Launched in Paris in January 2026, the Digital Resilience Index (IRN) does not ask whether your suppliers are European. It asks what happens the day one of them stops. What it measures, how it scores, what it leaves out, and a tool to run your own assessment.
On the night of 18 to 19 July 2024, CrowdStrike, a cybersecurity software vendor, pushed a faulty update to its customers that crashed Windows computers around the world. Microsoft tallied the damage the next day. Eight and a half million devices. Less than one percent of all Windows machines.
Yet the organisations that went down had chosen well. They had picked a reputable vendor, signed a contract and installed software designed to protect them, and that very software is what stopped them. A carefully chosen dependency fails just like any other.
Ten months later, in May 2025, the Associated Press reported, citing staff at the court, that Microsoft had cancelled the email address of Karim Khan, chief prosecutor of the International Criminal Court, who had been targeted by a US executive order of 6 February 2025. Brad Smith, Microsoft’s president, later denied that the company had stopped the account, insisting that its actions involved no cessation of services to the court.
Two versions, side by side.
So: a technical failure, then a political decision. Executives who followed both stories from their offices, whether they run a small business, an IT department or sit on a risk committee, ended up asking the same question.
And if a critical supplier stops tomorrow, how long can your organisation hold out?
Since early 2026, a French index has offered a shared way to answer it.
An index born of a public and private alliance
You can sum up its purpose in one sentence. The Digital Resilience Index (in French, Indice de résilience numérique, or IRN) maps an organisation’s digital dependencies, meaning everything it needs but does not control: a piece of software, a hosting provider, a data supplier, a scarce skill.
It then assesses the organisation’s digital resilience, which aDRI defines as the ability to keep operating, keep deciding and recover in the face of a cyberattack, an outage, a supplier failure or geopolitical tension. Cybersecurity covers only part of it.
aDRI announced the IRN on 4 July 2025 at the Rencontres économiques d’Aix-en-Provence, a yearly economics forum in the south of France, then launched it officially on 26 January 2026 at the French economy ministry in Bercy, with the backing of Anne Le Hénanff, the minister for digital affairs. In between, nine organisations, including the grid operator RTE, the national rail company SNCF, Orange, Groupe ADP and the insurer MAIF, volunteered to pilot it.
Behind the acronym stands a French non-profit association, A Digital Resilience Initiative, founded by David Djaïz, Yann Lechelle and Arno Pons. The Caisse des Dépôts, France’s public financial institution, backed it from the start, alongside RTE and Docaposte. No law forces a company to comply. aDRI itself presents the index as a strategic framework meant to inform executive decisions, not as a regulation.
Resilience is not sovereignty
For years, the French debate talked about digital sovereignty and looked first at the nationality of suppliers, as if a provider based in France were enough to shield a company from whatever might happen to it. aDRI presents the IRN as the operational answer to a goal that had remained mostly political.
David Djaïz, for his part, claims a model borrowed from finance. He says the founders drew their intellectual inspiration from the European DORA regulation. DORA, the EU Digital Operational Resilience Act, has applied since 17 January 2025 to most financial players, from asset managers to market infrastructures and investment firms.
So aDRI does not try to eliminate every dependency, a goal it considers rarely practical, and instead asks organisations to know each of their dependencies and to keep every one of them under control.
The consequence is surprising. Take a foreign supplier, bound by a contract with an exit clause and backed by a fallback your team tested last year, one Saturday morning, by deliberately cutting access for four hours. Compare it with a domestic supplier whose replacement nobody has ever planned. The first can make your system more resilient than the second, because you already know what you will do the morning it stops, who calls whom, and how many days the switch will take.
Geography still matters. The figures prevent anyone from waving it away. aDRI’s website cites an April 2025 study by Asterès for Cigref and Numeum, two French digital industry bodies: US players would capture 80% of European business spending on software and cloud services, the servers and software that companies rent online. When a single jurisdiction holds most of a market, your exit clauses rarely take you far, because the planned alternative often answers to the same laws as the supplier you want to leave.
Five layers, eight pillars
The IRN does not grade a company as a whole. It starts from its vital business functions, then from each critical system, the one without which activity stops: a software vendor’s invoicing, a retailer’s order taking, a factory’s production planning.
Then, for each critical system, the index works down five layers. Nothing is skipped. Applications carry the business, with its rules and automations, while data flows underneath, collected, cleaned and made available to analytics and artificial intelligence models. The platform is where things are built and deployed. Infrastructure supplies compute, storage and network. Human skills keep the whole thing running.
Take a small company’s invoicing. It runs on online software. Customer data sits with the vendor. The hosting provider was chosen by the vendor, not by the company. And only one employee knows how to export the invoices. Five layers, at least four dependencies.
Only one of them shows up on an invoice.

aDRI then questions each layer, from applications to skills, against eight pillars: strategic, economic and legal, data and artificial intelligence, operational, supply chain, technological, security, and environmental. Each criterion receives a binary verdict. R for resilient, NR for non-resilient.
The environmental pillar is surprising at first. It asks whether your critical infrastructure can withstand floods, heatwaves and power cuts, and whether you can secure the electricity your data centres need.
How many criteria in all? The trade press speaks of about twenty criteria and a maximum score of one hundred points. The consultancy Silexo notes that this figure circulates mostly in the media.
In the grid, the word no does not exist
To get a first idea without waiting for an audit, you can use the IRN Flash, an online questionnaire published by aDRI: sixteen questions, two per pillar, answered in three minutes. “Have you identified the digital suppliers that are genuinely critical to you?” sets the tone.
But the surprise lies in the answers.
There are only two. “Yes” and “Partially”. The word no appears nowhere. And the calculation treats “Partially” exactly like a no. A continuity plan that was written but never tested scores zero.
The choice makes sense. On the day of the crisis, a critical system holds or falls. A half-ready plan does not protect you halfway; it reassures the board, fills a line in the annual report, and hides the gap from you until the morning you need it.
Next, redo the arithmetic in your head. Each pillar is worth 0, 50 or 100 depending on the number of “Yes” answers. The overall score is the average of the eight pillars, so every “Yes” adds 6.25 points, wherever it falls. Above 70, aDRI rates the organisation resilient; between 40 and 70, to monitor; below, critical.
So you need twelve “Yes” answers out of sixteen to reach 75. Eleven give 68.75.
But the number hides what matters: twelve well-spread “Yes” answers and twelve that leave two pillars at zero produce the same 75, even though the second profile leaves two doors wide open.

Finally, answering “Yes” commits you. The consultancy Harington points out that the IRN relies on levels of evidence: a document, proof that the measure actually works, a tracked indicator. A disaster recovery plan, which describes how to restart after an incident, only counts if your team has already rehearsed it. Not on paper: for real.
What the index does not tell you
Self-assessment gives an indication, not an official score. aDRI keeps the full calculation, with its weightings and aggregation algorithm, to itself, and reserves for the firms it accredits the right to produce an IRN score and award a label.
It justifies this lock by comparability: without a common framework, each firm would produce its own number, and none would allow two organisations to be compared. According to aDRI, a first version of the framework was due in June 2026, and accreditation of assessors was to begin in July.
The scheme is only months old, and its licence raises another question. aDRI publishes its framework under Creative Commons CC BY-NC-ND, a licence that lets anyone read, copy and share it, but forbids anyone to modify it or use it commercially. The consultancy Yunova sees this as protecting the standard’s integrity, at the cost of making it harder to adopt. A standard described as open, with a closed calculation, asks you to trust the association.
However, the index assumes evidence that many organisations do not have to hand, and Silexo lists it: contracts, tested continuity plans, maps of systems, data location. A small company without a security officer will soon find that the first step is to dig through the filing cabinet and the inboxes for contracts nobody has reread since they were signed.
Finally, every self-assessment flatters whoever fills it in, especially the person who built the system. Have the board, IT and a business manager who uses the system every day answer separately: the gaps between them often say more than the grid.
One system, sixteen questions, one hour
So where do you start? Block out an hour, one morning. aDRI describes the process in this order: map the critical systems, analyse their dependencies, assess pillar by pillar, then build a roadmap.
- Choose a single critical system, the one whose outage costs the most in a day.
- Answer the sixteen questions for that system, ticking “Yes” only if you can show the evidence.
- Look at the pillars at zero before the overall score: they tell you where to start.
- Repeat with the next system.
The tool below reproduces the official IRN Flash grid without modification, applies exactly the same calculation, and turns each “Partially” into an action plan: one step this week, one project this quarter, the evidence that will let you answer “Yes”, and free public resources from ANSSI, the French cybersecurity agency, from the CNIL, the data protection authority, or from France Num. It does not produce an official score.
Going further
This quick diagnostic does not replace an assessment. aDRI is a non-profit association. For an assessment by an accredited assessor, write to it and choose the form topic « Entreprise souhaitant être auditée / labellisée » (company wishing to be audited or labelled).
- The official IRN Flash, aDRI
- Contact aDRI, aDRI
Official resources by pillar
Free public guides and services, checked on 1 October 2026. Most are in French.
RES-1 Strategic Resilience
- France Num (digital transition for small businesses, in French), DGE
- Maîtrise du risque numérique, l'atout confiance (Managing digital risk, in French), ANSSI and AMRAE
RES-2 Economic & Legal Resilience
- RGPD : par où commencer ? (GDPR: where to start, in French), CNIL
- NIS 2 test (MesServicesCyber, in French), ANSSI
RES-3 Data & AI Resilience
- Utiliser l'IA générative dans les TPE et PME (Generative AI in small businesses, in French), CNIL
- Guide de la sécurité des données personnelles (Personal data security guide, in French), CNIL
RES-4 Operational Resilience
- Crise cyber, les clés d'une gestion opérationnelle et stratégique (Cyber crisis management, in French), ANSSI and CDSE
- Organiser un exercice de gestion de crise cyber (Running a cyber crisis exercise, in French), ANSSI
RES-5 Supply-Chain Resilience
- Externalisation et sécurité des systèmes d'information (Outsourcing and IT security, 2010, model clauses, in French), ANSSI
- Good Practices for Supply Chain Cybersecurity, ENISA
RES-6 Technological Resilience
- Cloud and the SecNumCloud qualification (in French), ANSSI
- Catalogue of certified and qualified solutions (in French), ANSSI
- Interministerial free software list, SILL (in French), DINUM
RES-7 Security Resilience
- MonAideCyber: free 90-minute assessment by a volunteer (in French), ANSSI
- La cybersécurité pour les TPE/PME en treize questions (Cybersecurity for SMEs in 13 questions, in French), ANSSI
- Guide d'hygiène informatique (IT hygiene guide, in French), ANSSI
RES-8 Environmental Resilience
Answer for a single critical system. The calculation unfolds under your result.
Licence of the tool
The self-assessment tool reproduces without modification the IRN Flash grid © aDRI (A Digital Resilience Initiative), published under the CC BY-NC-ND 4.0 licence. To respect that licence, Impact Factories releases the whole tool, code and help texts included, under CC BY-NC-ND 4.0, and not under the CC BY-SA licence of the rest of this page: non-commercial use only, no derivatives. aDRI-IRN is a registered trademark of aDRI, which neither produced nor endorsed this tool. Original grid and official diagnostic: https://digitalresilienceinitiative.org/irn-flash. Licence text: https://creativecommons.org/licenses/by-nc-nd/4.0/
How long can you hold out?
On 19 July 2024, under one percent of Windows computers sufficed.
But the IRN will not answer that question for you. It makes you write the answer down, system by system, with evidence. The day the tap is turned off, that page will be worth more than a score.
Sources
- aDRI, « Foire aux questions », digitalresilienceinitiative.org, s.d. : https://digitalresilienceinitiative.org/faq (consulté le 2026-10-01)
- AMF, « The Regulation on Digital Operational Resilience in the Financial Sector (DORA) », amf-france.org, s.d. : https://www.amf-france.org/en/news-publications/depth/dora (consulté le 2026-10-01)
- Cabinet Silexo, « Indice de Résilience Numérique (IRN) : état des lieux, méthode, portée et implications », silexo.fr, s.d. : https://silexo.fr/article/198/indice-de-resilience-numerique-irn-etat-des-lieux-methode-portee-et-implications (consulté le 2026-10-01)
- Yunova Consulting, « Indice de résilience numérique (IRN) : l'outil lancé à Bercy pour piloter les dépendances cloud et IA », yunovaconsulting.com, 2026 : https://yunovaconsulting.com/indice-de-resilience-numerique-irn-loutil-lance-a-bercy-pour-piloter-les-dependances-cloud-et-ia/ (consulté le 2026-10-01)
- Harington, « Qu'est ce que l'Indice de résilience numérique (IRN) ? », harington.fr, 30 janvier 2026 : https://harington.fr/2026/01/30/indice-resilience-numerique-irn/ (consulté le 2026-10-01)
- Associated Press, « Trump's sanctions on ICC's chief prosecutor have halted tribunal's work, officials and lawyers say », PBS NewsHour, mai 2025 : https://www.pbs.org/newshour/world/trumps-sanctions-on-iccs-chief-prosecutor-have-halted-tribunals-work-officials-and-lawyers-say (consulté le 2026-10-01)
- aDRI, « Indice de Résilience Numérique », digitalresilienceinitiative.org, s.d. : https://digitalresilienceinitiative.org/ (consulté le 2026-10-01)
- aDRI, « IRN Flash, diagnostic de résilience numérique », digitalresilienceinitiative.org, s.d. : https://digitalresilienceinitiative.org/irn-flash (consulté le 2026-10-01)
- Caisse des Dépôts, « Souveraineté numérique : l'Indice de résilience numérique est lancé », caissedesdepots.fr, janvier 2026 : https://www.caissedesdepots.fr/eclairage/actualites/souverainete-numerique-lindice-de-resilience-numerique-est-lance (consulté le 2026-10-01)
- Caisse des Dépôts, « Lancement officiel de l'Indice de Résilience Numérique (IRN) », caissedesdepots.fr, 26 janvier 2026 : https://www.caissedesdepots.fr/presse/lancement-officiel-de-lindice-de-resilience-numerique-irn (consulté le 2026-10-01)
- RTE, « Lancement d'une initiative européenne inédite : une alliance d'acteurs publics et privés crée l'Indice de Résilience Numérique (IRN) », rte-france.com, 4 juillet 2025 : https://www.rte-france.com/actualites/lancement-initiative-europeenne-inedite-alliance-acteurs-publics-prives-cree-indice (consulté le 2026-10-01)
- INCYBER NEWS, « L'indice de résilience numérique, un thermomètre des dépendances critiques », incyber.org, 2026 : https://incyber.org/article/lindice-de-resilience-numerique-un-thermometre-des-dependances-critiques/ (consulté le 2026-10-01)
- Microsoft, « Helping our customers through the CrowdStrike outage », Official Microsoft Blog, 20 juillet 2024 : https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/ (consulté le 2026-10-01)
- Tjitske Lingsma, « How sanctions can weaponize US tech against the ICC », JusticeInfo.net, 19 mars 2026 : https://www.justiceinfo.net/en/156691-how-sanctions-can-weaponize-us-tech-against-the-icc.html (consulté le 2026-10-01)



