LexClawLaws & Regulations
Laws & RegulationsLPM 2024 (France)
In ForceDefense, Critical infrastructure, Essential services, Government

Military Programming Law 2024-2030 (LPM) — Cybersecurity Provisions

Also known as: LPM 2024 (France)

France's Military Programming Law 2024-2030 includes significant cybersecurity provisions expanding ANSSI's authority, mandating incident reporting for operators of vital importance (OIV) and essential services (OSE), and implementing NIS2 transposition requirements.

Jurisdiction
France
Regulator
Effective
8/1/2023
Sector
Defense, Critical infrastructure, Essential services, Government

Full Text / Summary

France's Military Programming Law 2024-2030 (Loi de programmation militaire, LPM) includes significant cybersecurity provisions that extend beyond defense to critical infrastructure operators. Article 35 of the LPM grants ANSSI (Agence nationale de la sécurité des systèmes d'information) enhanced powers to detect cyberattacks on French territory, including the authority to require internet service providers to implement technical measures to detect malicious traffic. The LPM introduces obligations for operators of vital importance (OIV) and operators of essential services (OSE) to implement security detection systems and cooperate with ANSSI during incident response. The Law also strengthens ANSSI's authority to conduct security audits of critical infrastructure operators and to issue binding security recommendations. For the cybersecurity legal community, the LPM represents a significant expansion of state cybersecurity powers and creates new compliance obligations for operators in 12 critical sectors including energy, transport, health, water, banking, financial market infrastructure, and digital infrastructure.