Skip to main content

From the ReCyF assessment to the signed quote, in one client meeting.

Your tools supply the evidence; Vigicap turns it into the action plan and the quote — at your prices, in your colours.

Built by a team that runs a managed-services business itself, after ten years of banking compliance: ISO 27001, audits, supplier questionnaires.

From assessment to quote, in a single loop

A journey designed to happen during the client meeting.

  1. Step 1
    ReCyF assessment · 7 / 20
    PROTECTION · OBJ-10

    Is multi-factor authentication enforced on privileged accounts?

    Pre-filled by Microsoft 365

    Assessment

    Guided questionnaire across the 20 ReCyF objectives. The client answers in natural language, and a maturity level from 0 to 4 is proposed: by a deterministic engine, to validate.

  2. Step 2
    Action plan · 6 gaps
    Enable MFA on privileged accountsCritical · OBJ-10
    Test backup restorationMajor · OBJ-13
    Run phishing awareness trainingMajor · OBJ-04
    Document the security policyModerate · OBJ-02

    Action plan

    Every gap becomes a prioritised action (impact × effort), written in plain language and linked to the relevant ReCyF objective.

  3. Step 3
    Quote · your catalogue
    MFA rollout€1,800
    Backup + DR test€1,200
    Awareness training€600
    Total excl. VAT€3,600

    Your services, your prices, your margin.

    Priced quote

    The selected actions become a quote ready to sign, in your agency's colours.

  4. Step 4
    YOUR AGENCY
    ANSSI ReCyF assessment
    Example Client · 24 employees
    2.4/ 4
    No mention of Vigicap

    White-label PDF

    Final report in your MSP's format: cover page, summary, register and plan. Vigicap appears nowhere.

Illustrative preview of the four steps: example figures, not real data.

They plug into your stack

71 connectors reading the real state of your clients' tools and pre-filling the ReCyF assessment. The commercial stack you resell, as much as the open source you self-host.

See the connectors in detail →
  • Microsoft 365
  • Google Workspace
  • Datto Autotask
  • HaloPSA
  • NinjaOne
  • Datto RMM
  • Kaseya VSA
  • Action1
  • Syncro
  • Veeam
  • Datto BCDR
  • Acronis
  • Bitdefender
  • SentinelOne
  • Sophos Central
  • ESET PROTECT
  • Huntress
  • ThreatDown
  • Wazuh
  • FortiGate
  • Cisco Meraki
  • UniFi
  • VMware vSphere
  • Proxmox VE
  • Lansweeper
  • IT Glue
  • GLPI
  • Bitwarden
  • KnowBe4
  • +42more

What you see on Monday morning

The console opens on what has gone backwards since the connectors last read — not on a row of counters at 100%.

Today

2 objectives have regressed since the last readingSee all drifts
  • Client A — multi-factor authentication: 68% → 28% · read on 12 September via microsoft365
  • Client B — email security: 66% → 39% · read on 12 September via vade
Average portfolio maturity▲ +36 pts between October 2025 and September 2026
oct. · 53 %sept. · 89 %

1 month with no finalised diagnostic: the curve breaks, it does not drop to zero.

NIS2 distribution
  • Essential entity2
  • Important entity6
  • Out of scope5
Score distribution
0–19
120–39
240–59
260–79
680–100

11 clients diagnosed · average 74%

Open actions

15open actions

5 clients concerned · 8 with none open

  • Client A5
  • Client B4
  • Client C3
  • Client D2
Value generated

€29,570

of work identified over the last 30 days


3

quotes in flight (draft/sent)

Sector benchmark
  • Industrie70 % · 2
  • Transports72 % · 2
  • Santé93 % · 1
Illustrative view of the dashboard: example figures, not real data.

Nine modules, one screen

What the platform does, on one page. The module-by-module detail is on the Features page.

The detail, module by module →
  • NIS2 compliance

    Incident register with notification deadlines, risk analysis, supplier register, continuity plan.

  • Connectors & verification

    71 connectors read the real state of the client's tools and pre-fill the objectives concerned.

  • PSA/RMM tickets

    Push corrective actions into HaloPSA, Autotask, ConnectWise, NinjaOne or Atera.

  • Client portal

    Read-only access for the SME: its maturity, its progress, its open actions — in your colours.

  • Evidence vault

    Every objective carries its supporting documents, timestamped and tied to the register.

  • Policies & ISSP

    Policy templates ready to adapt, a validation cycle and PDF export under the MSP's brand.

  • Drift

    Readings are kept, never overwritten. You see what has gone BACKWARDS since the last one.

  • External scan

    A passive read of what is already public — SPF, DKIM, DMARC, certificate, headers — to open the conversation.

  • ISO 27001 file

    The 93 Annex A controls and clauses 4 to 10, derived from the ReCyF assessment, never re-entered.

You are yourself in NIS2 scope

A regulated client has to prove the security of its critical suppliers. Its IT provider tops that list. Before selling cyber governance, your agency will have to demonstrate its own.

Your first client on Vigicap is you. Diagnose your own agency during the trial: the fifteen objectives of the common core, out of the referential's twenty.

We receive these questionnaires ourselves — that is where Vigicap comes from.

11 published analyses of ReCyF, ISO 27001 and NIS2

One price per portfolio size

14-day free trial, no card required. The subscription simply stops at the end unless a card has been added. Change plan or billing frequency at any time.

Included in every plan

  • Unlimited assessments against the ANSSI ReCyF framework
  • ISO 27001 module: statement of applicability and audit file
  • Actions pushed to your PSA
  • Automatic monthly campaigns and reports
  • White-label reports and client portal
  • Gratuit

    One client, free for life, to evaluate Vigicap with no time limit.

    1 clients max

    €0HT / month

    €0 excl. VAT billed once a year

  • Démarrage

    To try the loop on your first clients, at your own size.

    Billed on active clients, never beyond the cap

    €21excl. tax per active client per month

    €250 excl. VAT per active client, billed once a year, €50 saved per client per year

  • Essentiel

    To start a cyber governance practice.

    12 clients max

    €208HT / month

    €2,490 excl. VAT billed once a year, €498 saved per year

  • Croissance

    For a practice that has outgrown the starting plan.

    20 clients max

    €325HT / month

    €3,900 excl. VAT billed once a year, €780 saved per year

  • Cabinet

    Recommended

    The format for a consultancy or an established MSP.

    30 clients max

    €467HT / month

    €5,600 excl. VAT billed once a year, €1,120 saved per year

  • Portefeuille

    For a large portfolio, followed over the long term.

    80 clients max

    €992HT / month

    €11,900 excl. VAT billed once a year, €2,380 saved per year

  • Réseau

    For a network of agencies or a group.

    Beyond 80 active clients

    Every connector: Microsoft 365, Google Workspace, RMM, backup, EDR, identity

    Deployment support

Firm cap, no per-unit billing

Start the free trial

14-day trial · no card required · cancel at any time. Not sure which plan fits?

Hosting in France · ANSSI ReCyF framework v2.5 (17/03/2026) · 14-day free trial

A clear cap, no commitment on your total portfolio.

Prices excl. VAT; applicable VAT is added. Full detail and FAQ on the pricing page.

Deliver your first report in 30 minutes

Your first client file is you: assess your own agency and leave with your ANSSI ReCyF report under your own brand. A 14-day free trial, no card required.