Back to Frameworks
Frameworks

EBIOS Methodological Sheets (France)

Framework Name

EBIOS Methodological Sheets

Type

Voluntary

Region / Jurisdiction

France

Enforcing Body / Certifying Party

Agence nationale de la sécurité des systèmes d'information (ANSSI), France's national cybersecurity agency, developed with support from Club EBIOS, a nonprofit association of risk management practitioners. There is no certifying body and no certification, these are practical support materials, not an auditable standard

Penalty / Consequence of Non-Compliance

No direct penalty, and nothing to be certified against. The consequence is practical rather than legal: without them, teams applying the EBIOS Risk Manager methodology are left to build their own workshop materials, severity scales, threat actor profiles, facilitation templates, from scratch rather than using ANSSI's ready-made ones

What It Is & Why It Matters

The EBIOS Methodological Sheets are practical companion documents to the EBIOS Risk Manager guide, ANSSI's methodology for assessing and treating digital risk. Where the main EBIOS RM guide explains conceptually what each of its five workshops is meant to accomplish, the Methodological Sheets supply the actual working materials needed to run them: knowledge bases like standard categories of impact, catalogs of typical threat actors and their likely objectives, severity scales, and structured templates a team can use directly in a workshop rather than building their own from a blank page. They're explicitly designed as pedagogical, hands-on tools, and ANSSI and Club EBIOS update them regularly based on real feedback from practitioners actually using them in the field.

They matter because they solve the exact gap that appears once a methodology moves from paper to practice: a facilitator running an EBIOS RM workshop with a room full of stakeholders needs concrete building blocks in front of them, not just a conceptual explanation of what a "risk origin" or "operational scenario" is supposed to look like. This is a similar relationship to something we've already covered elsewhere on this list, ISO 27005 exists to fill the gap ISO 27001 leaves open around risk assessment methodology, and these Sheets fill an equivalent gap for EBIOS Risk Manager specifically, turning the guide's structure into something a team can actually execute in a room.

Who Needs It

  • You're already using, or planning to use, EBIOS Risk Manager and need practical, ready-to-use materials for running each risk assessment workshop
  • You're a French public sector entity or an operator of essential services (OIV/OSE) using EBIOS RM to meet French regulatory expectations for risk assessment
  • You're aligning cyber risk assessment with ANSSI-endorsed methodology, particularly relevant for critical infrastructure and government-adjacent contractors in France
  • You want a proven, structured facilitation toolkit for risk assessment workshops rather than building one internally
Book A Demo