Preparing a CyberVadis assessment as a small company
Many large French groups ask their suppliers to complete a CyberVadis assessment. For a small company, it is often the first time security has to be documented this formally.
How it differs from a standard questionnaire
Stating that a measure exists is not enough. Each answer must be backed by a document: policy, procedure, report, screenshot. Answers without acceptable evidence do not count towards the rating.
The evidence most often requested
- a security policy approved by management;
- security roles and responsibilities;
- access management and strong authentication;
- vulnerability and patch management;
- backups and tested restores;
- incident management and business continuity;
- staff awareness training.
Three common mistakes
- Providing a document with no date or approval. An unapproved policy proves nothing.
- Answering “yes” on the strength of an unwritten practice. What is not written down is not counted.
- Writing everything in a rush. Documents created the day before show, and do not describe reality.
How to prepare
Start with an inventory of what you already do: it is almost always more than what is written. Then formalise existing practices, and address the real gaps in order of impact. Allow several weeks for a first assessment.
Hadovia gathers the technical evidence from your systems, and our experts help you formalise the rest.
CyberVadis is a trademark of its owner. Hadovia is independent and not affiliated with it.
Tell us what your customer is asking for. We get back to you within one business day with the next steps.
Get a demo →