Skip to content
Security2 min read
Back to blog

Data security in BPO: the ANSSI approach for providers in France


Why security is a differentiator in BPO

In 2026, cybersecurity has gone from optional criterion to eliminating criterion in French BPO tenders. Security incidents at BPO providers cost victim companies an average of €4.2 million in 2025 (remediation costs, GDPR fines, reputational damage). Public sector buyers and large corporates now require certifications, not compliance declarations.

ANSSI certifications: SecNumCloud and PAMS qualification

SecNumCloud is the ANSSI requirements framework for cloud service providers. Its attainment guarantees the sovereignty of hosted data and is now required by most French public administrations for sensitive data. PAMS (Secure Administration and Maintenance Provider) qualification is required for providers managing information systems of OIVs (Vital Importance Operators).

EBIOS RM: the reference risk analysis method

The EBIOS Risk Manager method, published by ANSSI, is the French standard for security risk analysis and treatment. Any BPO provider handling sensitive data must have completed an EBIOS RM analysis of its information system, with workshops including its most exposed clients. This analysis must be updated annually and available for audit.

Minimum security measures to require

  • Annual penetration tests (pentest) by an ANSSI-qualified PASSI provider
  • Patch management: maximum 72 hours for critical vulnerabilities (CVSS ≥ 9)
  • Multi-factor authentication (MFA) on all access to client systems
  • Data encryption in transit (TLS 1.3+) and at rest (AES-256)
  • 24/7 active SOC with incident detection in under 15 minutes
  • Disaster recovery plan (DRP) with RTO ≤ 4 hours for critical services

How to audit your BPO provider on security

Before signing, ask for: the most recent pentest report (not just the executive summary), the incident management policy, the list of subprocessors with access to data, and a site visit if possible. Contractually provide for an annual audit right and mandatory notification of any incident within 24 hours.


📋 Request a quote