Read time : 12 min
Updated on 7 October 2026

Export control and defense cybersecurity: compliance guide for SMEs

SMEs supplying dual-use goods or working on classified information systems must master export control (ITAR, EAR, EU regulations) and defense cybersecurity (IGI 1300, SecNumCloud). Non-compliance carries criminal penalties and market exclusion.

The market in figures

French public procurement open data, 12 rolling months as of 2026-08-28. Amounts and durations are medians.

734
contracts awarded
380
winning companies
326
active public buyers
120,000 EUR
median amount
48 months
median duration

What these figures tell you

With 380 winning companies for 734 contracts, a company wins on average 1.9 contract(s) per year in this segment.

The median amount of 120,000 EUR indicates the size of consultation to target first.

The median duration of 48 months shows how often these contracts return to tender.

The median is used rather than the average: a handful of very large contracts is enough to distort an average.

Export control: ITAR, EAR and EU regulations

ITAR regulates US defense exports — any French company using USML-listed components is subject to it, even as a Tier 3 subcontractor. Violations carry up to $1M per infraction. EAR covers dual-use goods on the CCL (Commerce Control List). EU Regulation 2021/821 governs dual-use exports in Europe, with the French SBDU issuing licenses. SMEs must classify products (USML/CCL/ML), screen end-users, and maintain compliance documentation.

Defense cybersecurity: IGI 1300 and SecNumCloud

IGI 1300 sets classified information protection rules for IT systems: system accreditation, ANSSI-approved encryption, access logging, network separation (air gap for TS), annual penetration testing. SecNumCloud is ANSSI's cloud security qualification — increasingly required for sensitive defense data hosting. The PSSI (IT Security Policy) is mandatory for any classified contract, covering risk analysis (EBIOS RM), technical measures, incident management, and cyber training.

Building an SME compliance program

Implement an ICP (Internal Compliance Program) covering: management-signed policy, compliance officer, screening procedures, product classification, license management, staff training, annual audit. For cybersecurity, develop a PSSI with asset mapping, EBIOS RM risk analysis, and obtain SI accreditation before contract execution (3-6 months lead time).

Analyse your defense DCE

1 free analysis — No commitment

Frequently asked questions

Related guides

Ready to win more public contracts?

Join SMEs that respond 3x faster to public tenders.

Start for free →

1 free project • No commitment • Setup in 2 minutes