Country Overview Updated: August 2026

Cyber Resilience Act Enforcement in France

Learn how the EU Cyber Resilience Act applies to companies in France, including local market surveillance and enforcement by ANSSI.

Core Definition

The Cyber Resilience Act is an EU Regulation, meaning it applies directly in France without the need for national transposition. However, enforcement and market surveillance activities will be conducted by national authorities like ANSSI. Any product with digital elements sold or made available in France must comply with CRA standards by December 2027.

Key Compliance Steps for France

  1. Identify Local Representatives: If you are based outside the EU but selling into France, appoint an Authorized Representative in the Union.
  2. Monitor ANSSI Guidelines: Follow any localized guidance or translation of standards provided by ANSSI.
  3. Prepare ENISA Reporting: Ensure your vulnerability reporting pipelines are connected to the central ENISA platform and your national CSIRT.
  4. Localize Documentation: Ensure that the required EU Declaration of Conformity and user instructions are available in the languages required by France.

How This Plays Out in Practice

ANSSI, which already certifies products under France's CSPN scheme, is a natural fit to extend its technical evaluation capacity to CRA conformity assessment.

What to Watch For

France's telecom and public-sector software vendors are a likely early enforcement focus given ANSSI's existing sovereignty-driven scrutiny of critical software.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to France.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.