National Regulation Active

Loi de Programmation Militaire

France's Military Programming Law imposing strict cybersecurity obligations on Operators of Vital Importance (OIV), including cryptographic controls and certificate management for critical national infrastructure.

Quick Facts

Status
In Force (LPM 2024-2030)
Type
National Regulation
Country
France 🇫🇷
Authority
ANSSI / SGDSN
Scope
~250 OIV operators

Overview

The Loi de Programmation Militaire (LPM) establishes France's defense and national security framework, including mandatory cybersecurity requirements for Operators of Vital Importance (OIV). These approximately 250 operators span 12 critical sectors including energy, transport, telecommunications, health, and finance.

ANSSI (Agence nationale de la sécurité des systèmes d'information) enforces technical rules requiring OIVs to implement qualified detection systems, incident reporting, and cryptographic controls including PKI-based authentication and encrypted communications. The law gives ANSSI authority to audit OIV systems and enforce compliance.

Non-compliance with LPM cybersecurity obligations can lead to severe sanctions. The latest iteration, LPM 2024-2030, further strengthens these requirements and aligns them with emerging European frameworks such as NIS2, reinforcing France's position as a leader in critical infrastructure cybersecurity.

Key Requirements

OIV Security Obligations (Art. L.1332-6-1)

Operators of Vital Importance must implement security measures defined by the Prime Minister, including network segmentation, access controls, and cryptographic protections for critical information systems.

Qualified Intrusion Detection Systems

OIVs must deploy ANSSI-qualified intrusion detection probes on their critical information systems to detect and report cyberattacks in real time.

Incident Reporting to ANSSI

OIVs must report significant security incidents to ANSSI without delay, providing detailed technical information to enable coordinated response and threat intelligence sharing.

Cryptographic Controls & Key Management

OIVs must implement ANSSI-approved cryptographic mechanisms for data protection, including certificate-based authentication and encrypted communications on critical systems.

Security Audits by ANSSI-Qualified Providers

OIVs must undergo regular security audits conducted by ANSSI-qualified audit service providers (PASSI) to verify compliance with technical rules and security standards.

Compliance with ANSSI Technical Rules

OIVs must comply with sector-specific technical rules (arrêtés) issued by ANSSI, covering network architecture, access control, cryptography, and system hardening requirements.

Key Milestones

13
2013

LPM 2014-2019 adopted

Article 22 introduces mandatory cybersecurity obligations for Operators of Vital Importance (OIV) for the first time in French law.

16
2016

ANSSI technical rules published

ANSSI publishes sector-specific technical rules (arrêtés) detailing security requirements for each OIV sector.

18
2018

LPM 2019-2025 strengthens obligations

Updated law reinforces OIV cybersecurity obligations and expands ANSSI's audit and enforcement powers.

23
2023

LPM 2024-2030 adopted

New military programming law adopted, enhancing cyber defense capabilities and aligning OIV requirements with evolving threats.

25
2025 Current

Enhanced OIV requirements

Strengthened OIV obligations take effect with alignment to NIS2 transposition and updated ANSSI technical frameworks.

Impact on PKI & Certificates

The LPM's cybersecurity requirements have significant implications for PKI infrastructure and certificate management within OIV critical systems. Here are the critical areas:

1

Certificate-Based Authentication

Certificate-based authentication is mandatory for OIV critical systems, ensuring strong identity verification for administrators and automated processes accessing sensitive infrastructure.

2

ANSSI-Approved Cryptography

Encrypted communications must use ANSSI-approved cryptographic algorithms and protocols, requiring certificates issued by compliant PKI infrastructure.

3

Detection System Authentication

PKI infrastructure is required for authenticating qualified intrusion detection probes and ensuring the integrity of security event data transmitted to ANSSI.

4

Key Management for Sensitive Information

Key management obligations apply to classified and sensitive information, requiring rigorous certificate lifecycle processes and hardware security module integration.

How we help

Evertrust & LPM

ANSSI-certified PKI with Stream — Stream provides sovereign, ANSSI-certified PKI infrastructure delivering OIV-grade security for certificate authority, registration authority, and timestamping operations.

Certificate hygiene with Horizon — Horizon ensures complete certificate visibility and hygiene across all OIV critical systems through discovery, inventory, and policy enforcement.

Automated lifecycle management — Automated certificate issuance, renewal, and revocation meets ANSSI response time requirements, eliminating manual processes and reducing exposure windows.

Audit-ready compliance trails — Comprehensive audit trails and compliance reports ready for ANSSI inspections, demonstrating adherence to LPM technical rules and security standards.