National implementation

DORA in France: who supervises you, and through which portal

The Regulation is the same across the Union. What changes country by country is the authority that examines you, the portal you file through, and the language you write in. This is the French version.

ACPR and AMF Register due 31 March 2026 TIBER-FR Updated August 2026

ACPR or AMF: your authority follows your status

The question that comes up first is rarely "what does DORA say" but "who do I talk to". In France the answer does not depend on which DORA article is at stake. It depends on the status under which you are authorised.

Entity typeCompetent authorityFiling portal
Credit institutionsACPR (attached to the Banque de France)OneGate
Insurance and reinsurance undertakingsACPROneGate
Payment and e-money institutionsACPROneGate
Portfolio management companiesAMFGECO
Investment firms, market infrastructuresAMFGECO
Digital-asset service providersAMFGECO

A group holding both a bank and a management company therefore has two counterparties, two portals and two filing calendars. That is the first thing to settle before organising the reporting chain, and the one group programmes tend to discover last.

Significant credit institutions remain supervised directly by the ECB under the SSM. DORA compliance is examined there through the SREP, on top of the dialogue with the ACPR.

Register of Information: the French deadline and channel

Article 28(3) requires every in-scope entity to maintain a register of all contractual arrangements for ICT services provided by third parties, and to report it to its competent authority. The format is set at European level by ITS (EU) 2024/2956: fifteen inter-linked templates, in xBRL-CSV.

For France, the entity filing deadline is 31 March 2026. Authorities then consolidate and submit to the European Supervisory Authorities by 30 April 2026. Because the entity date is set nationally, confirm it with your own authority before planning the workload around it.

Two first-cycle mistakes cost the most, and neither is specifically French: aggregating contracts by provider instead of one record per arrangement, and leaving sub-outsourcing templates empty for large cloud providers. Supervisory cross-checking is automated.

The fifteen templates and the format are covered on the Register of Information page.

Reporting a major incident: OneGate and GECO

The notification deadlines are European and do not vary between Member States: initial notification, intermediate report, final report. What is national is the channel and the language.

In France, filing goes through OneGate for entities supervised by the ACPR, and through GECO for those under the AMF. French is the filing language, with English accepted as a secondary language depending on the case.

Test the portal outside an incident. Identify who holds the credentials, check that they work, run a dry-run filing. A team discovering the authentication flow in hour four of a major incident has already spent most of its window. This is where an annual rehearsal pays for itself.

The deadlines and templates are detailed on the incident reporting page.

TIBER-FR and threat-led testing

Articles 26 and 27 require threat-led penetration testing from entities identified by their competent authority on the basis of size, risk profile and systemic importance. Not every entity is in scope: designation is an act of the authority, not a self-assessment.

France runs its national implementation of the European TIBER-EU framework, TIBER-FR, steered on the Banque de France and ACPR side. An entity already running TIBER-FR exercises will recognise most of the method: red team, white team, threat intelligence, authority attestation. The deltas sit in the coordination with the authority and in the content of the closing report.

The full framework, the roles and the run of a test are on the TLPT page.

What DORA changes, and does not change, in French law

DORA is a Regulation. It applies directly, with no transposing statute, since 17 January 2025. That is the difference in kind with NIS2, which is a Directive and reaches you through national law.

For a French financial entity, three practical consequences:

Pre-existing French information-security obligations, notably those overseen by ANSSI for the operators concerned, continue under their own regime. DORA neither absorbs nor cancels them.

Penalties: what the Regulation says, and what it does not

This is where the largest number of false statements circulate, trade press included.

DORA sets no EU-wide maximum fine for financial entities: Article 50 leaves administrative penalties to national law, so the amount depends on the Member State. The only turnover-based percentage in the Regulation applies to designated critical ICT third-party providers (1% of average daily worldwide turnover, Article 35).

In France, the power to sanction sits with the enforcement committees of the ACPR and the AMF, depending on which authority you report to. The percentage of turnover often attributed to DORA in fact belongs to NIS2.

The full regime, with articles and verbatim citations, is on the What is DORA page.

Frequently asked questions

Does DORA apply to my French bank?

Yes, if it is authorised in the EU. DORA covers credit institutions of every size, from significant institutions supervised directly by the ECB to less significant institutions supervised by the ACPR. Proportionality affects the depth of the controls, not the scope: being small does not put you outside the Regulation.

ACPR or AMF: which authority is mine?

It follows your authorisation status, not the DORA article at hand. Banks, insurers and payment institutions sit with the ACPR. Portfolio management companies, investment firms and digital-asset service providers sit with the AMF. A mixed group therefore has two counterparties and two filing portals.

Do I file the Register of Information through OneGate?

Through OneGate if you report to the ACPR, through GECO if you report to the AMF. The format is European and identical either way: xBRL-CSV, fifteen templates, per ITS (EU) 2024/2956. The channel is national, the content is not.

Must an incident report be written in French?

French is the filing language in France, with English accepted as a secondary language depending on the case. The thing worth preparing is not the language but the access: identify who holds the portal credentials and run a dry-run filing before you need it.

Is TIBER-FR mandatory?

Not for everyone. The threat-led testing duty in Articles 26 and 27 applies to entities designated by their competent authority on the basis of size, risk profile and systemic importance. TIBER-FR is the French implementation of the European TIBER-EU framework, used by the entities concerned.

Does DORA replace my existing internal control framework?

No. DORA sits on top of what you have and reuses much of its evidence. Your risk mapping, continuity plans, committees and audit trails remain the foundation. The work is closing the DORA-specific gaps, not starting from a blank page.

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
89
certificates issued
59
certified professionals
14
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar