9112 Emergency Hub: France (FR)
This protocol is for critical cyber incidents affecting legal entities operating within French jurisdiction. Ensure all internal containment actions are documented to comply with the strict regulatory deadlines detailed below.
1. Operational & NIS2 Early Warning (24 Hours)
Operators of essential services (OES/OIV) must report significant cyber incidents within 24 hours.
- Authority: ANSSI / CERT-FR
- Direct Reporting Portal: CERT-FR Incident Reporting
- Emergency Contact: cert-fr.cossi@ssi.gouv.fr
2. GDPR Data Breach Notification (72 Hours)
If the incident involves the compromise of personal data, a formal notification must be submitted within 72 hours.
- Authority: CNIL (Commission Nationale de l’Informatique et des Libertés)
- Direct Reporting Portal: CNIL Notification Portal
- Contact: Via CNIL Tele-service
3. Law Enforcement / Cybercrime (Optional but Recommended)
For incidents involving extortion, ransomware, or state-sponsored actors, coordinate with federal law enforcement.
- Authority: Police Nationale (SDLC) / Gendarmerie (C3N)
- Contact: Via Cybermalveillance.gouv.fr or local authorities (17)