forumNew topic

Approved for Phase B of the Cyber PME program: how does it work and what do we get out of it?

YYasemin K***Member
Job title
Graphic Designer
Sector
Law
Organization type
chain store
Joined
Mar 2023
Message
12
#1

We're a 22-employee parts manufacturing and wholesale distribution business based in Lille, France. A few months back, we applied for the state-backed Cyber PME program to assess our cybersecurity vulnerabilities, and the initial audit phase is now complete. Our consultant submitted their report and told us we qualify for Phase B, where a significant portion of our budget will be covered by state subsidies.

The report lists numerous vulnerabilities ranging from our backup architecture to our authentication systems. We're looking at an out-of-pocket cash spend of around 12,000 EUR from our company budget, and the total project size is even higher once you factor in the public funding.

Has anyone here been through this process? What does Phase B actually cover; does the external expert just lay out a roadmap, or do they get hands-on with installing and configuring the systems?

DDamla K***Veteran
Job title
Graphic Designer
Sector
Consulting
Organization type
two-branch business
Joined
Jan 2022
Message
320
Most Helpful#2

Short answer: Phase B of Cyber PME is the co-funded implementation of the action plan designed to patch the vulnerabilities found in your initial audit. In this phase, the accredited expert doesn't just hand you theoretical advice; they actively support you in drafting technical specs, vetting vendors, and running post-implementation security validations.

The process works more like an advisory and auditing mechanism rather than hands-on technical labor. The assigned expert firm isn't going to show up to run cables to your servers or sell you software licenses. Instead, they handle: 1) prioritizing the report's vulnerabilities by risk level, 2) drafting vendor-neutral technical specs for outsourced IT services or security tools, and 3) verifying that the work done by your IT provider meets standards.

On the budget and grant side, the state typically covers a set percentage of eligible expenses, with your company funding the rest. If your budgeted 12,000 EUR is your own contribution, that money usually goes toward modern backup solutions, 2FA hardware, and implementation invoices from your IT vendor.

The single biggest benefit here is having an independent cybersecurity expert oversee and audit your IT contractor's work. By the end of the process, your business becomes much more resilient to ransomware and walks away with an official report proving its cyber maturity to authorities and partners.

OOrhan D***New memberCommunity member
Joined
Jul 2026
Message
347
#3

The most valuable takeaway from this program is the official audit trail. Down the line, when corporate clients or insurance brokers send you cybersecurity questionnaires for a policy, proving you completed a state-accredited process directly improves your premiums and customer trust.

ZZeynep U***Member
Job title
Front office accounting
Sector
E-commerce
Organization type
early-stage startup
Joined
Nov 2023
Message
22
#4

We finished the same phase last year. We paid around 11,500 EUR, matched by a similar amount in state support. The whole thing took about four months. The most time-consuming part was isolating our internal backups on a separate network and running phishing simulations on the staff.

MMelis Ç***Expert
Job title
System support specialist
Sector
Energy
Organization type
two-branch business
Joined
Apr 2025
Message
4
#5

Get your current IT support provider in the room right away. Since the expert assigned for Phase B won't be doing hands-on deployments, your IT provider will be the one executing the specs. Run your meetings jointly from day one to avoid technical friction between them.

GGürkan K***Member
Job title
Production planning
Sector
Packaging
Organization type
early-stage startup
Joined
May 2024
Message
109

Doki · Penetration test · 2026

#6

Keep an eye on the consultant's neutrality. Some experts try to steer you toward specific commercial security packages during Phase B. Make sure the specs are written neutrally and don't bundle in unnecessarily expensive subscriptions.

DDoruk K***Expert
Job title
Quality Assurance Manager
Sector
Construction
Organization type
20-person company
Joined
Feb 2024
Message
28
#7

Were there any critical, urgent vulnerabilities in the phase one report? The Phase B grant approval can sometimes take a few weeks, so if it's an obvious internet-facing vulnerability, you might need to patch it urgently without waiting for the subsidy.

DDilekNew member
Job title
Pastry Shop
Organization type
a company within a holding
Joined
Nov 2024
Message
19
#8

don't be intimidated at all, it's one of the most straightforward grants for small businesses in France but the only thing you need to watch out for is uploading the invoice and technical closing report to the portal on time, the rest runs like clockwork.

edit: I wrote something wrong above, sorry about that.

DDamla T***MemberCommunity member
Joined
Aug 2023
Message
95
#9

the paperwork might seem overwhelming at first but the accredited consultant shows you step by step how to submit the file anyway. definitely dont give up imo the budget contribution is great.

MMerve Ö***MemberCommunity member
Joined
Feb 2026
Message
1
#10

Let me summarize the topic, since several different answers were given. Don't hesitate to ask; those who don't ask always pay more.

Good luck with that.

MMehmet U***MemberCommunity member
Joined
Feb 2023
Message
32
#11

Timely topic. Hasty decisions become decisions you have to fix six months later.

Good luck with that.

MMehmet A***Expert
Job title
Agency owner
Organization type
early-stage startup
Joined
Sep 2023
Message
187
#12

To get into the details: If 2FA is on, a stolen password alone is useless.

I'm also curious if anyone does it differently.

TTülay S***MemberCommunity member
Joined
May 2024
Message
408
#13

I'd appreciate it if you shared the outcome.

NNeşeNew member
Job title
Hair salon
Joined
Oct 2024
Message
21
#14

The opposite happened to me that's why I'm writing. Just because everyone does it doesn't mean it's right.

Proven by experience.

ZZehra K***Member
Job title
System support specialist
Sector
Jewelry
Organization type
regional distributor
Joined
Apr 2025
Message
24
#15

I went through the same thing two years ago. The harder it is to reverse a decision, the slower you should make it.

If you don't write this down from the start, it leads to arguments later. Good luck with that.

ZZafer A***MemberCommunity member
Joined
Nov 2025
Message
152
#16

We've heard this a lot, but it never happened like that for us. Taking measures without an inventory leaves doors you haven't seen open.

That's all, sorry if I went on too long.

HHalil Ö***Member
Job title
System administrator
Sector
Chemistry
Organization type
20-person company
Joined
Jan 2022
Message
4
#17

Im a small business, let me explain from my side. The answer varies greatly by industry; there is no one-size-fits-all rule.

Everything goes well for the first three months; problems arise in the fourth... Proven by experience.

YYağmur B***MemberCommunity member
Joined
Jun 2024
Message
51
#18

Great work. Your time to detect an issue directly determines its cost.

Most incidents start with a leaked password, not a vulnerability.

ÖÖzgür Ç***Expert
Job title
Accounting clerk
Sector
Leather
Organization type
workshop
Joined
Oct 2024
Message
328
#19

I went through the same thing two years ago. The real issue isn't the number, but what it's based on.

Proven by experience.

EElif D***MemberCommunity member
Joined
Oct 2024
Message
98
#20

I think it's hard to be that definitive about cyber pme phase b. Most time waste accumulates in tasks waiting for approval.

If you have questions, write them; I'll answer as best I can.

Reply