The platform, in detail
What each module does and what it produces, from the ReCyF assessment to the report you hand your client.
Three promises, one screen
What your SME clients expect from a provider who takes cyber seriously — made tangible for you, white-labelled.
Native to France's ANSSI ReCyF
The assessment covers the 20 objectives of the ReCyF v2.5 framework — not a translated SOC 2 or NIST. Your clients answer in their own language, against their own regulatory reality.
Full white-label
Logo, colours and trading name dress the interface and the PDF reports. Vigicap stays invisible to the client SME.
Multi-client, single-pane
Your entire SME portfolio managed from a single dashboard: score, NIS2 category, latest assessment, open actions.
A complete platform, not a simple questionnaire
Everything you need to manage your SME clients' cyber compliance over time — from the NIS2 obligation to audit-ready evidence.
End-to-end NIS2 readiness
Incident register with ANSSI notifications (24h / 72h / 1 month), risk analysis, supplier register and business continuity plan (BCP/DRP) — the NIS2 obligations tracked in the same place as the assessment.
Connectors & automated verification
71 collection connectors — Microsoft 365, Intune/Defender, NinjaOne, Datto, Bitdefender, Wazuh, GLPI, Veeam and many more — read the real state of the client's tools and pre-fill the relevant ReCyF objectives. The consultant always validates.
PSA/RMM tickets
Push corrective actions as tickets directly into HaloPSA, Datto Autotask, ConnectWise, NinjaOne or Atera — remediation lands in the tool your technicians already use.
White-label client portal
Read-only access for the SME: its maturity, its progress over time and its ongoing actions — in your colours, never exposing Vigicap.
Evidence vault
Attach screenshots, policies and exports to every ReCyF objective or ISO 27001 control. Compliance evidence is stored, encrypted and ready for the auditor.
Ready-to-adapt policies
Template library (information security policy, IT charter, BCP…), tailored to the client and exported as a PDF under your brand.
Continuous drift and evidence over time
Connector readings are kept, never overwritten. You see what has REGRESSED since the last reading — "multi-factor authentication: 98% → 71%" — and you can establish coverage over time: "≥ 95% on 91 of 92 days". An auditor does not ask whether MFA is active, they ask you to prove it was, all year.
Passive external scan
From a domain name alone, with no account, no credentials and no authorisation: SPF, DKIM, DMARC, certificate, headers and hostnames already published. A read of what is public — enough to open the conversation with a prospect before any access is granted. This is not a penetration test and does not replace an audit.
Maturity over time
Per-client progress curve, a projected score based on the proposals awaiting validation, and a sector benchmark for your portfolio — enough to prove the value generated at every meeting.
A 30-minute assessment, a sellable engagement
Compliance is your client's problem. Your problem is what an hour of your consultant's time produces. Vigicap turns a meeting into a priced, signable plan.
- 20min
of assessment, not a day of audit
The 20 objectives of the ANSSI ReCyF framework, pre-filled by your connectors and validated by the consultant — not a 300-line questionnaire to re-key.
- 500–2 500€
per priced line item in the quote
Every gap found in the assessment becomes a quote line at your catalogue's price — MFA, backup, EDR, awareness training. One engagement typically combines several.
- 1dossier
remediation line covers the entry plan's year
The assessment itself is never billed: it opens the engagement. An MFA rollout at the default catalogue price (€1,800) already covers nearly three quarters of a year of the Essentiel plan (€2,490), and two remediation lines clear it outright. On a higher plan, it takes more — which the larger portfolio that justifies that plan makes possible. What you make of it depends on your business, not on our tool.
- 16
connectors read the whole portfolio from one key
Out of 73 connectors in total, these skip reconnecting client by client — Huntress connected once feeds the assessment for every client. It's what makes the 30 minutes hold at portfolio scale, not just for one client.
Range taken from Vigicap's default price catalogue, fully editable: your services, your prices, your margin.
Your ISO 27001 file, derived from your assessment
Not a second questionnaire: ISO 27001 compliance is a view derived from the ReCyF assessment you already ran. You take your clients from the gap to the certification file, with no double entry.
- Statement of Applicability (SoA) — the 93 Annex A controls, derived from the ReCyF assessment, never re-entered
- Management system: clauses 4 to 10, risk treatment plan, non-conformities (CAPA) and management reviews
- Certification-readiness file as a white-label PDF, ready to hand to the auditor
- Read-only auditor link + evidence vault attached to every control
Your gaps become tickets, with no re-keying
An action plan is only worth what gets executed. Push any Vigicap action into the ticketing tool your technicians already work in — credentials set at the agency level, routed per client.
Vigicap does not replace your PSA, it precedes it. The PSA executes and bills the ticket; Vigicap is what turns a client's situation into a sellable engagement — assessment, priced plan, report under your brand — then hands off to your tool for execution.
HaloPSA
Datto Autotask PSA

Hosted in France, and checkable — not a marketing line
Your SME clients operate under the NIS2 constraint; your governance tool cannot be the weak link.
Hosting in France
Infrastructure and data hosted in France, with a French provider. No data is ever sent to an AI model.
No trackers, no banner
No analytics cookie, no third-party script: traffic is counted server-side. Nothing to accept on arrival — open the inspector and check.
Traceable register
Every change to the compliance register is logged — the basis for a future audit, not a screenshot.
Human validation
The action plan comes from the framework, not from a model: every proposal stays marked "to validate" until the consultant signs off.