PASSI Morocco 2026: DGSSI Qualification & Audit Preparation
PASSI in Morocco: who must use one, the 6 DGSSI-recognized audit domains, how to verify a provider is genuinely qualified, and how to prepare for your audit.
PASSI at a glance. A PASSI (Prestataire d'Audit de la Sécurité des Systèmes d'Information / Information Systems Security Audit Provider) is a provider whose security-audit competence has been verified and qualified by the DGSSI, Morocco's national cybersecurity authority. Public administrations, public institutions and operators of vital infrastructure (OIV) must have their regulatory security audits carried out by a qualified provider. This guide covers who is affected, what the qualification actually covers, how to verify a provider genuinely holds it, and how to prepare your organization before the audit.
What is a PASSI?
PASSI qualification is the mechanism by which the DGSSI recognizes that a provider is competent to audit the security of information systems belonging to entities subject to Morocco's national cybersecurity regulation.
It is not a simple administrative accreditation. The qualification is granted for specific audit domains, imposes requirements on the provider's own structure, and distinguishes several classes of engagement according to the sensitivity of the systems being audited.
The intent is straightforward: when an organization is legally required to have its systems audited, the state wants assurance that the auditor has verified competence to do so, rather than the audit amounting to a rubber-stamp report.
Who must use a qualified PASSI?
The obligation stems from Law 05-20 and the national information systems security directive (DNSSI). It primarily concerns:
| Entity | Audit obligation | PASSI required |
|---|---|---|
| State administrations and public institutions | Periodic security audits | Required for regulatory audits |
| Operators of vital infrastructure (OIV) | Mandatory periodic audits | Required |
| Class A systems (highly sensitive) | Homologation before production + regular audits | Required, with reinforced conditions |
| Class B systems | Periodic audits | Required for regulatory audits |
| Private SME not classified as OIV | No direct DGSSI obligation | Optional, but recommended |
If your organization falls into none of these categories, you are not required to use a PASSI. Using a qualified provider nonetheless remains good practice: the qualification is a third-party-verified competence signal, and audit findings carry more weight with a client, an insurer or a partner.
To determine your exact classification, the DGSSI compliance guide details the A/B/C class system and the criteria used to identify OIVs. You can also use our free DGSSI compliance self-assessment to position your organization in a few minutes.
The 6 audit domains covered by the qualification
PASSI qualification is not granted as a single block. It is issued per audit domain, and a provider must cover at least three of them to be qualified:
| Audit domain | What it covers |
|---|---|
| Organizational and physical audit | Policies, procedures, security governance, physical access control to premises and technical rooms |
| Architecture audit | Information system design, network segmentation, partitioning, flows between zones of differing sensitivity |
| Configuration audit | Actual settings on servers, network equipment, workstations and security solutions |
| Penetration testing | Real exploitation of vulnerabilities to assess resilience against an attacker |
| Source code audit | Review of application code for vulnerabilities and poor development practice |
| Industrial systems audit | OT/SCADA environments, PLCs, production systems: a domain in its own right, with constraints very different from conventional IT |
This granularity has an important practical consequence: a PASSI-qualified provider is not necessarily qualified for the domain you need. A firm qualified in organizational and configuration audit cannot conduct your source-code audit under cover of that qualification. Always check the match between your requirement and the domains actually qualified.
Class A and Class B: what the qualification demands of the provider
Audit engagements are split by class according to the sensitivity of the systems concerned, and the requirements on the provider vary accordingly.
For Class A engagements, covering the most sensitive systems, the regulation notably requires:
- Share capital majority-held by Moroccan nationals;
- Auditors of Moroccan nationality to carry out the engagement;
- An organizational structure dedicated exclusively to information systems security auditing.
That last requirement is worth underlining: it effectively excludes firms for which security auditing would be one side activity among many. It is a deliberate barrier to entry, intended to professionalize Morocco's security audit market.
How to verify a provider is genuinely PASSI-qualified
This is where most organizations get caught out. Commercial wording is often deliberately vague: "security audit expert", "compliant with DGSSI standards", "certified team", none of these amount to PASSI qualification.
Before signing, check these five points:
- Ask for the qualification reference, not a claim. A qualified provider holds a qualification decision issued by the DGSSI and has no reason to withhold it.
- Check the DGSSI's official list. The authority publishes qualified providers on dgssi.gov.ma. That is the only authoritative source, not the provider's brochure.
- Check the domains covered. Qualification is granted per domain. Make sure the one you need (penetration testing, code audit, industrial systems…) is within the qualified scope.
- Check the class. If your systems fall under Class A, the provider must be qualified for that class, with the associated nationality and structure requirements.
- Check it is still valid. A qualification has a validity period and is subject to renewal. A decision obtained several years ago is not necessarily still in force.
One useful distinction to close on: do not confuse the provider's PASSI qualification with the individual certifications held by its auditors (CISA, CEH, OSCP, ISO 27001 Lead Auditor…). The latter attest to a person's skills; only the former carries the national authority's recognition of the firm.
What a PASSI audit costs, and how to budget for it
There is no regulated price: the cost of a PASSI audit depends on scope, and the gap between two engagements can be substantial. The factors that actually drive the budget are:
- The number of audit domains in scope: an organizational audit alone does not cost the same as an engagement combining architecture, configuration and penetration testing.
- The size and complexity of the perimeter: number of systems, applications, sites, network zones.
- The class of the systems, which determines the depth of testing and the documentary standard expected.
- The number of auditor-days required, still the most common billing unit.
- How prepared the organization is : and this is the one lever you control before you have even chosen your auditor.
That last point is underestimated. An audit conducted on an organization with no system mapping, no formalized security policy and no asset inventory burns considerable time on basic information gathering, time that is billed, and that produces no security value. At equal scope, a prepared organization shortens the engagement and reduces the number of non-conformities recorded.
Preparing for your PASSI audit: how we help
One point of clarity first: RMG Solutions is not a PASSI-qualified provider. We do not perform the regulatory audits themselves: those must be conducted by a provider on the DGSSI's official list, for the domains and class matching your situation.
What we do is the preparation that precedes that audit:
- Gap analysis between your current state and the requirements applicable under Law 05-20 and the DNSSI;
- System mapping and asset inventory, the documentary foundation any auditor will request first;
- Documentation: security policy, procedures, access management, continuity planning;
- Technical remediation of identified gaps: configuration hardening, network segmentation, logging, backups;
- Audit readiness: assembling the evidence pack, preparing teams for interviews, dry-running the control points.
The goal is simple: that you enter the official audit with a complete file and gaps already closed, rather than discovering non-conformities in the final report. Our approach to security audits and regulatory compliance sets out this method.
If your work is part of a broader information security management program, our ISO 27001 certification guide for Morocco shows how substantially the two overlap, most of the documentary effort can be shared.
Frequently Asked Questions
What is a PASSI in Morocco?
A PASSI (Prestataire d'Audit de la Sécurité des Systèmes d'Information) is a provider whose security-audit competence has been qualified by the DGSSI, Morocco's national cybersecurity authority. Qualification is granted per audit domain (organizational and physical, architecture, configuration, penetration testing, source code, industrial systems), and a provider must cover at least three. Entities subject to regulatory audits under Law 05-20 must use a qualified provider.
Who is required to use a PASSI-qualified provider?
State administrations, public institutions and operators of vital infrastructure (OIV) must have their regulatory audits carried out by a qualified PASSI. Systems classified A and B also fall under this obligation, with reinforced requirements for Class A. A private company not classified as an OIV is not required to, but may choose a qualified provider to strengthen the credibility of its audit findings.
How do I verify a provider is genuinely PASSI-qualified?
Check the official list of qualified providers published by the DGSSI on dgssi.gov.ma: that is the only authoritative source. Then ask the provider for its qualification decision and verify three things: the audit domains actually covered, the engagement class authorized, and that the qualification is valid at the date of your engagement. Commercial phrasing such as "compliant with DGSSI standards" never amounts to qualification.
What does a PASSI audit cost in Morocco?
There is no regulated price. Cost depends on the number of audit domains in scope, the size and complexity of the perimeter, the class of the systems involved, and the number of auditor-days required. Your level of preparation directly affects the bill: a poorly documented scope lengthens the engagement, because the auditor spends billed time reconstructing information you could have supplied.
Is RMG Solutions a PASSI-qualified provider?
No. We do not perform regulatory audits subject to PASSI qualification. Our work sits upstream: gap analysis, system mapping, documentation, technical remediation and readiness for the official audit, which must be conducted by a qualified provider on the DGSSI's list.
What is the difference between a PASSI audit and ISO 27001 certification?
They are two distinct exercises. A PASSI audit is a security assessment performed by a provider qualified by the Moroccan authority, within a national regulatory framework (Law 05-20, DNSSI). ISO 27001 certification attests that an information security management system conforms to an international standard, and is issued by an accredited certification body. The two overlap substantially in documentary and technical substance, which means much of the preparation can be shared.
By RMG Solutions
Certified Odoo Partner | Cybersecurity | Infrastructure | GRC
Last updated : July 25, 2026