ACPR or AMF: your authority follows your status
The question that comes up first is rarely "what does DORA say" but "who do I talk to". In France the answer does not depend on which DORA article is at stake. It depends on the status under which you are authorised.
| Entity type | Competent authority | Filing portal |
|---|---|---|
| Credit institutions | ACPR (attached to the Banque de France) | OneGate |
| Insurance and reinsurance undertakings | ACPR | OneGate |
| Payment and e-money institutions | ACPR | OneGate |
| Portfolio management companies | AMF | GECO |
| Investment firms, market infrastructures | AMF | GECO |
| Digital-asset service providers | AMF | GECO |
A group holding both a bank and a management company therefore has two counterparties, two portals and two filing calendars. That is the first thing to settle before organising the reporting chain, and the one group programmes tend to discover last.
Significant credit institutions remain supervised directly by the ECB under the SSM. DORA compliance is examined there through the SREP, on top of the dialogue with the ACPR.
Register of Information: the French deadline and channel
Article 28(3) requires every in-scope entity to maintain a register of all contractual arrangements for ICT services provided by third parties, and to report it to its competent authority. The format is set at European level by ITS (EU) 2024/2956: fifteen inter-linked templates, in xBRL-CSV.
For France, the entity filing deadline is 31 March 2026. Authorities then consolidate and submit to the European Supervisory Authorities by 30 April 2026. Because the entity date is set nationally, confirm it with your own authority before planning the workload around it.
Two first-cycle mistakes cost the most, and neither is specifically French: aggregating contracts by provider instead of one record per arrangement, and leaving sub-outsourcing templates empty for large cloud providers. Supervisory cross-checking is automated.
The fifteen templates and the format are covered on the Register of Information page.
Reporting a major incident: OneGate and GECO
The notification deadlines are European and do not vary between Member States: initial notification, intermediate report, final report. What is national is the channel and the language.
In France, filing goes through OneGate for entities supervised by the ACPR, and through GECO for those under the AMF. French is the filing language, with English accepted as a secondary language depending on the case.
Test the portal outside an incident. Identify who holds the credentials, check that they work, run a dry-run filing. A team discovering the authentication flow in hour four of a major incident has already spent most of its window. This is where an annual rehearsal pays for itself.
The deadlines and templates are detailed on the incident reporting page.
TIBER-FR and threat-led testing
Articles 26 and 27 require threat-led penetration testing from entities identified by their competent authority on the basis of size, risk profile and systemic importance. Not every entity is in scope: designation is an act of the authority, not a self-assessment.
France runs its national implementation of the European TIBER-EU framework, TIBER-FR, steered on the Banque de France and ACPR side. An entity already running TIBER-FR exercises will recognise most of the method: red team, white team, threat intelligence, authority attestation. The deltas sit in the coordination with the authority and in the content of the closing report.
The full framework, the roles and the run of a test are on the TLPT page.
What DORA changes, and does not change, in French law
DORA is a Regulation. It applies directly, with no transposing statute, since 17 January 2025. That is the difference in kind with NIS2, which is a Directive and reaches you through national law.
For a French financial entity, three practical consequences:
- There is no "French version of DORA" to wait for. The applicable text is the Regulation itself and its technical standards.
- DORA does not replace your existing internal control framework. It sits on top and reuses its evidence: risk mapping, continuity plans and existing committees remain the foundation.
- For financial entities covered by both, DORA prevails over NIS2 as lex specialis. The detailed comparison is on the DORA vs NIS2 page.
Pre-existing French information-security obligations, notably those overseen by ANSSI for the operators concerned, continue under their own regime. DORA neither absorbs nor cancels them.
Penalties: what the Regulation says, and what it does not
This is where the largest number of false statements circulate, trade press included.
DORA sets no EU-wide maximum fine for financial entities: Article 50 leaves administrative penalties to national law, so the amount depends on the Member State. The only turnover-based percentage in the Regulation applies to designated critical ICT third-party providers (1% of average daily worldwide turnover, Article 35).
In France, the power to sanction sits with the enforcement committees of the ACPR and the AMF, depending on which authority you report to. The percentage of turnover often attributed to DORA in fact belongs to NIS2.
The full regime, with articles and verbatim citations, is on the What is DORA page.