Why choose an ANSSI-Certified Bastion Host and which PAM Solutions actually qualify ?

Publish on August 06, 2026

Certification

by Loren Breux

When evaluating a Privileged Access Management (PAM) solution, one question consistently comes up on the CISO side: "Is it ANSSI-certified?" In a field as sensitive as privileged access management, trust isn't something you claim, it's something you prove.

Let's break it down: what this certification really covers, why it matters for the security of your information system, and most importantly, which solutions actually hold it today, in force.

ANSSI : France's National Cybersecurity Authority

The French Cybersecurity Agency (ANSSI) is France's national cybersecurity authority. Its mandate is broad : preventing cyber threats targeting critical information systems, supporting risk management and incident response, and publishing reference technical standards. As part of this scope, it also evaluates and certifies security products and service providers operating in France.

Its recommendations apply to a wide range of entities: operators of vital importance, public administrations, and increasingly, SMEs and mid-market companies, which are now prime targets. With the entry into force of the EU's NIS 2 regulation, the scope of entities subject to these security requirements is expanding further, reinforcing ANSSI's role as the national cybersecurity benchmark for a growing number of organizations, regardless of infrastructure size.

 

Understanding ANSSI's Different Frameworks : Certification vs. Qualification

This is a distinction worth clarifying, as it's often a gray area for buyers of security solutions.

  • CSPN (First-Level Security Certification) : A framework tailored to operational security products (bastion hosts, firewalls, authentication solutions, etc.). An accredited independent lab (CESTI) evaluates the product under real-world conditions, within a timeframe compatible with vendors' development cycles. Results are published in ANSSI's official catalog. This first-level certification is already demanding and represents a strong security signal for PAM solutions.
  • Common Criteria (CC) : An internationally recognized standard (ISO/IEC 15408) with assurance levels ranging from EAL1 to EAL7 (the higher the number, the more rigorous and in-depth the security evaluation). This framework is intentionally very demanding, making it difficult to reconcile with the rapid update cycles typical of modern bastion hosts, whose features evolve regularly to keep pace with infrastructure changes and administrator workflows.
  • Qualification (Standard or Enhanced) : A step above certification — ANSSI doesn't just validate the solution's security, it actively recommends it for sensitive use cases.
  • Security Visa : A generic term designating a product that has obtained either ANSSI certification or qualification. This is the label referenced in public procurement tenders and CISO requirements.
  • Service Provider Certifications (PASSI, PDIS, PRIS, PSCE) : Not to be confused with product certification — these frameworks apply to security service providers, not to PAM vendors as such.

 

Why This Certification Matters for a Bastion Host

  1. An objective guarantee, not a marketing promise : CSPN certification confirms, through an independent third party, that network flow isolation, action traceability, and user authentication actually function as advertised.
  2. A selection criterion in public tenders : For government agencies and public sector entities, the CSPN Security Visa is often a de facto requirement in RFPs related to privileged access management, regardless of the organization's scale or the number of accesses to protect.
  3. A concrete response to regulatory pressure : Relying on a certified solution helps secure your compliance roadmap, for instance, under NIS 2, particularly when it comes to governing access for both internal and external administrators to your information system.
  4. A critical point of vigilance : validity period : This is where things get interesting and where many buyers drop the ball. A CSPN certification isn't granted for life. It's issued for a specific product version and requires ongoing maintenance to remain valid over time. A solution still displaying its CSPN logo, but whose certification expired years ago, no longer offers the same security guarantee, nor the same level of trust within your cybersecurity toolchain.

Which PAM Solutions Are CSPN-Certified Today ?

In the French market, several bastion hosts have obtained CSPN certification at one point or another. But the question that truly matters to a CISO isn't "did it get certified at some point?", it's "does it still hold that certification, today?"

As of publication, PROVE IT by RUBYCAT is the only bastion host on the market with an active, up-to-date CSPN certification, verifiable in ANSSI's official catalog.

A concrete selection criterion for any organization evaluating a PAM solution : always check certification status in the official catalog before making your decision. The date of issuance isn't enough, only current validity counts.

What an ANSSI-Certified Bastion Host Concretely Delivers to Your Information System

A bastion host sits between your administrators and your critical assets (servers, network equipment, etc.). Its role: centralizing connections, tracing actions, and enforcing the principle of least privilege across all privileged accounts within your IT infrastructure.

In practice, a PAM solution like PROVE IT enables you to:

  • Centralize privileged access control through a single point, regardless of operating system or environment (including Microsoft and Active Directory environments), across all exposed workstations
  • Enforce strong authentication on every connection, for every user, without exception
  • Log the entirety of actions performed during administration sessions, with evidentiary value in the event of an incident
  • Govern access for both internal users and external service providers connecting over the internet, reducing your infrastructure's exposure
  • Isolate administrative traffic from the rest of the network, ensuring no direct connection to sensitive resources is possible from a compromised endpoint

These capabilities make the bastion host a core component of your cybersecurity arsenal, standing alongside the detection and monitoring tools already in place across your information system.

Our Position: PROVE IT, the Only Currently ANSSI-Certified Bastion Host

RUBYCAT develops PROVE IT, a PAM solution designed to address the security challenges faced by SMEs, mid-market companies, and public sector entities. It combines what certification guarantees — traceability, network flow segmentation, strong authentication — with what IT teams expect on a daily basis: fast deployment, an interface that's easy to adopt for all users and administrators, and responsive French-speaking support.

Built to integrate seamlessly into existing infrastructure, PROVE IT sits alongside your other security tools without adding complexity to your IT team's day-to-day operations.

In a landscape where privileged access risks weigh on large enterprises and SMEs alike, holding a bastion host that is certified, and actively certified, is a mark of trust that few players in the market can currently claim.

Discover our PROVE IT PAM solution

Our solution

Our bastion host is designed for organizations that want a high level of security without the complexity of traditional PAM solutions.

Written by

Loren Breux

Marketing project manager