For auditors

Duration: 5 minutes For whom: external auditors invited to review a cybersecurity assessment Prerequisite: having received an invitation email from an organisation

Welcome. As an external auditor, you access CyberPassport in read-only mode to review the report and evidence of one or more organisations that have invited you.


Step 1 — Accept an invitation

  1. You receive an email with the subject: "[CyberPassport] {Organisation name} invites you to review their cybersecurity assessment".
  2. Click the "Access the assessment" button in the email.
  3. Depending on your situation:
    • You already have a CyberPassport account (same email address) → you are signed in directly and access the org.
    • You don't have an account → you go through signup (Google or email/password — see guide 01).

📸 Screenshot location: auditor invitation email

⚠️ Important: the invitation expires 30 days after it is sent. After that, ask the organisation to re-invite you.


Step 2 — The auditor hub

Once signed in as an auditor, you land on /audit — your personal space listing the organisations you have access to.

Anatomy of the hub

  • List of organisations: for each one, the name, the sector, the date of last publication, and a "View report" button.
  • If you have no active access: a message inviting you to request an invitation.

📸 Screenshot location: /audit page with a list of 2-3 organisations

🟣 Tip: you can have access to several organisations at once (typical of an audit firm tracking 10 SMEs). They all appear in this hub.


Step 3 — Review an organisation's report

Click an organisation → you land on /audit/{slug} (read-only report page).

What you see

  1. Header: organisation name, sector, publication date, "Read only" badge.
  2. Scores by framework:
    • NIST CSF 2.0: overall score + maturity level (1–5)
    • ISO/IEC 27001:2022: same
    • Cyber-Safe (if activated): exposure category + sub-domains
    • nLPD: coverage rate (the mandatory requirements in Switzerland)
  3. Detail by domain: for each framework, scores by domain (e.g. NIST → Identify 78%, Protect 65%, etc.)
  4. Narrative AI report: executive summary, strengths, areas for improvement, recommendations, 90-day action plan.
  5. Sealing block: the report's SHA-256 hash + sealing date + link to /verify/[hash] for public verification.

📸 Screenshot location: audit report with scores + visible sealing

Important notes

⚠️ The report is a declarative self-assessment. It does not constitute an official audit or a certification of compliance. Certifications (ISO 27001, Cyber-Safe label, etc.) require an accredited auditor.

💡 If the organisation publishes a new version while you are reviewing, you will see the most recent one at the next refresh.

Multilingual

The report adapts to your interface language (FR / EN / DE / IT). Selector in the header.


Step 4 — Review the evidence (Evidence Vault)

On an organisation's report page, the "Evidence Vault" link (top right) → takes you to /audit/{slug}/evidences.

Anatomy of the list

For each piece of evidence:

  • Title + short description
  • Upload date
  • Expiry date (if applicable) — orange "Expired" badge if passed
  • Codes of the covered controls (e.g. A.5.1 · A.8.3 · PR.AA-01) — you immediately know which control(s) the evidence relates to
  • "Download" button

📸 Screenshot location: /audit/{slug}/evidences page with 3-4 pieces of evidence listed

Downloading

  1. Click "Download".
  2. A new tab opens with a temporary link (signed URL valid for 5 minutes).
  3. The file downloads automatically.

🟣 Tip: the download links are ephemeral. If you want to access a piece of evidence again later, click "Download" again — a new link is generated on each click.

⚠️ Important: no "Upload", "Modify" or "Delete" button appears on the auditor's side — this is by design. If you need an additional piece of evidence or an update, contact the organisation directly.

Case — no evidence

If the organisation has uploaded no evidence: a message "No evidence has been uploaded for this organisation."


Step 5 — Understand cryptographic sealing

Every published report contains a sealing block:

Sealed report · Self-hash · SHA-256 · 0x4a8b…1f2e
Sealed on 23 May 2026

Why it's useful to you

  • The SHA-256 hash attests that at the moment of sealing, the report contained exactly what you are reading today.
  • If the organisation modifies its assessment, a new hash will be created and the old one will be marked "replaced".
  • You can publicly verify a hash on the /verify/[hash] page (see guide 07) — useful if you keep a written record of the report and want to attest its authenticity later.

⚠️ Important for v0.9: the level of cryptographic assurance is "Self-hash" (application-level SHA-256 hash). The higher levels (qualified TSA timestamping, eIDAS signature) are planned for V1 and V2 — not delivered currently.


Limitations

  • You cannot annotate a report — feature planned for V2.
  • You cannot electronically sign your audit conclusion in CyberPassport — feature planned for V2 (qualified eIDAS signature).
  • You cannot request a new piece of evidence from the platform — do so by email or phone.

These features are on the V2 roadmap. For now, the intended use is: the auditor reviews the SME's structured working base, then carries out their official audit separately.


Next step

Publicly verify a sealed report (to archive or prove authenticity)