threats to assess the nature of the risks and prioritise the cybersecurity measures to be implemented.
2. Implementation of protective measures: the agency regularly emphasises the adoption of mechanisms such as data encryption, which protects sensitive information even in the event of a breach. It also stresses the adoption of sovereign technologies and tools to protect your data from extraterritorial regulations and cyber-espionage. Other measures such as multi-factor authentication or the principle of least privilege are also among the recommended fundamentals.
3. Incident detection and response: ANSSI recommends ensuring continuous monitoring of your IT systems to identify abnormal behaviour and quickly detect any intrusion attempts. This involves implementing a SOC, developing an incident response and critical business recovery plan, or deploying an EDR (Endpoint Detection and Response) / XDR (Extended Detection and Response) solution.
4. Staff training: to foster a culture of cybersecurity, regular training sessions and awareness-raising workshops should be organised for all staff. The aim is to inform them of best practices and help them identify cyber threats. Conducting crisis drills or using fake phishing emails helps to instil the right reflexes in teams.
Regulations & standards to comply with from ANSSI
ANSSI contributes to the development of certain national and European regulatory frameworks. It is also responsible for ensuring their proper application by French organisations. The agency distinguishes two areas of application: information systems security and digital trust.
Information systems security relies on regulations aimed at strengthening organisations’ cybersecurity levels as well as their cyber resilience. Among the main regulatory frameworks, the following can be mentioned:
- The European NIS2 directive: adopted by the Senate in March 2025, it extends the scope of the original NIS directive by imposing stronger cybersecurity obligations. Eighteen sectors of activity are directly concerned. The NIS2 directive states in particular that security incidents must be reported to ANSSI within 24 hours, holds executives accountable, requires a risk analysis, the development of a business continuity plan, and the adoption of protective measures. Consult our ebook to check whether you are affected by the directive and discover all its obligations.
- The DORA regulation: applicable since the beginning of 2025, the Digital Operational Resilience Act aims to strengthen the operational resilience of financial sector actors against digital risks. It requires the implementation of robust IT governance, continuous IT risk management, regular penetration testing, as well as mandatory reporting of major incidents.
- The GDPR: in force since 2018, the General Data Protection Regulation aims to protect the personal data of EU citizens. It defines individuals’ rights over their data and the obligations of organisations that process it.
- The RGS (General Security Framework): this French regulatory framework defines the security rules that must be followed by public administration information systems and their service providers. It notably governs the use of electronic certificates, digital signatures, and qualified trust services. It is currently being revised as part of alignment with European regulations (notably eIDAS 2).
To establish digital trust, ANSSI regulates and certifies the reliability of digital technologies and actors in cybersecurity. This digital trust is notably reflected through:
- The Cyber Resilience Act: this European regulation, adopted in 2024 and applicable from 2027, imposes cybersecurity requirements on all digital products placed on the European market (software, connected objects, hardware equipment).
- The Cybersecurity Act: in force since 2019, it establishes a European cybersecurity certification framework for digital products, services, and processes.
- The “Cloud-first” doctrine: driven by the French state, it requires all administrations as well as operators of vital importance or essential services to prioritise cloud solutions by default, in a logic of modernisation and strengthened digital resilience.
- The SecNumCloud framework: developed by ANSSI, it defines the security and sovereignty requirements that cloud service providers must meet to be qualified SecNumCloud. This label guarantees that your data is hosted in France according to the strictest standards and is not subject to extraterritorial regulations.
How to comply with these regulations?
Here are 5 steps to achieve compliance with these various regulations:
- Conduct a compliance audit to identify gaps between your existing environment and the applicable regulatory requirements, taking into account the specificities of your sector of activity.
- Streamline your tools to reduce your attack surface and adopt ANSSI-approved solutions in order to ensure a guaranteed level of security for the technologies deployed within your organisation.
- Adopt additional protective measures, for example to secure endpoints, protect remote access, or detect threats in real time.
Define clear processes in the event of a security incident, in order to restore critical activities, recover data as quickly as possible, and limit operational consequences. - Continuously train and raise awareness among your teams in order to reduce the risk of human error.
Far from being punitive, ANSSI supports organisations in securing their information systems and data. As such, the agency has published several reference guides that your company can rely on for compliance. The adoption of ANSSI-approved solutions, whether for cloud security, collaborative work, or endpoint protection, can significantly facilitate your regulatory compliance work.