Your scope. Your data. Your control.

Understand how we scope testing, handle evidence, and keep you in control. Explore our operating practices and the details to agree for your engagement.

The status of each practice is shown below. Engagement-specific terms are agreed before testing.

Testing under control

What is tested, how it runs, and how to stop it.

Every engagement starts with written scope: assets, exclusions, owners. Nothing outside it is touched.

Evidence & data

Who can access the results and how they are handled.

Requests, responses, and reproduction steps captured per finding, shared only with named recipients.

Your engagement

Access, hosting, providers, and security contacts.

Dedicated short-lived credentials with a defined lifecycle. Full process to be published.

The right framework for your organization.

Official references to consider when defining your engagement.

01 / CNDP · 09-08

Personal-data protection

Scope the engagement around applicable personal-data obligations: purpose, access, retention, and CNDP formalities. Review cross-border transfers before choosing where evidence is hosted or who receives it.

CNDP guidanceCross-border transfers
02 / DGSSI · 05-20

Applicable cybersecurity requirements

For entities in scope and sensitive information systems of critical infrastructure, assess Law 05-20 and its implementing requirements. Continuous validation does not replace a regulated audit that requires a DGSSI-qualified provider.

DGSSI guidance

Applicable requirements depend on your organization and the proposed processing. These scoping considerations are not a certification or a guarantee of compliance.

Questions before you start?

Let’s review your assets, data requirements, and testing limits together.

Discuss your scope
Website privacy