forumNew topic

How can a 12-person team set up ANSSI-compliant vulnerability management in France?

JJülide S***ExpertCommunity member
Joined
Sep 2023
Message
184
#1

We are an industrial design and prototyping firm of 12 people based in Lyon. Nearly all of our clients are French industrial manufacturers. Last month, a client of ours that is a major aerospace supplier asked whether we have an ANSSI-compliant vulnerability management process as part of their vendor review, and sent over a complex spreadsheet with dozens of line items for us to fill out.

Looking at the spreadsheet, it describes weekly corporate committees, vulnerability scoring matrices, and expensive monitoring software as if we were a tech firm with hundreds of employees. We don't even have a dedicated IT department; we have a mechanical engineer who manages the tech setup part-time and a local IT service provider we hire by the hour for outside support.

What does vulnerability management actually look like in practice for a company our size? How can we set up a minimum viable process that will satisfy client audits without burying our day-to-day operations in red tape?

HHilalMember
Job title
Translator
Joined
Aug 2024
Message
112
Most Helpful#2

Short answer: For a small business, vulnerability management under ANSSI guidelines doesn't mean buying complex software; it means maintaining a clear hardware and software inventory applying weekly OS patches promptly, and tracking and logging critical vulnerabilities. With a 12-person team, you can build this process around 3 core rules and pass audits without trouble.

Here are the steps expected under the baseline hygiene guide (guide d'hygiène informatique) published for SMEs by ANSSI, the French national cybersecurity agency: 1) Maintain a single-page inventory spreadsheet listing operating systems and version details for every PC server, and network appliance across the company. 2) Add a written clause to the contract with your external IT provider stating: "Critical security patches are applied within 7 days of disclosure, and regular patches on the first Tuesday of every month." 3) Subscribe to ANSSI's public CERT-FR bulletin by email to keep tabs on security flaws.

When you sit down for an audit, your client isn't looking for expensive security dashboard screens; they want to see a sensible workflow showing what you do when a vulnerability emerges. If you can say, "A flaw came out for our firewall brand, we received the email alert our IT vendor patched it within 48 hours, and logged it on this form," you satisfy the vulnerability management requirement.

When completing that complex form your client sent over, don't hesitate to mark enterprise-scale line items as "Not Applicable (SME scale)." Instead, list the concrete patching and maintenance measures you take by referencing ANSSI's guide for small businesses.

BBurhanMember
Job title
Retired Engineer
Joined
Aug 2024
Message
132
#3

Big industrial clients just copy-paste their internal corporate forms directly onto subcontractors. If a team of 12 checks "yes" on every single row, you'll hit a wall the moment the auditor asks for evidence. Showing a patch schedule that matches your actual operational scale is more than enough.

YYasemin K***Member
Job title
Board member
Sector
Jewelry
Organization type
cooperative
Joined
Feb 2023
Message
66
#4

We're a software team of 15. We have a maintenance contract with our IT provider for 400 EUR a month. Once a month, they provide a system scan report and sign off that critical patches have been applied. We passed two major corporate audits with this document without any issues.

İİlker K***Member
Job title
Information Security Specialist
Sector
Glass
Organization type
a company within a holding
Joined
Jul 2025
Message
185
#5

Start a spreadsheet first thing tomorrow. List the make, model and OS for the 12 computers, 1 shared server, and 1 modem/router in the office. Next to them, add the dates of the latest patches. Boom, your first vulnerability inventory is ready.

FFatih B***Member
Job title
Quality Assurance Manager
Sector
Education
Organization type
120-person company
Joined
Feb 2025
Message
321
#6

Most of the time, the client's procurement department doesn't even read those forms. The key is not leaving anything blank and explaining your own sensible process clearly while referencing industry standards.

HHalil K***Member
Job title
Clinic manager
Sector
Seafood
Organization type
medium-sized business
Joined
May 2024
Message
208

Doki · Interface design · 2026

#7

Here are the 3 tangible pieces of evidence an auditor will want to see: 1) An up-to-date hardware and software list. 2) Screenshots showing that automatic updates are turned on. 3) Service reports from your external IT specialist covering the updates done over the past 3 months.

GGamze Y***MemberCommunity member
Joined
Feb 2022
Message
14
#8

anssi has a great 12-step hygiene guide for smes on their website just reference the vulnerability section from there in your reply that guide is the cleanest shield against enterprise forms.

ÖÖmer E***MemberCommunity member
Joined
Aug 2023
Message
71
#9

Under French contract law, the security procedures you declare are legally binding. Therefore, I strongly advise against committing to weekly penetration tests or continuous vulnerability scanning that you won't actually be able to fulfill.

YYavuz Y***MemberCommunity member
Joined
Mar 2026
Message
15
#10

Correct.

FFatma U***Member
Job title
Site Manager
Sector
Sports and fitness
Organization type
two-branch business
Joined
Jan 2025
Message
96
#11

This thread is archived.

OOkan U***ExpertCommunity member
Joined
Apr 2023
Message
286
#12

Just a heads-up. If you scold false alarms, nobody will report again.

Just leaving this note, it might be useful.

KKader K***MemberCommunity member
Joined
Oct 2023
Message
6
#13

We got stuck at the same point for a while. When we decide without measuring, we always end up in the same place.

Everyone rushing into vulnerability management gets stuck at the same point. Just leaving this note, it might be useful.

İİlker A***MemberCommunity member
Joined
Feb 2023
Message
292
#14

Following. If permission and scope aren't in writing, don't start that test.

If you get three different answers on a topic, the question was asked wrong. Of course, it varies if your situation is different.

AAli Y***New member
Job title
Human Resources Specialist
Sector
Law
Organization type
workshop
Joined
Jul 2026
Message
259
#15

To get into the details: Solutions that work at a small scale collapse when you grow; I learned this late.

İİbrahim S***New memberCommunity member
Joined
Jun 2026
Message
20
#16

Sorry, but this doesn't apply in every case. People defend habits, not processes. Resistance comes from there.

Everyone rushing into vulnerability management gets stuck at the same point.

HHalil S***Member
Job title
General Manager
Sector
Textile
Organization type
medium-sized business
Joined
Aug 2024
Message
242

Doki · Server maintenance contract · 2023

#17

Same here.

FFiliz S***MemberCommunity member
Joined
Jun 2023
Message
3
#18

We need to make a distinction here. If you get three different answers on a topic, the question was asked wrong.

EErcan Y***MemberCommunity member
Joined
Mar 2024
Message
350
#19

I have a question, don't want to go off-topic though. Solutions that work at a small scale collapse when you grow; I learned this late.

That's all, sorry if I went on too long.

DDamla E***Veteran
Job title
Customer service representative
Sector
Freight
Organization type
boutique agency
Joined
Aug 2024
Message
414
#20

The discussion got scattered, let me summarize. If permission and scope aren't in writing, don't start that test.

I'm also curious if anyone does it differently.

Reply