Information Systems Security Accreditation
Understand, prepare and carry out the process by which an authority formally accepts the digital risks of an information system.
Security accreditation is the formal acknowledgment and acceptance of an information system's digital risks by a responsible authority. It is a prerequisite before any system goes into service and must be renewed periodically, at least every three years.
It is made mandatory by numerous texts depending on the nature of the information processed — the French General Security Framework (RGS), decree n°2022-513 on the digital security of the State, French Interministerial General Instructions (IGI 1300, IGI 2102, II 2100, II 901), the Military Programming Law for Vital Importance Information Systems (SIIV) — and strongly recommended by ANSSI, the French cybersecurity agency, for any system considered critical, even outside any regulatory obligation.
It applies to public administrations and operators as well as to private companies working with demanding principals. This is notably the case for contractors of the French Direction générale de l'armement (DGA) — the French defense procurement agency — for whom the Ministry of the Armed Forces requires an accreditation proportionate to the actual needs of the information system, following an elementary, adapted or standard approach set by their accreditation authority.
This page summarizes the methodology of the Guide to the Security Accreditation of Information Systems, published by ANSSI in partnership with DINUM (April 2025), whose details and associated method sheets are referenced at the bottom of the page.
The Prerequisites
These elements must be in place before assembling the accreditation file.
Security Governance
A security policy (PSSI), a three-lines-of-defense governance model (operational, CISO, control) and committed, funded management teams.
Defined Scope and Ecosystem
A precise map of the information system to be accredited and of the external building blocks — interconnections, hosting providers, service providers — it depends on without being part of it.
Regulations Identified
The texts applicable to the system (RGS, IGI 1300, IGI 2102, II 2100, II 901, LPM/SIIV…) that determine the competent accreditation authority, the maximum validity period and the specific audits required.
Security Measures Applied
Digital hygiene best practices and the requirements of the applicable frameworks and security policies, tracked and justified measure by measure.
Risk Analysis Carried Out
Identification and treatment of the risks related to the system's use, using a recognized method — ANSSI's EBIOS Risk Manager method is recommended.
Plans and Audits Completed
Operational continuity plan (MCO), security maintenance plan (MCS), resilience plan and security audits covering the chosen scope.
Accreditation in Four Steps
A cyclical process, to be adapted to the system's criticality and exposure.
Form the Accreditation Committee
Chaired by the CISO or the digital security advisor, the committee brings together business stakeholders, the design team (project owner and contractor), operations teams, auditors and any necessary experts. It must be formed before the system goes into service and before every re-accreditation.
Determine the Process Level and Assemble the File
The level — simplified, intermediate or reinforced — is determined by the system's criticality and its exposure to digital risk sources. It sets the list of documents to gather: summary document, architecture file, compliance matrix, risk analysis, operating procedures, continuity/security/resilience plans and audits.
Assess the File and Issue an Accreditation Opinion
The committee reviews the file's documents, discusses them with their authors and issues a reasoned opinion to the accreditation authority: favorable, favorable with reservations — with a plan to lift the reservations within 12 months maximum —, or unfavorable if the system cannot yet be put into service.
Hold the Accreditation Board
A meeting presenting the system to the accreditation authority, mandatory for any reinforced-level process. It rules on putting the system into service or keeping it in service, and sets the accreditation period — three years maximum, regardless of the applicable regulation.
Once obtained, accreditation does not exempt from ongoing follow-up: an annual security review, updates to the action plan and renewal of the process before expiry are required to maintain it.
ANSSI Method Sheets
ANSSI provides a comprehensive guide and additional method sheets, adapted to different types of information systems and contexts. These resources are published in French.
- The Guide to the Security Accreditation of Information Systems (ANSSI / DINUM, April 2025)
- Method sheet — Accreditation for Decision-Makers
- Method sheet — Identifying the Accreditation Authority
- Method sheet — Isolated and Simple Information System
- Method sheet — Replicated Information System
- Method sheet — Accreditation and ISO 27001
- Method sheet — Organizing an Information System Review
Sources
A security accreditation process to navigate with confidence
Dipole Security supports your teams with risk analysis, PASSI LPM qualified audits and building the accreditation file.
Contact us