Guide

ANSSI-labelled EBIOS RM software: the 2026 overview

The EBIOS Risk Manager tools labelled by ANSSI as of 9 October 2026, what the label guarantees, what it does not, and how to check it.

Back to blogOctober 9, 202610 min read

The EBIOS Risk Manager label in brief

This article is published by Vailor, the publisher of an EBIOS RM risk analysis platform that competes with the solutions presented here. It was last updated in October 2026. Everything about the label and the labelled solutions relies only on public ANSSI documents, cited throughout; the last section, about Vailor, relies on Vailor's own statements. The EBIOS Risk Manager label is a conformity label awarded by ANSSI, the French national cybersecurity agency, to software that implements its EBIOS Risk Manager risk analysis method. According to the label page on cyber.gouv.fr, ANSSI created it to give users a clear identification of the software solutions on the market that conform to the published method. The label is open to any publisher developing a solution that conforms to the principles and concepts of the method. Its framework consists of two documents published on the same page: the procedure for obtaining the EBIOS Risk Manager label, version 1.1 of 16 January 2019, and the specifications (cahier des charges), version 3.1 of 1 October 2024. The official label page publishes the list of labelled software solutions.

What the v3.1 specifications check

According to the v3.1 specifications, labelling means validating a functional, simple and ergonomic tool that allows the EBIOS Risk Manager method to be applied in full. Among other things, the software must let users carry out every workshop, activity and action of the method, adapt the approach and the metrics to the subject under study, import the input data of a study, track successive revisions of an analysis, apply a protection marking (for example unprotected, sensitive, restricted or confidential) and export the output data at the end of each workshop. Version 3.1 takes into account version 1.5 of the EBIOS Risk Manager guide, published in September 2024. By our count of the numbered references in the document, the specifications contain 128 requirements, some of them optional: 91 functional requirements across the five workshops, 32 security requirements and 5 requirements specific to the SaaS mode. For the evaluation, the publisher provides its software to ANSSI with the fictional example that runs through the guide, a biotechnology company manufacturing vaccines, implemented, so that every point of the method can be checked.

Three labelling modes: standalone, client-server and SaaS

The label comes in three modes, depending on how the software runs. The revision history of the specifications shows when each was added: version 1.0 of 28 December 2018 covered the standalone mode, meaning software running on its own on a workstation; version 2.0 of 24 October 2019 added the client-server mode, within a private network infrastructure; version 3.0 of 20 November 2023 added the SaaS mode. The functional requirements covering the five workshops apply to all three modes. The security requirements (accounts and profile separation, confidentiality and integrity of stored and transmitted data, logging, review of the publisher's development practices, security maintenance, terms of use) apply to the client-server and SaaS modes. The SaaS mode also requires the publisher to host its solution with a SecNumCloud-qualified provider, to supply a compliance matrix against the ANSSI guide on secure administration of information systems, to supply a compliance matrix against the access restriction requirements (chapter 9.7) of the SecNumCloud framework and to encrypt everything it hosts, including the virtual machine. The label is therefore awarded per mode and per version: software labelled in client-server mode is not, for that reason alone, labelled in SaaS mode.

Labelled solutions as of 9 October 2026

We present some of the solutions on the list published by ANSSI here, in its order and with no ranking of any kind; the complete list, which is authoritative, is on the label page. For each one, we give only the publisher's name, the solution's name and the labelled versions per mode, as they appear on the label page on cyber.gouv.fr. ARIMES, from the publisher ADACIS Sarl, is labelled in version 1.2 in standalone mode. Fence, from the publisher AIRBUS PROTECT, is labelled in version 3.16 in standalone mode and in version 3.16 in client-server mode. Agile Risk Manager, from the publisher ALL4TEC, is labelled in version 2.6.2 in client-server mode. EGERIE Risk Manager, from the publisher EGERIE Software, is labelled in version 4.0 in client-server mode and in version 4.0 in SaaS mode. Oligo Risk Manager, from the publisher RECIPROC-IT, is labelled in version 2.1.0 in standalone mode and in version 1.0.0 in client-server mode. C2R - Cyber Risk Review, from the publisher SIA PARTNERS, is labelled in version 1.0 in client-server mode. The official page does not publish the award date or the expiry date of the label for these solutions, nor the version of the specifications under which each was evaluated, so that information does not appear here. For anything else about these products, the publisher concerned is the source to consult.

What the label guarantees, and what it does not

The label attests that a given version of a piece of software, in a given mode, lets users carry out the EBIOS Risk Manager method in line with the guide and the specifications, at the time of the evaluation. Its limits are written into the specifications themselves: in client-server and SaaS modes, the publisher must display, in the terms of use of its application, a disclaimer restating requirements EXI_S6_02 to EXI_S6_04. According to the specifications, ANSSI's evaluation is limited to the functional aspects of the solution with respect to the EBIOS Risk Manager method. The label does not replace certification or qualification. It in no way guarantees the robustness of the application against malicious actions. The specifications also ask the publisher to recommend that users carry out a security accreditation (homologation) of the application. Finally, the label covers the tool, not what is done with it: neither the procedure nor the specifications provide for any evaluation of the risk analyses that users produce. The label attests, for the version and mode evaluated, that the method can be followed end to end; the quality of a given analysis still depends on the chosen scope, the participants and the rigour of the team.

Validity, renewal and withdrawal of the label

According to the label procedure (version 1.1), a label is valid for three years. The decision is taken by the Director General of ANSSI, on the opinion of the head of its Strategy sub-directorate; a label reference is then assigned and the solution is published on the ANSSI website with the status "labelled". Renewal is not automatic: the publisher must apply no later than three months before expiry, with a file identical to the initial application. Any change to the elements on which the label was granted must be reported to ANSSI, if possible before it takes effect: a minor change goes through a simplified process and keeps the label reference, while a major change is handled like an initial labelling. ANSSI can check at any time that labelled software still meets the specifications and the method, and start a withdrawal procedure. A label ends at the publisher's request, when no renewal has been requested by the expiry date, or after a withdrawal; the publisher must then immediately stop using the EBIOS Risk Manager name and its visual mark.

How to check that software is labelled

The list published on the label page on cyber.gouv.fr is authoritative: software that is not on that list is not labelled. Check three things, in this order: the exact name of the solution, the labelled mode (standalone, client-server or SaaS) and the version number. If the version or mode you plan to deploy differs from what ANSSI publishes, ask the publisher where the labelling of that version stands. The same page has a section for solutions "being labelled". According to ANSSI, only projects whose publishers have agreed to make them public appear there, and a suspended project is removed; as of 9 October 2026, that section has no entries. A solution that is being labelled is not labelled: only an ANSSI decision published in the list of labelled solutions counts as a label. Since the page does not publish award dates, also check the list on the date of your decision, not only when you first contact the publisher.

EBIOS RM label, certification and qualification: three different things

According to the "Visa de sécurité" page on cyber.gouv.fr, the security Visa is granted to solutions that have obtained a certification or a qualification, after an evaluation by approved laboratories. Certification evaluates the robustness against attacks of a specific version of a product, at a given moment, according to the state of the art of attacks at that moment. Qualification mainly concerns products and services relevant to the security of public administrations and regulated operators (OIV, OSE); it meets requirements of the French military programming law, the RGS and the eIDAS regulation, and also attests that the provider can keep its commitments over time. The EBIOS Risk Manager label belongs to neither process: it assesses functional conformity with a method, not resistance to attacks. The only overlap is the SaaS mode, which requires a SecNumCloud-qualified host; in that case it is the hosting that is qualified, not the risk analysis software.

Choosing EBIOS RM software, with or without AI: the questions to ask

The label is a good starting point, not a complete selection grid. First question: which version of the EBIOS Risk Manager guide does the software follow? The v3.1 specifications are aligned with guide v1.5 of September 2024, but the official list does not say under which version of the specifications each solution was evaluated, so ask. Second question: do the labelled mode and version match what you will deploy? Third question: exports. The label requires deliverables and an export of each workshop's output data; check the formats and how easily they fit into your accreditation files. Fourth question: reuse. The label requires managing successive versions of the same analysis, and importing knowledge bases is optional; carrying elements over from one analysis to another is not a label requirement, so test it on your own cases. Fifth question: hosting and administration of risk analysis data, which is often among the most sensitive data an organisation holds. Last question, for EBIOS RM tools with AI: the v3.1 specifications contain no requirement specific to artificial intelligence, so the label says nothing about these features. Ask which documents are sent to which model, where that model runs, whether your data is used to train it, and how an expert reviews and validates what the AI proposes. The safest approach remains a pilot on a real, narrow scope.

Vailor: a labelling request in progress

This article is published by Vailor, the publisher of an EBIOS RM risk analysis platform that competes with the solutions presented above; that is why Vailor is presented separately, based on its own statements. Vailor is an AI-native cyber GRC platform, built in France. Vailor's EBIOS Risk Manager labelling request has been submitted to ANSSI: Vailor is being labelled, not labelled. Vailor does not currently appear in the public section for solutions being labelled on the ANSSI page, and submitting a request does not amount to a label. The request covers the version of Vailor installed on the customer's premises, in client-server mode; Vailor's hosted offering is not covered by this request. It was prepared on the basis of the v3.1 specifications, the only version ANSSI currently publishes. In Vailor, the AI reads the project's documents and pre-fills the workshops; when it relies on a document, it quotes the passage, checked word for word, and every proposal remains a draft until an expert validates it. Customers choose their AI model, including a self-hosted one. If the label is awarded, the list published on cyber.gouv.fr will be the proof, as for any other solution.

Let's talk about your context

Book 30 minutes. We listen to your priorities, tell you concretely how Vailor addresses them, and if it makes sense, we scope a pilot together.

Book a demo