E-invoicing goes live and business owners fear a hack — Bercy imposes an emergency cyber audit on approved platforms
On August 26, 2026, France’s minister for Public Accounts, David Amiel, summoned the roughly 150 state-approved e-invoicing platforms to Bercy and gave them until the end of September to prove their security — or be suspended. A direct answer to SME leaders’ fears after the DGFiP tax data breach revealed in August. What this new audit changes for how you choose your platform.
September 1, 2026 was meant to be a single story: France’s e-invoicing reform generalizing, large enterprises and mid-market companies (ETI) starting to issue electronic invoices, every VAT-liable business required to be able to receive them. But alongside that compliance deadline, a second and distinct worry surfaced among French business owners in the days before it: is the data flowing through these approved platforms (“plateformes agréées”, PA) actually safe? The concern is not abstract — it follows directly from the breach of France’s tax administration, the DGFiP, revealed in August 2026, which exposed tax data belonging to 285,570 businesses. Bercy’s answer, delivered ten days before D-day, was a new cybersecurity audit regime for the platforms themselves.
A meeting at Bercy, ten days before the deadline
On August 26, 2026, the Ministry of Finance confirmed that minister David Amiel had gathered the roughly 150 approved platforms at Bercy to remind them that France’s security requirements for e-invoicing are, in the ministry’s words, “the highest in Europe” — and that from now on, platforms must supply continuous proof of it, not a one-time certification. The move came as several outlets, including Génération-NT, reported that business owners were increasingly voicing fears that a reform concentrating commercial and financial data from millions of companies into a handful of private intermediaries could turn those platforms into a prime target for hackers.
What Bercy now requires from every approved platform
- →A cyber-monitoring report (“rapport de veille cyber”) submitted to the administration before the end of September 2026.
- →Any security incident reported to state services without delay — no grace period.
- →Generalized penetration testing, starting this autumn.
- →Immediate suspension of a platform’s operations if it fails to demonstrate the required security level.
Why this worry is not overblown
The DGFiP breach that triggered this response was itself confirmed by the Ministry of Finance on August 13, 2026: a hacker claimed to have extracted 678,438 lines of tax data, 285,570 of them belonging to businesses. An approved e-invoicing platform, by design, will hold a comparable category of sensitive data — invoicing amounts, client and supplier identities, payment terms — for every company using it, concentrated in far fewer hands than the tax administration’s own systems. That concentration is exactly why Bercy is now treating the platforms’ security as a live, ongoing obligation rather than a box ticked once at approval.
What this actually changes for your SMB
- →You are not required to issue invoices electronically before September 2027, but you must already receive them through an approved platform today — the platform you use (or your accounting software connects to) is no longer just a price decision, it is a data-security decision.
- →Ask your platform, or your accounting software provider, whether it will publish its cyber-monitoring report by September 30, 2026. A provider that dodges the question is itself the warning sign.
- →Favor platforms that can point to real security certifications (SecNumCloud, ISO 27001, hosting in France or the EU) over the cheapest option among the roughly 150 approved providers.
- →Have a fallback in mind: if your platform were suspended for non-compliance, your incoming and outgoing invoices still need to keep moving — do not put every critical flow on a single provider with no visibility into its own compliance status.
A 2023 qualitative study of 34 UK SMEs published in the International Journal of Information Management Data Insights, by Rawindaran, Jayal, Prakash and Hewage, found that smaller firms’ trust in government-backed cybersecurity schemes depends less on the existence of the scheme itself than on continuous, visible follow-through from the public agencies involved — one-off assurances do little to change how exposed a small business actually feels. Bercy’s shift from a one-time platform approval to a recurring audit with a real suspension mechanism is precisely the kind of follow-through that study found missing in comparable programs elsewhere.
A shifting requirement like this one — a report due by a specific date, an inspection campaign starting in the autumn, a suspension clause that could take a platform off the approved list with no warning to its users — is exactly what a dedicated regulatory watch agent is built to track continuously, rather than your business discovering the problem the day an invoice fails to go through. Before your next platform renewal, it is worth asking the question directly rather than assuming approval today still means approval in October.
Frequently asked questions
Does my SMB need to switch e-invoicing platforms because of this announcement?+
Not automatically. But you should ask your current platform, or the accounting software connected to it, whether it will publish its cyber-monitoring report by September 30, 2026 as Bercy now requires, and what security certifications it holds. An evasive answer is the real signal to act on.
What exactly did the government announce on August 26, 2026?+
Minister David Amiel gathered France’s roughly 150 approved e-invoicing platforms and required them to submit a cyber-monitoring report before the end of September 2026, report any incident to the state without delay, undergo generalized penetration testing starting this autumn, and face immediate suspension if they cannot prove the required security level.
Is there a confirmed link between the DGFiP breach and the approved e-invoicing platforms?+
No breach of an approved platform itself has been reported. But the DGFiP breach, which exposed tax data from 285,570 businesses, is the direct trigger behind business owners’ distrust and Bercy’s decision to impose continuous, provable security standards on the platforms rather than a one-time approval.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
CNIL fines a hospital €500,000 for no MFA, no VPN: the RGPD security checklist that applies to your SMB too
4 September 2026·5 min read
Business & compliance
E-invoicing takes effect today, September 1, 2026 — and 42% of French businesses are not ready
1 September 2026·5 min read
Business & compliance
Google Workspace can now suspend AI agents and their Drive access — what SMBs should check before September 1
30 August 2026·5 min read