ANSSI security accreditation and breach tracking: what's new in Adequacy 6.4

Adequacy version 6.4, available since October 1, 2026, introduces a Security Accreditation module (part of the Adequacy Cyber option) that complies with ANSSI guidelines. It structures the process step-by-step, from defining the context to the accreditation committee's final decision. This update also enhances the Incident and Breach module with new settings and indicators, and adds three authorization groups for Control module reports.

By
Alessandro Fiorentino
1
Min
Share this article
GDPR AI Act software

A new ANSSI-compliant Security Accreditation module

‍

‍

The Security Certification module is part of the Adequacy Cyber option. It can be activated upon request.

‍

What is security accreditation?

‍

Security accreditation is a formal decision, often within a regulatory framework, by which a competent authority authorizes the commissioning and operation of an information system.

‍

A 5-step accreditation process

‍

In line with ANSSI guidelines, the security accreditation module is structured into steps:

‍

  1. Context and governance: description of the organizational context and technical challenges, summary of key project dates, and identification of key governance stakeholders (accreditation committee).
  2. Choosing the approach: selection of the appropriate accreditation approach and the security measure model against which your organization should be assessed. A wizard evaluates security needs based on the information system's criticality and risk exposure.
  3. Evaluating measures: a guided questionnaire to review expected measures, determining their presence and current level of satisfaction.
  4. Risk analysis: measurement of the information system's cybersecurity maturity via a dedicated chart, including complementary measures to help make the risk more acceptable.
  5. Decision and monitoring: based on the graphical summary of the risk level, expert opinions, and the review of the accreditation file, the accreditation committee provides a formal opinion and monitors the action plan.

‍

‍

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

‍

‍

Customizable security measure templates

‍

Adequacy provides administrators with a module for managing security measure templates:

‍

  • The original templates provided by Adequacy cannot be modified, but you can duplicate them and then adapt them to your requirements.
  • A measure import function makes it easy to create custom templates.

‍

A dedicated dashboard for certification

‍

The dashboard includes a new "Security Certification" tab. It brings together the key certification indicators:

  • Progress
  • Decision
  • Cyber maturity
  • Recency
  • Process level

‍

‍

Incidents and data breaches: a more configurable module

‍

‍

Support can now enable several options to tailor the screens of the Incident and breach module to each client's specific needs.

‍

List of breaches and incident identification

‍

In the list of breaches on the module home page:

‍

  • The "Late notification" and "Date of awareness" columns can be added to the displayable columns via the list settings button.
  • The "View processing activities" button under "Other actions" can be hidden. The user then manages processing activities solely from the entry form.

‍

In the incident identification tab:

‍

  • Entering a reference can be made mandatory.
  • Affected processing activities can be entered "inline" using a selector (similar to processing assets), directly during breach identification. In this case, the "x processing activities" link at the top right of the tabs is no longer available.

‍

Processing synchronization and notification

‍

  • Processing synchronization: button colors have been enhanced for better readability, especially when disabled
  • Notification tab: the comment field has been moved below the "Notification completed" checkbox

‍

Notification obligation: mandatory or advisory alerts

‍

Alerts related to notification or communication obligations can be displayed in two styles:

‍

  • Mandatory: notification or communication is "required"
  • Advisory: notification or communication is "recommended"

‍

The default style is "mandatory." It can be set to "advisory," for example, to account for entities located outside of Europe.

‍

New breach tracking indicators

‍

The dashboard and periodic tracking now include new indicators for breaches:

‍

  • Summary of notifications and communications completed and average incident duration
  • Breakdown by status
  • Breakdown by impact severity for individuals
  • Count of breaches by domain or by structure of the affected processing activities

‍

It is also possible to limit the scope to incidents and breaches identified within the last x months (e.g., 12 or 24 months).

‍

‍

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

‍

‍

Audit module: reports accessible via three authorization levels

‍

‍

The Control module now offers three report groups (Standard, Advanced, Other), linked to permissions for selective user access. A single report can belong to multiple groups at the same time.

‍

  • Standard: reports accessible to all users. Controlled by the "controle.export" permission under the "Read" authorization.
  • Advancedreports accessible to users with the"dpo" attribute.Controlled by the "controle.export_advanced" permission under the "Privilege" authorization
  • Other: reports reserved for platform administrators. Controlled by the "controle.export_other" permission under the "Settings" authorization. This group currently contains two reports.

‍

‍

Link to your terms of service in the footer

‍

‍

A link to terms of service can now be displayed in the footer. Support can replace the content with your own terms and conditions. This option is useful for external DPOs who provide their clients with access to their instance.

‍

‍

FAQ - Security Accreditation and What's New in Adequacy 6.4

‍

‍

What is security accreditation?

It is a formal decision, which may be part of a regulatory framework. Through this decision, a competent authority authorizes the commissioning and operation of an information system.

‍

How does Adequacy support the security accreditation process?

The Security Accreditation module follows the 5-step ANSSI guidelines:

  1. Context and governance
  2. Choice of approach and security measures model
  3. Assessment of security measures
  4. Risk analysis and cyber maturity
  5. Accreditation committee opinion and action plan monitoring

‍

How do I access the Security Accreditation module?

This module is part of the Adequacy Cyber option and can be activated upon request.

‍

Can security measure templates be customized?

Yes. Templates provided by Adequacy can be duplicated and then modified, and an import feature makes it easy to create custom templates.

‍

What data breach tracking indicators does version 6.4 offer?

Version 6.4 adds several indicators:

  • Summary of notifications and communications made
  • Average incident duration
  • Breakdown by status and impact severity for individuals
  • Count of breaches by domain or structure of the affected processing activities

‍

What is the difference between "directive" and "advisory" alerts?

With the directive style, notification or communication is "required." With the advisory style, it is "recommended," which is useful, for example, for entities located outside of Europe.

With version 6.4, Adequacy allows you to manage the security accreditation of your information systems within the same tool as your compliance. It also strengthens data breach tracking and report access management.

‍

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The latest news

They have trusted us for years

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.