What it is
Independent cybersecurity posture audit: mapping, maturity scoring, 12-month prioritised action plan. ANSSI, CIS, NIS2, GDPR, ISO 27001 frameworks.
For whom
Small businesses, SMEs, local authorities and non-profits under exposure (NIS2, tenders, enterprise clients) that must show a credible posture.
Indicative price
EUR 3,500 to 4,500 excl. VAT (EUR 4,200 to 5,400 incl. VAT) depending on scope. Quote before start.
Mission process
Scoping & collection
Free — no commitment
- Initial call (30-45 min video)
- Preliminary questionnaire
- Scope identification
- Report plan validation
Audit & analysis
Included in the mission
- Interviews with internal stakeholders
- Document review
- Organizational and technical analysis
- Domain maturity scoring (1→4)
Report & presentation
€3,500 – €4,500 excl. VAT (€4,200 – €5,400 incl. VAT)
- Full structured report (Word/PDF)
- Non-technical executive summary (1 page)
- Prioritized short/medium-term action plan
- Results presentation session (1h video call)
8 domains covered
Organizational
- Governance & policy
- Access & identity management
- Awareness & training
- Third-party management
Technical
- Infrastructure & network
- Workstations & endpoints
- Backup & continuity
- Monitoring & detection
Frameworks used and addressed
Each framework: who it applies to, what it requires, when to consider it
Every framework has a scope and a timing. We cross-reference them to avoid missing the point and target what actually protects your organization.
NIS2 Directive (EU 2022/2555)
- À qui
- Essential and important entities across 18 sectors (energy, health, transport, digital, food, waste, postal services, public administration, etc.). French transposition ongoing.
- Exige
- Risk analysis, technical and organizational measures, incident handling, business continuity, supply-chain security, notification of significant incidents within 24 h then 72 h.
- Quand y penser
- If a large buyer requires it in a tender, if your sector is directly concerned, or ahead of ANSSI notifying your status.
ISO/IEC 27001:2022
- À qui
- Any organization that wants to structure and certify its Information Security Management System (ISMS).
- Exige
- Context, leadership, planning, resources, risk analysis, risk treatment, monitoring, management review, continual improvement — plus the 93 Annex A controls.
- Quand y penser
- Before certification, before a tender requiring it, or to structure security governance sustainably.
ANSSI — IT Hygiene Guide
- À qui
- Any organization, at an effort level accessible to SMBs. French reference for security baseline.
- Exige
- 42 measures across 12 domains: identify, raise awareness, authenticate, secure workstations and servers, network, administration, segmentation, mobility, updates, monitoring, backups, incidents.
- Quand y penser
- As a starting baseline, before any heavier framework. Systematically addressed in our audits.
SecNumCloud v3.2 (ANSSI)
- À qui
- Cloud providers wanting to demonstrate a very high security level and immunity to extraterritorial laws. Not mandatory by default.
- Exige
- Technical, contractual, governance, hosting and staff requirements within the European Union. Qualification audit by an approved third party.
- Quand y penser
- If a public or regulated buyer demands it, or if you seek sovereign hosting with strong guarantees. Mentioned in passing, not systematically relevant.
GDPR — article 32
- À qui
- Any organization processing personal data of EU individuals — nearly everyone.
- Exige
- Technical and organizational measures appropriate to the risk: encryption, resilience, backup, regular testing of effectiveness, incident procedure. Authority notification within 72 h of a breach.
- Quand y penser
- Systematically. Cross-referenced with the audit to map your processing and assess article 32 compliance.
DORA Regulation (EU 2022/2554)
- À qui
- Financial entities (banks, insurers, asset managers, crypto platforms) and their critical IT vendors. Applicable since January 2025.
- Exige
- IT risk management framework, incident handling, operational resilience testing, third-party risk management, threat information sharing.
- Quand y penser
- If you are a regulated financial actor, or a critical vendor to one.
HDS — French Health Data Hosting
- À qui
- Any entity hosting personal health data on behalf of a third party under the French Public Health Code.
- Exige
- Certification by an accredited body. ISO 27001, ISO 20000-1, ISO 27018 requirements + health-specific requirements. Two levels: infrastructure and managed services.
- Quand y penser
- Mandatory to host health data for a third party. We systematically verify HDS accreditation of your hosts if you are in scope.
OWASP Top 10
- À qui
- Any web application or API accessible from a network, whatever the organization size. De facto standard in application security.
- Exige
- Mastery of the 10 most critical vulnerability categories: broken access control, misconfiguration, injection, authentication, vulnerable components, insufficient logging, etc.
- Quand y penser
- Systematically in an application audit. Basis of security code review and application penetration testing.
PCI DSS
- À qui
- Any organization storing, processing or transmitting card payment data (number, security code, authentication data).
- Exige
- 12 requirements across 6 objectives: secure network, cardholder data protection, vulnerability management, access control, monitoring, information security policy.
- Quand y penser
- If you handle cleartext card numbers — avoid where possible by delegating to a PCI DSS-certified payment provider, dramatically reducing your scope.
Typical cyber audit use cases
- NIS2 compliance forced by a large buyer — you must demonstrate a posture before the next contractual review.
- Audit before a fundraise — an investor wants to assess cyber maturity before the formal due diligence.
- Audit after an incident — after a leak, an intrusion or ransomware, measure residual exposure and prove remediation.
- Yearly renewal audit — maintain a proven posture over time, feed the management review and the cyber insurance policy.
Why MAG&Cie?
Frequently asked questions
How much does a MAG&Cie cybersecurity posture audit cost?
Three modular phases: Phase 1 (scoping) free with no commitment, Phase 2 (data collection + interviews) from €990 excl. VAT, Phase 3 (report, scoring and action plan) from €1,490 excl. VAT. Final quote depends on scope (number of entities, systems covered, target frameworks). All prices excl. VAT — French VAT 20% applies.
Which frameworks are used for the audit?
We systematically cross four frameworks: French ANSSI hygiene guide (42 measures), CIS Controls v8 (18 domains), ISO/IEC 27001:2022 (annex A) and NIST Cybersecurity Framework. The primary framework is chosen during scoping based on your industry, your clients and your objectives (cyber insurance, certification, RFPs, NIS2 compliance).
What does the final report contain?
A structured report directly shareable with your clients and partners: executive summary (1 page), domain-by-domain maturity scoring on a 1→4 grid, risk mapping, prioritized action plan (quick wins 0–3 months then structuring initiatives 3–12 months) with budget ballparks and effort estimates. A 1h video debrief is included.
Is the audit compatible with ISO 27001 or NIS2?
Yes. The audit identifies gaps against ISO/IEC 27001:2022 (annex A) or the NIS2 directive requirements (article 21 of EU directive 2022/2555). It is not a certification audit, but a gap analysis pre-audit: you know exactly where you stand before engaging in formal certification or compliance.
How long does a full audit take?
5 to 7 business days between the end of data collection and report delivery. Full calendar depends on your availability for interviews (typically 3 to 5 one-hour interviews with management, IT, business owners). We adapt to small business and SME constraints.
Is my confidential data protected during the audit?
Yes. A non-disclosure agreement (NDA) is signed before any information sharing. Exchanges go through an encrypted channel (encrypted email or a sovereign shared workspace on request). All collected data is hosted in the European Union and deleted 12 months after mission end. No client data is used for other missions or shared with third parties.
Who performs the audit at MAG&Cie?
The audit is performed by Antoine Guittet, freelance CTO/CPO/CISO with 10+ years of experience in technical leadership and information security, principal of MAG&Cie. The perspective is dual: operational (what actually works in SMEs, not out-of-touch theoretical recommendations) and strategic (what reassures your clients, investors and insurers).
Not ready for a full audit?
Start with the free self-assessment
A ~20-minute online questionnaire covering the 8 audit domains: governance, access, awareness, third parties, network, endpoints, backups, monitoring. You receive your maturity report by email within 48 hours.
Free self-assessment (20 min, in French)Free, no commitment, confidential answers. Questionnaire available in French.
Request your free scoping call
First call with no commitment to define the scope and provide a precise budget.
Delivery: 5 to 7 business days after information collection. Prices excl. VAT and incl. VAT (French VAT 20 %) — EU VAT number: FR47519015713.
Continue with
Pages that pair well with this one
Adjacent topics covered by MAG&Cie, hand-curated to stay on your problem.