Skip to content
Nenkin

ANSSI: France's Common Criteria Scheme

ANSSI, the Agence nationale de la sécurité des systèmes d’information, is France’s national cybersecurity agency and the certification body for Common Criteria evaluations performed in France. It is a long-standing CCRA authorizing scheme and a major issuer of high-assurance certifications.

Key facts

  • Authorizing body: Agence nationale de la sécurité des systèmes d’information (ANSSI)
  • Country / region: France
  • Year established: ANSSI was created in 2009, taking over responsibilities from the former DCSSI; France has operated a national CC scheme since the original Common Criteria were published
  • Product types: smart cards and ICs, HSMs, secure microcontrollers, eID components, network devices, operating systems, mobile devices
  • CCRA status: Certificate Authorizing Member; historically a SOG-IS authorizing member; designated EUCC certification authority in France
  • Canonical portal: https://cyber.gouv.fr/ (certified solutions section under “offre-de-service/solutions-certifiees-et-qualifiees”)

Overview

ANSSI is known for strict procedural discipline and for operating the Certification de Sécurité de Premier Niveau (CSPN), a national, lighter-weight scheme distinct from Common Criteria. For CC proper, ANSSI certifies at EAL levels up to EAL7 in technical domains where SOG-IS (and now EUCC) allowed high-assurance recognition, most notably smart card hardware and software.

How evaluations work under this scheme

Evaluations are carried out by ANSSI-licensed Centres d’évaluation de la sécurité des technologies de l’information (CESTI), the French designation for an ITSEF. The CESTI produces an Evaluation Technical Report and ANSSI issues the final Certification Report. France has a strong tradition in formal methods, which makes ANSSI one of the schemes most familiar with EAL5+, EAL6, and EAL7 evaluations.

Beyond standard CC, ANSSI actively publishes technical notes and interpretations, and coordinates with its European peers on smart card attack methodology.

Notable product categories

  • Smart card ICs and embedded secure elements at high EALs with AVA_VAN.5
  • Smart card operating systems (including Java Card platforms)
  • Payment and banking products
  • eID components for French and European government use
  • Qualified trust service components under eIDAS

Relationship to CC baseline

ANSSI evaluations follow ISO/IEC 15408 and CC:2022. France participates in international Protection Profile development, particularly for smart cards and embedded devices, and is a designated EUCC authority issuing certificates under the EU Cybersecurity Act framework.

Where to find official records

See also: What is Common Criteria?, EAL Levels, Protection Profiles, Glossary.

Frequently asked questions

What is ANSSI?
ANSSI is the Agence nationale de la sécurité des systèmes d'information, France's national cybersecurity agency. It was created in 2009, taking over from the former DCSSI, and operates France's Common Criteria certification scheme. ANSSI is a CCRA Certificate Authorizing Member and a designated EUCC certification authority in France.
What does ANSSI certify?
ANSSI issues Common Criteria certificates for smart cards and integrated circuits, hardware security modules, secure microcontrollers, eID components, network devices, operating systems, and mobile devices. The scheme is particularly active in high-assurance smart card and embedded evaluations, and certifies qualified trust service components used under the eIDAS regulation.
How is an ANSSI certificate issued?
An ANSSI-licensed Centre d'évaluation de la sécurité des technologies de l'information (CESTI), the French ITSEF, performs the technical evaluation against the Common Evaluation Methodology and produces an Evaluation Technical Report. ANSSI reviews the report, resolves observations, and issues the final Certification Report. Smart card evaluations follow joint smart card interpretation documents.
Is ANSSI a CCRA member?
Yes. ANSSI is a CCRA Certificate Authorizing Member, so certificates it issues are recognised by all other CCRA member nations up to the standard cap (EAL2 for arbitrary evaluations, higher for products conforming to a collaborative Protection Profile). ANSSI was historically a SOG-IS authorizing member and now also acts as the French EUCC certification authority.
What is the difference between ANSSI Common Criteria and CSPN?
ANSSI runs two distinct programmes. Common Criteria evaluations follow ISO/IEC 15408 and produce CCRA-recognised certificates up to EAL7. CSPN (Certification de Sécurité de Premier Niveau) is a separate, lighter-weight national scheme designed for faster, lower-assurance evaluations against a fixed effort budget. CSPN certificates are national to France and are not part of CCRA mutual recognition.
Why is ANSSI known for high-assurance evaluations?
France has a strong tradition in formal methods, and ANSSI is one of the schemes most experienced with EAL5+, EAL6, and EAL7 evaluations. This expertise concentrates in smart card hardware and software, payment and banking products, and eID components for French and European government use. ANSSI also publishes technical notes and coordinates smart card attack methodology with European peers.