The ANSSI investigation guidance, read with SIM3

France’s ANSSI has published decision-level guidance on incident qualification and investigation. The accelerators it assumes are already in place are, almost one by one, parameters of the SIM3 maturity model, and their level decides which strategies are actually open on the day of the incident.

TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use.
Published
17 September 2026
Subject
ANSSI guidance and SIM3
Distribution
Public
Confidence
High
Sources
8

The facts

On 16 September 2026, the French national cybersecurity agency ANSSI (1) published a body of guidance on investigation. The first volume, L’investigation et la qualification d’incidents : les clés de décision, or incident investigation and qualification, the keys to decision-making, carries the label Collection Investigation, version 1.0, September 2026. It runs to twelve pages under the Etalab Open Licence version 2.0. It is presented as a strategic-level document, aimed at decision makers in an organisation that has been hit by an incident or suspects one. Its scope is limited to cybersecurity incidents of malicious origin: outages and misconfigurations are explicitly excluded. The document is published in French only.

The guidance defines qualification as the estimate of the established and potential severity of an incident, made in order to set a level of engagement matched to the business impact. It defines investigation as the acquisition of technical knowledge about that incident, and adds enhanced monitoring dedicated to the incident in progress. These three activities form the understanding phase, described as multi-iterative: qualification and investigation, collection and analysis, investigation and monitoring. The guidance then lists the accelerators to be built outside any incident, sets out the limits of the exercise, offers five investigation strategies and closes with seven recommendations.

SIM3 (2), the Security Incident Management Maturity Model, was created in 2008 and is owned and maintained by the Open CSIRT Foundation, OCF (3). It measures the maturity of an incident management capability, which the model calls a CSIRT (4) for economy of words, across parameters grouped into four quadrants: Organisation, Human, Tools, Processes. The reference version is SIM3 v2 interim, dated 1 January 2023, with forty-five parameters. Version 1, in use from 2008 to 2022, had forty-four, the difference being the addition of parameter O-6 on public media policy. The full version 2, expected during 2026, will extend the model to SOCs (5), PSIRTs (6) and ISACs (7). Every parameter is scored on a single five-level scale, from 0 to 4.

  • Level 0: the subject is neither handled nor recognised by the team.
  • Level 1: implicit, known to a few people but not written down.
  • Level 2: written down internally, with no formalisation or approval.
  • Level 3: written down and approved by the team head or above.
  • Level 4: level 3, plus a periodic check decided above the team head, with feedback returned to the team.
The takeaway

The two texts do not overlap, they interlock. The ANSSI guidance describes a decision to be made during the incident, with the knowledge available at that moment. SIM3 measures, outside any incident, what will be available on the day. The accelerators the guidance assumes are in place are for the most part SIM3 parameters, and their level decides which investigation strategies are genuinely open.

Two instruments, two questions

The ANSSI guidance answers the question of what to do now and at what cost. SIM3 answers the question of what the team has and how long it has been written down. Neither document cites the other. Their difference in nature is why they cannot stand in for one another.

CriterionANSSI guidanceSIM3
NatureDecision doctrine, five archetypes to adaptMaturity model, measurement scale
ObjectThe handling of one given incidentThe standing incident management capability
When usedDuring the incidentOutside any incident
ReaderDecision maker in the affected organisationThe team, the governance above it, the auditor
Unit of reasoningThe investigation strategyThe parameter, scored 0 to 4
OutputAn investigation plan, revised as the incident unfoldsA maturity profile, the basis of an improvement plan
ScopeIncidents of malicious originPrevention, detection, resolution, quality control
External controlNone, the document is not a compliance standardAudit by a certified auditor, basis of Trusted Introducer certification since 2010
LicensingEtalab Open Licence version 2.0Owned by OCF, free for internal and not-for-profit use, commercial use and training subject to permission

The practical consequence is straightforward. A team can know the five strategies by heart and have none of them available. Conversely, a flattering SIM3 profile says nothing about the quality of a call made at three in the morning on a poorly mapped perimeter.

The ANSSI accelerators are SIM3 parameters

One section of the guidance is devoted to the third-party knowledge whose prior acquisition determines whether investigations succeed and how fast they move. It lists four items, then adds the ability of the information system to retain its logs and to protect them. These five read almost term for term against the Tools and Processes quadrants of SIM3, with one exception.

Accelerator in the guidanceSIM3 parameterWhat the level adds
Information system cartographyT-1, IT assets and configurationsSIM3 does not require the team to own the inventory, only to have access to it. Level 1 describes a map that exists solely in the memory of a few administrators
Vulnerabilities identified through audits and risk analysisT-8 and P-4, incident preventionThe prevention process and its toolset become citable in a trade-off from level 3 onwards, once approved
The nature of threats and their objectivesT-2 and P-12, information sourcesT-2 is the list of sources, P-12 the process that maintains it. A list without a process goes stale with nobody noticing
Administration perimeters and actionable points of contactP-17, O-7 and P-9The guidance notes that an outsourcing contract without a service level suited to urgent incidents delays the start of investigation. That is precisely what O-7 covers
Retention and protection of logsNo dedicated parameterT-9 measures the detection toolset, P-11 the secure handling of information. The logging policy of the information system itself sits outside the model

SIM3 also sets two numeric floors that speak directly to incident response. Parameter H-2 puts three members, part-time or full-time, as the absolute minimum for a team. Parameter O-7 requires a human reaction to peer teams within two working days. The second is a model floor, not a target for handling a live incident.

Point of caution

SIM3 measures a level of formalisation, not effectiveness. A parameter at 4 means the subject is written down, approved and checked above the team head, with feedback to the team. It does not mean the process holds under pressure. Self-assessment, which the model accepts as a starting point, produces higher scores than independent audit.

The five strategies and the maturity they assume

The guidance presents five investigation strategies as archetypes to be adapted, which can be used one after another as the incident develops. Two of them rest explicitly on real-time detection measures and on teams able to work the alerts. The guidance does not say how to know, before the incident, whether those conditions are met. SIM3 does. The strategy names below render the French originals.

StrategyWhat it requires of the organisationDetermining parameters
Investigation under isolationComplete map of interconnections, authority to cut access, an accepted trade-off on degraded business operationT-1, O-3, O-8, P-1
Investigation in a degraded environmentChoice of a restoration date, response to legal obligations on the data reached, controlled communicationP-3, P-2, P-14, T-10
Observe and constrainReal-time detection, teams able to work the alerts continuously, correct qualification of the compromised perimeterT-9, P-5, O-8, H-2, P-9
Observe without interveningStrong discretion, working channels outside the compromised information system, red lines set by the businessP-11, T-3, T-6, O-3, P-1
Exploratory investigationKnowledge of business practice and of how uniform it is, current threat sources, a scoped resource commitmentT-1, T-2, P-12, P-7

What the cross-reading brings out

A strategy is not available because it appears in a guide. The two observation strategies assume a defined detection toolset and enough staff to sustain monitoring over time. A T-9 at 1 or 2, or an H-2 below the three-member minimum, closes both options before any cost trade-off is even reached. What remains is isolation, with its business impact, or the degraded environment, which is a situation endured rather than chosen.

The guidance describes the failure mode of observe and constrain itself: a wrong qualification of the compromised perimeter, possibly stemming from a misjudged monitoring capability, makes the strategy entirely ineffective and exhausts the teams. Translated into parameters, that risk reads on O-8, the incident classification scheme, and on P-5, the detection process. Both are parameters a team can score well on paper while being unable to qualify a perimeter under time pressure.

Finally, the guidance requires residual uncertainties to be subjected to risk analysis and validated at the right hierarchical level. That is exactly the logic of SIM3 level 4, which separates what the team head approves from what is checked above the team head. The parameter that carries this step is P-1, escalation to governance level.

The seven recommendations reread with SIM3

The guidance closes with seven recommendations for a successful investigation. Six of them attach to one or more parameters of the model. The seventh has no equivalent, which is information in itself.

RecommendationParametersReading
Serve the strategic objectivesO-1, O-3, O-4, P-1The gap between what the team is allowed to do and what is expected of it is paid for at the moment an isolation is decided
Avoid fixed ideasH-5, P-6No parameter measures an analytical bias. The model touches the subject only through technical training and the resolution process
Preserve the evidenceP-11, T-10P-11 covers the confidentiality of information, not its integrity nor the chain of custody. The inventory and hashes the guidance asks for have no parameter
Document your analysisP-6, P-7, P-8Traceability and repeatability of the analysis belong to the resolution process, and their control to the audit process
Think about blind spotsT-1, T-9The question the guidance poses, absence of activity or absence of visibility, is settled with the inventory and the detection toolset
Think like the attackerT-2, P-12CTI (8) is not a feed, it is a list of sources and a process that maintains it
Do not stay aloneO-9, H-7, P-17Three separate parameters: belonging to a CSIRT system, actually sending people to it, and having a defined process with peers

The last recommendation deserves an extra word. The guidance points to incident response providers, including the PRIS (9) qualified by ANSSI, and to the ministerial, sectoral, territorial and national incident response centres. SIM3 sets the same requirement across three separate parameters, which makes it possible to see which one is missing: a team can belong to a community without anyone attending it, and attend meetings without having written down what it shares and with whom.

What neither text provides

The cross-reading leaves three areas uncovered, none of which either document claims to address.

  • The log retention policy of the information system. The guidance makes it a precondition for investigation, SIM3 does not measure it: it belongs to the architecture of the information system and to whoever operates it.
  • The chain of custody. The guidance asks for collections that are reproducible, centralised, inventoried and hashed with legal proceedings in view. No SIM3 parameter carries that requirement, P-11 dealing with confidentiality rather than integrity.
  • The quality of the decision itself. SIM3 measures formalisation, the guidance offers archetypes. Neither says whether the strategy chosen was the right one, which is a matter for lessons learnt and for process P-8.
Reading note

The two documents address different readers: the guidance speaks to the decision maker in the affected organisation, SIM3 to the team and to the governance above it. Their meeting point is a single parameter, P-1, escalation to governance level. It is also the parameter that decides whether the investigation call is made at the right level or by default.

Source qualification

Both documents analysed here are primary. The SIM3 parameters were taken from the v2 interim standard rather than from a third-party presentation, and the values from the guidance from the original file.

ItemStatusComment
Content of the guidance: definitions, accelerators, five strategies, seven recommendationscorroboratedPrimary ANSSI document, read page by page
Publication of the body of guidance on 16 September 2026corroboratedANSSI announcement and specialist press coverage of 16 and 17 September 2026
Forty-five parameters in SIM3 v2 interimsingle sourceCounted from the standard itself, which only states “over 40”: O-1 to O-11, H-1 to H-7, T-1 to T-10, P-1 to P-17
Forty-four parameters in SIM3 v1corroboratedGlobal CSIRT Maturity Framework and third-party publications agree, the difference being parameter O-6 alone
Full version 2 expected during 2026single sourceOCF page as it stood on the date of consultation. No publication observed to date
The mapping between accelerators, strategies and parameterssingle sourceThe author’s own analysis. Neither document refers to the other
Parameter levels required for Trusted Introducer certificationdiscardedNot verified against the certification scheme, therefore not quoted

Assessment

Complementarity
The accelerators and six of the seven recommendations map onto identified parameters of the model.
High
Overlap
Neither document cites the other and neither addresses the other’s object: decision doctrine on one side, capability measurement on the other.
Low
Coverage of evidence handling
Log retention and the chain of custody are measured by no parameter of the model.
Low
Effort to cross-read
For a team that already holds a maturity profile, rereading the five strategies against its parameters is a workshop.
Moderate
Method note

This analysis is built on two primary documents read in full: the ANSSI guidance, twelve pages, version 1.0 of September 2026, and the SIM3 v2 interim standard of 1 January 2023. The mapping between accelerators, strategies and parameters is the author’s own: neither text refers to the other, and these correspondences bind neither ANSSI nor the Open CSIRT Foundation. No SIM3 audit or self-assessment was carried out for this article, and the ratings for effort and coverage are judgement. The author is a certified SIM3 auditor.

What to do

Use the strategies as a prioritisation grid

A team scored across forty-five parameters rarely has the means to raise all of them. The five strategies provide a sorting criterion: raise first the parameters that open the strategies the organisation will need, given its threat picture and its business constraints.

  • Take the current level of the ten parameters that drive the five strategies: T-1, T-2, T-9, O-3, O-7, O-8, P-1, P-5, P-9 and P-17.
  • Check the two numeric floors of the model, three members minimum for H-2 and a human reaction within two working days for O-7, then write down the response time that actually applies during an incident, which is not that one.
  • Record in the team charter, parameter O-10, the investigation strategies adopted and the red lines that trigger a switch from one to another. The guidance asks for those red lines without saying where to write them.
  • Attach the trade-off on residual uncertainties to the escalation process P-1, naming the level that validates it, since the guidance requires that validation without naming the level.
  • Document, for every administration perimeter whether internal or outsourced, an actionable contact and the service level applicable during an urgent incident, the guidance flagging its absence as a direct obstacle.
  • Handle outside the model what the model does not measure: log retention periods, inventory and hashes of collected items, chain of custody. With no parameter available, make them an explicit item of the resolution process P-6 and of the audit process P-8.

What cannot be made up during the incident

The guidance says it in one sentence: the accelerators are prepared outside any incident. Cartography, threat sources, administration contacts and logging are not built during the crisis, and their absence is paid for in collection hours and in uncertainties left unresolved. That is precisely what a maturity profile taken in calm conditions measures. Such a profile is of no use taken during the incident, and of full use six months before.

Glossary

  1. ANSSI (1): Agence nationale de la sécurité des systèmes d’information, the French national authority for cybersecurity and cyberdefence.
  2. SIM3 (2): Security Incident Management Maturity Model, a model measuring the maturity of a security incident management capability.
  3. OCF (3): Open CSIRT Foundation, the Dutch not-for-profit foundation that owns and maintains SIM3 and trains and certifies its auditors.
  4. CSIRT (4): Computer Security Incident Response Team. SIM3 uses the term for any incident management capability, whether team, service or function.
  5. SOC (5): Security Operations Centre, the function running continuous security monitoring.
  6. PSIRT (6): Product Security Incident Response Team, handling incidents affecting a vendor’s products.
  7. ISAC (7): Information Sharing and Analysis Center, a sector body for sharing and analysing security information.
  8. CTI (8): Cyber Threat Intelligence, documented knowledge of threats, their modes of operation and their objectives.
  9. PRIS (9): Prestataire de réponse aux incidents de sécurité, the incident response provider qualification issued by ANSSI.
  10. TLP (10): Traffic Light Protocol, the marking protocol that sets the conditions for onward disclosure of information. Support for it is the minimum required by SIM3 parameter P-11.

Sources

  1. ANSSI, L’investigation et la qualification d’incidents : les clés de décision, Collection Investigation, version 1.0, September 2026, 12 pages, Etalab Open Licence version 2.0.
  2. ANSSI, announcement of the body of guidance on investigation, 16 September 2026. x.com
  3. ANSSI, remediation guidance, referenced in a footnote of the document analysed. cyber.gouv.fr
  4. CERT-FR, CTI bulletins, referenced by the guidance as a source of threat knowledge. cert.ssi.gouv.fr
  5. Open CSIRT Foundation, SIM3 v2 interim, Security Incident Management Maturity Model, Full Standard, 1 January 2023. opencsirt.org
  6. Open CSIRT Foundation, SIM3 Model & References page, consulted on 17 September 2026. opencsirt.org
  7. Open CSIRT Foundation, SIM3 v1, version mkXVIIIc, in use from 2008 to 2022. opencsirt.org
  8. GFCE, Global CSIRT Maturity Framework, version 2.0, April 2021, which uses the forty-four parameters of SIM3 v1. cybilportal.org

Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.

The analysis presented here reflects the author’s own views and rests on the public sources listed above.