QuietHours by securITDiscuss your scope

Testing

PASSI qualification: what French buyers should expect, and when they don't need it

France is a qualification-sensitive market. ANSSI's PASSI scheme gives buyers a state-backed way to verify an audit provider's competence — which is genuinely useful, and also frequently applied to procurements where it was never required.

Minimalist concentric rings with a single accent tick

French buyers ask a question that Nordic buyers rarely do: what recognised framework stands behind you? That is not bureaucratic reflex. It reflects a market where the national cybersecurity agency operates a formal qualification scheme, and where certain organisations are legally or contractually obliged to use it.

What PASSI actually is

PASSI — Prestataires d'Audit de la Sécurité des Systèmes d'Information — is ANSSI's qualification scheme for information system security audit providers. Qualification is granted per activity, not as a blanket status, across a defined set of audit types.

  • Architecture audit — review of the design and structure of an information system.
  • Configuration audit — review of the actual configuration of systems and components.
  • Source code audit — review of application source code.
  • Intrusion testing — penetration testing.
  • Organisational and physical audit — review of governance, processes and physical security.

Who genuinely needs a PASSI-qualified provider

The scheme exists primarily for organisations whose obligations flow from French national security regulation. Broadly, that means operators of vital importance, entities in the most sensitive sectors, and much of the French administration — plus anyone whose contract, sector regulator or funding conditions specify it.

Outside those groups, PASSI is a signal rather than a requirement. A French mid-market SaaS company selling to private-sector customers is not obliged to use a qualified provider, and often should not pay the premium unless a customer contract demands it.

BuyerPASSI needed?Why
Operator of vital importanceYes, in most casesRegulatory obligation for audits in the relevant scope
French public administrationUsuallyProcurement policy and ANSSI guidance
Entity in a highly sensitive sectorOftenSector regulator or contractual requirement
Regulated financial entityDependsDORA independence criteria are separate; check contract terms
Private mid-market companyRarelySignal of competence, not an obligation
Startup or scale-upNoEvaluate the team directly instead

PASSI and PACS are different things

PACS — Prestataires d'Accompagnement et de Conseil en Sécurité — covers security support and consultancy providers rather than auditors. If your need is advisory, architecture support or programme guidance rather than audit, PACS is the relevant scheme. Conflating the two produces procurement documents that ask for the wrong qualification and then exclude perfectly appropriate providers.

How to evaluate a provider without a qualification scheme

If PASSI is not required for your procurement, you still need to assess competence. The qualification scheme is essentially a structured way of asking a handful of questions — you can ask them directly.

  1. Who specifically will do the work? Ask for names, and for the CVs of the individuals assigned rather than the firm's best consultant.
  2. What is their methodology, and does it reference a recognised standard such as the OWASP testing guides or the Penetration Testing Execution Standard?
  3. Show me a redacted report. Judge reproducibility and specificity, as covered in our reporting article.
  4. How is testing evidence stored, for how long, and under what jurisdiction? This is a GDPR question and a confidentiality question at once.
  5. What are your insurance arrangements and liability terms?
  6. How do you handle a critical finding discovered mid-engagement?
  7. Is retesting included, and what does the retest report look like?
  8. Can you provide references from organisations of comparable size and sector?

A provider who answers all eight of those clearly is demonstrating substantially what a qualification scheme verifies. A provider who deflects on the first two is a risk regardless of what badges appear on their website.

The language question

French B2B procurement does not legally require French-language documentation between professionals; the strict French-language obligation applies to consumer-facing information. In practice, technical buyers in France often work comfortably in English, while procurement and legal functions are considerably less likely to.

The pragmatic approach for a non-French provider is English delivery with French-language commercial and trust documentation for the late stages: the proposal summary, the contract terms, the executive summary of the report, and any material that goes to legal or procurement. Translating an entire technical report is usually unnecessary; translating the executive summary is usually decisive.

Frequently asked questions

What is PASSI qualification?

PASSI (Prestataires d'Audit de la Sécurité des Systèmes d'Information) is ANSSI's qualification scheme for information system security audit providers in France. It is granted per activity across architecture audit, configuration audit, source code audit, intrusion testing, and organisational and physical audit.

Do I need a PASSI-qualified provider for a penetration test in France?

Only if your obligations require it — typically operators of vital importance, French public administration, entities in highly sensitive sectors, or where a contract, regulator or funding condition specifies it. Private-sector companies without such obligations are free to select on competence, and PASSI then functions as a signal rather than a requirement.

What is the difference between PASSI and PACS?

PASSI qualifies security audit providers. PACS (Prestataires d'Accompagnement et de Conseil en Sécurité) qualifies security support and consultancy providers. Audit and advisory are different activities, and asking for the wrong qualification in a tender can exclude appropriate providers.

Talk to the team

Need this tested rather than described?

QuietHours is a European cybersecurity practice operated by the securIT team. Send us the system, service, or control you are concerned about and we will help turn it into a workable scope.

Discuss your scope

Related reading