
France’s ANSSI has published decision-level guidance on incident qualification and investigation. The accelerators it assumes are already in place are, almost one by one, parameters of the SIM3 maturity model, and their level decides which strategies are actually open on the day of the incident.
The facts
On 16 September 2026, the French national cybersecurity agency ANSSI (1) published a body of guidance on investigation. The first volume, L’investigation et la qualification d’incidents : les clés de décision, or incident investigation and qualification, the keys to decision-making, carries the label Collection Investigation, version 1.0, September 2026. It runs to twelve pages under the Etalab Open Licence version 2.0. It is presented as a strategic-level document, aimed at decision makers in an organisation that has been hit by an incident or suspects one. Its scope is limited to cybersecurity incidents of malicious origin: outages and misconfigurations are explicitly excluded. The document is published in French only.
The guidance defines qualification as the estimate of the established and potential severity of an incident, made in order to set a level of engagement matched to the business impact. It defines investigation as the acquisition of technical knowledge about that incident, and adds enhanced monitoring dedicated to the incident in progress. These three activities form the understanding phase, described as multi-iterative: qualification and investigation, collection and analysis, investigation and monitoring. The guidance then lists the accelerators to be built outside any incident, sets out the limits of the exercise, offers five investigation strategies and closes with seven recommendations.
SIM3 (2), the Security Incident Management Maturity Model, was created in 2008 and is owned and maintained by the Open CSIRT Foundation, OCF (3). It measures the maturity of an incident management capability, which the model calls a CSIRT (4) for economy of words, across parameters grouped into four quadrants: Organisation, Human, Tools, Processes. The reference version is SIM3 v2 interim, dated 1 January 2023, with forty-five parameters. Version 1, in use from 2008 to 2022, had forty-four, the difference being the addition of parameter O-6 on public media policy. The full version 2, expected during 2026, will extend the model to SOCs (5), PSIRTs (6) and ISACs (7). Every parameter is scored on a single five-level scale, from 0 to 4.
- Level 0: the subject is neither handled nor recognised by the team.
- Level 1: implicit, known to a few people but not written down.
- Level 2: written down internally, with no formalisation or approval.
- Level 3: written down and approved by the team head or above.
- Level 4: level 3, plus a periodic check decided above the team head, with feedback returned to the team.
The two texts do not overlap, they interlock. The ANSSI guidance describes a decision to be made during the incident, with the knowledge available at that moment. SIM3 measures, outside any incident, what will be available on the day. The accelerators the guidance assumes are in place are for the most part SIM3 parameters, and their level decides which investigation strategies are genuinely open.
Two instruments, two questions
The ANSSI guidance answers the question of what to do now and at what cost. SIM3 answers the question of what the team has and how long it has been written down. Neither document cites the other. Their difference in nature is why they cannot stand in for one another.
| Criterion | ANSSI guidance | SIM3 |
|---|---|---|
| Nature | Decision doctrine, five archetypes to adapt | Maturity model, measurement scale |
| Object | The handling of one given incident | The standing incident management capability |
| When used | During the incident | Outside any incident |
| Reader | Decision maker in the affected organisation | The team, the governance above it, the auditor |
| Unit of reasoning | The investigation strategy | The parameter, scored 0 to 4 |
| Output | An investigation plan, revised as the incident unfolds | A maturity profile, the basis of an improvement plan |
| Scope | Incidents of malicious origin | Prevention, detection, resolution, quality control |
| External control | None, the document is not a compliance standard | Audit by a certified auditor, basis of Trusted Introducer certification since 2010 |
| Licensing | Etalab Open Licence version 2.0 | Owned by OCF, free for internal and not-for-profit use, commercial use and training subject to permission |
The practical consequence is straightforward. A team can know the five strategies by heart and have none of them available. Conversely, a flattering SIM3 profile says nothing about the quality of a call made at three in the morning on a poorly mapped perimeter.
The ANSSI accelerators are SIM3 parameters
One section of the guidance is devoted to the third-party knowledge whose prior acquisition determines whether investigations succeed and how fast they move. It lists four items, then adds the ability of the information system to retain its logs and to protect them. These five read almost term for term against the Tools and Processes quadrants of SIM3, with one exception.
| Accelerator in the guidance | SIM3 parameter | What the level adds |
|---|---|---|
| Information system cartography | T-1, IT assets and configurations | SIM3 does not require the team to own the inventory, only to have access to it. Level 1 describes a map that exists solely in the memory of a few administrators |
| Vulnerabilities identified through audits and risk analysis | T-8 and P-4, incident prevention | The prevention process and its toolset become citable in a trade-off from level 3 onwards, once approved |
| The nature of threats and their objectives | T-2 and P-12, information sources | T-2 is the list of sources, P-12 the process that maintains it. A list without a process goes stale with nobody noticing |
| Administration perimeters and actionable points of contact | P-17, O-7 and P-9 | The guidance notes that an outsourcing contract without a service level suited to urgent incidents delays the start of investigation. That is precisely what O-7 covers |
| Retention and protection of logs | No dedicated parameter | T-9 measures the detection toolset, P-11 the secure handling of information. The logging policy of the information system itself sits outside the model |
SIM3 also sets two numeric floors that speak directly to incident response. Parameter H-2 puts three members, part-time or full-time, as the absolute minimum for a team. Parameter O-7 requires a human reaction to peer teams within two working days. The second is a model floor, not a target for handling a live incident.
SIM3 measures a level of formalisation, not effectiveness. A parameter at 4 means the subject is written down, approved and checked above the team head, with feedback to the team. It does not mean the process holds under pressure. Self-assessment, which the model accepts as a starting point, produces higher scores than independent audit.
The five strategies and the maturity they assume
The guidance presents five investigation strategies as archetypes to be adapted, which can be used one after another as the incident develops. Two of them rest explicitly on real-time detection measures and on teams able to work the alerts. The guidance does not say how to know, before the incident, whether those conditions are met. SIM3 does. The strategy names below render the French originals.
| Strategy | What it requires of the organisation | Determining parameters |
|---|---|---|
| Investigation under isolation | Complete map of interconnections, authority to cut access, an accepted trade-off on degraded business operation | T-1, O-3, O-8, P-1 |
| Investigation in a degraded environment | Choice of a restoration date, response to legal obligations on the data reached, controlled communication | P-3, P-2, P-14, T-10 |
| Observe and constrain | Real-time detection, teams able to work the alerts continuously, correct qualification of the compromised perimeter | T-9, P-5, O-8, H-2, P-9 |
| Observe without intervening | Strong discretion, working channels outside the compromised information system, red lines set by the business | P-11, T-3, T-6, O-3, P-1 |
| Exploratory investigation | Knowledge of business practice and of how uniform it is, current threat sources, a scoped resource commitment | T-1, T-2, P-12, P-7 |
What the cross-reading brings out
A strategy is not available because it appears in a guide. The two observation strategies assume a defined detection toolset and enough staff to sustain monitoring over time. A T-9 at 1 or 2, or an H-2 below the three-member minimum, closes both options before any cost trade-off is even reached. What remains is isolation, with its business impact, or the degraded environment, which is a situation endured rather than chosen.
The guidance describes the failure mode of observe and constrain itself: a wrong qualification of the compromised perimeter, possibly stemming from a misjudged monitoring capability, makes the strategy entirely ineffective and exhausts the teams. Translated into parameters, that risk reads on O-8, the incident classification scheme, and on P-5, the detection process. Both are parameters a team can score well on paper while being unable to qualify a perimeter under time pressure.
Finally, the guidance requires residual uncertainties to be subjected to risk analysis and validated at the right hierarchical level. That is exactly the logic of SIM3 level 4, which separates what the team head approves from what is checked above the team head. The parameter that carries this step is P-1, escalation to governance level.
The seven recommendations reread with SIM3
The guidance closes with seven recommendations for a successful investigation. Six of them attach to one or more parameters of the model. The seventh has no equivalent, which is information in itself.
| Recommendation | Parameters | Reading |
|---|---|---|
| Serve the strategic objectives | O-1, O-3, O-4, P-1 | The gap between what the team is allowed to do and what is expected of it is paid for at the moment an isolation is decided |
| Avoid fixed ideas | H-5, P-6 | No parameter measures an analytical bias. The model touches the subject only through technical training and the resolution process |
| Preserve the evidence | P-11, T-10 | P-11 covers the confidentiality of information, not its integrity nor the chain of custody. The inventory and hashes the guidance asks for have no parameter |
| Document your analysis | P-6, P-7, P-8 | Traceability and repeatability of the analysis belong to the resolution process, and their control to the audit process |
| Think about blind spots | T-1, T-9 | The question the guidance poses, absence of activity or absence of visibility, is settled with the inventory and the detection toolset |
| Think like the attacker | T-2, P-12 | CTI (8) is not a feed, it is a list of sources and a process that maintains it |
| Do not stay alone | O-9, H-7, P-17 | Three separate parameters: belonging to a CSIRT system, actually sending people to it, and having a defined process with peers |
The last recommendation deserves an extra word. The guidance points to incident response providers, including the PRIS (9) qualified by ANSSI, and to the ministerial, sectoral, territorial and national incident response centres. SIM3 sets the same requirement across three separate parameters, which makes it possible to see which one is missing: a team can belong to a community without anyone attending it, and attend meetings without having written down what it shares and with whom.
What neither text provides
The cross-reading leaves three areas uncovered, none of which either document claims to address.
- The log retention policy of the information system. The guidance makes it a precondition for investigation, SIM3 does not measure it: it belongs to the architecture of the information system and to whoever operates it.
- The chain of custody. The guidance asks for collections that are reproducible, centralised, inventoried and hashed with legal proceedings in view. No SIM3 parameter carries that requirement, P-11 dealing with confidentiality rather than integrity.
- The quality of the decision itself. SIM3 measures formalisation, the guidance offers archetypes. Neither says whether the strategy chosen was the right one, which is a matter for lessons learnt and for process P-8.
The two documents address different readers: the guidance speaks to the decision maker in the affected organisation, SIM3 to the team and to the governance above it. Their meeting point is a single parameter, P-1, escalation to governance level. It is also the parameter that decides whether the investigation call is made at the right level or by default.
Source qualification
Both documents analysed here are primary. The SIM3 parameters were taken from the v2 interim standard rather than from a third-party presentation, and the values from the guidance from the original file.
| Item | Status | Comment |
|---|---|---|
| Content of the guidance: definitions, accelerators, five strategies, seven recommendations | corroborated | Primary ANSSI document, read page by page |
| Publication of the body of guidance on 16 September 2026 | corroborated | ANSSI announcement and specialist press coverage of 16 and 17 September 2026 |
| Forty-five parameters in SIM3 v2 interim | single source | Counted from the standard itself, which only states “over 40”: O-1 to O-11, H-1 to H-7, T-1 to T-10, P-1 to P-17 |
| Forty-four parameters in SIM3 v1 | corroborated | Global CSIRT Maturity Framework and third-party publications agree, the difference being parameter O-6 alone |
| Full version 2 expected during 2026 | single source | OCF page as it stood on the date of consultation. No publication observed to date |
| The mapping between accelerators, strategies and parameters | single source | The author’s own analysis. Neither document refers to the other |
| Parameter levels required for Trusted Introducer certification | discarded | Not verified against the certification scheme, therefore not quoted |
Assessment
This analysis is built on two primary documents read in full: the ANSSI guidance, twelve pages, version 1.0 of September 2026, and the SIM3 v2 interim standard of 1 January 2023. The mapping between accelerators, strategies and parameters is the author’s own: neither text refers to the other, and these correspondences bind neither ANSSI nor the Open CSIRT Foundation. No SIM3 audit or self-assessment was carried out for this article, and the ratings for effort and coverage are judgement. The author is a certified SIM3 auditor.
What to do
Use the strategies as a prioritisation grid
A team scored across forty-five parameters rarely has the means to raise all of them. The five strategies provide a sorting criterion: raise first the parameters that open the strategies the organisation will need, given its threat picture and its business constraints.
- Take the current level of the ten parameters that drive the five strategies: T-1, T-2, T-9, O-3, O-7, O-8, P-1, P-5, P-9 and P-17.
- Check the two numeric floors of the model, three members minimum for H-2 and a human reaction within two working days for O-7, then write down the response time that actually applies during an incident, which is not that one.
- Record in the team charter, parameter O-10, the investigation strategies adopted and the red lines that trigger a switch from one to another. The guidance asks for those red lines without saying where to write them.
- Attach the trade-off on residual uncertainties to the escalation process P-1, naming the level that validates it, since the guidance requires that validation without naming the level.
- Document, for every administration perimeter whether internal or outsourced, an actionable contact and the service level applicable during an urgent incident, the guidance flagging its absence as a direct obstacle.
- Handle outside the model what the model does not measure: log retention periods, inventory and hashes of collected items, chain of custody. With no parameter available, make them an explicit item of the resolution process P-6 and of the audit process P-8.
What cannot be made up during the incident
The guidance says it in one sentence: the accelerators are prepared outside any incident. Cartography, threat sources, administration contacts and logging are not built during the crisis, and their absence is paid for in collection hours and in uncertainties left unresolved. That is precisely what a maturity profile taken in calm conditions measures. Such a profile is of no use taken during the incident, and of full use six months before.
Glossary
- ANSSI (1): Agence nationale de la sécurité des systèmes d’information, the French national authority for cybersecurity and cyberdefence.
- SIM3 (2): Security Incident Management Maturity Model, a model measuring the maturity of a security incident management capability.
- OCF (3): Open CSIRT Foundation, the Dutch not-for-profit foundation that owns and maintains SIM3 and trains and certifies its auditors.
- CSIRT (4): Computer Security Incident Response Team. SIM3 uses the term for any incident management capability, whether team, service or function.
- SOC (5): Security Operations Centre, the function running continuous security monitoring.
- PSIRT (6): Product Security Incident Response Team, handling incidents affecting a vendor’s products.
- ISAC (7): Information Sharing and Analysis Center, a sector body for sharing and analysing security information.
- CTI (8): Cyber Threat Intelligence, documented knowledge of threats, their modes of operation and their objectives.
- PRIS (9): Prestataire de réponse aux incidents de sécurité, the incident response provider qualification issued by ANSSI.
- TLP (10): Traffic Light Protocol, the marking protocol that sets the conditions for onward disclosure of information. Support for it is the minimum required by SIM3 parameter P-11.
Sources
- ANSSI, L’investigation et la qualification d’incidents : les clés de décision, Collection Investigation, version 1.0, September 2026, 12 pages, Etalab Open Licence version 2.0.
- ANSSI, announcement of the body of guidance on investigation, 16 September 2026. x.com
- ANSSI, remediation guidance, referenced in a footnote of the document analysed. cyber.gouv.fr
- CERT-FR, CTI bulletins, referenced by the guidance as a source of threat knowledge. cert.ssi.gouv.fr
- Open CSIRT Foundation, SIM3 v2 interim, Security Incident Management Maturity Model, Full Standard, 1 January 2023. opencsirt.org
- Open CSIRT Foundation, SIM3 Model & References page, consulted on 17 September 2026. opencsirt.org
- Open CSIRT Foundation, SIM3 v1, version mkXVIIIc, in use from 2008 to 2022. opencsirt.org
- GFCE, Global CSIRT Maturity Framework, version 2.0, April 2021, which uses the forty-four parameters of SIM3 v1. cybilportal.org
Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.
The analysis presented here reflects the author’s own views and rests on the public sources listed above.



