What Is ANSSI ReCyF Objective 13?
ANSSI ReCyF (Référentiel Cyber) is the baseline security framework published by France's national cybersecurity agency, ANSSI, to help organizations meet their obligations under the NIS2 directive as transposed into French law. The framework is organized into a series of numbered control objectives covering governance, risk management, and technical security measures. Objective 13 focuses specifically on the management of privileged and non-human accounts: service accounts, technical accounts, and machine-to-machine credentials used by applications, scripts, and infrastructure components. It requires organizations to maintain an inventory of these accounts, apply least-privilege access, enforce credential rotation, and monitor for anomalous use. For essential and important entities in scope of NIS2, demonstrating compliance with Objective 13 is part of the broader audit process ANSSI oversees in France.
Why It Matters
Service and technical accounts are exactly the kind of identity ReCyF Objective 13 was written for, and they are also where breaches concentrate: 80% of identity breaches now involve a non-human identity (OWASP NHI Top 10, 2025). Unlike a human employee, a service account rarely gets offboarded when a project ends, rarely has its permissions reviewed, and often holds standing credentials that never expire. In a mid-sized organization these accounts can outnumber human employees 45 to 1, and a typical 100-person company already runs more than 2,000 of them — far more than any manual inventory can track. NIS2 enforcement in France begins October 1, 2026, and ReCyF Objective 13 makes this concrete: entities in scope must show which service accounts exist, what they can access, and how their credentials are rotated. Organizations that cannot produce that inventory face both a compliance gap and a live attack surface, since an orphaned or over-privileged machine credential is one of the easiest footholds for an attacker to exploit undetected.
How Cydenti Helps
Cydenti builds and maintains a continuously updated inventory of service accounts, technical accounts, and machine credentials across cloud and on-premises environments, mapping each one to its owner, permissions, and usage pattern. This gives compliance and security teams the evidence base ReCyF Objective 13 asks for, without manual spreadsheets that go stale within weeks. Risk scoring highlights orphaned, over-privileged, or dormant accounts before an auditor or an attacker finds them, and reporting is structured to align with ANSSI's control objectives. For teams preparing for NIS2 audits under the French transposition, that turns an abstract requirement into something you can actually demonstrate.
Explore →Frequently Asked Questions
Does ReCyF Objective 13 apply to my organization?
It applies to entities classified as essential or important under France's NIS2 transposition, which ANSSI oversees. This spans sectors like energy, transport, health, digital infrastructure, and increasingly mid-sized suppliers in their supply chains. If NIS2 applies to you, ReCyF's control objectives, including Objective 13, form part of the baseline you'll be assessed against.
What counts as a service account under Objective 13?
Any non-human credential used by an application, script, integration, or piece of infrastructure to authenticate and access resources — not just accounts labeled 'service account.' This includes API keys, automation bots, CI/CD credentials, and machine-to-machine tokens. Objective 13 expects these to be inventoried, least-privilege, and rotated like any other sensitive credential.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h