Duration: 5 minutes For whom: external auditors invited to review a cybersecurity assessment Prerequisite: having received an invitation email from an organisation
Welcome. As an external auditor, you access CyberPassport in read-only mode to review the report and evidence of one or more organisations that have invited you.
Step 1 — Accept an invitation
- You receive an email with the subject: "[CyberPassport] {Organisation name} invites you to review their cybersecurity assessment".
- Click the "Access the assessment" button in the email.
- Depending on your situation:
- You already have a CyberPassport account (same email address) → you are signed in directly and access the org.
- You don't have an account → you go through signup (Google or email/password — see guide 01).
📸 Screenshot location: auditor invitation email
⚠️ Important: the invitation expires 30 days after it is sent. After that, ask the organisation to re-invite you.
Step 2 — The auditor hub
Once signed in as an auditor, you land on /audit — your personal space listing the organisations you have access to.
Anatomy of the hub
- List of organisations: for each one, the name, the sector, the date of last publication, and a "View report" button.
- If you have no active access: a message inviting you to request an invitation.
📸 Screenshot location: /audit page with a list of 2-3 organisations
🟣 Tip: you can have access to several organisations at once (typical of an audit firm tracking 10 SMEs). They all appear in this hub.
Step 3 — Review an organisation's report
Click an organisation → you land on /audit/{slug} (read-only report page).
What you see
- Header: organisation name, sector, publication date, "Read only" badge.
- Scores by framework:
- NIST CSF 2.0: overall score + maturity level (1–5)
- ISO/IEC 27001:2022: same
- Cyber-Safe (if activated): exposure category + sub-domains
- nLPD: coverage rate (the mandatory requirements in Switzerland)
- Detail by domain: for each framework, scores by domain (e.g. NIST → Identify 78%, Protect 65%, etc.)
- Narrative AI report: executive summary, strengths, areas for improvement, recommendations, 90-day action plan.
- Sealing block: the report's SHA-256 hash + sealing date + link to
/verify/[hash]for public verification.
📸 Screenshot location: audit report with scores + visible sealing
Important notes
⚠️ The report is a declarative self-assessment. It does not constitute an official audit or a certification of compliance. Certifications (ISO 27001, Cyber-Safe label, etc.) require an accredited auditor.
💡 If the organisation publishes a new version while you are reviewing, you will see the most recent one at the next refresh.
Multilingual
The report adapts to your interface language (FR / EN / DE / IT). Selector in the header.
Step 4 — Review the evidence (Evidence Vault)
On an organisation's report page, the "Evidence Vault" link (top right) → takes you to /audit/{slug}/evidences.
Anatomy of the list
For each piece of evidence:
- Title + short description
- Upload date
- Expiry date (if applicable) — orange "Expired" badge if passed
- Codes of the covered controls (e.g.
A.5.1 · A.8.3 · PR.AA-01) — you immediately know which control(s) the evidence relates to - "Download" button
📸 Screenshot location: /audit/{slug}/evidences page with 3-4 pieces of evidence listed
Downloading
- Click "Download".
- A new tab opens with a temporary link (signed URL valid for 5 minutes).
- The file downloads automatically.
🟣 Tip: the download links are ephemeral. If you want to access a piece of evidence again later, click "Download" again — a new link is generated on each click.
⚠️ Important: no "Upload", "Modify" or "Delete" button appears on the auditor's side — this is by design. If you need an additional piece of evidence or an update, contact the organisation directly.
Case — no evidence
If the organisation has uploaded no evidence: a message "No evidence has been uploaded for this organisation."
Step 5 — Understand cryptographic sealing
Every published report contains a sealing block:
Sealed report · Self-hash · SHA-256 · 0x4a8b…1f2e
Sealed on 23 May 2026
Why it's useful to you
- The SHA-256 hash attests that at the moment of sealing, the report contained exactly what you are reading today.
- If the organisation modifies its assessment, a new hash will be created and the old one will be marked "replaced".
- You can publicly verify a hash on the
/verify/[hash]page (see guide 07) — useful if you keep a written record of the report and want to attest its authenticity later.
⚠️ Important for v0.9: the level of cryptographic assurance is "Self-hash" (application-level SHA-256 hash). The higher levels (qualified TSA timestamping, eIDAS signature) are planned for V1 and V2 — not delivered currently.
Limitations
- ❌ You cannot annotate a report — feature planned for V2.
- ❌ You cannot electronically sign your audit conclusion in CyberPassport — feature planned for V2 (qualified eIDAS signature).
- ❌ You cannot request a new piece of evidence from the platform — do so by email or phone.
These features are on the V2 roadmap. For now, the intended use is: the auditor reviews the SME's structured working base, then carries out their official audit separately.
Next step
→ Publicly verify a sealed report (to archive or prove authenticity)