RGS (French general security framework): what it requires

Who must apply it, which version is in force, and why everything hinges on security accreditation.

· 10 min read
Illustration: a document approved with an orange checked stamp

The RGS, or référentiel général de sécurité (general security framework), sets the rules French administrative authorities must follow to secure their information systems, especially online services and electronic exchanges with users. Stemming from a 2005 ordinance and a 2010 decree, it is now at version 2.0, in force since 1 July 2014. Its first obligation is security accreditation (homologation): a formal decision, taken before go-live, that accepts a system's residual risks.

01

RGS: what the general security framework is

The acronym RGS has several meanings; in cybersecurity, it refers to the general security framework published by ANSSI, France's national cybersecurity agency. Its aim is to build trust in electronic exchanges between public administration and users, and between administrations.

According to ANSSI, it brings together three things:

  • a method for securing an information system, from risk analysis to accreditation;
  • a state of the art for security functions: identification, electronic signature, confidentiality, timestamping, cryptographic mechanisms;
  • a qualification scheme for security products and trust service providers.

The RGS is not a tick-box list. It asks each administration to start from its own risks and decide, with full knowledge, on suitable measures. In that sense it is closer to a risk management approach than to a catalogue of controls.

02

Who does the RGS apply to?

The RGS applies to administrative authorities, which ANSSI groups into six categories:

  • State administrations;
  • local authorities;
  • administrative public bodies;
  • bodies managing social security schemes;
  • other bodies managing an administrative public service;
  • committees for the prevention of evictions.

A town hall opening an online services portal, a county council managing benefits electronically or a social security fund are therefore directly concerned. The RGS also covers providers, public or private, supplying trust products or services to these authorities: it sets the standards they must meet to be qualified. For all other organisations, ANSSI presents it as a good-practice reference in line with the state of the art.

03

The RGS texts and the current version

The RGS rests on Ordinance No. 2005-1516 of 8 December 2005 on electronic exchanges with and between administrative authorities, and on Decree No. 2010-112 of 2 February 2010, which implements its Articles 9, 10 and 12. The framework itself is approved by ministerial order.

The RGS texts, from 2005 to today RGS text Related text
  1. 2005 8 December

    Ordinance No. 2005-1516

    On electronic exchanges between users and administrative authorities. It provides for a general security framework.

  2. 2010 2 February

    Decree No. 2010-112

    Implements the ordinance: risk analysis, security objectives, measures, accreditation, qualified products and providers.

  3. 2010 6 May

    Order approving the first RGS

    Published in the Official Journal on 18 May 2010, with compliance deadlines for systems already in service.

  4. 2014 13 June

    Order approving RGS 2.0

    Published on 24 June 2014, version 2.0 has applied since 1 July 2014. It is still the current version.

  5. 2014 17 July

    PSSIE circular No. 5725/SG

    The French State's information systems security policy, for ministries and their public bodies.

  6. 2015 10 June

    Order on deadlines

    Extends the deadlines for implementing the RGS.

  7. 2022 8 April

    Decree No. 2022-513

    Digital security of the information and communication system of the State and its public bodies.

  8. 2025 April

    Security accreditation guide

    Published by ANSSI and DINUM: three levels of process and accreditation to be renewed at least every three years.

The current version is RGS 2.0, approved by the order of 13 June 2014, published in the Official Journal on 24 June and applicable since 1 July 2014. It consists of a main text and annexes, some of which have been revised since. ANSSI's documents page lists, for example, version 2.04 of Annex B1 on choosing and sizing cryptographic mechanisms, dated 1 January 2020, and a 2016 erratum to Annex A3. ANSSI and the interministerial digital directorate (DINUM) are responsible for keeping the framework up to date, and ANSSI mentions update work to simplify its alignment with the EU eIDAS regulation.

04

The RGS process in five steps

The 2010 decree and chapter 2 of the RGS describe a five-stage process: risk analysis, security objectives, measures, accreditation, then operational monitoring. For a system already in service, the RGS provides a simplified process starting with an audit. Switch between the two.

The security process required by the RGS
  1. Risk analysis Decree, Art. 3

    Identify what could affect the system, estimate the consequences and decide how to bring risk down to an acceptable level.

  2. Security objectives Decree, Art. 3

    Set the needs for availability, integrity and confidentiality, as well as authentication and traceability.

  3. Protection measures Decree, Art. 3 and 4

    Choose technical and organisational measures, using qualified products and providers wherever possible.

  4. Accreditation Decree, Art. 5

    Before go-live, the accreditation authority certifies that the system is protected and accepts the residual risks.

  5. Operational monitoring RGS, ch. 2.5

    Monitor, detect and handle incidents day to day, and review the accreditation periodically.

Based on RGS version 2.0, chapters 1 and 2, and Decree No. 2010-112, Articles 3 and 5.

Security objectives are expressed in the familiar DICP terms: availability, integrity, confidentiality, to which the RGS adds authentication and traceability. The text does not prescribe a particular risk analysis method; in practice, administrations largely rely on EBIOS Risk Manager, ANSSI's method, or on ISO 27005.

05

Security accreditation, the RGS's first obligation

ANSSI is clear on its RGS page: the first and most important obligation is to carry out security accreditation. The RGS also calls it a “formal attestation”. It is issued by an accreditation authority appointed by the administrative authority, which certifies that the system is protected in line with the objectives set and that the residual risks are accepted. For an online service, the decision is made available to users.

What the 2025 guide adds

In 2025, ANSSI and DINUM published a guide to security accreditation, described by Next as a set of four documents. It stresses that accreditation is a formal act binding the authority that issues it, and organises the process:

  • three levels, simplified, intermediate and reinforced, chosen according to the system's criticality and exposure;
  • an accreditation committee, often chaired by the CISO, which reviews the file and gives an opinion, and a commission, mandatory at the reinforced level, where the system is presented to the authority;
  • a proportionate file: a one- to two-page cover document, supplemented depending on the level by the risk analysis, a compliance matrix, audit results and an action plan;
  • a limited duration: three years at most under many regulatory frameworks, and ANSSI strongly recommends not exceeding three years elsewhere.

For small organisations, ANSSI also offers a free online service, MonServiceSécurisé, that guides the process. Finally, the RGS recommends periodic review of accredited systems: accreditation is not a permanent diploma but a decision to revisit when the system, the threat or the context changes.

06

Qualified products and providers

The 2010 decree encourages administrative authorities to use qualified security products and trust service providers. As ANSSI puts it, using a service qualified under the RGS creates a presumption of compliance. Where no qualified product or service exists, the administration must check and attest compliance itself.

  • Security products: ANSSI grants qualifications at elementary, standard or reinforced level.
  • Trust services (electronic certification, timestamping, audit): qualification is granted by a body accredited by COFRAC and approved by ANSSI, for three years.
  • Audits: the RGS recommends using qualified audit providers (PASSI) whenever possible. See our article on cybersecurity audits.

The same reflex applies to hosting: for their most sensitive data entrusted to a commercial cloud, the French State and its operators must now use a SecNumCloud-qualified service, and the question often arises during accreditation.

07

RGS, PSSIE, eIDAS and NIS 2: how they fit together

The PSSIE and the State governance framework

The State information systems security policy (PSSIE), from circular No. 5725/SG of 17 July 2014, applies to ministries and their public bodies. Decree No. 2022-513 of 8 April 2022 set up a governance framework for the State's digital security, intended eventually to replace the 2014 circular; for now the two coexist. The RGS, for its part, covers all administrative authorities, local authorities included. Each body translates these requirements into its own security policy.

The eIDAS regulation

For electronic identification and signatures, the EU eIDAS regulation comes on top of the RGS. According to ANSSI, the RGS still applies to exchanges between administrations and users, but administrations must accept identification means and signatures or seals that comply with eIDAS, even if they do not meet the RGS. The agency recommends that administrations use services qualified under both the RGS and eIDAS.

NIS 2 and the resilience bill

The NIS 2 directive includes public administration among the sectors covered. In France, it is being transposed through the resilience bill, which notably targets nearly 1,500 local authorities and had still not been passed on 9 October 2026. NIS 2 obligations will add to the RGS without replacing it: an administration already used to risk analysis and accreditation will have a head start. Our article on the LPM, OIV and OSE also shows that accreditation is among the rules imposed on operators of essential services.

To manage your accreditations over time, with risk analyses, decisions and reservations in one place, see Phinasoft's risk analysis module.

Summary

01

A framework for public bodies

The RGS applies to French State administrations, local authorities, administrative public bodies and social security bodies, for their information systems and online services.

02

Version 2.0 since 2014

Approved by the order of 13 June 2014, RGS 2.0 has applied since 1 July 2014. ANSSI maintains it with DINUM and is working on better alignment with the eIDAS regulation.

03

Accreditation at the core

Risk analysis, objectives, measures, then a formal decision by an authority that accepts the residual risks: this is the RGS's first obligation, to be renewed over time.

Frequently asked questions

What is the RGS?

The RGS (référentiel général de sécurité, or general security framework) is the French regulatory framework that sets security rules for the information systems of administrative authorities, especially for their electronic exchanges with users and with each other. It derives from Ordinance No. 2005-1516 and Decree No. 2010-112, and is maintained by ANSSI with DINUM.

Who does the RGS apply to?

French administrative authorities: State administrations, local authorities, administrative public bodies, social security bodies and other bodies managing an administrative public service. Providers of trust products or services to them are also concerned. For other organisations, the RGS serves as a good-practice guide.

Does the RGS apply to local authorities?

Yes. French local authorities are among the administrative authorities covered by the 2005 ordinance. Their information systems and online services must therefore follow the RGS process, starting with security accreditation.

What is the current version of the RGS?

The current version is RGS 2.0, approved by the order of 13 June 2014 and applicable since 1 July 2014. Several annexes have been updated since, for example Annex B1 on cryptographic mechanisms (version 2.04 of 1 January 2020). ANSSI says it is working on an update to simplify alignment with the eIDAS regulation.

What is RGS accreditation?

It is the formal decision by which an accreditation authority, appointed by the administrative authority, certifies that an information system is protected in line with its security objectives and accepts the residual risks, before go-live. It relies on a risk analysis and must be reviewed periodically; ANSSI recommends not exceeding three years.

What is the difference between the RGS and the PSSIE?

The RGS applies to all French administrative authorities, local authorities included, and covers the security of their information systems and electronic exchanges. The PSSIE, from circular No. 5725/SG of 17 July 2014, is the security policy specific to ministries and their public bodies. The two complement each other.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.