ANSSI ReCyF: immutable, isolated backups to meet DORA Art. 12
ANSSI’s ReCyF (17/03/2026) calls for immutable, isolated backups to counter ransomware. Here’s how to deploy them and evidence compliance with DORA Art. 12 and NIS 2.
On 17 March 2026, ANSSI released the Cyber France Framework (ReCyF) with concrete requirements for ransomware-resilient backups. Here is how to implement immutable and isolated backups that evidence compliance with DORA Art. 12.
Key facts
On 17 March 2026, ANSSI presented the “Référentiel Cyber France” (ReCyF) — working version 2.5 — operationalising NIS 2 measures for essential and important entities. It introduces concrete expectations for business continuity and recovery, including isolating and protecting backups against ransomware, with examples such as “offline storage” where needed. The official 47‑page PDF is available on ANSSI’s MesServicesCyber platform (ANSSI, 17/03/2026). French IT media highlighted the release and mentioned tools and a comparator for companies (ChannelNews, 24/03/2026).
Why it matters in 2026 for Luxembourg and the Greater Region (BE/FR/DE): similar resilience obligations already apply to financial entities under DORA, and national authorities (CSSF in Luxembourg, ILR for NIS 2) expect evidence of fast and clean restoration after incidents. ReCyF provides a practical checklist executives can adopt now to materialise backup and recovery controls. For local specifics, see our summary of DORA in Luxembourg and the CSSF.
The applicable legal framework
- DORA — Regulation (EU) 2022/2554, Article 12: mandates backup policies and procedures and proven, regularly tested restoration and recovery methods. Backups must be activated and restored under the entity’s control, including after major incidents (EUR‑Lex — DORA; see also the ESAs’ Q&A on Art. 12(3) EIOPA Q&A DORA038).
- NIS 2 — Article 21(2)(c): requires business continuity measures, including backup and recovery. ANSSI’s ReCyF (17/03/2026) implements these expectations: Objective 13 “Continuity and recovery”, Objective 14 “Crisis response”, with explicit recommendations to isolate and protect systems and backups and to plan offline storage for ransomware scenarios (ANSSI — ReCyF).
- Luxembourg — CSSF (DORA): 2026 reminders on the ICT register and DORA preparedness, including traceability of services and controls supporting restoration (CSSF, 11/02/2026; CSSF, 12/03/2026).
The technical solution to deploy
Goal: make your backups ransomware‑resistant and operational for recovery, with audit‑ready DORA/NIS 2 evidence. To structure your business continuity and disaster recovery plan, align architecture and procedures to the points below.
- 3‑2‑1‑1‑0 strategy: 3 copies, 2 different media, 1 offsite copy, 1 immutable/offline copy, 0 errors verified by restore tests. Align policy with ReCyF Objective 13 and DORA Art. 12.
- Immutability (WORM) and object lock on the backup target (e.g., S3 Object Lock, WORM appliances, immutable snapshots) with retention and legal hold where required. Controls: append‑only access, tamper‑proof logging, MFA on the console.
- Network isolation for the backup fabric: dedicated VLAN/segment, access via hardened jump hosts and PAM, default deny‑all rules, periodic air‑gap or fully offline storage for the “1” copy.
- Hardened auth and administration chain: separate backup admin accounts, phishing‑resistant MFA, secret vaults, and bastions. Signed logging.
- Detection and validation: anti‑malware/ransomware scanning prior to ingestion (commonly recommended in ENISA/NIS2 guidance), anomaly scoring (volume, entropy), malware canary.
- Restore testing at least quarterly, in a recovery enclave (quarantine network) with documented T‑0/T‑24/T‑72 procedures and realistic RTO/RPO.
- Evidence and traceability: policy registers, access logs, test reports, and a DORA Art. 12 and NIS 2 Art. 21 mapping via the ReCyF correspondence table.
References: ISO/IEC 27001:2022 Annex A 8.13 “Information backup”, A 5.30 “ICT readiness for business continuity”; NIST CSF 2.0 PR.DS‑08, RC.IM‑01/02; CIS Controls v8 Control 11 “Data Recovery”.
How Luxgap implements this
- Our ISO 27001 governance: we define the backup policy (scope, RTO/RPO, data classes), the ransomware‑specific threat model, and the recurring test plan. We deliver a mapping DORA Art. 12 / NIS 2 Art. 21 / ReCyF Obj. 13‑14 with regulator‑grade evidence.
- Our 24/7 managed SOC: integrate backup consoles (APIs) into the SIEM, detect anomalies (job deletions, shortened retention, failure spikes), correlate with EDR/XDR to trigger snapshot freezes and failover to the immutable copy.
- Our fractional DPOs and CISOs: align with GDPR Art. 32 (security), retention policies and records, and coordinate with incident notification plans (NIS 2/DORA) to evidence restore capability and limit impact on individuals.
Real‑world case in Luxembourg or the EU
A Luxembourg investment firm (in scope of DORA) delivered in 6 weeks: an object WORM target with 30‑day retention, an encrypted offsite tier, network isolation of the backup fabric, and a recovery runbook tested in an enclave. Observable results: automated monthly restore tests (~2 h for a critical service), signed logs exported to the SIEM, and an evidence pack ready for the CSSF (policy, architecture diagrams, audit screenshots, test minutes) mapped to DORA Art. 12 and ReCyF Obj. 13‑14.
First concrete steps
- Lock down the backup policy (DORA Art. 12): application scope, service‑level RTO/RPO, test periodicity, roles and responsibilities. Get management sign‑off.
- Add an immutable copy: enable WORM/object lock on an S3‑compatible target or appliance, set minimum retention (≥ 14–30 days), and isolate admin via a bastion + PAM.
- Separate the backup network: dedicated segment, explicit ACLs, deny‑all by default, access via a jump server, phishing‑resistant MFA for consoles.
- Automate restore tests in a quarantine enclave: one “gold” scenario per month (files), one “platinum” scenario per quarter (critical app), with signed minutes and metrics.
- Stream evidence to the SIEM: ingest backup logs, WORM attestations, and test minutes to build an audit‑ready DORA/NIS 2 dossier (and trigger alerts on drift).
Official sources
- ANSSI — Référentiel Cyber France (ReCyF), v2.5, 17/03/2026
- EUR‑Lex — Regulation (EU) 2022/2554 (DORA), Art. 12
- CSSF — DORA: ICT register collection (11/02/2026)
News source
Need help to prioritise and execute these workstreams? Reach out via the Luxgap website or our contact form.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →