The French state's cybersecurity roadmap: the document that says everything without meaning to
An official document lands on your desk. It comes from the Prime Minister. It is called "Roadmap of priority efforts for the state's digital security 2026-2027". You open it.

You are a CISO in a French company. For months you have been told to prepare for NIS2, to structure your governance, to prove that your access is under control, that your backups are tested, that your systems are up to date for a solid level of cybersecurity. You are working on it, with tight budgets and constant trade-offs. And then an official document lands on your desk. It comes from the Prime Minister. It is called "Roadmap of priority efforts for the state's digital security 2026-2027". You open it. And you discover that the state, the very one that sets the rules, has not yet done what it demands of you.
This document, approved by the strategic committee on digital security, is meant to be a roadmap. In reality, it is an inventory of admissions. Not because what it asks for is absurd. On the contrary, every action listed is perfectly sensible. The problem lies elsewhere. The problem is that these actions should have been in place for years, and that the entities involved are not small rural businesses. They are ministries.
What does the French state's cybersecurity roadmap require?
Published on 9 April 2026, the 2026-2027 roadmap is drawn up every year under interministerial general instruction no. 1337, approved by the strategic committee on the state's digital security, COSINUS, and then through interministerial consultation. It sets out around forty dated actions spread across ten chapters. Taken one by one, those actions sketch in negative the real state of the systems.
Action 7.a asks ministries to put in place multi-factor authentication for all information system administrators by 31 December 2026. Which means that in April 2026, privileged accounts, the ones with total access to the state's most sensitive infrastructure, are still running on a simple password. We are not talking about guest Wi-Fi access. We are talking about the keys to the kingdom. MFA on administrator accounts is the foundation. It is the first thing any auditor checks. And the state is giving itself another eight months to do it.
More telling still, MFA for ordinary users is only required later: by 28 February 2027 for high-stakes systems, by 28 February 2028 for all the rest (Action 6.c). In other words, the daily access of tens of thousands of civil servants to their working tools will still rest, in part, on a simple password until 2028.
Action 6.e calls for the removal of generic accounts by 30 June 2026. A generic account is a login shared between several people. When an incident occurs, it is impossible to know who did what. It is anti-traceability by design. Every security framework for the past fifteen years has banned this practice. And yet the document admits that these accounts still exist in ministerial information systems, and that a formal target is needed to eliminate them. The text even provides an escape hatch: failing removal, "strengthen their traceability". So it is acknowledged that some will remain.
Action 6.b provides for reviews of access rights "at least once a year" for high-stakes systems. Once a year. For critical state systems. In the banking sector, privileged accounts are reviewed quarterly. In most compliance frameworks, an annual review is the minimum for standard access, not for the systems that support a ministry's essential missions.
Action 7.c adds another telling marker: raising the security of critical directories, Active Directory in particular, to the level that protects against already known vulnerabilities, meaning level 3 of the ADS indicator, by 30 June 2026. We are talking here about flaws documented for years, routinely exploited by attackers in almost every large-scale compromise.
Detection, backups, email: the other blind spots
Action 8.b calls for the rollout of EDR or XDR solutions across all workstations and servers by 31 December 2026. Which means that ministries are today operating without advanced detection capability on their endpoints. In a context that the document itself describes as "a general rise in the threat and a degraded geopolitical situation". Companies have been asked to monitor their endpoints for years, and the state has not yet finished doing so at home.
Action 9.b concerns backup tests. The document specifies that a first test was "previously planned from 31 March 2025" and that a new test must be carried out by 30 June 2026. The wording is telling. It does not say "continue regular testing". It says "a test must be carried out". Which suggests that the first appointment was not kept everywhere, or that the results were bad enough to justify a reminder.
The document is even explicit about the ways in. "Cyberattacks against the state make preferential use of vulnerabilities in DNS and email", it writes, before calling for DNS security to be strengthened by 30 September 2026 (Action 5.a) and email systems by 31 December 2026 (Action 5.b). The two attack vectors best known to the profession are therefore still not handled everywhere.
Which cyber incidents does the state acknowledge for 2025?
The roadmap says it itself, without dwelling on it: "the multiple intrusions and data breaches that affected the information systems of ministries and of the bodies under their supervision in 2025 are a reminder of the persistence of serious vulnerabilities". It is a remarkable sentence, both for what it contains and for what it does not develop. It gives no figures. It does not name the ministries hit. It does not describe the nature of the breaches. But it acknowledges, in an official document approved at the highest level, that the state's systems were breached and that data leaked. And that the response is a two-year catch-up plan.
That finding does not come out of nowhere. In its Panorama de la cybermenace 2025, published on 11 March 2026, ANSSI reports having handled 3,586 security events over the year, down 18% year on year. Public administrations, ministries and local authorities together account for 24% of those events, just behind education and research (34%). And of the 460 events potentially involving a data breach, 42% were confirmed as actual leaks. The roadmap quotes none of these figures, but they set the scene.
The document also acknowledges, again between the lines, that budget constraints slowed the implementation of the previous roadmap. This is not trivial. It means that the 2025-2026 roadmap was not fully carried out, and that the 2026-2027 version "takes up its actions" and "firms up certain deadlines". In other words, we push back and start over. The cycle is familiar to anyone who has worked with large organizations, but it takes on a particular dimension when the organization in question is the one writing the rules for everyone else.
The NIS2 paradox: does the state apply its own rules?
This is where the dissonance becomes hard to ignore. Through NIS2, the French state is building a regulatory framework that will impose strict obligations on essential and important entities regarding governance, risk management, detection and incident response. These obligations are necessary. No serious person disputes it. But when the state itself fails to apply these same principles to its own systems, the regulator's credibility is at stake.
The roadmap owns up to it in black and white: the previous version had been written "with a view to bringing state administrations into compliance with the NIS 2 directive", whose Article 2 now brings public administrations inside the regulated perimeter, and whose Articles 20 and 21 set the obligations. The state therefore knows it is subject to the same rules as companies. It simply gives itself deadlines that nobody would grant a company in the middle of an audit.
And the problem goes beyond credibility. In 2025, during the debates on the anti-narcotrafficking law, the National Assembly seriously discussed installing access mechanisms in encrypted messaging. The government found the time and the political energy to propose weakening encryption, while it had not yet managed to impose MFA on its own administrators. There is in that sequence an inconsistency that goes beyond political clumsiness. It is a problem of priority ordering, and it reveals a deep confusion about what "digital security" means in practice.
Post-quantum preparation, the document's real strength
Not everything here is catch-up. Chapter 10 adds a dimension that few companies have even started to look at: the transition to post-quantum cryptography. And the reasoning is sound. A quantum computer capable of breaking current cryptographic mechanisms would make them obsolete overnight, and some attacks already consist, according to the document, of "capturing lastingly sensitive information now and storing it in order to decrypt it once the capabilities are available". That is the harvest now, decrypt later logic. The text therefore sets two inventories (end of 2026, then end of 2027), a rollout for systems handling restricted-distribution information before the end of 2030, and the obligation, from 2030, to deploy only encryption products that embed this cryptography (Actions 10.a to 10.d). On this ground, the state genuinely anticipates.
Other signals point the right way. The obligation, in the event of a significant incident, to send a follow-up report to ANSSI, to the inspectorate and to the Prime Minister six months after the facts. The consolidation of ministerial CSIRTs and their networking with CERT-FR, with the possibility of sharing useful information without prior sign-off from the ministerial hierarchy. The oversight of the cybersecurity of public bodies under ministerial supervision. These are real steps forward, and they deserve credit.
What this roadmap says about us
The document is not bad in itself. It is clear-eyed about the gaps, precise in its deadlines, structured in its priorities. The problem is not the plan. The problem is that we are still at the plan stage.
When a state publishes a roadmap in 2026 asking its ministries to remove generic accounts, to test their backups and to put MFA on admin accounts, that is not a signal of maturity. It is a signal of emergency disguised as a governance document. And any professional who reads it with a minimum of field experience understands exactly what it means about the real state of the systems behind the facade.
The state asks French companies to bring themselves into compliance. It would do well to start by applying that to itself. Not because it would be symbolically elegant, but because attackers do not read roadmaps. They read vulnerabilities.
Sources
- Feuille de route des efforts prioritaires en matière de sécurité numérique de l'État 2026-2027, Prime Minister, published 9 April 2026 (actions, deadlines, acknowledgement of the 2025 intrusions and breaches, budget constraints, post-quantum transition): cyber.gouv.fr.
- Panorama de la cybermenace 2025, ANSSI, 11 March 2026 (3,586 security events handled, down 18%, public administrations at 24% of events, education and research at 34%): cyber.gouv.fr.
- Directive (EU) 2022/2555 (NIS 2), inclusion of public administrations in the regulated perimeter (Article 2) and governance and risk management obligations (Articles 20 and 21).
Frequently asked questions
What does Action 7.a of the roadmap require?
It requires putting in place multi-factor authentication for all information system administrators in the ministries by 31 December 2026. This reveals that in April 2026, privileged accounts were still running on a simple password.
When was the state's 2026-2027 cybersecurity roadmap published?
It was published on 9 April 2026. Drawn up every year under interministerial general instruction no. 1337, it is approved by the strategic committee on the state's digital security (COSINUS) and then through interministerial consultation.
Why is removing generic accounts important?
A generic account is a login shared between several people, which makes it impossible to know who did what during an incident. Action 6.e sets their removal for 30 June 2026, or failing that the strengthening of their traceability, even though this practice has been banned by security frameworks for fifteen years.
Does the document acknowledge security incidents?
Yes. It mentions "the multiple intrusions and data breaches that affected the information systems of ministries in 2025", without giving figures, naming the ministries, or describing the nature of the breaches. In parallel, ANSSI handled 3,586 security events in 2025, 24% of which targeted public administrations.
What is the paradox with NIS2?
Through NIS2, the state is building a framework that imposes strict obligations on companies for governance, risk management and detection, while it has not yet applied these same basic principles to its own systems. This weakens the regulator's credibility.
Does the roadmap include forward-looking measures?
Yes. Actions 10.a to 10.d organise the transition to post-quantum cryptography: an inventory of lastingly sensitive data by the end of 2026, then a rollout for restricted-distribution information before the end of 2030. The author sees a genuine capacity for anticipation there.
Which systems must be secured first according to the roadmap?
The high-stakes information systems, meaning those that support a ministry's essential missions or process sensitive data. Most of the nearest deadlines, access reviews, accreditation, EDR or MFA, give them priority.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
