The ANSSI, the French National Frequencies Agency (ANFR), and the Directorate-General for Enterprises (DGE) gathered digital product manufacturers, conformity assessment bodies (OEC), and the digital solutions ecosystem on Wednesday, September 23, 2026, at the Centre Pierre Mendès France. The aim was to emphasize the importance of the Cyber Resilience Act (CRA) regulations.
In their opening remarks, Anne Le Hénanff, Minister Delegate for Artificial Intelligence and Digital, Despina Spanou, Deputy Director-General of DG Connect at the European Commission, Gilles Brégant, Director-General of ANFR, and Vincent Strubel, Director-General of ANSSI, highlighted that the CRA must become a fundamental regulatory framework for manufacturers of solutions incorporating digital elements.
Numerous vulnerabilities identified between 2025 and 2026 could have been avoided by implementing the basic security rules outlined in the CRA. The event served to remind digital solution providers of their obligations, introduce them to trusted third parties and notified bodies for compliance, and explain the ANFR's procedures for product control and market surveillance.
Since September 11, 2026, actively exploited vulnerabilities and serious incidents are addressed under Article 14 of the CRA. By December 11, 2027, all digital products available on the European market must meet the essential requirements defined in the regulation.
The ANSSI and ANFR will play a central role in the CRA's implementation in France. The ANFR will act as the market surveillance authority for digital products in the national market, conducting product analyses to verify compliance and having the power to take administrative police measures or impose financial penalties for non-compliance. The ANSSI will serve as the notifying authority and national CSIRT, responsible for assessing and notifying conformity assessment bodies (OEC).




