CyberScore: prepare and maintain your rating between audits
France's CyberScore law requires major digital platforms to display a cybersecurity audit result to consumers, Nutri-Score style. That audit is performed non-intrusively, from openly accessible information — precisely what Purplemet observes and monitors continuously. See what the auditor will see, before they do.
CyberScore at a glance
What the French CyberScore law requires,
in three points
- An audit displayed to the public French law no. 2022-309 (article L.111-7-3 of the Consumer Code) requires digital platforms above audience thresholds (set by decree, in the tens of millions of monthly unique visitors) to display the result of a cybersecurity audit, as a visual A-to-F rating, on their home screen.
- A qualified, non-intrusive, renewable audit The audit is performed by an ANSSI-qualified provider (PASSI), based on openly and freely accessible information, non-intrusively. It is valid for 12 months and must be renewed within 3 months of expiry.
- Criteria that include internet exposure The audit grid covers data protection, control of the digital service, the level of outsourcing and the level of internet exposure. Penalties for non-compliance: up to €375,000 for a legal entity.
Where Purplemet fits
Our method is the audit's method — made continuous
The CyberScore audit observes your platform the way an attacker would: from the outside, without intrusion, from open information. That is exactly Purplemet's method — with one difference: the audit is an annual snapshot, Purplemet is continuous monitoring.
- Prepare the audit: see what the auditor will see Before the audit, Purplemet maps what your platform actually exposes — applications, subdomains, technologies, versions — and reveals externally visible weaknesses. No bad surprise on audit day: you fix before the rating, not after.
- Maintain your level between audits A rating is valid for 12 months; your platform changes every week — deployments, new components, published CVEs. Purplemet continuously monitors your exposure and alerts you as soon as a change degrades what the next audit will measure. Your rating stops being an annual discovery.
- Document control of your digital service The audit grid values control of the service and of its exposure. Purplemet's continuous inventory feeds that demonstration: at any moment, you know what is exposed and in what state.
Common questions about the CyberScore and Web ASM
Can Purplemet issue a CyberScore?
No. The CyberScore results exclusively from an audit performed by an ANSSI-qualified provider (PASSI), following the official grid. Purplemet is not an audit body: it is a continuous monitoring tool that lets you prepare for that audit and maintain your level between evaluations.
How does a CyberScore audit work?
The audit is performed by a qualified provider, based on openly and freely accessible information, non-intrusively. It evaluates data protection, control of the digital service and the level of internet exposure, among others. The resulting rating (A to F) is valid for 12 months and must be displayed visibly on the service.
How does a Web ASM tool help with the CyberScore?
Because the audit observes your platform from the outside, without intrusion — exactly the viewpoint of a web attack surface management tool. Continuous monitoring shows you permanently what the auditor will see punctually: you fix before the audit, and you immediately detect anything that could degrade the next evaluation.

