Security accreditation is the formal acknowledgment and acceptance of an information system's digital risks by a responsible authority. It is a prerequisite before any system goes into service and must be renewed periodically, at least every three years.

It is made mandatory by numerous texts depending on the nature of the information processed — the French General Security Framework (RGS), decree n°2022-513 on the digital security of the State, French Interministerial General Instructions (IGI 1300, IGI 2102, II 2100, II 901), the Military Programming Law for Vital Importance Information Systems (SIIV) — and strongly recommended by ANSSI, the French cybersecurity agency, for any system considered critical, even outside any regulatory obligation.

It applies to public administrations and operators as well as to private companies working with demanding principals. This is notably the case for contractors of the French Direction générale de l'armement (DGA) — the French defense procurement agency — for whom the Ministry of the Armed Forces requires an accreditation proportionate to the actual needs of the information system, following an elementary, adapted or standard approach set by their accreditation authority.

This page summarizes the methodology of the Guide to the Security Accreditation of Information Systems, published by ANSSI in partnership with DINUM (April 2025), whose details and associated method sheets are referenced at the bottom of the page.

Before Starting the Process

The Prerequisites

These elements must be in place before assembling the accreditation file.

Security Governance

A security policy (PSSI), a three-lines-of-defense governance model (operational, CISO, control) and committed, funded management teams.

Defined Scope and Ecosystem

A precise map of the information system to be accredited and of the external building blocks — interconnections, hosting providers, service providers — it depends on without being part of it.

Regulations Identified

The texts applicable to the system (RGS, IGI 1300, IGI 2102, II 2100, II 901, LPM/SIIV…) that determine the competent accreditation authority, the maximum validity period and the specific audits required.

Security Measures Applied

Digital hygiene best practices and the requirements of the applicable frameworks and security policies, tracked and justified measure by measure.

Risk Analysis Carried Out

Identification and treatment of the risks related to the system's use, using a recognized method — ANSSI's EBIOS Risk Manager method is recommended.

Plans and Audits Completed

Operational continuity plan (MCO), security maintenance plan (MCS), resilience plan and security audits covering the chosen scope.

ANSSI / DINUM Methodology

Accreditation in Four Steps

A cyclical process, to be adapted to the system's criticality and exposure.

1

Form the Accreditation Committee

Chaired by the CISO or the digital security advisor, the committee brings together business stakeholders, the design team (project owner and contractor), operations teams, auditors and any necessary experts. It must be formed before the system goes into service and before every re-accreditation.

2

Determine the Process Level and Assemble the File

The level — simplified, intermediate or reinforced — is determined by the system's criticality and its exposure to digital risk sources. It sets the list of documents to gather: summary document, architecture file, compliance matrix, risk analysis, operating procedures, continuity/security/resilience plans and audits.

3

Assess the File and Issue an Accreditation Opinion

The committee reviews the file's documents, discusses them with their authors and issues a reasoned opinion to the accreditation authority: favorable, favorable with reservations — with a plan to lift the reservations within 12 months maximum —, or unfavorable if the system cannot yet be put into service.

4

Hold the Accreditation Board

A meeting presenting the system to the accreditation authority, mandatory for any reinforced-level process. It rules on putting the system into service or keeping it in service, and sets the accreditation period — three years maximum, regardless of the applicable regulation.

Once obtained, accreditation does not exempt from ongoing follow-up: an annual security review, updates to the action plan and renewal of the process before expiry are required to maintain it.

A security accreditation process to navigate with confidence

Dipole Security supports your teams with risk analysis, PASSI LPM qualified audits and building the accreditation file.

Contact us