Skip to main content
MAG&Cie
Cybersecurity Audit Offer

Assess your cybersecurity posture

An independent and pragmatic audit, tailored for SMBs. Structured report, maturity scoring and prioritized action plan.

TL;DR
  • What it is

    Independent cybersecurity posture audit: mapping, maturity scoring, 12-month prioritised action plan. ANSSI, CIS, NIS2, GDPR, ISO 27001 frameworks.

  • For whom

    Small businesses, SMEs, local authorities and non-profits under exposure (NIS2, tenders, enterprise clients) that must show a credible posture.

  • Indicative price

    EUR 3,500 to 4,500 excl. VAT (EUR 4,200 to 5,400 incl. VAT) depending on scope. Quote before start.

5/5 · 2 reviews

10+ years CTO / CPO expertise

  • EU hosting
  • GDPR & ANSSI
  • Strict independence

Mission process

Phase 1

Scoping & collection

Free — no commitment

  • Initial call (30-45 min video)
  • Preliminary questionnaire
  • Scope identification
  • Report plan validation
Phase 2

Audit & analysis

Included in the mission

  • Interviews with internal stakeholders
  • Document review
  • Organizational and technical analysis
  • Domain maturity scoring (1→4)
Phase 3

Report & presentation

€3,500 – €4,500 excl. VAT (€4,200 – €5,400 incl. VAT)

  • Full structured report (Word/PDF)
  • Non-technical executive summary (1 page)
  • Prioritized short/medium-term action plan
  • Results presentation session (1h video call)

8 domains covered

Organizational

  • Governance & policy
  • Access & identity management
  • Awareness & training
  • Third-party management

Technical

  • Infrastructure & network
  • Workstations & endpoints
  • Backup & continuity
  • Monitoring & detection

Frameworks used and addressed

ANSSI — IT Hygiene Guide
CIS Controls v8 (IG1 = SMBs)
ISO/IEC 27001:2022
NIST Cybersecurity Framework
NIS2 Directive (EU 2022/2555)
GDPR — article 32
DORA Regulation (finance)
HDS — French Health Data Hosting
OWASP Top 10 (application)
PCI DSS (card payments)
SecNumCloud v3.2 (ANSSI — descriptive)

Each framework: who it applies to, what it requires, when to consider it

Every framework has a scope and a timing. We cross-reference them to avoid missing the point and target what actually protects your organization.

NIS2 Directive (EU 2022/2555)

À qui
Essential and important entities across 18 sectors (energy, health, transport, digital, food, waste, postal services, public administration, etc.). French transposition ongoing.
Exige
Risk analysis, technical and organizational measures, incident handling, business continuity, supply-chain security, notification of significant incidents within 24 h then 72 h.
Quand y penser
If a large buyer requires it in a tender, if your sector is directly concerned, or ahead of ANSSI notifying your status.

ISO/IEC 27001:2022

À qui
Any organization that wants to structure and certify its Information Security Management System (ISMS).
Exige
Context, leadership, planning, resources, risk analysis, risk treatment, monitoring, management review, continual improvement — plus the 93 Annex A controls.
Quand y penser
Before certification, before a tender requiring it, or to structure security governance sustainably.

ANSSI — IT Hygiene Guide

À qui
Any organization, at an effort level accessible to SMBs. French reference for security baseline.
Exige
42 measures across 12 domains: identify, raise awareness, authenticate, secure workstations and servers, network, administration, segmentation, mobility, updates, monitoring, backups, incidents.
Quand y penser
As a starting baseline, before any heavier framework. Systematically addressed in our audits.

SecNumCloud v3.2 (ANSSI)

À qui
Cloud providers wanting to demonstrate a very high security level and immunity to extraterritorial laws. Not mandatory by default.
Exige
Technical, contractual, governance, hosting and staff requirements within the European Union. Qualification audit by an approved third party.
Quand y penser
If a public or regulated buyer demands it, or if you seek sovereign hosting with strong guarantees. Mentioned in passing, not systematically relevant.

GDPR — article 32

À qui
Any organization processing personal data of EU individuals — nearly everyone.
Exige
Technical and organizational measures appropriate to the risk: encryption, resilience, backup, regular testing of effectiveness, incident procedure. Authority notification within 72 h of a breach.
Quand y penser
Systematically. Cross-referenced with the audit to map your processing and assess article 32 compliance.

DORA Regulation (EU 2022/2554)

À qui
Financial entities (banks, insurers, asset managers, crypto platforms) and their critical IT vendors. Applicable since January 2025.
Exige
IT risk management framework, incident handling, operational resilience testing, third-party risk management, threat information sharing.
Quand y penser
If you are a regulated financial actor, or a critical vendor to one.

HDS — French Health Data Hosting

À qui
Any entity hosting personal health data on behalf of a third party under the French Public Health Code.
Exige
Certification by an accredited body. ISO 27001, ISO 20000-1, ISO 27018 requirements + health-specific requirements. Two levels: infrastructure and managed services.
Quand y penser
Mandatory to host health data for a third party. We systematically verify HDS accreditation of your hosts if you are in scope.

OWASP Top 10

À qui
Any web application or API accessible from a network, whatever the organization size. De facto standard in application security.
Exige
Mastery of the 10 most critical vulnerability categories: broken access control, misconfiguration, injection, authentication, vulnerable components, insufficient logging, etc.
Quand y penser
Systematically in an application audit. Basis of security code review and application penetration testing.

PCI DSS

À qui
Any organization storing, processing or transmitting card payment data (number, security code, authentication data).
Exige
12 requirements across 6 objectives: secure network, cardholder data protection, vulnerability management, access control, monitoring, information security policy.
Quand y penser
If you handle cleartext card numbers — avoid where possible by delegating to a PCI DSS-certified payment provider, dramatically reducing your scope.

Typical cyber audit use cases

  • NIS2 compliance forced by a large buyer — you must demonstrate a posture before the next contractual review.
  • Audit before a fundraise — an investor wants to assess cyber maturity before the formal due diligence.
  • Audit after an incident — after a leak, an intrusion or ransomware, measure residual exposure and prove remediation.
  • Yearly renewal audit — maintain a proven posture over time, feed the management review and the cyber insurance policy.

Why MAG&Cie?

10 years of CTO/CPO experience in SMBs/mid-market companies
Cybersecurity audits conducted and experienced in real contexts
Deliverables directly presentable to non-technical decision-makers
Pragmatic approach adapted to SMB resources
Reusable report, no confidential client data
Fully remote — available within 2 to 4 weeks

Frequently asked questions

How much does a MAG&Cie cybersecurity posture audit cost?

Three modular phases: Phase 1 (scoping) free with no commitment, Phase 2 (data collection + interviews) from €990 excl. VAT, Phase 3 (report, scoring and action plan) from €1,490 excl. VAT. Final quote depends on scope (number of entities, systems covered, target frameworks). All prices excl. VAT — French VAT 20% applies.

Which frameworks are used for the audit?

We systematically cross four frameworks: French ANSSI hygiene guide (42 measures), CIS Controls v8 (18 domains), ISO/IEC 27001:2022 (annex A) and NIST Cybersecurity Framework. The primary framework is chosen during scoping based on your industry, your clients and your objectives (cyber insurance, certification, RFPs, NIS2 compliance).

What does the final report contain?

A structured report directly shareable with your clients and partners: executive summary (1 page), domain-by-domain maturity scoring on a 1→4 grid, risk mapping, prioritized action plan (quick wins 0–3 months then structuring initiatives 3–12 months) with budget ballparks and effort estimates. A 1h video debrief is included.

Is the audit compatible with ISO 27001 or NIS2?

Yes. The audit identifies gaps against ISO/IEC 27001:2022 (annex A) or the NIS2 directive requirements (article 21 of EU directive 2022/2555). It is not a certification audit, but a gap analysis pre-audit: you know exactly where you stand before engaging in formal certification or compliance.

How long does a full audit take?

5 to 7 business days between the end of data collection and report delivery. Full calendar depends on your availability for interviews (typically 3 to 5 one-hour interviews with management, IT, business owners). We adapt to small business and SME constraints.

Is my confidential data protected during the audit?

Yes. A non-disclosure agreement (NDA) is signed before any information sharing. Exchanges go through an encrypted channel (encrypted email or a sovereign shared workspace on request). All collected data is hosted in the European Union and deleted 12 months after mission end. No client data is used for other missions or shared with third parties.

Who performs the audit at MAG&Cie?

The audit is performed by Antoine Guittet, freelance CTO/CPO/CISO with 10+ years of experience in technical leadership and information security, principal of MAG&Cie. The perspective is dual: operational (what actually works in SMEs, not out-of-touch theoretical recommendations) and strategic (what reassures your clients, investors and insurers).

Not ready for a full audit?

Start with the free self-assessment

A ~20-minute online questionnaire covering the 8 audit domains: governance, access, awareness, third parties, network, endpoints, backups, monitoring. You receive your maturity report by email within 48 hours.

Free self-assessment (20 min, in French)

Free, no commitment, confidential answers. Questionnaire available in French.

Request your free scoping call

First call with no commitment to define the scope and provide a precise budget.

This form is for general questions. For a scoped quote with budget and timeline: use the detailed quote form

Delivery: 5 to 7 business days after information collection. Prices excl. VAT and incl. VAT (French VAT 20 %) — EU VAT number: FR47519015713.