Choosing an IT provider comes down to twelve verifiable criteria: official labels and qualifications, named skills, a written SLA, on-site response capability, a security assurance plan, a GDPR processing agreement, data location, tested backups, NIS2 requirements, exit terms, incident procedure and company solidity. Everything else is sales talk.
What are the 12 criteria to check?
- Verifiable solidity: years in business, company registration, size of the managed estate.
- Labels and qualifications awarded by a third party: ExpertCyber, ANSSI security visa and qualifications.
- Named skills: who actually works on your systems, and with which certifications.
- Written SLA: acknowledgement time, restoration time, covered hours, severity levels.
- On-site response capability and a contractual travel time.
- Security assurance plan: remote access, administrator accounts, staff departures.
- Processing agreement compliant with Article 28 of the GDPR.
- Location of data and backups, and applicable jurisdiction.
- Backups disconnected, duplicated on separate media, and restore-tested.
- NIS2 taken into account across the subcontracting chain.
- Exit terms: licence ownership, documentation, handover of credentials.
- Incident procedure: call chain, evidence preservation, notification, escalation.
Is the provider solid and verifiable?
Check three things before anything else: years in business, company registration and the size of the estate under contract. A searchable company number, filed accounts and an incorporation date tell you more than a brochure. Ask for the number of business clients and the number of devices under contract: a serious provider gives those figures without hesitating. BISPRO, for instance, has been registered since 2012 and looks after 215 business clients and 5,000 devices, for around 5,000 interventions a year.
Which labels and qualifications should you require?
Require at least one label checked by a third party. The French ExpertCyber label is awarded after AFNOR Certification audits the application file, against a framework built by Cybermalveillance.gouv.fr and the sector trade bodies. It covers system hardening, keeping systems operational and secure, and technical assistance during an incident, and it is valid for two years. You can check a provider yourself in the Cybermalveillance.gouv.fr directory, without going through them. For more regulated needs, ANSSI also issues a security visa and qualifies specialised providers: security audit (PASSI), incident response (PRIS), incident detection (PDIS) and cloud services (SecNumCloud). BISPRO holds the ExpertCyber label and is listed on Cybermalveillance.gouv.fr.
Who will actually work on my systems?
Ask for names and certifications, not an anonymous team of experts. Vendor certifications are issued to individuals and can be verified: they prove that a specific person knows how to configure the equipment you are about to hand over. Three questions are enough: who will administer my firewall, which certification does that person hold, and who covers for them during holidays. At BISPRO, founder and managing director Nicolas Bourcier is certified Stormshield CSNA and CSNE.
Should you insist on a contractual SLA?
Yes, written into the contract rather than into a sales email. A useful SLA separates acknowledgement time from restoration time, states the hours covered, defines severity levels, and sets out what happens when the commitment is missed. Without those four elements, the phrase responsive support commits to nothing. Ask how performance is reported too: a monthly intervention report can be checked, a verbal promise cannot.
Can the provider come on site, and how fast?
Many failures cannot be fixed remotely: a dead switch, a carrier outage, a server that will not restart, a camera offline. Ask the real distance between your site and the nearest engineer, then have a travel time written into the SLA. For an SME in Moselle or a local authority in the former coalfield area, a provider based in the Grand Est region can be there the same day; a support centre 600 kilometres away will not.
Does the contract include a security assurance plan?
This is the document describing how the provider secures its own access to your systems. The ANSSI guide on outsourcing identifies three major risks: loss of control over the information system, remote interventions, and shared hosting. It recommends addressing them with a security assurance plan and with model contractual clauses built into the specification. At a minimum, check how remote access is authenticated, who holds the administrator accounts, and how access is revoked when an employee leaves the provider.
Is the GDPR processing agreement signed?
It is mandatory as soon as the provider touches personal data, which is the case for any managed service. Article 28 of the GDPR requires a written contract covering, among other things: processing only on documented instructions, staff confidentiality, security measures, prior written authorisation before engaging another processor, assistance with data subject rights requests, deletion or return of the data at the end of the contract, and making available whatever your audits and inspections require. The CNIL publishes reusable example clauses. If you are told it is in the general terms, ask to see the passage.
Where will my data be hosted?
Ask for the country, the name of the data centre and the identity of the final host, including for the sub-processors of your processor. Chapter V of the GDPR governs any transfer outside the European Union: without an adequacy decision from the Commission, appropriate safeguards such as standard contractual clauses are required. A provider who cannot tell you where your backups sit will not be able to document that point during an inspection either. Ask the same question about telephony, video surveillance and email, not only about office files.
Are backups disconnected and restore-tested?
This is the criterion that decides whether you survive ransomware. Cybermalveillance.gouv.fr recommends disconnecting the backup medium after use, because a backup left attached to the network can be destroyed along with everything else; keeping several copies on different media; storing one copy away from the original data; and testing restoration regularly. Two questions settle the matter: when was the last successful restore test, and how long did it take. A backup that has never been restored is not a backup.
Does the provider take NIS2 into account?
If your organisation falls within the scope of NIS2, your provider becomes part of your compliance. Directive (EU) 2022/2555, Article 21(2), sets a baseline of minimum measures including supply chain security, in particular the security-related aspects of the relationship between the entity and its direct suppliers or service providers (point d), as well as business continuity and backup management (point c). In France, the transposition law had not been enacted when this article was written; ANSSI publishes progress updates on its MonEspaceNIS2 platform. A provider hearing about this for the first time in your meeting will not help you document the requirement.
Will I be able to switch providers without losing everything?
Deal with the exit before the entry. Have the contract state: ownership of licences and domain names, handover of technical documentation and the asset inventory, return of administrator accounts and passwords, and the length and cost of the transition period. A provider who refuses to hand over the administrator credentials for your own equipment is creating dependency, not a service relationship. The GDPR separately requires personal data to be deleted or returned when the service ends.
What happens during a cyberattack?
Ask for the written procedure, not an intention. Who do you call at three in the morning, on which number, and who decides to isolate the network? Does the provider know how to preserve technical evidence before reinstalling everything, which determines whether you can file a criminal complaint? Will it help you notify the CNIL when personal data is involved? Can it escalate to a PRIS-qualified incident response provider when the incident exceeds its scope? Test the call chain once a year, outside a real incident.
One provider or several?
A single point of contact removes grey areas, provided the scope is genuinely covered. The classic multi-vendor scenario: IP telephony goes down, the carrier blames the local network, the integrator blames the carrier, and nobody turns up. List what you need covered — workstations, servers, network, IP telephony, carrier access, hosting, video surveillance, alarms, staff awareness training — then check line by line who answers for each. BISPRO covers those areas and is also a telecom operator, which removes one of the most common blame handovers.
How long does it take to check all this?
About an hour, if you ask for the documents up front. Request in writing, before any quote: the framework contract and its SLA appendices, the security assurance plan, the GDPR processing agreement, the professional liability insurance certificate, and the list of labels and qualifications with their validity dates. Providers able to send those five documents within forty-eight hours are already a useful shortlist.
Where can you check this information yourself?
- ExpertCyber label and provider directory: https://www.cybermalveillance.gouv.fr/tous-nos-contenus/label-expertcyber/decouvrir-le-label-expertcyber
- How to find a qualified professional (Cybermalveillance.gouv.fr): https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/cybersecurite-comment-trouver-un-professionnel-qualifie
- Backup good practice (Cybermalveillance.gouv.fr): https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/sauvegardes
- ANSSI guide on outsourcing and information system security: https://messervices.cyber.gouv.fr/guides/externalisation-et-securite-des-systemes-dinformation-un-guide-pour-maitriser-les
- ANSSI security visa and qualifications: https://cyber.gouv.fr/le-visa-de-securite
- Article 28 GDPR, processor obligations (CNIL): https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre4
- Example processing clauses (CNIL): https://www.cnil.fr/fr/sous-traitance-exemple-de-clauses
- Transfers outside the European Union, Chapter V GDPR (CNIL): https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre5
- Directive NIS2 (EU) 2022/2555, Article 21: https://eur-lex.europa.eu/legal-content/FR/TXT/HTML/?uri=CELEX:32022L2555
- Status of the NIS2 transposition in France (ANSSI): https://aide.monespacenis2.cyber.gouv.fr/fr/article/avancement-de-la-transposition-de-la-directive-nis-2-1b3j1da/

