Cyber Resilience Act Enforcement in France
Learn how the EU Cyber Resilience Act applies to companies in France, including local market surveillance and enforcement by ANSSI.
Core Definition
The Cyber Resilience Act is an EU Regulation, meaning it applies directly in France without the need for national transposition. However, enforcement and market surveillance activities will be conducted by national authorities like ANSSI. Any product with digital elements sold or made available in France must comply with CRA standards by December 2027.
Key Compliance Steps for France
- Identify Local Representatives: If you are based outside the EU but selling into France, appoint an Authorized Representative in the Union.
- Monitor ANSSI Guidelines: Follow any localized guidance or translation of standards provided by ANSSI.
- Prepare ENISA Reporting: Ensure your vulnerability reporting pipelines are connected to the central ENISA platform and your national CSIRT.
- Localize Documentation: Ensure that the required EU Declaration of Conformity and user instructions are available in the languages required by France.
How This Plays Out in Practice
ANSSI, which already certifies products under France's CSPN scheme, is a natural fit to extend its technical evaluation capacity to CRA conformity assessment.
What to Watch For
France's telecom and public-sector software vendors are a likely early enforcement focus given ANSSI's existing sovereignty-driven scrutiny of critical software.
Assess Your CRA Readiness
Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to France.