For auditors · Read access

Audit an SME, without Excel, without lost attachments.

CyberPassport gives you a structured, time-stamped, read-only view of the cyber report of every SME you audit. Same data for everyone, same equivalences across frameworks, same auditable evidence — you save time and raise your assurance level.

See the workflow
Designed for

Four professions, one single source of truth.

CISOs & risk teams

Internal auditors of large groups. Assess your suppliers without sending one more questionnaire.

Audit firms

Big 4 and specialised cyber firms. Standard format, encrypted evidence, billable time savings.

Regulators & authorities

FINMA, cantonal authorities. A read-only, immutable view, exportable in an auditable format.

Cyber insurers

Price more accurately. Underwrite with confidence. Reduce claims with standardised assessments.

Audit workflow · 4 steps

From the SME to your validated

Each step leaves a time-stamped trace. No information is lost, no version contradicts another. The report you read is exactly the one the SME published.

01 — SME

The SME answers

In business language, not technical. They upload their evidence to an encrypted vault. Each answer is versioned.

SME side
02 — SME

They invite you

The SME generates a secure auditor access link, dated and revocable. You receive an invitation by email.

SME side
03 — Auditor

You review

Read-only view of the report, evidence and history. Multi-framework mapping to align your controls.

Auditor side
04 — Auditor

You validate

You validate your audit conclusion, attached to the report's hash. The SME keeps the proof, you keep the trace.

Auditor side
Auditor view · Preview

The same report, two faces.

On the SME side, it's the editor — where they fill in, update and upload evidence. On the auditor side, it's the showcase — read-only, immutable, sealed. Toggle to see.

Audit / Atelier Baume & Cie / ISO 27001 · A.8 Asset ManagementRead-only · auditor
Domain · A.8

Asset Management

Sealed · v.4.2Published on Apr 18, 2026 · 14:32 CET
Domain conformity
94%
Validated controls
9/ 10
Attached evidence
17
Recent evidence — time-stamped vault
Inventaire-actifs-2026-Q1.pdf· 2.4 MB
0x4a8b·1f2e11 avr. · 09:14Vérifié
Classification-données-v3.xlsx· 184 KB
0x9d12·3b7104 avr. · 16:42Vérifié
Capture-MDM-Intune.png· 612 KB
0xe8a3·d44f02 avr. · 11:08Vérifié
Multi-framework mapping
ISO ↔ NIST ↔ Cyber-Safe. This A.8 section corresponds to NIST PR.AC-1 and Cyber-Safe N2.4. Your auditors can cross-reference controls without reading three times.

What you'll find on the auditor side.

Four features designed with CISOs, Big 4 and insurers. No gadget features, no generative AI rewriting what the SME declared — the raw truth, just better organised.

Read-only view

You see exactly what the SME published — no more, no less. No edits possible, no ambiguity about which version you are reading.

Read-only

Evidence vault

Every supporting document is stored in an encrypted vault and time-stamped at upload. You see the date and size — the evidence is tied to the report.

Time-stamped vault

History & drift

Every revision of the report since its creation. See what changed between two audits — and who changed what, exactly.

Time travel

Multi-framework mapping

An answer on ISO 27001 shows you the equivalent controls in NIST CSF and Cyber-Safe. No need to read the same thing three times.

Cross-walk
Supported frameworks

Three today, more to come.

ISODisponible

ISO/IEC 27001

International reference standard for information security management systems.

93 controls · 14 domains
NISTDisponible

NIST CSF v2.0

NIST Cybersecurity Framework, structured around the 6 functions Govern / Identify / Protect / Detect / Respond / Recover.

108 sub-categories · 6 functions
CSDisponible

Cyber-Safe (CH)

Swiss label tailored to SMEs. Levels 1 to 3, designed to become the reference in French-speaking Switzerland.

42 controls · 3 levels
Roadmap

Upcoming additions

These frameworks will join the platform in upcoming versions, in order of customer priority.

FINMANIS2GDPR/nFADPSOC 2
Auditor access

A modest subscription, a major time saver.

Auditor access is billed directly to your firm or your group — not to the SME. That is what guarantees your independence.

Auditor Access · annual

CyberPassport Auditor

On request
  • Unlimited audits on the SMEs that invite you
  • Read-only view, evidence vault, history
  • Multi-framework mapping (ISO · NIST · Cyber-Safe)
  • PDF & Excel export for your files

Auditor questions.

If yours isn't listed, ask it — one of our (human) analysts will reply within the day.

From their workspace, the SME generates an invitation link to your professional email address. The link is dated, revocable and tied to your identity. You create your auditor account in two clicks if you don't already have one, then access the report in read-only mode.

The next audit you save is the first one on CyberPassport.

Request your auditor access today. Let's discuss the terms together.