CNAPS Inspections and Sanctions: What a Training Provider Risks
Obtaining the CNAPS operating authorisation is only half the journey: keeping it is the other half. The Conseil national des activités privées de sécurité (the French national council for private-security activities) is not a registration desk but a regulator with real administrative-police and disciplinary powers — on-site inspections, six-figure financial penalties, operating bans. Here is what a private-security training provider concretely risks, and how to protect yourself.
Who inspects you, and on what?
Since the reform in force since 1 March 2025 (ordinance no. 2023-374 of 16 May 2023, decree no. 2024-311 of 4 April 2024), oversight of training providers is shared:
- The CNAPS checks compliance with the internal-security code: validity of the operating authorisation, director approval (agrément), trainers’ professional cards, session declarations (at least 15 days before opening), trainees’ prior authorisations. Session declarations are precisely what lets it target inspections, including unannounced ones.
- Professional branches and certification bodies behind the CQPs (branch certificates) and titles being prepared check the material and pedagogical conditions of courses and examination arrangements, through periodic audits; they can refer breaches to the CNAPS.
- Ordinary oversight continues in parallel: the DREETS on training-provider obligations (see our article on DREETS inspections), and your Qualiopi certifier on the national quality framework.
This architecture of regulation through a dedicated public body is a well-documented French specificity: Cédric Paulin’s doctoral thesis (Université Paris-Saclay, 2017), “Vers une politique publique de la sécurité privée ? Réguler la sécurité privée (1983-2014)”, analyses the rise of the CNAPS and its disciplinary apparatus as the shift from a self-regulated market to a sector under access control. Frédéric Ocqueteau documented this regulator’s genesis as early as 2013 (“Genèse et premiers pas du Conseil national des activités privées de sécurité (CNAPS)”).
The scale of sanctions
Disciplinary sanctions
The internal-security code (articles L. 634-7 et seq.) gives the CNAPS a graduated range:
| Sanction | Scope |
|---|---|
| Warning | Formal notice, kept on file |
| Reprimand | A heavier formal censure |
| Temporary operating ban | Up to 7 years |
| Financial penalties | Up to €150,000 (legal entity or sole trader), €7,500 (employee) |
Penalty amounts are set according to the seriousness of the breaches and, where relevant, the advantages drawn from them — a provider that cashed in irregular sessions can therefore see the penalty calibrated on that revenue.
Measures against the authorisation itself
Independently of disciplinary sanctions, the operating authorisation can be suspended or withdrawn when the conditions of its issuance are no longer met: Qualiopi certification lost, director approval expired or revoked, serious breaches established. Economically it is the heaviest sanction: without the authorisation, no session may open, and the training portfolio shuts down immediately.
Criminal penalties
The criminal layer completes the arsenal: running a private-security training organisation without the required approval exposes the person to up to three years’ imprisonment and a €45,000 fine. Operating without authorisation therefore stacks administrative, disciplinary and criminal risk.
The most exposed breaches
Crossing the current regime’s obligations, the typical weak points of a training provider in this sector are:
- The undeclared session, or one declared less than 15 days before opening — the easiest breach for the CNAPS to establish.
- The trainer without a professional card: since 1 March 2025, every instructor must hold their CNAPS trainer card, teaching directors included.
- The trainee without prior authorisation: the individual authorisation (valid six months) must be checked before entry into training, not regularised afterwards.
- Expired titles: director approval (5 years, renewal to be requested 3 months before expiry), trainer cards (5 years), Qualiopi certification (3-year cycle with a surveillance audit).
- Non-compliant subcontracting: entrusting a course to a third party without the required prior agreement or without checking its authorisation.
- A misleading name: an organisation name that suggests a public service breaches article L. 625-3 of the internal-security code.
Protecting yourself: compliance as a routine
The best defence is an evidence system kept current continuously, not reconstructed the night before an inspection:
- a title schedule (authorisation, approval, cards, certification) with alerts at 6 and 3 months;
- a register of declared sessions with CNAPS declaration receipts;
- a systematic enrolment check of trainees’ prior authorisations;
- a file per trainer (card, aptitude, attendance sheets) aligned with the national quality framework’s expectations.
This work pays twice: the same evidence feeds your Qualiopi audits and the sector inspections. Our guide to the CNAPS authorisation covers the scheme from the obtaining side.
Take action
Map your risks now: titles, sessions, trainers, trainees, subcontracting. Our page CNAPS authorisation for private-security training providers gathers the conditions, procedures and deadlines to track — with a free ebook including the list of costly mistakes.
Frequently asked questions
+What is the maximum financial penalty the CNAPS can impose?
Financial penalties imposed by the CNAPS can reach €150,000 for legal entities and non-salaried individuals, and €7,500 for salaried individuals. The amount is set according to the seriousness of the breaches and, where relevant, the advantages drawn from them.
+Can the CNAPS ban a training provider from operating?
Yes. Disciplinary sanctions include the warning, the reprimand and a temporary operating ban of up to seven years. The CNAPS can also suspend or withdraw the operating authorisation when the conditions of its issuance are no longer met.
+Is training private-security agents without authorisation a criminal offence?
Yes. Beyond administrative and disciplinary sanctions, the internal-security code provides criminal penalties: running a private-security training organisation without the required approval exposes the person to up to three years' imprisonment and a €45,000 fine.