# FRANCE-CRYPTO.md — French cryptology declaration, and Apple's France question

Research date: **2 September 2026**. Companion to `EXPORT-COMPLIANCE.md` (US/EAR side, and the
App Store Connect answers already given for build 5).

> **This is a report of what the sources say. It is not legal advice.** Where a real judgement call
> is needed, §7 says so explicitly.

---

---

## 0. FILED — 3 September 2026, and what ANSSI's acknowledgement confirms [VERIFIED — primary]

An initial filing was emailed to `controle@ssi.gouv.fr` at **03:49:50 UTC on 3 September 2026**
(05:49:50 Paris), subject `[formalités] CHANNEL MESSENGER – Channel Messenger`, from `de57@me.com`. It
requested the Annexe I form (the published link 404s) and supplied the product description, publisher,
and the full algorithm/key-length list.

ANSSI's automated reply arrived within minutes and **settles several points this document had marked
uncertain**:

- **It was logged as a `dossier de déclaration`**, not treated as a mere enquiry: *"Nous avons bien
  reçu votre dossier de déclaration et/ou demande d'autorisation d'opérations relatives à un moyen ou
  à une prestation de cryptologie en date du jeudi 3 septembre 2026 05:49:50."* Electronic filing
  works and is acknowledged immediately.
- **One month to review**, *"étendu à deux mois lorsque la déclaration concerne la fourniture de
  prestations de cryptologie ou l'exportation de moyens de cryptologie vers des Etats non membres de
  l'Union européenne."* Confirms the *moyen* / *prestation* distinction is live in ANSSI's actual
  process, not only in the statute — and that the prestation limb costs an extra month.
- ANSSI checks two things in that month: whether the dossier is **complete**, and whether the means
  **falls under the authorisation regime rather than declaration**.
- **Silence is permission.** *"En cas de silence de l'agence, vous pourrez procéder librement, à
  l'expiration des mêmes délais, aux opérations faisant l'objet de votre déclaration et demander à
  l'ANSSI une attestation confirmant que vous vous êtes acquitté de votre obligation déclarative."*
  No approval is needed — an attestation is available on request afterwards.

**Expect an incompleteness request.** The filing carried the substance but not the Annexe I form
itself, a KBis-equivalent registration document, or the attachments §3.2 lists. Under décret art. 5
that restarts the one-month clock from receipt of the additional material, so **the operative date
will likely be the follow-up, not 3 September.**

**Open, for Don:** the declaration named *"Donald Elton (États-Unis)"* personally, matching the Apple
and Google developer accounts. If Elton Services (EIN, Florida fictitious name) is the intended filer,
`Donald Elton d/b/a Elton Services` keeps the developer-account match while giving ANSSI a
registration document to point at. Decide before the complete dossier goes back.

## Bottom line

1. **The obligation is real, still in force in 2026, and has not been superseded by EU law.** Supply
   (`fourniture`) or import of a confidentiality-capable cryptographic means in France requires a
   **prior declaration to ANSSI**, under LCEN art. 30 III (2004) and décret 2007-663. Free-of-charge
   supply counts. EU dual-use regulation 2021/821 governs *export*; it did not replace this.

2. **It is a declaration, not an approval.** You file and you may proceed — there is no waiting for a
   "yes". The statutory hook is **file at least one month before** you start supplying (décret art. 4).
   **No fee.** No lawyer legally required. The form is short; the burden is a technical description.

3. **The developer files, not Apple.** ANSSI puts the duty on "le fournisseur ou le primo-importateur",
   including foreign suppliers. Apple's App Store question is Apple enforcing the French rule against
   its developers — it is not Apple filing on your behalf.

4. **There is no exemption that plainly covers us.** Using only standard published algorithms does not
   exempt. "Grand public" (mass-market) status almost certainly applies to us but **only frees export**
   — it does not remove the supply/import declaration. Décret Annexe 1's exemptions are narrow and
   hardware-flavoured.

5. **Answering "No" to Apple is a genuinely low-risk holding position — but it does *not* by itself
   remove France from sale.** The obligation is triggered by *supplying in France*, so not distributing
   there means the duty is not engaged. **Critically: Apple's France answer only records intent; it
   does not change your territory list.** To actually not supply France you must separately remove it
   under *Pricing and Availability*. Right now our answer says "No" while France is, in all likelihood,
   still an enabled territory — an inconsistency worth closing. Nothing here is a global block, and it
   is reversible without a rebuild.

6. **But the enforcement risk is not zero and not merely theoretical.** In August 2024 French
   prosecutors charged Pavel Durov with, among other things, **exactly these two offences** — verbatim
   from the Tribunal de Paris release. That is the single most important fact in this document, and it
   is why the "everyone ignores it" framing is wrong.

**Practical recommendation for Channel Messenger:**

- **Now (beta):** keep "No". The position is sound — we are not supplying in France.
- **Check:** confirm France is actually removed under *Monetization > Pricing and Availability*.
  Answering "No" did **not** do this for us (§4.1). Do the same for Google Play, which never asks.
- **Before App Store release:** either file the declaration (a free form, ~1 month lead time) or
  consciously ship without France. Do not let the answer default.
- **Counsel:** worth it only for the narrower `prestation de cryptologie` question in §7 — not for the
  basic filing, which is a form anyone can submit.
- **Do not** treat "standard published algorithms" as an exemption. In French law that axis does not
  exist (§3.5), even though it is exactly the axis Apple and BIS use.

---

## How to read this

Every claim below is tagged:

- **[VERIFIED]** — I read the primary text myself (statute, decree, ANSSI page, official PDF).
- **[SECONDARY]** — reported by a credible source, not confirmed against a primary text.
- **[INFERRED]** — my reasoning from verified facts; the reasoning is shown so you can disagree.
- **[UNRESOLVED]** — sources conflict, or I could not establish it.

---

## 1. Is the French requirement still in force in 2026?

**Yes. [VERIFIED]** Nothing has repealed or relaxed it, and no EU instrument has taken it over.

### 1.1 The statute — LCEN art. 30, unmodified since 2004

Loi n° 2004-575 du 21 juin 2004 (LCEN), art. 30, verbatim:

> **I.** — L'utilisation des moyens de cryptologie est libre.
>
> **II.** — La fourniture, le transfert […] l'importation et l'exportation des moyens de cryptologie
> assurant **exclusivement** des fonctions d'authentification ou de contrôle d'intégrité sont libres.
>
> **III.** — La fourniture, le transfert depuis un Etat membre de la Communauté européenne ou
> l'importation d'un moyen de cryptologie **n'assurant pas exclusivement** des fonctions
> d'authentification ou de contrôle d'intégrité sont soumis à une **déclaration préalable** auprès du
> Premier ministre […] Le fournisseur […] tien[t] à la disposition du Premier ministre une description
> des caractéristiques techniques de ce moyen de cryptologie, **ainsi que le code source des logiciels
> utilisés**.

Legifrance shows art. 30 in force with **no modification since 22 June 2004**. **[VERIFIED]**

**Does Channel Messenger fall in III rather than II?** Yes, unambiguously. **[INFERRED, high confidence]**
Art. 29 defines a *moyen de cryptologie* as any hardware or software designed to transform data using
secret conventions, to ensure confidentiality, authentication or integrity. We do X25519 key agreement
and ChaCha20-Poly1305 authenticated encryption for **message confidentiality** — that is squarely
"not exclusively authentication or integrity." The art. 30 II free pass is for signature/MAC-only
products. It does not apply to an E2EE messenger.

Note the sting in III: the supplier must **hold the source code available** to the Prime Minister
(i.e. ANSSI) on request. It need not be *submitted* with the declaration, but it must exist and be
producible. For a closed-source Rust core this is a real, if low-probability, obligation.

### 1.2 The decree — 2007-663

- **Art. 1** — exemption from all prior formalities only for operations listed in **Annexe 1**.
- **Art. 3, 1°** — declaration required for "les opérations […] de fourniture, de transfert depuis un
  Etat membre […] et d'importation de moyens de cryptologie n'assurant pas exclusivement des fonctions
  d'authentification ou de contrôle d'intégrité". **[VERIFIED, read verbatim]**
- **Art. 4** — "**Un mois au moins avant l'opération** mentionnée à l'article 3, le dossier de
  déclaration est adressé […] à l'Agence nationale de la sécurité des systèmes d'information".
  **[VERIFIED]**
- **Art. 5** — if the dossier is incomplete ANSSI asks for more within one month, and the one-month
  clock **restarts** from receipt of the additional material. **[VERIFIED]**

### 1.3 ANSSI's own current pages — with an important internal conflict

**[UNRESOLVED — flagged, then resolved on the balance of evidence]**

ANSSI has two live pages that present the same summary table differently:

| Page | "Importation en France" | "Fourniture en France" |
|---|---|---|
| [Contrôle relatif à un moyen de cryptologie](https://cyber.gouv.fr/reglementation/reglementation-identite-confiance-numerique/controles-reglementaires-cryptographie/controle-moyen-de-cryptologie/) | *(cell empty)* | *(cell empty)* |
| [Démarches à accomplir](https://cyber.gouv.fr/reglementation/reglementation-identite-confiance-numerique/controles-reglementaires-cryptographie/controle-moyen-de-cryptologie/controle-rglementaire-cryptographie-demarches/) | **Déclaration auprès de l'ANSSI** | **Déclaration auprès de l'ANSSI** |

I checked the raw HTML of both. On the first page the *moyen de cryptologie* column is genuinely
**blank** for those two rows (the visible "/" belongs to the adjacent *double usage* column). It would
be easy to misread that page as saying supply and import in France now require nothing — an earlier
automated read of it did exactly that.

**The blank cells are a page-authoring defect, not a legal change.** Four things settle it: **[INFERRED,
high confidence]**

1. The prose on that same page says supply, import, intra-EU transfer and export "sont soumis, sauf
   exception, à déclaration ou à demande d'autorisation."
2. The same page describes the *attestation de déclaration* as the document that "permet de **fournir,
   importer en France** et transférer le moyen" — meaningless if neither required a declaration.
3. The sibling *Démarches* page states "Déclaration auprès de l'ANSSI" explicitly for both rows.
4. LCEN art. 30 III and décret art. 3 are unrepealed.

**Other defects on ANSSI's own pages, worth knowing before you rely on them:** **[VERIFIED]**

- The two form links are **swapped**. The link labelled "déclaration […] relative à un moyen de
  cryptologie" serves `crypto_form_fourniture_prestation_annexe2.pdf`, which I opened: it is
  **Annexe II — déclaration de fourniture d'une *prestation* de cryptologie**, the wrong form.
- The link that should serve **Annexe I** (the actual *moyen* form) **404s**.
- The "exception" link points at a dead legacy `ssi.gouv.fr` URL.
- One page says exports go to **8** "EU001" countries; the other says **7** and lists them (Australia,
  Canada, USA, Japan, New Zealand, Norway, Switzerland — the UK is absent). Post-Brexit the UK was
  added to EU001, so "7 + UK = 8" is the likely explanation, but the pages contradict each other.
  **[UNRESOLVED, minor]**

Practical consequence: **email `controle@ssi.gouv.fr` and ask for the current Annexe I form** rather
than trusting the site's links.

### 1.4 Has EU law superseded it? No. [VERIFIED / INFERRED]

- **Regulation (EU) 2021/821** (dual-use) controls **export and intra-EU transfer** of Category 5 Part 2
  "Information Security" items. ANSSI's own pages run the two regimes **in parallel** — its table has a
  separate column for "démarches liées au classement « double usage »". It does not touch supply
  *inside* France. **[VERIFIED]**
- Nothing in NIS2 or the Cyber Resilience Act addresses cryptology supply declarations. **[INFERRED]**
- A February 2026 French practitioner overview still describes the declaration regime as current.
  **[SECONDARY]**

I found **no** 2024–2026 reform, sunset, or relaxation. **[VERIFIED to the limits of searching]**

---

## 2. Who must file — the developer, not the store

**ANSSI: "Ces démarches incombent au fournisseur ou au primo-importateur du moyen de cryptologie et
sont à accomplir auprès de l'ANSSI."** **[VERIFIED]**

- **Each developer is independently responsible.** There is no filing by Apple or Google that
  discharges a third-party developer's obligation. Neither company claims to make one. **[VERIFIED
  that no such claim exists; INFERRED that none covers you]**
- **Foreign suppliers are included.** ANSSI's FAQ requires a KBis extract "**ou équivalent pour les
  sociétés étrangères**" — the dossier is explicitly built to accept non-French companies. **[VERIFIED]**
- **An individual can file.** The form has an "A-2. Particulier" branch, and Debian's real attestation
  was issued to a named individual, not a company (§5.2). **[VERIFIED]**
- **Apple is, in practice, the only enforcer.** An ANSSI official said publicly in 2017 that "Apple, en
  tant qu'**importateur**, demande au fournisseur de remplir une déclaration" — Apple pushes the duty
  *down* to developers rather than absorbing it. The same reporting concluded Apple has been the sole
  platform checking since 2013. **[SECONDARY]**
- **Google Play says nothing at all.** Google's export compliance page mentions France **zero times**,
  ANSSI zero times, and covers only US export law and embargoed countries. **[VERIFIED as an absence]**

**The asymmetry to internalise:** Apple's check and French legal liability are *different things*. The
duty under LCEN arts. 30–31 falls on the supplier or first importer **regardless of platform**. An
Android-only developer is in exactly the same legal position as an iOS one — nobody is merely policing
it. So "Google didn't ask" is not evidence that no obligation exists on the Play side. **[INFERRED,
high confidence]**

**[UNRESOLVED]** Whether Apple itself files a declaration covering *iOS and its own frameworks* is not
publicly documented. Even if it does, it would cover Apple's crypto, not our Rust core — which is
precisely why Apple asks whether you implement your own algorithms.

---

## 3. The process, timing, cost, and exemptions

### 3.1 What it is

A **declaration** (`déclaration`), not an authorisation. You notify; you do not wait for approval.
Distinct from the *export* authorisation (4-month statutory window) and from the "grand public"
classification decision (2 months). **[VERIFIED]**

### 3.2 How to file [VERIFIED]

Electronic, by email to **`controle@ssi.gouv.fr`**, subject line exactly:

```
[formalités] MARQUE – nom du produit
```

Attach: the saved electronic form, a signed scanned copy, and supporting documents (`.pdf`, `.xls`,
`.doc`). Postal filing to SGDSN/ANSSI, 51 boulevard de La Tour-Maubourg, 75700 Paris 07 SP remains
possible. Electronic submission has been available since 13 September 2022. **[SECONDARY for the date]**

**Dossier contents** (ANSSI FAQ): **[VERIFIED]**

- company presentation
- KBis extract < 3 months, **or foreign equivalent**
- commercial brochure
- technical description
- user guide and administrator guide, if they exist

Plus, on the form itself: generic designation in `MARQUE — NOM DU MOYEN` format, version, commercial
reference, and — the technical heart of it — **the algorithms used and the maximum key length for
each**, broken out by function (authentication, signature, confidentiality, key management…).

For us that is a short and genuinely easy list: X25519 (RFC 7748), Ed25519 (RFC 8032),
ChaCha20-Poly1305 (RFC 8439), HKDF-SHA256 (RFC 5869), SHA-256.

**Language:** the site and forms are French-only, and ANSSI's replies come in French. But this is less
of a barrier than the folklore suggests: **[SECONDARY]**

- ANSSI **holds a courtesy English translation of the form** for foreign filers, on request.
- Cryptomator (2016) filled the form in **English** and it was accepted.
- Conversely, ChatSecure's maintainer was blocked from the French App Store **for over three years**
  purely because of the French-language paperwork and international postage — the worst documented
  outcome, and it predates electronic filing.

**Postal filing is no longer required.** ANSSI dropped paper-only at the end of 2015 and email
submission has been available since at least 13 September 2022. Cryptomator's much-quoted 2016 line
that you must submit "via mail (yes, not email)" is **stale** — do not plan around it. **[VERIFIED
against ANSSI's current page; conflict with the 2016 blog noted]**

**Source code:** not required *with* the declaration, but must be **held available** for ANSSI on
request (LCEN art. 30 III). **[VERIFIED]**

### 3.3 Timing

- **Statutory:** file **at least one month before** supplying in France (décret art. 4). **[VERIFIED]**
- **Incomplete dossier** restarts the one-month clock (art. 5). **[VERIFIED]**
- **Real-world, dated anecdotes** — all old, treat with caution: **[SECONDARY]**
  - Cryptomator (2016): ~2 months from filing to approval.
  - Wire: "weeks to a month", and they **pulled Wire from the French App Store while waiting**.
  - ProtonMail: iOS launch slipped about a month.
  - Status (2018): GitHub issue opened 4 May, closed "Submitted!" 4 June.
  - ChatSecure: blocked from the French App Store for 3+ years — the worst reported outcome.

### 3.4 Cost

**No fee is mentioned anywhere** — not in the decree, the 2015 arrêté, or any ANSSI page. **[VERIFIED
as an absence]** The cost is preparation time, and translation if you do not write French.

Do not confuse this with **CSPN/Common Criteria certification**, which is voluntary, published, and
genuinely expensive. The declaration is neither an evaluation nor a quality judgement — the Debian
attestation says so in terms: *"La présente attestation ne constitue en aucun cas une indication sur la
qualité de ce moyen de cryptologie ou une recommandation."* **[VERIFIED]**

### 3.5 Exemptions — none that plainly covers us

**There is no "standard published algorithms" exemption.** **[VERIFIED as an absence]** Nothing in LCEN
art. 30, décret 2007-663, or the 2015 arrêté conditions the duty on algorithm novelty. That axis is
Apple's and BIS's, not France's. France asks *what the product does* (confidentiality → declare), not
*whether you invented the primitive*.

**"Grand public" / mass-market does not exempt you from the supply declaration.** This is the most
commonly misunderstood point. **[VERIFIED]** ANSSI: *"Les moyens de cryptologie « grand public »
s'exportent librement, sans autorisation d'exportation de l'ANSSI ni licence du SBDU."* — it is an
**export** freedom. It is *requested at the time of the declaration*, which presupposes that you
declare. The three conditions (décret Annexe 2, point 3) are the familiar Wassenaar Cryptography Note:

> a) sont couramment à la disposition du public en étant vendus directement sur stock, sans
> restriction, à des points de vente au détail […]
> b) la fonctionnalité cryptographique ne peut pas être modifiée facilement par l'utilisateur
> c) sont conçus pour être installés par l'utilisateur sans assistance ultérieure importante de la part
> du fournisseur

Channel Messenger, distributed free through the App Store and Play Store, meets all three comfortably.
**[INFERRED, high confidence]** So we would likely obtain "grand public" classification — valuable for
export, irrelevant to whether we must declare.

**Annexe 1's exemptions do not reach us.** **[SECONDARY — see caveat]** The ~15 exempt categories are
narrow and mostly hardware: smartcards, broadcast receivers, banking equipment, mobile radio, cordless
phones (≤400 m), copyright protection, 802.11/802.15 equipment, system administration tools, personal
development means, weak-key algorithms. None is a general-purpose consumer messaging application.

*Caveat:* Legifrance is behind a Cloudflare challenge I did not bypass, so **I read Annexe 1 only in
summarised form, not verbatim.** The official decree PDF mirror I obtained (New Caledonia juridoc) omits
the annexes. **Before relying on "no exemption applies", read Annexe 1 in full on Legifrance.** My
confidence that nothing covers a messaging app is high but not primary-source-verified.

### 3.6 A documented failure mode: ANSSI may say "out of scope" and issue nothing

**[SECONDARY, but attested twice independently]** At least two developers who filed in 2020 were told by
ANSSI that their app fell outside the regime and that **no document would be issued at all**. ANSSI's
reply to one, verbatim:

> "Please be informed that the mobile application […] is out of the scope of both domestic (decree
> n°2007-663) & european (Regulation n°2019/2199) regulations. Consequently, **we will not be issuing
> any document**. You may market the aforementioned product without any restriction."

A second developer reported the identical outcome on Apple's forums. Both were then stuck: App Store
Connect still presents a document-upload field, and **Apple publishes no guidance on what to upload
when ANSSI declines to issue anything.** This is a genuine, undocumented gap.

**Does it apply to us? Almost certainly not.** **[INFERRED]** The reported case involved weak, local-only
storage encryption (DES-56), which plausibly falls in Annexe 1's weak-algorithm category. An E2EE
messenger doing X25519 + ChaCha20-Poly1305 for message confidentiality is the paradigm case *inside*
the regime, not outside it. Do not plan on being told we are out of scope.

There is one adjacent and more encouraging data point: Apple's export compliance team reportedly
resolved a 2024 case by simply **waiting out ANSSI's one-month window** rather than demanding an
approval document — *"We had to wait until the ANSSI submission timeframe of one month had passed."*
That matches Apple's softened wording (§4.5) but rests on a single support interaction. **[SECONDARY,
weak]**

---

## 4. Answering "No" to Apple vs "Yes" and filing

### 4.1 What "No" actually does — and what it does *not* do

Apple's official documentation states: **"French encryption declaration form is only required if you're
distributing your app on the App Store in France."** **[VERIFIED]**

Apple's overview page also describes what France controls, which is worth reading closely:

> "The import and export of encryption apps distributed in France are also controlled by the French
> Government. The main items of control for France are **Secure Storage, Secure Communications**, and
> Security Anti-Virus applications. Exemptions include Banking and Medical applications." **[VERIFIED]**

"Secure Communications" is exactly what Channel Messenger is, and neither listed exemption applies to
us. Apple's own framing puts us squarely in scope.

**The single most important mechanical fact: answering "No" records an intent flag. It does not remove
France from your territories.** **[VERIFIED]**

Apple's App Store Connect API defines the field as:

> **`availableOnFrenchStore`** — "A Boolean value that indicates **the intent** to distribute your app
> on the French App Store."

It is `required: true` on declaration creation, and there is **no documented link** anywhere in the API
between `AppEncryptionDeclaration` and `Territory` or app availability. Third-party integration
documentation makes the separation explicit:

> "**Important** — If your app is not going to be available for distribution in France, then it is
> important to **remove France from App Store Connect**. To do this, go to Monetization > Pricing and
> Availability" **[VERIFIED — Signicat iOS SDK docs, © 2026]**

**Consequence for us:** answering "No" while France remains an enabled territory is an internal
inconsistency that Apple's systems do not auto-reconcile. It is fine for a closed TestFlight beta, but
**before any App Store release, France must be removed under Pricing and Availability if we intend the
"No" to be true.** Otherwise we would be answering "not distributing in France" while shipping there.

**Other mechanics:** **[VERIFIED]**

- **It does not block the build.** What blocks is a required-but-missing declaration document. Answering
  "No" makes the France document not required, so the declaration completes. Declaration states are
  `CREATED`, `IN_REVIEW`, `APPROVED`, `REJECTED`, `INVALID`, `EXPIRED`.
- **France only.** No other EU country appears anywhere in the flow or API.
- **Changeable later without a rebuild.** There is no PATCH endpoint for declaration attributes; the
  documented path is *create a new declaration* and then *assign existing builds to it*. So reversing
  the France answer does **not** require a new binary.
- Per `EXPORT-COMPLIANCE.md` §3b, answering per build in the TestFlight UI is the working path for this
  app; the Info.plist route produced upload failures.

**[UNRESOLVED]**

- **TestFlight testers in France.** Export compliance applies to beta builds, and the France answer is
  part of the same app-level declaration. But no source — Apple or otherwise — indicates that answering
  "No" restricts *TestFlight tester* access in France. TestFlight is governed by invitations and public
  links rather than storefront territory, so I would expect no effect, but that is inference. Verify
  before relying on it if we recruit French testers.
- **French overseas territories.** An empirical probe of Apple's search API found only `FR` returns a
  storefront (NC, PF, RE, GP, MQ, GF, YT, WF, PM, BL, MF returned nothing), consistent with DOM-TOM
  being served by the France storefront. This is an API probe, **not** Apple's published territory list.

### 4.2 The real risk of "No"

**Low, and structurally sound rather than merely tolerated.** **[INFERRED, high confidence]**

The obligation in LCEN art. 30 III attaches to *la fourniture […] ou l'importation* — supplying or
importing **in France**. If the app is genuinely not available in France, we are not supplying there,
so the duty is not triggered. This is not evasion of an applicable rule; it is not meeting the rule's
trigger. The cost is commercial (no French users), not legal.

The load-bearing word is *genuinely*: this reasoning holds only if France is actually removed from
availability, which the Apple answer alone does not do (§4.1). "No" on the form plus a live French
listing is the one combination that gets the worst of both.

Two honest caveats:

1. **"Fourniture" may be broader than "the French storefront."** If French residents can obtain and use
   the app by other routes — a French-language website, direct APK distribution, a web client, or an
   Android build available in France while iOS is not — the "we don't supply in France" position gets
   weaker. **[INFERRED]** Note that Apple's question governs *Apple's* storefront only; **it does not
   answer for Google Play or for any direct distribution we do.** If Channel Messenger ships on Play in
   France while answering "No" to Apple, the legal position is inconsistent.
2. **Mere accessibility is not obviously "supply", but the line is untested here.** **[UNRESOLVED]**

### 4.3 The risk of distributing in France *without* declaring

This is the branch that actually carries teeth, and it is worse than the folklore suggests.

**Criminal penalties, LCEN art. 35 [VERIFIED verbatim]:**

- Failing to declare supply/transfer/import/export of a *moyen*: **1 year imprisonment and €15,000**.
- Export/EU transfer without required authorisation: **2 years and €30,000**.
- Supplying *prestations de cryptologie* for confidentiality without declaring (art. 31): **2 years and
  €30,000**.

**Administrative sanction, LCEN art. 34 [VERIFIED]:** the Prime Minister may prohibit circulation of the
means **throughout France**, and compel **withdrawal** from commercial distributors — expressly
applicable to a supplier acting **"même à titre gratuit"** (even free of charge). Free distribution is
no shield.

**And it has actually been charged.** The Tribunal de Paris press release of 28 August 2024 on Pavel
Durov's *mise en examen* lists, verbatim (I extracted this from the official PDF myself): **[VERIFIED]**

> - Fourniture de prestations de cryptologie visant à assurer des fonctions de confidentialité sans
>   déclaration conforme
> - Fourniture et importation d'un moyen de cryptologie n'assurant pas exclusivement des fonctions
>   d'authentification ou de contrôle d'intégrité sans déclaration préalable

Those are **both** of the obligations discussed in this document, charged criminally against the
operator of a mass-market encrypted messenger. It was not the only or the most serious charge, and
prosecutors plainly reached for everything available — but the "nobody enforces this" assumption died
in August 2024, and it should not be relied on.

### 4.4 The risk of "Yes" and filing

Low, and mostly cost-of-time. **[INFERRED]** The declaration is not an approval gate, there is no fee,
and the "grand public" classification we would likely receive is a benefit for export. The realistic
downsides are: preparing a French-language technical description; the standing obligation to hold
source code available for ANSSI; and — on the dated anecdotes — the possibility of a delay during which
Apple withholds French availability (Wire pulled its app while waiting).

**On balance:** filing is a form, not a legal battle. The reason to defer is that we are in beta and
not yet supplying anywhere publicly — not that filing is hard.

### 4.5 Does Apple want a *filed* declaration or an *approved* one? [UNRESOLVED]

This matters for scheduling a French launch, and Apple has never documented the change:

- **2013** — Apple's export compliance email said: "Apple will require you to upload a copy of your
  **approved** French declaration." **[VERIFIED, archived]**
- **2016** — Cryptomator likewise describes needing "approval from the ANSSI." **[SECONDARY]**
- **Today** — Apple's live reference page says only "Upload your **French encryption declaration**."
  The word "approved" is gone. **[VERIFIED]**
- **2024** — one developer's support thread suggests Apple accepts the filing and waits out ANSSI's
  one-month window. **[SECONDARY, single report]**

**Reading:** the trend favours "filed, plus the statutory month" rather than "approved", which is also
what the law implies — art. 30 III creates a *declaration*, and there is no approval to wait for. But
Apple has not said so, so budget for the possibility that a French launch slips by roughly a month
after filing. The declaration is **also not deprecated**: Apple's API still exposes
`AppEncryptionDeclarationDocument` and its upload endpoints, and `availableOnFrenchStore` is **not**
among the deprecated fields. Claims that "Apple removed the French requirement" are false — what
actually happened is that most developers now set `ITSAppUsesNonExemptEncryption = NO` and never see
the flow. We cannot: we ship our own crypto. **[VERIFIED]**

---

## 5. What comparable apps do

### 5.1 They all ship in France [VERIFIED]

Signal, WhatsApp, Threema, Wire, Telegram, Element, and Session are **all currently available on both
the French App Store and Google Play France**. None is geo-restricted out of France.

Apple's evidence is conclusive: `itunes.apple.com/lookup?country=fr` is a true per-storefront query and
all seven returned `resultCount=1` with French-localised names and pricing (Signal → "Signal -
Messagerie privée"; Threema → **7,99 €**). Google Play evidence is strong but one notch weaker: all
seven return HTTP 200 on FR-locale pages with no unavailability notice, though only Threema (**6,49 €**)
gives currency-level proof. **[VERIFIED]**

**Note the tension this creates with §4.** These apps are all shipping in France, and at least Wire,
ProtonMail, Cryptomator and Status are on record as having filed. Whichever of the seven did *not* file
is invisible to us — see §5.2.

### 5.2 There is no public record of what any of them filed [VERIFIED]

**ANSSI does not publish cryptology declarations.** This is confirmed about as strongly as it can be: a
French freedom-of-information request (Ma Dada, Aug–Oct 2024) asked ANSSI for exactly the *"Liste des
moyens de cryptologie déclarés auprès de l'ANSSI"* and met an **implicit refusal** — silence past the
statutory deadline. CADA was seized and had still issued no opinion as of September 2026.
<https://madada.fr/demande/liste_des_moyens_de_cryptologie>

The regime is structurally **bilateral**: ANSSI issues the *attestation de déclaration* to the
declarant, and it is the **supplier** who must make copies available to customs and exporters. Nothing
is published.

**Critical distinction — do not confuse these two things:**

| | Published? | Nature |
|---|---|---|
| **Certification** (CSPN, Common Criteria) | **Yes**, exhaustively — ANSSI publishes a monthly catalogue and per-product reports | Voluntary, evaluated, expensive |
| **Déclaration d'un moyen de cryptologie** | **No** — nothing published, FOIA refused | Mandatory, administrative, free |

So: seeing an app in ANSSI's published catalogue tells you it *paid for certification*, not that it
declared. And the absence of any public list means **you cannot verify whether Signal or WhatsApp
filed** — that is not publicly knowable. **[VERIFIED as unknowable]**

The one real public example is **Debian**, which self-published its own attestation because no registry
exists: dossier **no. 1101027**, 20 January 2011, issued to Yves-Alexis Perez for Debian 5.0 (Lenny),
classified **catégorie 3** (grand public). <https://www.debian.org/legal/anssi.fr.html> **[VERIFIED]**
It shows an individual maintainer of a free OS completing the process — evidence this is not a
corporate-only undertaking. It is also 15 years old.

### 5.3 Company statements [SECONDARY]

None of Signal, Threema, Wire, Element, or Session has publicly discussed an ANSSI filing — searches of
Signal's blog, GitHub org, and community forum returned zero hits for ANSSI; Threema's legal-compliance
FAQ never mentions France. The substantive accounts come from *adjacent* projects, mostly 2016–18, via
Next INpact's 2017 article *"Les outils de chiffrement face à la déclaration à l'ANSSI, une exception
française"*: Wire (removed from the French App Store while waiting), ProtonMail (filed at Apple's
request; called it intrusive government interference), Cryptomator, ChatSecure, Status, Dashlane.

Apple, Meta and Google all declined to comment in 2017, and ANSSI cancelled its own scheduled
interview. Two Apple Developer Forums threads on the French declaration have **no Apple staff reply at
all**. The information environment here is genuinely poor.

### 5.4 French context, briefly [SECONDARY unless noted]

- **Olvid**, a French E2EE messenger, is CSPN-certified and was **mandated for French government
  officials** by a November 2023 circular, displacing WhatsApp/Signal/Telegram on ministers' phones.
  Its visibility comes from *certification*, not declaration — reinforcing §5.2's distinction.
- **France has not banned or backdoored E2EE.** The *narcotrafic* bill's article 8 ter would have forced
  encrypted messengers to enable intelligence access; it was **rejected on the floor 119–24 on 20–21
  March 2025**, and the final [LOI n° 2025-532 du 13 juin 2025](https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000051734851)
  contains no such provision. Meredith Whittaker had threatened Signal's exit from France. Context only
  — unrelated to the declaration duty, but it is the reason France/E2EE searches are full of noise.

---

## 6. Where sources conflict or may be out of date

| Issue | Status |
|---|---|
| ANSSI's two summary tables disagree on whether supply/import in France requires a declaration | **Resolved** in favour of "declaration required" (§1.3), but be aware the first page reads otherwise |
| ANSSI's form links are swapped; the Annexe I form 404s; the "exception" link is dead | **Verified broken.** Email `controle@ssi.gouv.fr` for the current form |
| EU001 country count: 8 on one ANSSI page, 7 on another | **Unresolved**, minor; likely the UK |
| Annexe 1 exemption list read in summary only, not verbatim | **Open** — verify on Legifrance before relying on "no exemption applies" |
| Processing-time anecdotes are all 2016–2018 | **Stale.** Treat as weak evidence for 2026 |
| Apple's flow has changed repeatedly over the years | Current wording verified; historical behaviour varies. See `EXPORT-COMPLIANCE.md` §3b |
| TestFlight/DOM-TOM behaviour when answering "No" | **Unresolved** (§4.1) |
| Whether Apple needs a *filed* or *ANSSI-approved* declaration | **Unresolved** (§4.5); budget ~1 month either way |
| Cryptomator's "postal only" (2016) vs ANSSI's electronic filing | **Resolved** — electronic since end-2015; the blog is stale |
| Exact 2026 App Store Connect UI wording for the France question | Apple never publishes it. Two attested variants (2016, ~2024); the API field semantics match our recollection |
| Whether major messengers actually filed | **Not publicly knowable** (§5.2) |
| ANSSI may declare an app "out of scope" and issue no document | **Real, attested twice** (§3.6); Apple has no guidance for that case |

---

## 7. Lawyer, or form anyone can file?

**A form anyone can file:**
- The declaration of a *moyen de cryptologie* itself. Short form, no fee, no approval gate, foreign
  companies and individuals explicitly accommodated. Debian's maintainer did it. The hardest parts are
  writing the technical description in French and assembling a KBis equivalent.

**Where French counsel is genuinely worth it:**

1. **The `prestation de cryptologie` question (art. 31) — the real open issue.** Art. 29 defines a
   *prestation* as "toute opération visant à la mise en œuvre, **pour le compte d'autrui**, de moyens de
   cryptologie", and art. 31 requires its own declaration, carrying the **heavier** penalty (2 years,
   €30,000). In a true E2EE design, keys live on the client and the server relays ciphertext, so the
   natural reading is that we supply a *moyen* and do **not** provide a *prestation*. **But French
   prosecutors charged Telegram's founder with exactly that** (§4.3). Whether operating Channel
   Messenger's servers constitutes a *prestation* is a genuine legal question with a criminal penalty
   attached, and it is the one question I would not answer from a website. **[UNRESOLVED — get advice]**
2. Whether our overall distribution footprint (website, Play Store, any web client) amounts to
   *fourniture en France* even with the French App Store storefront switched off (§4.2).
3. Confirming no Annexe 1 exemption applies, from the verbatim current text.

**Not worth a lawyer:** deciding whether standard published algorithms exempt us. They do not — that
axis does not exist in French law (§3.5).

---

## 8. Sources

**Primary — statute and regulation**
- Loi n° 2004-575 du 21 juin 2004 (LCEN), arts. 29–36 — [Legifrance art. 30](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000006421577/); full text read via [mirror](https://www.marche-public.fr/Marches-publics/Textes/Lois/LCEN/loi-2004-575-LEN.htm)
- Décret n° 2007-663 du 2 mai 2007 — [Legifrance](https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000646995/); arts. 1–13 read verbatim from the [official juridoc PDF mirror](https://mobi-juridoc.gouv.nc/juridoc/jdtextes.nsf/85DAFE301032F06C4B257D6D00012364/$file/decret_2007-663_du_02-05-2007_CG.pdf)
- Annexe 1 (exemptions) — [Legifrance](https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006428332/) *(read in summary only)*
- Annexe 2 (incl. "grand public" conditions) — [Legifrance](https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000006428333/)
- Arrêté du 29 janvier 2015 (dossier form and content) — [Legifrance](https://www.legifrance.gouv.fr/loda/id/JORFTEXT000030255024/)
- Règlement (UE) 2021/821, Cat. 5 Part 2 — referenced by ANSSI's export page

**Primary — ANSSI**
- [Contrôle relatif à un moyen de cryptologie](https://cyber.gouv.fr/reglementation/reglementation-identite-confiance-numerique/controles-reglementaires-cryptographie/controle-moyen-de-cryptologie/)
- [Démarches à accomplir](https://cyber.gouv.fr/reglementation/reglementation-identite-confiance-numerique/controles-reglementaires-cryptographie/controle-moyen-de-cryptologie/controle-rglementaire-cryptographie-demarches/)
- [FAQ — demande d'autorisation](https://cyber.gouv.fr/faq-demande-dautorisation)
- [Contrôle export](https://cyber.gouv.fr/reglementation/reglementation-identite-confiance-numerique/controles-reglementaires-cryptographie/controle-export/)

**Primary — other official**
- Tribunal de Paris, communiqué de presse, 28 Aug 2024 (Durov *mise en examen*) — [PDF](https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-28%20-%20CP%20TELEGRAM%20mise%20en%20examen.pdf) *(text extracted and quoted verbatim)*
- [LOI n° 2025-532 du 13 juin 2025](https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000051734851) (narcotrafic; no E2EE provision)
- [Ma Dada FOIA request for the list of declared cryptology means](https://madada.fr/demande/liste_des_moyens_de_cryptologie) — refused

**Primary — Apple** *(all fetched live 2 Sep 2026, © 2026 Apple Inc.)*
- [Export compliance documentation for encryption](https://developer.apple.com/help/app-store-connect/reference/app-information/export-compliance-documentation-for-encryption/) — the "French encryption declaration" table
- [Overview of export compliance](https://developer.apple.com/help/app-store-connect/manage-app-information/overview-of-export-compliance/) — the "Secure Storage, Secure Communications" France paragraph
- [Provide export compliance information for beta builds](https://developer.apple.com/help/app-store-connect/test-a-beta-version/provide-export-compliance-information-for-beta-builds/)
- [Complying with Encryption Export Regulations](https://developer.apple.com/documentation/security/complying-with-encryption-export-regulations) — note: mentions France **zero** times, the likely source of the "Apple removed it" folklore
- [App Store Connect API — `AppEncryptionDeclaration.Attributes`](https://developer.apple.com/documentation/appstoreconnectapi/appencryptiondeclaration/attributes-data.dictionary) — the `availableOnFrenchStore` "intent" definition
- [App Store Connect API — App Encryption Declarations endpoints](https://developer.apple.com/documentation/appstoreconnectapi/app-encryption-declarations)
- [Apple Export Compliance email, 2013](https://gist.github.com/chrisballinger/7239932) — the older "**approved** French declaration" wording
- [Google Play — Export compliance](https://support.google.com/googleplay/android-developer/answer/113770) — mentions France zero times
- [Signicat iOS SDK — Apple export compliance requirements](https://developer.signicat.com/docs/mobile-identity/encap/sdk-ios/publish-your-app/apple-export-compliance-requirements/) — the "remove France from App Store Connect" instruction

**Secondary**
- [Debian — Attestation de déclaration d'un moyen de cryptologie](https://www.debian.org/legal/anssi.fr.html) (real 2011 attestation)
- Next INpact, *"Les outils de chiffrement face à la déclaration à l'ANSSI, une exception française"*, 13 Mar 2017 — <https://next.ink/10408/103575-les-outils-chiffrement-face-a-declaration-a-anssi-exception-francaise/>
- [Cryptomator, "In-Depth: Export Compliance for French iOS App Store"](https://cryptomator.org/blog/2016/06/16/indepth-french-app-store/) (2016)
- [Chris Ballinger gist, French encryption import compliance](https://gist.github.com/chrisballinger/7239932) (2013, comments through 2026)
- [status-im/status-legacy#4109](https://github.com/status-im/status-legacy/issues/4109) (2018 filing, tracked openly)
- Domanski Avocat, *Déclaration à l'ANSSI d'une application mobile intégrant un outil de chiffrement* (2022)

**Deliberately excluded:** a widely-circulated gist promoting a paid "declaration generation" service,
whose claim that HTTPS/APNs/Keychain use alone triggers the requirement is contested and which is
marketing, not community experience.
