Attestation de niveau OneFD is becoming a central topic for French public sector organizations in 2026, as agencies align their digital trajectories with strict security and interoperability standards. This overview explains what the attestation covers, how it integrates with existing frameworks, and why it matters for operational continuity.
Designed to formalize service levels and technical compliance, the 2026 version of the attestation builds on previous editions while introducing more precise identity and access management requirements. The following sections outline the key dimensions that public sector teams need to manage.
| Dimension | 2024 Baseline | 2026 Update | Impact on Teams |
|---|---|---|---|
| Governance | Project-level ownership | Enterprise risk and cross-service steering | Closer alignment with ISO 27001 and local mandates |
| Security Controls | Baseline hardening | Identity proofing, MFA, and session assurance | More rigorous validation and audit artifacts |
| Service Continuity | Availability metrics | Resilience testing and failover procedures | Improved incident response SLAs |
| Interoperability | Basic API exposure | OpenID Connect, standardized attestations, and catalog registration | Easier integration with shared French public service platforms |
Operational Implementation Path for OneFD Attestation
Implementing the 2026 attestation requires a structured path from inventory to continuous monitoring. Teams should start by mapping existing services against the expected assurance levels and then define clear owners for each control.
Technical teams must coordinate identity strategies, logging standards, and change management processes to ensure that evidence can be produced consistently. The attestation workflow should be integrated into existing service management practices rather than treated as a separate initiative.
Identity and Access Management Requirements
Identity and access management forms a core component of the 2026 attestation, with particular emphasis on verifiable authentication, least privilege, and session integrity. Organizations need to document how users and systems are identified, authenticated, and authorized across digital services.
Specific expectations include support for phishing-resistant MFA, clear role definitions, and traceable access reviews. Aligning these measures with national identification frameworks helps reduce friction for public users while maintaining robust security.
Compliance, Risk, and Policy Alignment
Compliance under the 2026 attestation extends beyond technical checkboxes to include policy alignment, risk treatment plans, and measurable service levels. Organizations should map attestation requirements to relevant regulations and internal governance documents.
Risk treatment activities must be documented with clear remediation timelines, responsible parties, and residual risk acceptance records. This structure supports stronger oversight by senior leadership and facilitates audits by supervisory authorities.
Architecture, Integration, and Lifecycle Management
The architectural perspective focuses on how services, identity providers, and security tools interoperate within the attestation boundary. Teams should define integration patterns, data flows, and trust boundaries that can be validated during assessment cycles.
Lifecycle management ensures that attestations are reviewed at planned intervals, especially when services evolve or new vulnerabilities emerge. Automated evidence collection and version-controlled documentation reduce manual effort and improve accuracy.
Key Implementation Steps and Takeaways
- Map services and identity flows against the 2026 attestation requirements.
- Define enterprise-level governance and assign clear responsibility for each control.
- Strengthen identity and access management with MFA, role management, and session controls.
- Integrate compliance, risk treatment, and policy alignment into operational processes.
- Establish continuous monitoring, evidence collection, and periodic review cycles.
FAQ
Reader questions
How does OneFD attestation relate to existing security certifications in the public sector?
It complements existing certifications by providing a structured service-level attestation that integrates identity, access, and continuity evidence, reducing duplicated assessments.
What are the most common gaps observed during 2026 attestation assessments?
Common gaps include incomplete identity proofing records, inconsistent MFA coverage, and insufficient documentation of risk treatment actions across services.
Can legacy systems be included in the attestation scope for 2026?
Yes, legacy systems can be included when appropriate compensating controls are defined and their risk is formally accepted and documented. Evidence should be refreshed at least annually, with additional updates tied to significant changes in architecture, identity providers, or major incidents.