Cybersecurity audit: process, types, cost and deliverables
The different types of audit, the role of PASSI providers, the seven steps of an engagement, the report and what drives the cost.
· 11 min read
Audit report
CriticalAdmin account without MFA
HighUnpatched exposed server
MediumLogs kept for 7 days
A cybersecurity audit independently assesses the security level of an information system or its compliance with a framework. It can cover the organisation, the architecture, device configuration or an application's code, or take the form of a penetration test. In France, ANSSI, the national cybersecurity agency, qualifies audit providers against a public framework known as PASSI, which also describes the standard seven-step course of an engagement. Here is how to choose the right audit, what you should receive at the end, and what is actually known about its cost.
01
What is a cybersecurity audit?
A security audit compares an actual situation with a reference: a requirements framework, a security policy, good practice, or the behaviour expected of a system facing an attacker. Three features set it apart from a simple internal review:
the independence of the auditors from the scope being audited;
a written framework: objectives, scope, method and rules of engagement set before starting;
evidence-backed findings, ranked by severity and with recommendations.
It should not be confused with an ISO 27001 certification audit, carried out by an accredited body to decide whether your ISMS can be certified, nor with a regulatory inspection that an authority may trigger at a regulated operator. Both rely on audits but serve a different purpose. Nor does an audit replace risk analysis: it checks measures, whereas risk analysis decides which ones are needed.
02
Types of cybersecurity audit
ANSSI's PASSI framework distinguishes five audit activities, each matching a layer of the information system. Compliance audits against a framework and maturity assessments are commonly added; they fall outside PASSI qualification. Pick a question to see which audit answers it and which layer it examines.
Which audit answers which question?Your question
OutsideGovernance and complianceOrganisation and physical securityNetwork architectureDevice configurationApplication code
PASSI activity
Organisational and physical audit
Are our rules applied in practice?
What is examined
Security policy, procedures, access management, awareness, physical security of premises, through interviews, document review and site visits.
What you get
The gaps between what is written and what is done, ranked by severity.
PASSI activity
Architecture audit
Is our network well designed and segmented?
What is examined
Diagrams, flows, trust zones, segmentation, administration access and dependencies between systems.
What you get
Design weaknesses and segmentation recommendations.
PASSI activity
Configuration audit
Are our servers and devices hardened?
What is examined
The settings actually applied on a sample of servers, workstations, network devices or online services, compared with good practice.
What you get
The list of settings to fix, device by device.
PASSI activity
Source code audit
Does our application contain flaws?
What is examined
The application code: authentication, access rights, input handling, cryptography, logging.
What you get
Vulnerabilities located in the code, with their fix.
PASSI activity
Penetration test
Could an attacker get in, and how far?
What is examined
The scope is attacked within an authorised framework, from the internet or inside, to find and exploit real attack paths.
What you get
Demonstrated attack paths, with evidence and remediation priorities.
Outside PASSI qualification
Compliance audit
Do we meet ISO 27001 or NIS 2?
What is examined
The gap between your measures and the requirements of a framework. For ISO 27001 certification, the final audit is carried out by an accredited certification body.
What you get
A compliance rate per requirement and an action plan.
Outside PASSI qualification
Maturity assessment
Where do we stand, where to start?
What is examined
A quick overview of the organisation, the information system and practices, often for a small business.
What you get
A maturity level and a list of priority actions.
These audits work best together. A penetration test on its own shows that a door is open, without always explaining why; a configuration or architecture audit explains the cause and avoids treating only the symptom. Conversely, a purely document-based audit may declare compliant a system that an attacker would compromise in a day. For an internet-facing system, combining a configuration audit with a penetration test is a good starting point; ransomware entering through edge devices shows why.
Black, grey or white box
For a penetration test, you specify what the auditors know at the outset: nothing (black box, like an external attacker), a user account (grey box) or full documentation (white box). The PASSI framework requires the test mode and the attacker profiles simulated to be set out in the scoping note.
03
ANSSI's PASSI-qualified providers
PASSI stands for information systems security audit provider. It is a qualification granted by ANSSI, after an evaluation, to providers that meet a public requirements framework covering the provider, its auditors and the conduct of audits. The current version is 2.2, dated 1 August 2024 and announced by ANSSI on 29 November 2024.
It introduced two qualification levels, aligned with the EU Cybersecurity Act:
substantial, recommended where the threats considered are systemic, hacktivist or isolated;
high, recommended where risks are significant or the threat is strategic. It adds, among other things, daily check-ins during the audit and written material on critical vulnerabilities as soon as the work ends.
A provider is qualified for certain activities and a certain level, not for everything: check its scope in ANSSI's catalogue of qualified providers.
When do you need a PASSI provider?
Operators of vital importance: security inspections of their vital information systems can be carried out by ANSSI, another State service or a qualified audit provider, according to ANSSI's page on the SAIV scheme. See our article on the LPM, OIV and OSE.
Operators of essential services: inspections under France's NIS 1 transposition are carried out by ANSSI or by qualified providers.
Outside these settings, nothing requires a company to choose a qualified provider. Qualification remains a useful benchmark: it guarantees verified competence, confidentiality rules and a controlled process.
04
The seven steps of a cybersecurity audit
Chapter VI of the PASSI framework describes a standard engagement. Even if your provider is not qualified, it is a good checklist to make sure nothing is missed. Each step adds a document to the audit file.
Audit process according to ANSSI's PASSI framework
Given the objectives and scope, the provider checks whether it can carry out the whole audit. It only accepts the engagement if it can.
A service agreement sets the approach, scope, milestones, deliverables, responsibilities and confidentiality rules. It is signed by authorised representatives of both parties.
The lead auditor drafts a scoping note with the client, then an audit plan. For a penetration test, an authorisation form is drawn up. An opening meeting is recommended.
Interviews, document reviews, configuration or code analysis, penetration tests, depending on the activities planned. Any action that could cause downtime requires the client's written approval.
As soon as the work ends, without waiting for the report, the team presents its findings and first conclusions to the client.
The report sets out the audit framework, gives a summary management can read, then each finding with its severity and the recommended measures.
A closing meeting is recommended. The provider returns, erases or destroys any information it is not authorised to keep.
Step 1
Check capability
Given the objectives and scope, the provider checks whether it can carry out the whole audit. It only accepts the engagement if it can.
Audit file
Capability decision
Service agreement
Scoping note and audit plan
Findings and evidence
Findings debrief
Audit report
Data returned or destroyed
Based on ANSSI's PASSI requirements framework, version 2.2 (August 2024), chapter VI. Some requirements apply only at the “high” qualification level.
Clients often neglect two steps. First the scoping note: it sets what will be tested, with which access, at what times and with which precautions. A penetration test in production without a recent backup or stop procedure is a risk in itself. Then the closing step: the provider has handled sensitive information about your weaknesses, and you need to know what it keeps.
05
Deliverables: what an audit report should contain
PASSI version 2.2 details the expected content of the report. Ask at least for:
the framework: objectives, criteria, scope, dates, locations and reference documents;
a management summary that executives can read: overall assessment, critical risks, audit limitations and a recommendation for a follow-up audit;
detailed results: each finding uniquely identified, with evidence, severity on an explicit scale and recommended measures with their priority;
annexes: audit plan and scoping note.
Before the report, you should have received a debrief of the findings as soon as the work ended. A good report is read at two levels: the summary for management and the CISO, the finding sheets for technical teams. Severity ratings are worth more when they use the same scale as your risk matrix.
06
The cost of a cybersecurity audit
There is no public price list for PASSI audits, and the ranges found online are rarely sourced. The price is built from the number of auditor days, which depends on a few factors:
scope: number of sites, applications, exposed addresses, servers in the sample;
activities combined: an organisational audit and a penetration test call on different profiles;
level of assurance: substantial or high qualification, depth of testing, black or white box;
constraints: testing outside working hours, industrial environments, on-site work.
Two published reference points for French SMEs
Bpifrance's Diag Cybersécurité costs €8,800 excluding VAT, 50% of which is covered by Bpifrance. It is aimed at independent SMEs and runs over 8 days in 4 stages: scoping, organisational assessment, technical assessment with tests, then a debrief with a prioritised action plan.
MonAideCyber, run by ANSSI, offers a free assessment by a volunteer from its community, for organisations that do not know where to start.
To compare quotes, break them down into days per activity and check that preparation, debrief, report and any follow-up check are included.
07
After the audit: from report to action plan
An audit report improves nothing until its recommendations are dealt with. Three habits help:
Turn each finding into an action, with an owner, a deadline and proof of completion. Findings left unfixed should be covered by an explicit risk acceptance decision.
Link findings to risks: a critical vulnerability on a secondary system does not weigh the same as a medium weakness on an essential one. Risk analysis is what lets you prioritise.
Plan a follow-up check on critical points, and update your security policy if the audit reveals rules that cannot be applied.
Finally, think of your suppliers: audits of your critical providers, or the evidence they give you, fall under third-party risk management and can be built into a security assurance plan. To track audit actions over time and link them to your risk scenarios, a risk analysis tool saves you from scattering information across spreadsheets and reports.
Summary
01
One question, one type of audit
Architecture, configuration, code, penetration test, organisation: each activity answers a different question. Scoping matters more than the volume of tests.
02
PASSI qualification
France's ANSSI qualifies audit providers against a public framework, at two levels. It is required in some settings (operators of vital importance) and recommended in others (RGS).
03
An audit is only as good as its follow-up
The report ranks findings and recommends measures. Without a tracked action plan and a follow-up check, it remains a snapshot.
Frequently asked questions
What is a cybersecurity audit?
It is an assessment, by auditors independent of the scope audited, of an information system's security level or its compliance with a framework. Depending on the question, the audit covers organisation, architecture, configuration or code, or takes the form of a penetration test. It ends with a report that ranks findings and recommends measures.
What is a PASSI provider?
PASSI is the French acronym for information systems security audit provider. It is a qualification granted by ANSSI to providers that meet a public requirements framework, whose version 2.2 dates from August 2024. It covers five activities: architecture, configuration and source code audits, penetration testing, and organisational and physical audits, at a substantial or high level.
How much does a cybersecurity audit cost?
The cost depends on the scope, the activities chosen, the level of assurance and the number of auditor days, and there is no public price list for PASSI audits. As a published reference point, Bpifrance's Diag Cybersécurité for French SMEs costs €8,800 excluding VAT, half of which is covered by Bpifrance. MonAideCyber, run by ANSSI, offers a free first assessment.
How long does a cybersecurity audit take?
It depends on the scope and activities: an SME assessment takes a few days, while an audit combining architecture, configuration and penetration testing on a large system can stretch over several weeks, including preparation and reporting. Bpifrance's Diag Cybersécurité, for example, runs over 8 days in 4 stages.
What is the difference between an audit and a penetration test?
A penetration test is one type of audit: auditors attack the scope, within an authorised framework, to demonstrate real attack paths. An audit can also be organisational, architectural, configuration-based or code-based, with no attack involved. The two complement each other.
Is a cybersecurity audit mandatory?
There is no general obligation for all companies. Inspections apply to French operators of vital importance (OIV) and operators of essential services (OSE), ISO 27001 certification relies on audits, and NIS 2 and DORA require organisations to assess the effectiveness of their security measures. Customers and insurers also increasingly ask for audit evidence.