## 1fraea2025003

## Source details

**Canonical URL:** [1fraea2025003](https://www.imf.org/-/media/files/publications/cr/2025/english/1fraea2025003.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2025/english/1fraea2025003.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2025/english/1fraea2025003.pdf.json)

---

### EXECUTIVE SUMMARY — Introduction and Context
- Scope: Assessment covered the cyber risk supervision and regulation of the financial sector in France. Authorities in scope: Autorité de Contrôle Prudentiel et de Résolution (ACPR), Autorité des Marchés Financiers (AMF), and Banque de France (BdF). Supervision of Significant Banking Institutions (SIs) in France is within the remit of the European Central Bank’s Single Supervisory Mechanism (ECB/SSM) and was outside the scope of the France FSAP.
- Complexity: Overall complexity of cyber risk supervision is high, involving four dedicated teams within the three financial authorities (ACPR, AMF, BdF), a financial regulator (Trésor), and the cybersecurity agency (ANSSI).
- Financial stability concern:
  - BdF dedicated parts of its 2023 and 2024 financial stability reports to cyber risk.
  - ENISA: "9 percent of all attacks in the European Union (EU) targeting banking and finance."
  - France experienced a data breach in 2024 impacting the personal data of more than 33 million people.
- Threat trends:
  - Ransomware attacks in France increased by 30% between 2022 and 2023, with the trend continuing in 2024.
  - Types of threats: traditional data exfiltration, ransomware, and at least one deepfake executive impersonation attempt.

### Regulatory Developments and Legal Basis
- Major EU legislative acts affecting France:
  - Digital Operational Resilience Act (DORA): in force since January 16, 2022, and applicable from January 17, 2025.
  - Network Information Security Directive 2 (NIS2) and Critical Entities Resilience Directive (CER): transposition should have taken place by October 17, 2024 (transposition to be expected first half of 2025).
  - Markets in Crypto-Assets Regulation (MiCA): in force since July 2023; delegated acts gradually entering applicability in the next 18 months.
- National implementation status:
  - DORA and its delegated acts are directly applicable in France from January 17, 2025.
  - NIS2 and CER had not been fully transposed at the time of the FSAP assessment; the European Commission started a formal infringement notification procedure in November 2024.
- Legal powers: French supervisory authorities have sufficiently broad powers to collect information, assess compliance, impose corrective actions or sanctions, and take enforcement action as a last resort.

### Supervisory Practices and Strengths
- Overall effectiveness: Cyber risk supervision in France is found to be effective, built on EU regulatory framework and strong national laws. Framework for French LSIs and FMIs is very similar to other EU member jurisdictions.
- Key strengths:
  - Strong educational and awareness-raising approach to help supervised entities prepare for DORA applicability.
  - Cross-functional working groups for DORA preparation.
  - AMF knowledge base for cyber risk supervision.
  - Paris Resilience Group’s (PRG) mature approach to crisis management.
  - ACPR insurance supervisory team’s comprehensive approach using available cyber insurance data.
  - AMF cyberattack first aid page.
- Ongoing preparations: Organizational changes for a dedicated ACPR team and new national legislation were in the pipeline at the time of the FSAP assessment.
- Need for shared tools: Common tools for DORA-related new activities should be developed and shared between the financial supervisors.

### Organizational arrangements, mandates, and FMI oversight
- BdF:
  - Has a dedicated Cyber Unit for oversight of cyber and operational risk issues.
  - Cyber Unit consists of three experts with professional certifications and experience in IT and cyber security audit.
  - Cyber Unit provides expertise to Payments, CSD and CCP oversight units and participates in cooperative oversight of SWIFT and international work (e.g., G7 Cyber Expert Group).
  - Cyber Unit performs oversight duties and does not routinely engage in onsite supervisory activities for the three French FMIs (ACPR performs these activities at the request of BdF) but has the mandate to do so.
  - All FMIs are covered by cyber risk supervision on a three-year onsite supervision cycle.
- Tripartite cooperation:
  - Cooperation of BdF, ACPR and AMF governed by a simple tripartite agreement developed in 2019; a new cooperation framework is being designed with two agreements: one between ANSSI and BdF+ACPR and one between ANSSI and AMF.
  - Legal constraints: Some information available to ANSSI is classified and may only be shared under the strictest confidentiality; access requires a security clearance.

### Organization, Resourcing, and Staffing (key statistics)
- Total dedicated FTEs across ACPR, BdF, and AMF for ICT and cyber risk supervision at time of FSAP mission: 22.5 FTEs (17.5 at ACPR across 2 teams, 3 in BdF, 2 in AMF).
- ACPR estimation in March 2025: about 24.5 FTEs currently dedicated to cyber risk, with more than 40 persons in the ACPR working on cyber risk supervision/cyber risk topics.
- BdF Cyber Unit: 3 experts.
- ACPR banking onsite team: 12 FTE dedicated to ICT and cyber risk supervision (ICT Risk Assessment Unit — CERSI).
- ACPR insurance onsite team: 5.5 FTEs dedicated to supervision of information systems; SI-QDD Unit is composed of 12 onsite inspectors under Heads of mission, of which 5.5 FTEs are dedicated to information systems supervision.
- AMF: 1 fully dedicated FTE for cyber risk supervision and DORA; 2 FTEs specifically working on MiCA cyber related activities.
- TLPT staffing: 1 FTE within BdF working on TLPT exercises; ACPR planning to have 1 FTE dedicated to TLPT.
- Recommendation on headcount: Necessary headcount should be estimated based on 2-3 year work plans including onsite and offsite supervisory activities, joint examinations and oversight, international work, regulatory activities, and licensing.
- Skills guidance: Employ supervisors with international certifications such as CISA or CISSP; ENISA Cyber Skill Framework recommended as a reference.

### Supervisory Practices — ACPR, BdF, AMF (selected findings)
- ACPR (Banking):
  - Onsite inspections on cyber risk carried out by CERSI; CERSI carries out 3-4 dedicated ICT missions for ACPR each year, in addition to 2-3 SSM missions and onsite missions for FMIs and retail payment entities overseen by BdF.
  - CERSI uses the SSM methodology for all missions.
  - At the time of the onsite mission, there were no banking onsite cyber missions planned for 2025 in France in line with the request of the ECB.
  - Offsite cyber risk supervision is carried out by two Bank Supervision Directorates; cyber risk considered part of operational risk and assessed in annual SREP.
  - Offsite supervisors send an annual IT risk questionnaire to LSIs; aggregated results are communicated to LSIs and used to identify key issues.
- ACPR (Insurance):
  - Onsite inspections on cyber risk carried out by GPEOA; group carries out 3-4 dedicated ICT missions each year.
  - Two insurance onsite cyber missions were planned for 2025 at the time of the FSAP mission, focusing on DORA compliance.
  - Offsite insurance supervisors assess cyber risk as part of operational risk within Solvency II and annual reporting.
- BdF (FMI oversight):
  - Cyber Unit works closely with Payments, CCPs, and CSDs; quarterly oversight meetings with FMIs include ICT and cyber topics; additional dedicated IT meetings occur (example: data center migration).
- AMF (Markets and Asset Management):
  - Cybersecurity is a focus area in AMF strategic plan; Investigations and Inspections directorate performs onsite activities and engages external ANSSI-qualified auditors for technical reviews.
  - AMF conducted three SPOT inspections dedicated to cyber risk between 2019-2023 and overall 26 cyber security inspections since 2019.
  - AMF uses an internal tool to collect supervision results and workpapers to build a supervisory knowledge base; licensing questionnaire for crypto companies covers major IT and cyber topics in about 100 questions.

### Data collection, DORA implications, and need for common tools
- DORA elevates existing ESA guideline requirements to EU law, introduces new reporting requirements and enhances existing reports; supervisors will need to process more information and perform necessary supervisory actions.
- Current data handling issues:
  - Each supervisor collects DORA-related reports in the same format per DORA delegated acts, but the data collected by the authorities is not correlated at a national level.
  - Each authority forwards data to the ESAs; a holistic view of all available French data will only be accessible to European authorities, not to any French authority.
  - Risk example: concentration risk may span different entity types and reach a critical national level but not exceed EU criticality; without a national holistic view French authorities may not anticipate such risks.
- Recommendation: develop and share common tools for DORA-related activities among financial supervisors (incident reporting tools, databases and the Register of Information on third party service providers should be standardized).
  - At least one authority should be positioned to have a complete overview of incident and outsourcing information for the whole French financial sector with enough details (not full granularity) to recognize and manage cyber risk holistically and timely.
- Note on duplication: Duplication exists in efforts to develop tools for managing DORA data across authorities.

### Testing, TLPT/TIBER FR, and penetration testing
- TIBER FR implementation: beginning of 2024; BdF and ACPR joined by AMF forming a common TIBER cyber team (TCT) to manage tests.
- TLPT expectations:
  - The Threat Led Penetration Tests (TLPT) required by DORA will be conducted according to the TIBER FR framework.
  - Authorities stated they have the necessary expertise and resources to allocate the test manager and alternate for each TLPT.
  - It is expected that around 30 entities will be covered within the three-year TLPT cycle, but the exact plan depends on ECB decisions for the “Significant Institutions” in the banking sector where the ECB is the TLPT competent authority.
  - Results of TLPTs will be followed up by offsite supervisors similarly to existing penetration test follow-ups.
  - Entities not subject to TLPT will receive simple penetration tests or voluntary TIBER tests depending on criticality.
- Penetration testing practice:
  - ACPR and BdF onsite teams utilize the Red Team of BdF for penetration testing during onsite inspections.
  - Penetration test timeframe limit used by BdF/ACPR Red Team: one week.
  - Supervised entities may choose which IT systems are tested.
  - AMF engages external companies via public tender to perform penetration tests on its behalf.
  - About a third of the cyber security onsite controls include penetration testing.

### Crisis Management, PRG, and incident reporting
- Crisis management strengths and limitations:
  - France has mature public-private cooperation and exercises in crisis management; PRG (Paris Resilience Group) is a voluntary collaborative group established in 2005 chaired by BdF with PRG Secretariat availability 24/7.
  - PRG organizes annual functional exercises; in 2024 PRG organized a successful exercise for the G7.
  - Limitations: PRG is private-public and voluntary, focused on payments and financial stability, excludes insurance undertakings, and does not replace a formal public-authority intervention framework.
- Recommendation: Formal crisis management roles and procedures must be defined for cyber crisis, including escalation thresholds, communication chains and precedence of overlapping responsibilities, with clear interfaces to bodies responsible for financial stability.
- Incident reporting and information flows:
  - DORA will extend reporting obligations to all supervised entities in case of major incidents and provides detailed templates for report content.
  - ACPR received an average of 2-3 voluntary incident reports since the introduction of voluntary incident reporting in 2023.
  - As of December 13, 2024, 1.9 percent of total cyber events reported to ANSSI concern the financial sector.
  - AMF is notified of about 20 major incidents each year.
  - DORA aims to simplify multiple reporting obligations by regulating information exchange between financial supervisors and NIS2 national competent authorities, but ANSSI does not share critical infrastructure details with supervisory authorities; details of incident reporting regime remain under discussion.
- Recommendation: Formalize and improve information sharing about specific incidents and general cybersecurity trends among BdF, ACPR, AMF and ANSSI to allow timely critical incident information exchange in line with DORA objectives and to potentially simplify double incident reporting.

### Coordination, cooperation, and convergence of supervisory methodologies
- Fragmentation and interplay with ANSSI:
  - Regulatory landscape complexity is higher than other European jurisdictions due to interplay with national critical infrastructure protection laws.
  - ANSSI supervises financial entities designated as critical under NIS and SAIV frameworks; designation lists and some criteria are strictly confidential.
  - DORA is the lex specialist of NIS2; DORA responsibilities may involve ANSSI in addition to BdF, ACPR and AMF supervisory responsibilities.
- Coordination needs:
  - Stronger information sharing, cooperation, and coordination among authorities are necessary in the fragmented cyber supervisory landscape.
  - Cooperation should be formalized and regular at operational and management levels, supplementing existing informal and flexible approaches.
  - More cooperation needed on critical infrastructure protection to cover both technical (ANSSI) and financial stability (BdF) aspects.
  - Cyber crisis management protocols need strengthening and formalization.
  - Cyber risk supervisory methodologies of financial supervisors should converge with the applicability of DORA.
  - Authorities should explore the possibility of using automated tools.
  - Current coverage of onsite cyber risk supervisory controls needs to be increased in coming years.

### Technology, automation, and supervisory resourcing recommendations
- Automation:
  - Supervisors should increase use of automated tools to evaluate documents, reports and questionnaires, and to trigger actions on red flags.
  - Basic tools (macros, database triggers) can make questionnaire evaluation more efficient and reduce human error; advanced technologies such as artificial intelligence or large language models may be used for more sophisticated analytics.
  - Current practice: apart from some AI experiments, authorities do not use automated tools to facilitate cyber risk supervision; questionnaires are evaluated manually without technical aids or red-flag triggers.
  - ACPR uses macros to evaluate LSIs’ IT questionnaires and has an ongoing internally developed tool project for banking supervision to process documentation.
- Onsite presence:
  - Recommendation: Plan an increased onsite supervisory presence for the coming years; onsite supervision provides the best assurance of control frameworks and operations and cannot be fully replaced by offsite activities.
  - Workplans and resources should reflect DORA’s intention to raise digital operational resilience when planning annual supervision.

### Key Recommendations (selected)
- Institutional and regulatory framework
  - Formalize and enhance collaboration among authorities in protection of designated critical entities to facilitate optimal cooperation and information sharing. (Reference: 43; Authorities: ACPR, AMF, BdF; Timing: I)
  - Develop and share common tools for DORA related new activities. (Reference: 45; Authorities: ACPR, AMF, BdF; Timing: ST)
  - Allocate more dedicated, specialized resources for cyber risk supervision and digital operational resilience supervision (including DORA). (Reference: 47; Authorities: ACPR, AMF; Timing: MT)
- Supervisory practices
  - Ensure cyber risk supervisory practices become more consistent, and methodologies converge with the applicability of DORA. (Reference: 67; Authorities: ACPR, AMF, BdF; Timing: ST)
- Common Supervisory Tasks
  - Define crisis management roles and procedures for cyber crisis. (Reference: 94; Authorities: ACPR, AMF, BdF; Timing: ST)
  - Formalize information sharing about specific incidents and general cybersecurity trends within the authorities and among BdF, ACPR, AMF and build a strong partnership with ANSSI. (Reference: 95; Authorities: ACPR, AMF, BdF; Timing: ST)
  - Increase use of automated tools to evaluate documents, reports, and questionnaires and trigger actions on red flags. (Reference: 96; Authorities: ACPR, AMF, BdF; Timing: MT)
  - Plan for an increased onsite supervisory presence for the coming years. (Reference: 97; Authorities: ACPR, AMF, BdF; Timing: MT)
- Timing legend preserved from source: I Immediate (within 1 year); ST Short term (within 1-2 years); MT Medium Term (within 3−5 years).

### Key statistics and operational figures (as reported)
- DORA applicability date: January 2025.
- Onsite missions evaluating DORA: performed in 2024.
- ACPR voluntary incident reports average since 2023: 2-3.
- As of December 13, 2024, 1.9 percent of total cyber events reported to ANSSI concern the financial sector.
- AMF notified incidents: about 20 major incidents each year.
- TIBER FR implementation: beginning of 2024.
- Expected entities covered in TLPT three-year cycle: around 30.
- Penetration test timeframe limit used by BdF/ACPR Red Team: one week.
- ACPR ICT security network membership: 16-20 cyber and ICT experts.
- PRG Secretariat availability: 24/7.

*Source: EXECUTIVE SUMMARY and selected sections (France FSAP technical note, information current as of December 20, 2024).*

### EXECUTIVE SUMMARY __________________________________________________________________________ 5

### EXECUTIVE SUMMARY

### Introduction and Context
- Scope: Assessment covered the cyber risk supervision and regulation of the financial sector in France. Authorities in scope: Autorité de Contrôle Prudentiel et de Résolution (ACPR), Autorité des Marchés Financiers (AMF), and Banque de France (BdF). Supervision of Significant Banking Institutions (SIs) in France is within the remit of the European Central Bank’s Single Supervisory Mechanism (ECB/SSM) and was outside the scope of the France FSAP.
- Complexity: Overall complexity of cyber risk supervision is high, involving four dedicated teams within the three financial authorities (ACPR, AMF, BdF), a financial regulator (Trésor), and the cybersecurity agency (ANSSI).
- Financial stability concern:
  - BdF dedicated parts of its 2023 and 2024 financial stability reports to cyber risk.
  - ENISA: "9 percent of all attacks in the European Union (EU) targeting banking and finance."
  - France experienced a data breach in 2024 impacting the personal data of more than 33 million people.
- Threat trends:
  - Ransomware attacks in France increased by 30% between 2022 and 2023, with the trend continuing in 2024.
  - Types of threats: traditional data exfiltration, ransomware, and at least one deepfake executive impersonation attempt.

### Regulatory Developments and Legal Basis
- Major EU legislative acts affecting France:
  - Digital Operational Resilience Act (DORA): in force since January 16, 2022, and applicable from January 17, 2025.
  - Network Information Security Directive 2 (NIS2) and Critical Entities Resilience Directive (CER): transposition should have taken place by October 17, 2024 (transposition to be expected first half of 2025).
  - Markets in Crypto-Assets Regulation (MiCA): in force since July 2023; delegated acts gradually entering applicability in the next 18 months.
- National implementation status:
  - DORA and its delegated acts are directly applicable in France from January 17, 2025.
  - NIS2 and CER had not been fully transposed at the time of the FSAP assessment; the European Commission started a formal infringement notification procedure in November 2024.
- Legal powers: French supervisory authorities have sufficiently broad powers to collect information, assess compliance, impose corrective actions or sanctions, and take enforcement action as a last resort.

### Supervisory Practices and Strengths
- Overall effectiveness: Cyber risk supervision in France is found to be effective, built on EU regulatory framework and strong national laws. Framework for French LSIs and FMIs is very similar to other EU member jurisdictions.
- Key strengths:
  - Strong educational and awareness-raising approach to help supervised entities prepare for DORA applicability.
  - Cross-functional working groups for DORA preparation.
  - AMF knowledge base for cyber risk supervision.
  - Paris Resilience Group’s (PRG) mature approach to crisis management.
  - ACPR insurance supervisory team’s comprehensive approach using available cyber insurance data.
  - AMF cyberattack first aid page.
- Ongoing preparations: Organizational changes for a dedicated ACPR team and new national legislation were in the pipeline at the time of the FSAP assessment.
- Need for shared tools: Common tools for DORA-related new activities should be developed and shared between the financial supervisors.

### Resource, Coordination, and Common Tasks Challenges
- Resourcing:
  - Resource constraints and staffing challenges are prominent.
  - More dedicated, specialized resources needed for cyber risk supervision and digital operational resilience supervision (including DORA) within AMF and ACPR.
  - Necessary headcount should be estimated based on 2-3 year work plans, including onsite and offsite supervisory activities, joint examinations and oversight, international work, regulatory activities, and licensing.
- Coordination and information sharing:
  - Stronger information sharing, cooperation, and coordination among authorities are necessary in the fragmented cyber supervisory landscape.
  - Cooperation should be formalized and regular at operational and management levels, supplementing existing informal and flexible approaches.
  - More cooperation needed on critical infrastructure protection, including the confidential list of critical entities and incident information to cover technical aspects (ANSSI) and financial stability aspects (BdF).
- Other weaknesses:
  - Need for common tools and information sharing among authorities.
  - Cyber crisis management protocols need strengthening and formalization.
  - Cyber risk supervisory methodologies of financial supervisors should converge with the applicability of DORA.
  - Authorities should explore the possibility of using automated tools.
  - Current coverage of onsite cyber risk supervisory controls needs to be increased in coming years.

### Key Recommendations (selected from Table 1)
- Institutional and regulatory framework
  - Formalize and enhance collaboration among authorities in protection of designated critical entities to facilitate optimal cooperation and information sharing. (Reference: 43; Authorities: ACPR, AMF, BdF; Timing: I)
  - Develop and share common tools for DORA related new activities. (Reference: 45; Authorities: ACPR, AMF, BdF; Timing: ST)
  - Allocate more dedicated, specialized resources for cyber risk supervision and digital operational resilience supervision (including DORA). (Reference: 47; Authorities: ACPR, AMF; Timing: MT)
- Supervisory practices
  - Ensure cyber risk supervisory practices become more consistent, and methodologies converge with the applicability of DORA. (Reference: 67; Authorities: ACPR, AMF, BdF; Timing: ST)
- Common Supervisory Tasks
  - Define crisis management roles and procedures for cyber crisis. (Reference: 94; Authorities: ACPR, AMF, BdF; Timing: ST)
  - Formalize information sharing about specific incidents and general cybersecurity trends within the authorities and among BdF, ACPR, AMF and build a strong partnership with ANSSI. (Reference: 95; Authorities: ACPR, AMF, BdF; Timing: ST)
  - Increase use of automated tools to evaluate documents, reports, and questionnaires and trigger actions on red flags. (Reference: 96; Authorities: ACPR, AMF, BdF; Timing: MT)
  - Plan for an increased onsite supervisory presence for the coming years. (Reference: 97; Authorities: ACPR, AMF, BdF; Timing: MT)

- Timing legend preserved from source: I Immediate (within 1 year); ST Short term (within 1-2 years); MT Medium Term (within 3−5 years).

*Source: EXECUTIVE SUMMARY (France FSAP technical note, information current as of December 20, 2024).*

### 9.      The assessment covered the authorities’ risk-based supervision practices, cyber

### 1fraea2025003 - 9.      The assessment covered the authorities’ risk-based supervision practices, cyber

### Assessment scope
- Covered authorities’ risk-based supervision practices, cyber incident response and recovery, the incident reporting regime, cyber security testing, and crisis exercises.
- DORA-related topics included the Threat-Led Penetration Testing (TLPT) regime and supervisory expectations for entities not covered by DORA.
- Focus areas:
  - The cyber supervisory and oversight framework for Financial Market Infrastructures (FMI).
  - Financial sector (specifically banks and FMIs) and authorities’ preparedness to deal with a potential cyber crisis, including cooperation between authorities, the crisis management framework, and its testing through simulations.

### Information sources and methodology
- Collected information from:
  - Questionnaire answers provided prior to the on-site mission by the BdF, ACPR, AMF, and Trésor.
  - Interviews with BdF, ACPR, AMF, Trésor, ANSSI, and supervised institutions.
  - Study of relevant laws and decrees.
  - Documentation of authorities’ work: internal documents, supervisory plans, reports, and other evidence as needed.
- Analysis, conclusions, and recommendations guided by international regulatory and supervisory good practices based on the following documents:
  - (i) EBA Guidelines on information and communication technology (ICT) Risk Assessment under SREP;
  - (ii) EBA Guidelines on ICT and security risk management;
  - (iii) EBA Guidelines on outsourcing arrangements;
  - (iv) EIOPA Guidelines on information and communication technology security and governance (EIOPA-BoS-20/600);
  - (v) EIOPA Guidelines on outsourcing to cloud service providers (EIOPA-BoS-20-002);
  - (vi) ESMA Guidelines on outsourcing to cloud service providers;
  - (vii) Cyber resilience oversight expectations for financial market infrastructures (CROE);
  - (viii) CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures;
  - (ix) FSB Cyber Lexicon and Format for Incident Reporting Exchange (FIRE).

### Legal basis and scope of supervision
- Legal basis:
  - ACPR, BdF and AMF operate according to a national legal framework in which all relevant EU legislation is either transposed to domestic law or directly applicable.
  - Authorities have internal procedure and decision mechanisms to impose sanctions or penalties on supervised entities that do not comply with legal requirements.
- Division of supervisory roles:
  - ACPR, AMF and BdF supervise cyber risks in cooperation; roles and responsibilities are allocated by designating a lead NCA and one or two supporting NCAs.
  - A brief tripartite agreement was developed in 2019 for co-supervised institutions; the agreement is a simple table format list of activities without date, signature, versioning, or specific contact information.
  - The division of competences is likely to evolve with DORA implementation.
- Entities outside or extended under DORA:
  - Two entity types not covered by DORA: (i) Sociétés de Financement; (ii) Caisse des Dépôts et des Consignations (CDC).
  - Authorities plan to design a national framework inspired by DORA for the CDC.
  - DORA requirements will be extended to financial entities in overseas French territories not part of the EU and branches of third-country credit institutions and investment firms.
- Payment systems:
  - Payment systems are not within the scope of DORA; oversight follows the Eurosystem Cyber Resilience Strategy.
  - The French regulator does not intend to expand DORA requirements to payment systems beyond the preamble suggestion.
- Applicable EU regulations for BdF supervision:
  - Central Securities Depositories Regulation (CSDR) for CSD;
  - European Market Infrastructure Regulation (EMIR) for CCP;
  - Regulation (EU) No 795/2014 of July 3, 2014 on oversight requirements for systemically important payment systems (ECB/2014/28) (SIPSR) for Payment Systems.
- MiCA responsibilities:
  - AMF: provisions related to crypto-asset service providers (CASPs), crypto-assets’ white papers, and market abuse.
  - ACPR: provisions related to stablecoins (e-money tokens and asset-referenced tokens under MiCA).
  - MiCA last titles entering into applicability in December 2024.
  - During 2024, six digital assets service providers (PSAN in French) authorized under PACTE law requirements.
  - DASPs with "simple" registration before 1 January 2024 benefit from a grandfathering clause and remain subject to prior registration requirements.
- National legal provisions relevant to cybersecurity:
  - French Monetary and Financial Code, French Insurance Code, AMF General Regulation, ACPR Decree of November 3, 2014 on internal control.
  - Dedicated French Mutuality Code and French Social Security Code for mutual societies and provident institutions.

### Interplay with critical infrastructure and national cyber authorities
- Regulatory landscape complexity:
  - More complex than other European jurisdictions due to interplay with national critical infrastructure protection laws.
  - Financial entities anticipate simplification from DORA.
- ANSSI mandate and designations:
  - ANSSI supervises financial entities designated as critical under: (i) NIS Directive (operators of essential services); (ii) SAIV (operators of vital importance) designated under Public Policy for Securing Vital Importance Activities.
  - SAIV implemented by SGDSN under the French Prime Minister; designated operators must secure critical information systems on the basis of article 22 of the French Military Programming Act of December 18, 2013 (LPM).
- NIS2 and DORA interaction:
  - NIS2 will be applicable to some financial entities already designated as critical; supervision mandate remains with ANSSI.
  - DORA is the lex specialist of NIS2; entities under NIS2 will have to comply with DORA instead.
  - French implementation gives some DORA responsibilities to ANSSI in addition to BdF, ACPR and AMF supervisory responsibilities.
  - Bill No. 33 that implements NIS2 and CER Directives in France, and contains changes related to DORA, is still pending (as of December 2024).
  - GDPR not covered in this report; no change anticipated in GDPR-related activities due to other new regulations.
- Insurance undertakings and NIS2:
  - Insurance undertakings are not under the scope of NIS2, but some will be included in French NIS2 implementation due to past status as operators of essential services and criticality in managing funds.
  - Bill No. 33 will modify the Insurance Code to extend applicability of NIS2 to insurance undertakings, giving ANSSI a mandate over insurance undertakings.
- Confidentiality and information sharing:
  - Exact list of entities designated as critical is strictly confidential; ANSSI publishes the number of such entities in the finance sector.
  - Financial authorities are officially not informed if a supervised entity is designated as critical or if particular ICT systems fall under ANSSI additional requirements.
  - A cooperation framework is being designed to foster information sharing to comply with NIS2 and DORA; scope of critical systems under LPM requirements will remain ANSSI competence.

### Supervisory expectations and standards used
- Fragmented regulatory expectations:
  - Landscape of regulatory expectations is very fragmented across ESAs’ guidelines without additional national legislation.
  - European Commission drafted DORA to unify regulatory landscape.
- French regulatory reliance:
  - Relies on national framework aligned with European regulations and ESAs’ guidelines.
  - French authorities are involved in drafting ESA guidelines; guidelines will be reviewed after DORA preparation is completed.
- Applicable ESA guidelines:
  - EBA: EBA/GL/2019/04; EBA/GL/2019/02; EBA/GL/2017/05.
  - EIOPA: EIOPA-BoS-20/600; EIOPA-BoS-20-002; EIOPA-BoS-14/253.
  - ESMA: ESMA50-157-2403.
- BdF oversight of payment systems:
  - Follows Eurosystem Cyber Resilience Strategy (issued in 2017) as part of Eurosystem Oversight Framework.
  - Applies Principles for Financial Market Infrastructures (PFMIs) and Guidance on cyber resilience for FMIs.
  - Uses Cyber Resilience Oversight Expectations (CROE) published in 2018 for payment systems, T2S, payment schemes, and payment arrangements.
- ACPR supervisory notices:
  - ACPR issues notices to clarify supervisory guidelines or expectations.
  - Current ACPR notices: one for the banking sector and one for the insurance sector on IT risk management.
  - Supervisor planning to publish notices on specific DORA requirements.
- International standards and ANSSI resources:
  - International standards used supplementary: NIST cybersecurity framework, ISO27001, COBIT.
  - ANSSI provides methodologies and guidelines: cloud security guidelines, secure coding, virtualization, EBIOS risk management methodology.
  - ANSSI issues qualifications for auditors (PASSI), advisors, service providers, and service qualifications such as SecNumCloud label.

### Organization and resourcing of cyber risk supervision
- Structural complexity:
  - High structural complexity with four distinct teams working across three authorities (BdF, ACPR, AMF), an inherent risk if not mitigated.
  - BdF and ACPR cooperation facilitated by being within the same organization with some shared IT systems and resources.
  - AMF is a separate entity with separate infrastructure and resources.

*Source: INTERNATIONAL MONETARY FUND*

### 34.      BdF has a dedicated Cyber Unit for the oversight of cyber and operational risk issues.

### 1fraea2025003 - 34.      BdF has a dedicated Cyber Unit for the oversight of cyber and operational risk issues.

### Organizational arrangements and mandates
- BdF has a dedicated Cyber Unit for the oversight of cyber and operational risk issues.
- The Cyber Unit provides its expertise to the three other oversight units (Payments, CSD and CCP).
- The Cyber Unit consists of three experts with professional certifications and experience in IT and cyber security audit.
- The Cyber Unit performs oversight duties, does not routinely engage in onsite supervisory activities for the three French FMIs (ACPR performs these activities at the request of BdF), but has the necessary mandate to do so.
- The Cyber Unit participates in the cooperative oversight of SWIFT and contributes to international work such as the G7 Cyber Expert Group.
- Cooperation framework:
  - The cooperation of BdF, ACPR and AMF on cyber risk supervision is governed by a simple 3-page tripartite agreement signed in 2019.
  - Information sharing between AMF and ANSSI is allowed by law and will be modified in the context of DORA preparation to allow information sharing between ACPR, BdF and ANSSI.
  - Existing 2018 letters of intention between ACPR and AMF and between AMF and ANSSI have not evolved to MoUs due to SSM and French law limitations.
  - A new cooperation framework is being designed with two agreements: one between ANSSI and BdF+ACPR and one between ANSSI and AMF.
  - Once the implementing bill No. 33 for NIS2, CER and DORA is adopted, ANSSI, ACPR, BdF and AMF will be able to officially share more information.
- Legal constraints:
  - Some information available to ANSSI is classified and may only be shared under the strictest confidentiality; access requires a security clearance.

### Resources and staffing (key statistics)
- At the time of the FSAP mission, total dedicated FTEs across ACPR, BdF, and AMF for ICT and cyber risk supervision: 22.5 FTEs (17.5 at ACPR across 2 teams, 3 in BdF, 2 in AMF).
- ACPR estimation in March 2025: about 24.5 FTEs currently dedicated to cyber risk, with more than 40 persons in the ACPR working on cyber risk supervision/cyber risk topics.
- BdF Cyber Unit: 3 experts.
- ACPR banking onsite team: 12 FTE dedicated to ICT and cyber risk supervision (ICT Risk Assessment Unit — CERSI).
- ACPR insurance onsite team: 5.5 FTEs dedicated to supervision of information systems; SI-QDD Unit is composed of 12 onsite inspectors under Heads of mission, of which 5.5 FTEs are dedicated to information systems supervision.
- AMF: 1 fully dedicated FTE for cyber risk supervision and DORA; 2 FTEs specifically working on MiCA cyber related activities.
- TLPT staffing: 1 FTE within BdF working on TLPT exercises; ACPR planning to have 1 FTE dedicated to TLPT.

### Capacity, specialization, and planned changes
- ACPR:
  - CERSI performs onsite inspection of credit institutions and investment firms, supervises LSIs locally, contributes to SSM missions and performs onsite visits on behalf of BdF.
  - Team members hold internationally acknowledged certifications and include subject matter experts on data center physical security and cloud security.
  - Offsite supervisory teams generally do not have dedicated resources to cyber risk supervision; offsite supervisors follow up on ICT related topics and consult specialized onsite teams as needed.
  - A new dedicated team is expected to be set up within ACPR to provide DORA related expertise as a cross-sectoral function, independent of banking and insurance supervisory teams; no new FTEs will be allocated—existing resources will be utilized.
- AMF:
  - Internal cybersecurity team lends one expert to supervisory teams when necessary and relies on external audit service providers with ANSSI qualifications (PASSI).
  - The internal cyber expert works almost exclusively on supervisory tasks due to DORA, MiCA implementations and MiCA licensing.
  - AMF is educating supervisors on DORA and cyber resilience to “spread cyber all over the organization”; anticipates additional supervisory resources will be needed after July 2026 when DASPs must fully comply.
- Staffing and skills guidance:
  - More dedicated, specialized resources will be needed for cyber risk supervision and digital operational resilience supervision (including DORA).
  - Headcount for ACPR and AMF should be estimated based on workplans for the next 2-3 years including onsite and offsite activities and international/regulatory work.
  - Good practice: employ supervisors with international certifications such as CISA or CISSP.
  - ENISA Cyber Skill Framework is recommended as a reference for determining necessary skills.

### Supervisory practices — ACPR (Banking and Insurance)
- ACPR: Banking Supervision
  - Onsite inspections on cyber risk carried out by CERSI.
  - CERSI carries out 3-4 dedicated ICT missions for ACPR each year, in addition to 2-3 SSM missions and onsite missions for FMIs and retail payment entities overseen by BdF.
  - CERSI uses the SSM methodology for all missions.
  - At the time of the onsite mission, there were no banking onsite cyber missions planned for 2025 in France in line with the request of the ECB.
  - Results and findings of onsite inspections are communicated to supervised entities by offsite supervisors; agreed action-plan deadlines; to date no onsite cyber related findings have resulted in sanctions or penalties.
  - Offsite cyber risk supervision is carried out by two Bank Supervision Directorates; cyber risk considered part of operational risk and assessed in annual SREP.
  - Offsite supervisors send an annual IT risk questionnaire to LSIs; aggregated results are communicated to LSIs and used to identify key issues such as insufficient risk management related to outsourcing.
- ACPR: Insurance Supervision
  - Onsite inspections on cyber risk carried out by GPEOA; group carries out 3-4 dedicated ICT missions each year covering ISS Governance, operational security, IT continuity plan, and outsourcing.
  - Two insurance onsite cyber missions were planned for 2025 at the time of the FSAP mission, focusing on DORA compliance.
  - Focus shifting to offsite supervision to allow supervised entities to prepare for DORA.
  - Results and findings: communicated by onsite supervisors then officially received from offsite supervisors; agreed action-plan deadlines; to date no onsite cyber related findings have resulted in sanctions or penalties. Typical finding: insufficient independence of the ICT security function.
  - Offsite insurance supervisors assess cyber risk as part of operational risk within Solvency II and annual reporting and regular meetings.
  - Insurance offsite supervisors leverage the cyber insurance landscape and sources such as the annual AMRAE report on cyber insurance.

### Supervisory practices — BdF (FMI oversight)
- Cyber risk topics overseen by BdF’s dedicated Cyber Unit working closely with three general oversight units (payments, CCPs, CSDs).
- Quarterly oversight meetings with FMIs usually include ICT and cyber topics; additional dedicated IT meetings occur (example: data center migration).
- 2024 focus areas: governance of cyber and operational risk and the “three lines of defense”; DORA was an additional topic.
- All FMIs are covered by cyber risk supervision on a three-year onsite supervision cycle.

### Supervisory practices — AMF (Markets and Asset Management)
- IT and cyber risk are key issues due to increased reliance of supervised entities, especially crypto asset managers.
- AMF strategic plan includes cybersecurity as a focus area; inspection targets and thematic topics are identified via supervisory activity, ESMA heatmap and AMF annual priorities.
- Onsite activities performed by Investigations and Inspections directorate; offsite by Markets and Asset Management directorates.
- Investigations and Inspections engages external ANSSI-qualified auditors for technical reviews (penetration tests, system configuration reviews).
- AMF has conducted three SPOT inspections dedicated to cyber risk between 2019-2023 and overall 26 cyber security inspections since 2019; summarized SPOT results are published and presented to supervised entities.
- AMF uses an internal tool to collect supervision results and workpapers to build a supervisory knowledge base, enabling consistent inspections without a dedicated large team.
- AMF licensing questionnaire for crypto companies covers all major IT and cyber topics in about 100 questions with supporting documents; separate questionnaire for regular inspections includes an asset mapping (“Carthographie”); no automated tools used to evaluate the questionnaire.

### Data collection, reporting, and coordination issues
- DORA elevates existing ESA guideline requirements to EU law, introduces new reporting requirements and enhances existing reports; supervisors will need to process more information and perform necessary supervisory actions.
- New frameworks, tools and cooperation agreements are under development to meet DORA requirements.
- Each supervisor collects DORA-related reports (incident reporting and Register of Information for third party service providers) in the same format per DORA delegated acts, but:
  - The data collected by the authorities is not correlated at a national level.
  - Each authority forwards data to the ESAs; a holistic view of all available French data will only be accessible to European authorities, not to any French authority.
  - Risk example: concentration risk may span different entity types and reach a critical national level but not exceed EU criticality; without a national holistic view French authorities may not anticipate such risks.
- Recommendation: develop and share common tools for DORA-related activities among financial supervisors to create a holistic risk landscape.
  - Incident reporting tools, databases and the Register of Information on third party service providers should be standardized for all supervisory authorities.
  - At least one authority should be in a position to have a complete overview of incident and outsourcing information for the whole French financial sector with enough details (not full granularity) to recognize and manage cyber risk holistically and timely.
- Duplication exists in efforts to develop tools for managing DORA data across authorities.

### Conclusions and key recommendations
- Institutional and regulatory framework for cyber risk supervision is generally strong; legal basis and regulations convey adequate powers for effective supervision.
- DORA does not fundamentally change key principles but raises responsibilities and tasks to a new level, requiring more stringent supervisory approaches.
- The supervisory landscape is complex and requires strong coordination, cooperation and information sharing.
- Collaboration among BdF, ACPR, AMF and ANSSI should be formalized and enhanced:
  - Regular interaction at operational and management levels is recommended beyond current informal approaches.
  - Legal basis for sharing all necessary information should be clearly established at an appropriate legal level (e.g., MoU or law) depending on sensitivity.
  - Procedures, channels, specific contact details for each topic and regular review/update procedures should be established.
  - More cooperation needed on critical infrastructure protection to cover both technical (ANSSI) and financial stability aspects.
- Staffing: more dedicated, specialized resources are needed; headcount planning should cover next 2-3 years and account for onsite/offsite, international, regulatory and support activities.
- Skills: recruit supervisors with international certifications (CISA, CISSP); refer to ENISA Cyber Skill Framework for determining necessary skills.

*Source: 1fraea2025003 - 34.      BdF has a dedicated Cyber Unit for the oversight of cyber and operational risk issues.*

### Conclusions and Recommendations

### Conclusions and Recommendations

### Supervisory capacity and consistency
- All onsite supervisory teams have relevant IT experience and some of them also have experts with national (ANSSI) qualifications 22 or internationally recognized certifications of IT audit.
- BdF and ACPR stated their primary source of recruitment is the IT department of BdF.
- All three supervisory authorities have some excellent practices within their teams.
- Authorities should ensure that cyber risk supervisory practices become more consistent, and methodologies converge with the applicability of DORA.
  - A regular platform should be set up with all three financial supervisors for sharing and discussing cyber risk related technical case studies, good practices, and methodologies.
  - The platform objective: formulate standard types of recommendations based on DORA requirements that are the same for banks, insurance undertakings and financial infrastructures.
  - The platform could also be utilized for relevant technology, cyber security, or audit training.
- With the applicability of DORA from January 2025, the educational focus of cyber risk supervision will have to change due to the more rigid regulatory framework.
- At the time of the FSAP mission:
  - ACPR planned to reduce onsite supervisory activity for cyber risk supervision in 2025 and shift focus to offsite supervisory practice to allow supervised entities more space to proceed with DORA compliance tasks. 23
  - AMF intended to increase onsite supervisory activity and implement more formal onsite controls.
- DORA requirements were evaluated by all authorities during onsite missions in 2024 and feedback was included in the reports; supervisors intended to provide early evaluation of institutions' expected level of compliance (DORA applicable from January 2025).

### Testing and exercising
- Cyber security testing and exercising are performed regularly and adhere to high professional standards; external or independent penetration testers are used by onsite supervisory teams.
- ACPR and BdF onsite teams utilize the Red Team 24 of BdF for penetration testing during onsite inspections.
  - Supervised entities may choose which IT systems are tested; tests are limited to a timeframe of one week.
  - Results are communicated in a special report, independent from the supervisory report; remediation actions are followed up by offsite supervisory teams.
- AMF engages external companies via public tender to perform penetration tests on its behalf during onsite supervision.
  - About a third of the cyber security onsite controls include penetration testing.
  - Scope is determined based on risk level and criticality; systems tested in the last three years are excluded.
- The French TIBER FR 25 was implemented at the beginning of 2024 with BdF and ACPR, then joined by AMF, forming a common TIBER cyber team (TCT) to manage tests.
  - The Threat Led Penetration Tests (TLPT) required by DORA will be conducted according to the TIBER FR framework.
  - Authorities stated they have the necessary expertise and resources to allocate the test manager and alternate for each TLPT.
  - It is expected that around 30 entities will be covered within the three-year TLPT cycle, but the exact plan depends on ECB decisions for the “Significant Institutions” in the banking sector where the ECB is the TLPT competent authority.
  - Results of TLPTs will be followed up by offsite supervisors similarly to existing penetration test follow-ups.
  - Entities not subject to TLPT will receive simple penetration tests or voluntary TIBER tests depending on criticality.
- Supervised entities that are subject to TLPT due to criticality, but are also designated as critical infrastructure, may only be tested by providers with ANSSI qualification.
  - Supervisors are not informed if an entity is designated as critical infrastructure; it is the entity’s responsibility to comply with qualification requirements.
  - ANSSI will not be involved in scoping or result sharing of TLPTs but may provide a general threat landscape as input.

### Crisis management
- France has mature public-private cooperation and exercises in crisis management, but formalized crisis management cooperation procedures and agreements among public authorities are missing.
  - Informal and voluntary cooperation (e.g., the Paris Resilience Group—PRG) works well but formal procedures can further improve preparedness and resilience.
- BdF chairs the PRG, established in 2005, a voluntary collaborative group including major French banks, FMIs, ACPR, AMF, ANSSI, the MoEF and the Interministerial Defense and Security Official Service.
  - BdF provides the PRG secretariat and separates voluntary PRG information sharing from BdF/ACPR supervisory information flow.
  - PRG has two working groups: crisis management system and sector-wide simulation exercises.
  - There is a dedicated Inter-authority Crisis Communication Subgroup (PCCA) for coordinating authorities on crisis communication.
  - PRG simulation capabilities cover communication but not technical simulations or cyber ranges.
- PRG has increasingly been involved in cyber-related information sharing and exercises; it organizes annual functional exercises with multidimensional scenarios (cyber/IT, communication, financial markets, card payment systems, cash management).
  - In 2024 PRG organized a successful exercise for the G7.
  - ACPR modeled its internal cyber crisis protocol for supervised entities based on PRG protocol.
  - PRG crisis management mechanism can be triggered by phone; BdF analysts at the Secretariat are available 24/7.
- Limitations of PRG:
  - Focused on payments and financial stability; does not cover all critical financial sector entities (specifically excludes insurance undertakings).
  - Composition has not changed since inception and PRG is a public-private initiative without official public mandate for critical financial infrastructure protection.
  - ANSSI is in charge of critical infrastructure protection and applies its own crisis protocol independently.

- Recommendation: Formal crisis management roles and procedures must be defined for cyber crisis, including escalation thresholds, communication chains and precedence of overlapping responsibilities, with clear interfaces to bodies responsible for financial stability.
  - ENISA Best Practices of Cyber Crisis Management 26 and the United Kingdom Authorities’ Response Framework are cited as useful models.
  - While PRG should be further developed for private-sector involvement, it does not replace a specific public-authority framework for formalized intervention.

### Incident reporting and information flows
- The French financial sector experiences a large number of attacks, but very few escalate to significant incidents.
  - Large financial entities report a constant flood of attacks, some very sophisticated.
- DORA will extend reporting obligations to all supervised entities in case of major incidents and provides detailed templates for report content.
- ACPR and BdF reported no major cyber security incidents regarding their supervised entities since the last FSAP.
  - ACPR received an average of 2-3 voluntary incident reports since the introduction of voluntary incident reporting in 2023.
  - Supervisory authorities are confident they receive timely information on incidents.
  - As of December 13, 2024, for the 2024-year, 1.9 percent of total cyber events reported to ANSSI concern the financial sector.
- AMF:
  - Was informed about several ransomware and data exfiltration incidents in recent years.
  - Is notified of about 20 major incidents each year.
  - Some attacks on crypto asset companies are technically sophisticated; most attacks remain standard phishing.
  - Expects to receive a few dozen additional incidents under the new DORA reporting regime and expects reporting quality to improve.
  - Created an internal “first aid list” of recommendations and links to resources for supervisors to support entities suffering cyberattacks.
- To meet ANSSI incident information requirements on critical infrastructures, French authorities intend to implement double incident reporting.
  - DORA aims to simplify multiple reporting obligations by regulating information exchange between financial supervisors and NIS2 national competent authorities, so that the financial supervisor receives the report and shares it with the NIS2 authority.
  - ANSSI does not share critical infrastructure details with supervisory authorities, so supervisors lack necessary information to know which incidents must be shared.
  - ANSSI seeks indicators of compromise and technical information; DORA authorities seek other types of information.
  - Details of the incident reporting regime remain under discussion; some institutions may need to do double reporting to comply with all legal requirements.
- Information flow inefficiencies among authorities:
  - Cyber security risk features in BdF semiannual financial stability report, but data sources are largely outside the French financial ecosystem.
  - Data collected by supervisors does not feed into the financial stability report.
  - ANSSI prepares a financial sector threat landscape, but incidents reported to AMF do not feature in that report.
  - BdF has cyber information from its CERT not shared outside BdF and ACPR.
  - BdF CERT, CERT-FR and large financial entities' CERTs participate in InterCERT France community.
  - Expected improvement in information sources for financial stability reports with DORA reporting requirements.
- Recommendation: Information sharing about specific incidents and general cybersecurity trends should be formalized and improved among BdF, ACPR, AMF and ANSSI to allow timely critical incident information exchange in line with DORA objectives 27.
  - Improved information sharing may simplify double incident reporting.
  - Incident information should inform risk management decisions, identify common trends or modus operandi, and be channeled into financial stability reports and macroprudential monitoring (while preserving confidentiality).

### Coordination and cooperation
- Internal information exchange within each authority is generally sufficient, but DORA implementation and international work increase the need for cross-functional cooperation and information sharing.
- ACPR has an internal ICT security network (since 2015) gathering 16-20 cyber and ICT experts for information-sharing and benchmarking; the group has focused on DORA preparedness since 2022.
  - With a planned dedicated DORA unit, the future of the group is to be decided.
- Banking and insurance onsite cyber supervisory groups have distinct methodologies and approaches; DORA unifies requirements and overrides distinct EBA and EIOPA guidelines.
  - Despite identical requirements under DORA for both sectors, the two onsite teams have shown no sign of convergence of practices.
- Cooperation among the three supervisory authorities operates well in a flexible, informal manner with operational meetings organized as needed.
- Cooperation between supervisory authorities and ANSSI is based on formal or informal bilateral agreements, with limited information sharing but working operational interactions.
  - All four authorities are PRG members, but PRG’s private composition limits sharing on topics like critical financial infrastructure.
- Protection of critical financial infrastructure is the sole mandate of ANSSI, with ad hoc consultation from other authorities.
  - Designation as an Operator of Vital Importance (OVI) is by order of the Minister of Economy and Finances on proposal of the French Treasury and SHFDS; ANSSI may be consulted; ACPR, AMF and BdF may be involved confidentially.
  - Supervisors do not know if their supervised entities are designated as critical infrastructure because information is classified and legal provisions prevent access.
  - EU directive requires documentation of horizontal and sectoral criteria (including economic impact) for identification, but those constitute classified information; ANSSI would not share them unless supervisors request specific accreditations.
  - The new CER directive requires determination of economic impact for service disruptions and market share to identify critical infrastructures and defines vital operators, essential services and critical infrastructure.

### Technology, automation and supervisory resources
- Supervisors should increase use of automated tools for evaluation of documents, reports and questionnaires, and to trigger actions on red flags.
  - Basic tools (macros, database triggers) can make questionnaire evaluation more efficient and reduce human error.
  - Increased reporting requirements under DORA and use of self-assessment questionnaires for offsite supervision and licensing make automation a source of efficiency gains and labor redeployment.
  - Advanced technologies such as artificial intelligence or large language models may be used for more sophisticated analytics.
- Current practice:
  - Apart from some AI experiments, authorities do not use automated tools to facilitate cyber risk supervision; questionnaires are evaluated manually without technical aids or red-flag triggers.
  - Innovative suptech developments are carried out independently by BdF/ACPR and AMF.
  - ACPR uses macros to evaluate LSIs’ IT questionnaires and has an ongoing internally developed tool project for banking supervision to process documentation.
- Recommendation: Plan an increased onsite supervisory presence for upcoming years; onsite supervision provides the best assurance of control frameworks and operations and cannot be fully replaced by offsite activities.
  - Workplans and resources should reflect this need.
  - Final DORA text published in 2022 gave entities time to prepare; some delegated acts with detailed requirements were published in July 2024, and French authorities should consider DORA’s intention to raise digital operational resilience when planning annual supervision.

### Key statistics and operational figures (as reported)
- DORA applicability date: January 2025.
- Onsite missions evaluating DORA: performed in 2024.
- ACPR voluntary incident reports average since 2023: 2-3.
- As of December 13, 2024, 1.9 percent of total cyber events reported to ANSSI concern the financial sector.
- AMF notified incidents: about 20 major incidents each year.
- TIBER FR implementation: beginning of 2024.
- Expected entities covered in TLPT three-year cycle: around 30.
- Penetration test timeframe limit used by BdF/ACPR Red Team: one week.
- ACPR ICT security network membership: 16-20 cyber and ICT experts.
- PRG Secretariat availability: 24/7.

_Conclusions and Recommendations — 1fraea2025003 - Conclusions and Recommendations_

---


_Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1fraea2025003.pdf_
