What we do

The French Cybersecurity Agency (ANSSI) is the national authority for cybersecurity and cyberdefence in France. ANSSI’s purpose is to develop and coordinate, across government departments, the nation’s protection against cyberattacks, and to contribute to the stability of cyberspace.

Its work forms part of the State’s sovereign responsibilities, serving the overarching public policy objective of security and resilience for government departments, the economy and society as a whole.

Its work is divided into five main areas of responsibility: defending, understanding, sharing, supporting and regulating.

Protect

the Nation’s critical information systems by designing and operating cyberattack detection capabilities, and by ensuring the availability of trusted security products capable of safeguarding the most sensitive data and addressing the most serious threats;

the victims of cyberattacks and the Nation by structuring national-level victim assistance;

an autonomous vision of cybersecurity and stability in cyberspace at the international level.

Understand

the state of the art in information technology and systems security; the threats and risks in cyberspace; and the latest trends in cybersecurity, in France, Europe, and internationally.

Share

guidance, methodologies and tools with stakeholders in the cybersecurity and digital sectors;

knowledge and expertise on cyber threats and potential responses, in collaboration with technical, operational and strategic partners, whether French, European or non-European;

its expertise widely to strengthen collective security against cyber risks.

Support

the deployment of public cybersecurity policy and its territorial implementation;

authorities in understanding cyber issues;

regulated organisations in applying protective measures for their information systems and in responding to incidents;

the upskilling of public administrations and the private sector through the development of cybersecurity training programmes;

the growth of a trusted ecosystem of private providers of cybersecurity products and services.

Regulate

the quality of cybersecurity products and services through qualification and certification processes;

the quality of products incorporating digital components by promoting security by design and by default;

by designing normative and regulatory frameworks at the national, European, and international levels;

and by monitoring their proper implementation.