In brief: On July 3, 2026, ANSSI, ACPR, and the Banque de France signed a cooperation agreement to strengthen information sharing and cyber crisis management for the financial sector, within the framework of NIS2 and DORA. In particular, the agreement introduces a common framework for advanced threat-led penetration testing (TLPT). For any organization subject to DORA or NIS2, this type of agreement signals one thing: the actual technical robustness of systems—not just compliance documentation—is becoming the direct focus of regulatory oversight—and endpoint hardening is the foundation of that.

What does the ANSSI/ACPR/Banque de France agreement provide for?

On July 3, 2026, the National Cybersecurity Agency (ANSSI), the Prudential Supervision and Resolution Authority (ACPR), and the Bank of France signed a cooperation agreement aimed at strengthening information sharing and coordination in response to cyber threats in the financial sector, in compliance with the NIS2 Directive and the DORA Regulation. This agreement, which extends a cooperation initiative launched in 2018, defines the respective roles: ANSSI leads the technical response to incidents through CERT-FR; the ACPR ensures that financial institutions comply with DORA; and the Banque de France is responsible for the resilience of the financial infrastructures themselves.

The collaboration is organized around four areas: incidents and cyber threats, audits and mutual assistance, cyber crisis management, and, above all, advanced threat-based penetration testing (TLPT), which aims to provide a practical assessment of the robustness of information systems rather than merely verifying their compliance on paper. Source: ANSSI news release dated July 6, 2026.

Why does this type of agreement extend beyond the financial sector alone?

At first glance, this agreement directly affects only financial entities subject to DORA. However, it illustrates a broader trend that the NIS2 Directive applies to a much wider scope—more than 15,000 entities across eighteen sectors in France, including small and medium-sized enterprises (SMEs) and mid-sized companies, provided they operate in a regulated sector or are a critical supplier to a regulated entity: regulatory oversight is no longer limited to verifying the existence of a security policy on paper. It seeks to verify, through exercises such as the TLPT, that systems can effectively withstand a realistic simulated attack.

For an organization that discovers during an advanced penetration test that its Windows workstations and servers do not have basic controls in place—unrestricted local administrative rights, no audit logging, and unnecessarily exposed services—the evidence of noncompliance is immediate and potentially costly.

How does endpoint hardening actually prepare for a TLPT or a NIS2/DORA audit?

A threat-based penetration test generally follows the same path as a real attacker: initial access, followed by privilege escalation and lateral movement from a compromised workstation or server. Endpoint hardening specifically targets this chain:

  • Reduced local administrator privileges: Without a privileged local account available, a tester (or an attacker) cannot easily escalate their privileges after gaining initial access—this is often the first obstacle encountered during a TLPT.
  • Audit logging in compliance with regulatory requirements: Both NIS2 and DORA require the ability to quickly detect and report incidents; a properly configured Windows audit (process creation, privilege escalation, logins) provides the raw data on which this capability is based.
  • Alignment with a recognized standard: Documenting compliance with the CIS Benchmarks or the ANSSI Windows Hardening Guide provides auditors (internal, ACPR, or third parties commissioned for a TLPT) with an objective basis for comparison rather than a mere statement of intent.
  • Reducing the attack surface before the test —by disabling unnecessary services and restricting legacy protocols (SMBv1, unencrypted NTLM)—limits the number of attack vectors that a tester—or a real attacker—can exploit.

Does hardening replace a regulatory audit or TLPT?

No. Endpoint hardening is a necessary but not sufficient condition: a TLPT remains an exercise conducted by qualified service providers, overseen by the ACPR for the financial institutions involved, using its own methodology. What hardening provides is the assurance that basic controls are already in place before the exercise—preventing a costly test from merely confirming basic, already known gaps. An agentless hardening platform like Cyberlib, by continuously verifying the compliance of Windows workstations and servers with CIS and ANSSI baselines, enables an IT team at an SME or mid-sized company to approach a NIS2 audit, a DORA review, or a TLPT with established visibility into the actual state of their infrastructure, rather than discovering it on the day of the audit.

FAQ

Does this ANSSI/ACPR/Banque de France agreement apply to my small business if I'm not in the financial sector?

Not directly, but it illustrates the general direction of European cybersecurity regulations (NIS2, DORA): oversight is increasingly focused on demonstrated technical robustness, not just on documentation. Any entity subject to NIS2—or any supplier to such an entity—is affected by this same approach.

What is TLPT (Threat-Led Penetration Testing)?

It is an advanced penetration test based on realistic threat scenarios specific to the sector or organization being tested, designed to assess the actual resilience of systems rather than simply identifying generic vulnerabilities. DORA requires this for certain financial institutions.

Does endpoint hardening help ensure a successful NIS2 audit?

Yes, insofar as Article 21 of NIS2 requires risk management and cybersecurity practices, including the secure configuration of systems. A hardened infrastructure that is documented according to a recognized standard (CIS, ANSSI) makes it easier to demonstrate compliance during an audit.

What is the difference between the ACPR and the ANSSI under this new agreement?

The ACPR monitors financial institutions’ compliance with DORA regulations; ANSSI, through CERT-FR, is responsible for the technical response to cybersecurity incidents. The Banque de France rounds out the framework by ensuring the resilience of the financial infrastructure itself.

Should you wait for a regulatory audit before securing your Windows environment?

No—waiting risks uncovering gaps during an audit or a real-world incident, at which point correcting them is most costly and most visible. Continuous monitoring allows you to correct discrepancies as they arise.

Sources


Conducting a NIS2 audit, a DORA assessment, or an advanced penetration test requires knowing, on an ongoing basis, how your Windows environment actually measures up against the CIS and ANSSI standards—not just on the day of the assessment. Cyberlib automates this continuous, agentless compliance monitoring across your entire environment.