Skip to main content

Scoring methodology

Last updated: September 2026

This translation is provided for convenience. Only the French version is legally binding.

The Vigicap score is not an ANSSI grade. It is a steering grid that we own, calculated from the official framework. This page describes the exact formula, what enters the calculation and what is deliberately excluded from it.

What comes from ANSSI, and what comes from us

The distinction matters and we state it up front, because it changes what the score proves:

  • From ANSSI: the 20 objectives, their titles, their distribution across four pillars (Governance, Protection, Defence, Resilience) and the EI/EE scope — framework ReCyF v2.5 of 17/03/2026. That document carries the words “working document”: no final version will be published before the NIS 2 transposition is complete. We therefore speak of preparation, never of compliance with a settled standard.
  • From us: the 0–4 maturity scale, the expected threshold per objective, the formula below, and the explanatory text shown under each objective — ANSSI publishes “acceptable means of compliance” which we do not reproduce; our descriptions are a restatement written for the consultant. ReCyF defines no maturity scale — the word does not appear in it. Proportionality there runs solely through objectives 16 to 20, reserved for essential entities, and through the EI/EE marking of each means of compliance. Our scale is a steering and prioritisation tool; it has no regulatory value.

The maturity scale

  • 0 — Non-existent: nothing in place.
  • 1 — Initial: informal, undocumented practices, dependent on individuals.
  • 2 — In progress: work under way, partial coverage.
  • 3 — Defined: documented, applied and verifiable practice.
  • 4 — Managed / optimised: practice measured and improved over time.

The scope: which objectives count

Only the objectives applicable to the client's NIS 2 category enter the calculation:

  • Essential entity (EE): all 20 objectives.
  • Important entity (EI): the core of 15 objectives (objectives 16 to 20 are reserved for EEs).
  • Out of scope: the core of 15 objectives is assessed all the same, to give a working baseline — without that carrying the slightest regulatory obligation.

An objective that is not applicable does not penalise the score: it is removed from it, numerator and denominator alike.

The formula

For each applicable objective, the level attained is compared with the expected threshold, capped at the threshold:

score = Σ min(level, threshold) ÷ Σ threshold × 100

Two consequences worth knowing:

  • Exceeding a threshold earns nothing. An objective at level 4 where 3 is expected counts as 3. The score measures coverage of what is expected, not excellence — a blocking gap cannot be offset by a strength elsewhere.
  • The thresholds are a weighting in effect. An objective whose expected threshold is 3 weighs more than an objective at 2, since both enter the denominator up to their threshold. There is no other, hidden weighting.

What counts as the level attained

In order of priority: the level validated by the consultant, failing that the level declared by the client. In the absence of both, the objective counts as 0.

A proposal — computed from the consultant's notes, or reported automatically by a connector — never enters the retained score. That is a governance rule, not an implementation detail: a report presented to a client or to an auditor must rest only on items a human has validated. An unvalidated proposal remains visible, marked “to be validated”, and feeds the projected score alone.

Projected score

The projected score applies the same formula, but fills the objectives with no human level using the pending proposal. It answers the question “where would we be if I validated everything as it stands?”. It is always greater than or equal to the retained score, and equal to it when there is no pending proposal. Where proposals are pending, it appears on the summary page of the client report, explicitly presented as conditional (“projected score if N proposals were validated”): it never substitutes for the retained score, which remains the figure displayed.

The radar by pillar

Each pillar shows the arithmetic mean of the levels attained across its applicable objectives, compared with the mean of the thresholds. It is a simple average, without weighting: it serves to read a silhouette, not to produce a ranking.

Gaps and action plan

An objective is a gap as soon as it is applicable and its level attained is strictly below the expected threshold. This detection is deterministic.

The action plan is built from that list: each gap produces an action, and its priority follows from the size of the gap to the threshold and the effect of the measure. Entirely deterministic.

The action plan does not enter the calculation of the score: it follows from it.

What the score does not say

  • It does not establish NIS 2 compliance. Compliance is assessed against the transposing legislation and, where applicable, an inspection by the competent authority.
  • It does not replace an audit. It rests on declarative input validated by a consultant, supplemented where possible by technical readings from the connectors.
  • It is not intended to compare two entities with one another: the thresholds are the same, but the scopes and the contexts are not.

Reproducibility

The formula is deterministic: identical answers, identical score. No artificial-intelligence model takes part, neither in the calculation nor anywhere else in the platform.