E-invoicing: Bercy imposes cybersecurity audits on approved platforms after the tax authority hack — what to check before September 1
On August 26, 2026, six days before every VAT-liable company must be able to receive e-invoices, minister David Amiel summoned approved e-invoicing platforms to Bercy and imposed new cybersecurity reporting duties, after repeated intrusions into the tax authority’s systems this summer. What actually changed, and what your SMB should verify about its own platform before September 1.
On August 26, 2026, David Amiel, France’s minister for Public Action and Accounts, convened the leaders of every approved e-invoicing platform (“plateforme agréée”, PA) at Bercy to remind them of their IT security obligations, according to Public Sénat. The timing is not neutral: the meeting comes after the DGFiP data breach — which we covered here when it was confirmed on August 13, 2026 — and repeated intrusions into the tax authority’s systems over the summer — six days before September 1, 2026, the date on which every company subject to VAT, whatever its size, must be able to receive its invoices electronically through one of these approved platforms.
What Bercy actually announced on August 26
- →Every private approved-platform operator must submit a cybersecurity monitoring report to the tax administration before the end of September 2026.
- →Operators are now obligated to report any security incident to state services without delay, rather than after the fact.
- →Generalized penetration tests will be imposed on approved platforms starting this autumn.
- →A platform unable to demonstrate the highest level of security can have its operations suspended.
- →The ministry’s entourage describes the specifications imposed on these platforms as “the highest standards in Europe,” aligned with the principles of the NIS2 directive.
For companies themselves, the minister struck a reassuring note: the coming months are described as a phase of “progressive deployment and support,” with no sanctions applied to any company in 2026 — a stance consistent with the tolerance approach announced on July 10. What changed on August 26 is not the deadline or the penalty scale for companies — it is a new layer of accountability imposed on the roughly 130 platforms your company might be choosing between.
Why this matters for your SMB, not just for platform operators
It is tempting to read this as a story about IT vendors, not about your business. It is not. Starting September 1, your accounting and invoicing data routes through a private company you selected, largely on price and integration ease, rarely on its security posture. Bercy’s announcement effectively says the same thing a security researcher would: an approved platform is now a critical piece of your own financial data chain, and its incident-reporting obligations only kick in once something has already gone wrong — the report and the pentest requirement do not retroactively vet the platform you already picked.
What the research says about compliance and SME cybersecurity
A 2025 systematic mapping study covering 73 academic articles, Cybersecurity Threats and Defensive Strategies for Small and Medium Firms: A Systematic Mapping Study, by Awan Mujtaba and Abu Alam, lists supply-chain visibility — knowing the security posture of the vendors your company depends on — among the defensive practices SMEs most often lack the resources to implement. A separate 2026 study published in SAGE Open, Strengthening Cybersecurity in Small and Medium-Sized Enterprises: Balancing Technology, Costs, Compliance, and Employee Awareness, surveying 847 SMEs, found that regulatory compliance pressure has a measurable positive effect on cybersecurity management effectiveness (β = .234, p < .001) — exactly the mechanism at play here: a state mandate on your platform provider is more likely to produce real security improvement than waiting for the market to self-regulate.
What to actually check before September 1
- →Confirm the platform you connected to (or are about to connect to) still appears on the official approved-platforms registry published by the tax administration — a suspension would remove it from that list.
- →Ask your platform provider directly whether it has submitted, or plans to submit, its cybersecurity monitoring report and whether a penetration test is scheduled this autumn — a serious provider will have a straightforward answer.
- →Do not treat “no sanctions in 2026” as “nothing to do” — the September 1 reception obligation itself is unchanged, only the tolerance for good-faith technical hiccups.
- →Add a security question to any vendor comparison you still have open, the same way you would for any SaaS handling financial or client data — not just for e-invoicing.
This is exactly the kind of moving regulatory detail a dedicated regulatory watch agent is built to track continuously — the official list of approved platforms, ministry announcements, suspension notices — rather than something your team discovers weeks later because a payment or an invoice silently failed to route. Six days from the deadline, the safest move is not to relax because sanctions are paused; it is to spend those six days actually verifying the provider you picked.
Frequently asked questions
Does the August 26, 2026 announcement change the September 1 e-invoicing deadline?+
No. Every VAT-liable company, regardless of size, must still be able to receive electronic invoices through an approved platform from September 1, 2026. The announcement adds new cybersecurity obligations on the platform operators themselves, not on companies.
What new obligations do approved e-invoicing platforms now have?+
They must submit a cybersecurity monitoring report to the tax administration before the end of September 2026, report any incident to state services without delay, and undergo generalized penetration tests starting this autumn. A platform that cannot prove the highest level of security can be suspended.
Should my SMB worry about being sanctioned in 2026?+
The minister said no sanctions will be applied to any company in 2026, consistent with the tolerance approach announced in July for good-faith technical difficulties. This does not remove the obligation to be able to receive e-invoices from September 1 — it only softens the penalty for genuine, documented hiccups.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
Google Workspace can now suspend AI agents and their Drive access — what SMBs should check before September 1
30 August 2026·5 min read
Business & compliance
Training organization software: off-the-shelf Qualiopi tool or a custom management platform?
28 August 2026·5 min read
Business & compliance
Anthropic launches Claude Security with Mythos 5: what the AI patching race changes for your SMB
26 August 2026·5 min read