From the ReCyF assessment to the signed quote, in one client meeting.
Your tools supply the evidence; Vigicap turns it into the action plan and the quote — at your prices, in your colours.
Built by a team that runs a managed-services business itself, after ten years of banking compliance: ISO 27001, audits, supplier questionnaires.
From assessment to quote, in a single loop
A journey designed to happen during the client meeting.
- Step 1ReCyF assessment · 7 / 20PROTECTION · OBJ-10
Is multi-factor authentication enforced on privileged accounts?
Pre-filled by Microsoft 365Assessment
Guided questionnaire across the 20 ReCyF objectives. The client answers in natural language, and a maturity level from 0 to 4 is proposed: by a deterministic engine, to validate.
- Step 2Action plan · 6 gapsEnable MFA on privileged accountsCritical · OBJ-10Test backup restorationMajor · OBJ-13Run phishing awareness trainingMajor · OBJ-04Document the security policyModerate · OBJ-02
Action plan
Every gap becomes a prioritised action (impact × effort), written in plain language and linked to the relevant ReCyF objective.
- Step 3Quote · your catalogueMFA rollout€1,800Backup + DR test€1,200Awareness training€600Total excl. VAT€3,600
Your services, your prices, your margin.
Priced quote
The selected actions become a quote ready to sign, in your agency's colours.
- Step 4YOUR AGENCYANSSI ReCyF assessmentExample Client · 24 employees2.4/ 4No mention of Vigicap
White-label PDF
Final report in your MSP's format: cover page, summary, register and plan. Vigicap appears nowhere.
Illustrative preview of the four steps: example figures, not real data.
They plug into your stack
71 connectors reading the real state of your clients' tools and pre-filling the ReCyF assessment. The commercial stack you resell, as much as the open source you self-host.
- Microsoft 365
- Google Workspace
Datto Autotask
HaloPSANinjaOne
Datto RMM
Kaseya VSA
Action1
Syncro
VeeamDatto BCDR
Acronis
Bitdefender
SentinelOne- Sophos Central
ESET PROTECT
Huntress- ThreatDown
Wazuh
- FortiGate
- Cisco Meraki
UniFi- VMware vSphere
- Proxmox VE
Lansweeper
IT Glue
GLPI
Bitwarden
KnowBe4- +42more
What you see on Monday morning
The console opens on what has gone backwards since the connectors last read — not on a row of counters at 100%.
Today
- Client A — multi-factor authentication: 68% → 28% · read on 12 September via microsoft365
- Client B — email security: 66% → 39% · read on 12 September via vade
1 month with no finalised diagnostic: the curve breaks, it does not drop to zero.
- Essential entity2
- Important entity6
- Out of scope5
11 clients diagnosed · average 74%
15open actions
5 clients concerned · 8 with none open
- Client A5
- Client B4
- Client C3
- Client D2
€29,570
of work identified over the last 30 days
3
quotes in flight (draft/sent)
- Industrie70 % · 2
- Transports72 % · 2
- Santé93 % · 1
Nine modules, one screen
What the platform does, on one page. The module-by-module detail is on the Features page.
The detail, module by module →NIS2 compliance
Incident register with notification deadlines, risk analysis, supplier register, continuity plan.
Connectors & verification
71 connectors read the real state of the client's tools and pre-fill the objectives concerned.
PSA/RMM tickets
Push corrective actions into HaloPSA, Autotask, ConnectWise, NinjaOne or Atera.
Client portal
Read-only access for the SME: its maturity, its progress, its open actions — in your colours.
Evidence vault
Every objective carries its supporting documents, timestamped and tied to the register.
Policies & ISSP
Policy templates ready to adapt, a validation cycle and PDF export under the MSP's brand.
Drift
Readings are kept, never overwritten. You see what has gone BACKWARDS since the last one.
External scan
A passive read of what is already public — SPF, DKIM, DMARC, certificate, headers — to open the conversation.
ISO 27001 file
The 93 Annex A controls and clauses 4 to 10, derived from the ReCyF assessment, never re-entered.
You are yourself in NIS2 scope
A regulated client has to prove the security of its critical suppliers. Its IT provider tops that list. Before selling cyber governance, your agency will have to demonstrate its own.
Your first client on Vigicap is you. Diagnose your own agency during the trial: the fifteen objectives of the common core, out of the referential's twenty.
We receive these questionnaires ourselves — that is where Vigicap comes from.
One price per portfolio size
14-day free trial, no card required. The subscription simply stops at the end unless a card has been added. Change plan or billing frequency at any time.
Included in every plan
- Unlimited assessments against the ANSSI ReCyF framework
- ISO 27001 module: statement of applicability and audit file
- Actions pushed to your PSA
- Automatic monthly campaigns and reports
- White-label reports and client portal
Gratuit
One client, free for life, to evaluate Vigicap with no time limit.
1 clients max
€0HT / month
€0 excl. VAT billed once a year
Démarrage
To try the loop on your first clients, at your own size.
Billed on active clients, never beyond the cap
€21excl. tax per active client per month
€250 excl. VAT per active client, billed once a year, €50 saved per client per year
Essentiel
To start a cyber governance practice.
12 clients max
€208HT / month
€2,490 excl. VAT billed once a year, €498 saved per year
Croissance
For a practice that has outgrown the starting plan.
20 clients max
€325HT / month
€3,900 excl. VAT billed once a year, €780 saved per year
Cabinet
RecommendedThe format for a consultancy or an established MSP.
30 clients max
€467HT / month
€5,600 excl. VAT billed once a year, €1,120 saved per year
Portefeuille
For a large portfolio, followed over the long term.
80 clients max
€992HT / month
€11,900 excl. VAT billed once a year, €2,380 saved per year
Réseau
For a network of agencies or a group.
Beyond 80 active clients
Every connector: Microsoft 365, Google Workspace, RMM, backup, EDR, identity
Deployment support
Firm cap, no per-unit billing
14-day trial · no card required · cancel at any time. Not sure which plan fits?
Hosting in France · ANSSI ReCyF framework v2.5 (17/03/2026) · 14-day free trial
A clear cap, no commitment on your total portfolio.
Prices excl. VAT; applicable VAT is added. Full detail and FAQ on the pricing page.
Deliver your first report in 30 minutes
Your first client file is you: assess your own agency and leave with your ANSSI ReCyF report under your own brand. A 14-day free trial, no card required.