The Systems Security Audit Provider (PASSI) qualification
Accredited by ANSSI since 2014, LSTI is the first certification body (CB) to conduct audits according to the PASSI standard, which is part of the General Security Regulations (RGS) designed by ANSSI.
This qualification is intended for trusted service providers who carry out organisational and physical security audits as well as technical audits. This qualification has become necessary in order to offer audit services to certain companies or to respond to calls for tenders.
The qualification process is detailed on our page dedicated to PASSI qualification: it consists of a head office audit, a witness observation and written and oral examinations.
The purpose of the examinations is to validate the technical knowledge of the service provider's auditors, as well as their mastery of the PASSI standard and their compliance with certain ethical standards.
For the service provider, the qualification ensures compliance with strict contractual clauses, the implementation of an effective recruitment and skills management process, and the protection of audit data at the level set by the reference framework.
PASSI qualification: how does it work at LSTI?
- 1 - Definition of the client project
1 - Definition of the client project
- Initial review
- Definition of scope and criteria
- Feasibility studies
- Contract drafting
- 2 - Intervention review
2 - Intervention review
- Documentary review
- Preparation with stakeholders
- If on-site audit, site visit
- Initial report
- 3 - Audit preparation
3 - Audit preparation
- Planning
- Selection of auditors
- Development of audit tests
- Preparation of working materials
- 4 - Audit
4 - Audit
- Kick-off meeting
- Information gathering
- Testing
- Identification of discrepancies
- Quality review
- 5 - Closing
5 - Closing
- Drafting of conclusions
- Closing meeting
- Audit report: drafting and validation
- Implementation of an action plan
- Certification
- 6 - Follow-up
6 - Follow-up
- Monitoring
- Audit monitoring
- Renewal audit
- 1 - Definition of the client project
1 - Definition of the client project
- Initial review
- Definition of scope and criteria
- Feasibility studies
- Contract drafting
- 2 - Intervention review
2 - Intervention review
- Documentary review
- Preparation with stakeholders
- If on-site audit, site visit
- Initial report
- 3 - Audit preparation
3 - Audit preparation
- Planning
- Selection of auditors
- Development of audit tests
- Preparation of working materials
- 4 - Audit
4 - Audit
- Kick-off meeting
- Information gathering
- Testing
- Identification of discrepancies
- Quality review
- 5 - Closing
5 - Closing
- Drafting of conclusions
- Closing meeting
- Audit report: drafting and validation
- Implementation of an action plan
- Certification
- 6 - Follow-up
6 - Follow-up
- Monitoring
- Audit monitoring
- Renewal audit
- 1 - Definition of the client project
1 - Definition of the client project
- Initial review
- Definition of scope and criteria
- Feasibility studies
- Contract drafting
- 2 - Intervention review
2 - Intervention review
- Documentary review
- Preparation with stakeholders
- If on-site audit, site visit
- Initial report
- 3 - Audit preparation
3 - Audit preparation
- Planning
- Selection of auditors
- Development of audit tests
- Preparation of working materials
- 4 - Audit
4 - Audit
- Kick-off meeting
- Information gathering
- Testing
- Identification of discrepancies
- Quality review
- 5 - Closing
5 - Closing
- Drafting of conclusions
- Closing meeting
- Audit report: drafting and validation
- Implementation of an action plan
- Certification
- 6 - Follow-up
6 - Follow-up
- Monitoring
- Audit monitoring
- Renewal audit
Our guarantees throughout the entire process
- Customer communication - LSTI with dedicated contact person
- Customer communication - fluent auditor
- Impartiality respected
- Risk management
Qualification is granted by the conformity assessment body (OEC) LSTI after validation of the audit and successful completion of the examinations by candidates, for a period of three years. Monitoring takes place after 18 months, and a renewal audit allows conformity to be declared for a further three years.
If you have any questions about our PASSI service, contact us with the subject line ‘company certification information’

