What is the cybersecurity assessment designed to do?
The assessment helps you review the cybersecurity practices currently used within your organisation.
It identifies the practices that are already established, the areas that should be strengthened and the first actions to prioritise.
Who is this assessment intended for?
It is mainly intended for businesses, associations, self-employed professionals and small organisations seeking a clearer view of their cybersecurity priorities.
It may also support legal, compliance, IT and security professionals.
Do I need to be a cybersecurity specialist?
No. The questionnaire is designed to be understood without specialist technical knowledge.
The questions focus on practical matters such as accounts, access rights, backups, updates, incident management and staff awareness.
How does the assessment work?
You complete a guided questionnaire about the practices used within your organisation.
Your answers are then used to produce a summary, identify priority areas and create a practical 30-day action plan.
What will I receive?
You will receive a personalised report setting out your declared maturity level, established practices, points to verify and areas requiring improvement.
The report also contains prioritised actions that should be adapted to your organisation, tools and available resources.
Why is the action plan organised over 30 days?
The 30-day structure turns the assessment results into a manageable sequence of practical actions.
It helps you organise priorities and make progress without attempting to address every issue at the same time.
Is this a cybersecurity audit?
No. The assessment is based exclusively on the answers you provide in the questionnaire.
It does not include evidence checks, vulnerability scans, penetration testing or technical examination of your systems.
Does the report guarantee that my organisation is secure?
No. The report is not a certification, a security assurance statement or a guarantee that no risk exists.
It provides an initial structured assessment and helps you identify the additional checks and actions that may be required.
What should I do if I do not know an answer?
You may select the option indicating that you are unsure.
The issue will then be presented as a point to verify, helping you identify the information to request from your team, service providers or IT contacts.
Can I share the report with my team?
Yes. The report can support discussions with management, employees, IT teams, service providers or the people responsible for compliance and security.
It provides a shared view of the priorities and the next practical steps.
What should I do if an important risk is identified?
Important issues should be reviewed promptly and, where appropriate, discussed with a competent cybersecurity professional.
Some situations may require a more detailed technical assessment or specialist intervention adapted to your information systems.
This assessment is based on the information declared in the questionnaire. It is not a technical audit, penetration test, security certification or guarantee that no risk exists. The results and proposed actions should be reviewed and adapted to the circumstances of each organisation.