top of page

France's E-Invoicing Reform Enters a New Phase: Cybersecurity Compliance Takes Center Stage

3 days ago
3 min read

France's mandatory e-invoicing reform has moved past its pilot stage and into a new chapter for its network of approved platforms (Plateformes Agréées – PA). At a meeting held on September 3, 2026, the Direction Générale des Finances Publiques (DGFiP) and the Agence pour l'Informatique Financière de l'État (AIFE) shared both an overview of the reform's rollout and details of a newly launched cybersecurity compliance program covering the entire ecosystem.


Pilot Results: An Accelerating Rollout

Run between February 25 and August 30, 2026, the pilot phase demonstrated the reform's growing operational maturity. The numbers point to a sharp acceleration: more than 4.4 million legal entities have now been registered in the national directory (Annuaire) across 142 platforms — with 1.9 million of those added in the last month alone. Over the same period, 69 platforms transmitted invoice flows from 22,267 issuing companies to 49,126 receiving companies, resulting in 1.6 million F1 files and roughly 7,500 F10 files processed by the public invoicing portal (PPF).

Support demand also reflects the reform's scale: more than 71,000 calls to the national assistance line, 32,000 e-contact forms processed by DGFiP, and over 1,300 tickets resolved by AIFE support.

Data quality, however, still needs work. On August 31 alone, 22.5% of directory (Annuaire) flows were technically rejected (KO_TECH), with 90% of those failures traced to a single rule: directory entries must carry a future effective start date. The administration also flagged a recurring error among platforms that did not participate in the pilot: using the FULL profile instead of the BASE profile on declaration flows.


A New Cybersecurity Unit: Balancing Transparency and Confidentiality

The most notable new development is the formal launch of a dedicated Cybersecurity Unit, bringing together AIFE's Architecture and Security department with relevant DGFiP technical teams. Its guiding principle is clear: increase visibility and transparency around incidents and cyber risks across the ecosystem, while protecting sensitive information and preserving each platform's confidentiality.

To that end, the administration is establishing an alert chain between itself and the platforms, clarifying escalation procedures, and creating a dedicated incident category in ServiceNow. Crisis-management exercises and enriched documentation are intended to continuously strengthen operational readiness.


Compliance Timeline: From September to Year-End

Platforms are now expected to submit four key deliverables by September 7, 2026: a description of their security governance (including a designated security contact), an updated DC-POD, a technical architecture file, and a risk analysis aligned with the ISO 27005 standard.

This will be followed, starting September 14, by mandatory, confidential, one-on-one bilateral review meetings with every platform. Lasting 30–45 minutes, these sessions will cover governance, risk analysis, monitoring, incident management, and penetration testing.

The roadmap unfolds in three stages: establishing organizational visibility in September 2026, consolidating compliance elements during Q4, and verifying the robustness of security measures by year-end through completed penetration tests and risk-maturity analysis.


Upcoming Operational Changes

A concrete near-term change will also affect platforms directly: public certificates will be renewed on the QUAL environment on September 8 and on PROD on September 9, an operation that may temporarily impact EDI, API, and portal services. The administration also reiterated the mandatory connection to Chorus Pro for G2B flows — as of September 2, only 53 platforms were connected in the PROD environment — and announced weekly follow-up meetings every Tuesday through the end of September.

As transaction volumes continue to scale, France's e-invoicing ecosystem is now being held to a parallel standard of security maturity. For approved platforms, the coming months will require advancing technical compliance and cybersecurity governance in lockstep.

For more on SAP integration and regulatory readiness, read the SAP E-Invoice overview of France e-invoicing cybersecurity compliance.


Related E-Invoicing Resources

Read the original article and explore Docnova e-invoicing insights.

For SAP-integrated compliance, visit the Melasoft SAP e-invoicing solution.

 
 
 

Recent Posts

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page