Back to Frameworks
Frameworks

EBIOS Risk Manager (France)

Framework Name

EBIOS Risk Manager (EBIOS RM)

Type

Voluntary, though functionally expected in specific French regulatory contexts (explained below)

Region / Jurisdiction

France (also used elsewhere in Francophone Europe and Africa, given ANSSI's regional influence)

Enforcing Body / Certifying Party

Agence nationale de la sécurité des systèmes d'information (ANSSI), France's national cybersecurity agency, which publishes and maintains the method with support from Club EBIOS. There is no organizational certification against EBIOS RM itself, it's a methodology, not a management system standard, but individual practitioner certifications are available through third parties such as PECB, LSTI, and AFNOR, as well as ANSSI's own training center

Penalty / Consequence of Non-Compliance

No direct legal penalty tied to EBIOS RM by name. NIS2 and DORA both require a documented, defensible risk analysis but don't legally mandate a specific method. In practice, though, ANSSI positions EBIOS RM as the reference method in France, and it's treated as the de facto expectation for essential entities under France's NIS2 transposition, and it's specifically recommended by CNIL, France's data protection authority, for conducting GDPR Article 35 privacy impact assessments

What It Is & Why It Matters

EBIOS Risk Manager, published by ANSSI in 2018 and meaningfully updated to a second version in 2024, is France's reference method for assessing and treating digital risk, structured around five workshops: scoping and security baseline, risk origins, strategic scenarios, operational scenarios, and risk treatment. Unlike a generic, compliance-oriented approach, it's built specifically around attacker-driven thinking, working backward from who would target an organization and why, then forward through the realistic paths they'd take. The 2024 update simplified the scenario-building workshops, added a formal upfront scoping step, and explicitly wired in compatibility with NIS2, DORA, and GDPR privacy impact assessment requirements, while also trimming the typical amount of documentation a full study produces.

It matters because it's the concrete, prescriptive complement to a more general standard like ISO 27005, which we covered earlier: ISO 27005 sets out risk management principles at a global, strategic level, while EBIOS RM gives a French organization a specific, ready-to-run process with real workshops, deliverables, and facilitation materials, including the Methodological Sheets we covered previously. It can serve directly as the risk assessment methodology inside an ISO 27001 ISMS, and it's become the practical anchor point for French organizations navigating NIS2, DORA, and GDPR risk obligations simultaneously, rather than building separate, disconnected risk processes for each one.

Who Needs It

  • You are a French public sector entity or need security accreditation for a government-facing system, where EBIOS RM is often the expected method
  • You are an essential or important entity under France's NIS2 transposition and need a documented, defensible risk analysis method
  • You need to conduct a GDPR Article 35 privacy impact assessment and want the method CNIL specifically recommends for it
  • You're pursuing ISO 27001 certification in France and want a risk assessment methodology ANSSI-aligned auditors will readily recognize
Book A Demo