ACG Cybersecurity
Paris-based independent cybersecurity consultancy specializing in penetration testing, ISO 27001 implementation, and regulatory compliance audits (GDPR, PCI DSS, NIS).
Visit Website ↗ + Add to CompareOverview
ACG Cybersecurity is a vendor-independent consulting firm based in Paris that performs technical security audits, penetration testing, and compliance work for mid-market and enterprise clients across France. Its practice covers internal and external intrusion testing, infrastructure and code configuration audits, and the implementation of ISO 27001 information security management systems and ISO 22301 business continuity plans, alongside GDPR, PCI DSS, HDS (health data hosting), NIS, and DSP2 compliance work.
Founded in 2019, the firm has grown into a recognized player in the French cybersecurity consulting market, holding ANSSI PASSI qualification (France’s official accreditation for security audit providers used in regulated and public-sector engagements) and ISO 27001:2022 certification of its own operations. Its consultants carry Lead Auditor and Lead Implementer ISO 27001 credentials, positioning the firm for governance and audit work rather than product sales.
As a boutique consultancy rather than a software vendor, ACG Cybersecurity’s relevance rests on its regulatory credentials and audit methodology rather than a proprietary platform. It is best understood as a compliance and assurance partner for organizations navigating French and EU security regulation, not a technology differentiator in its own right.
Innovation Matrix Assessment
As a services firm rather than a product company, ACG's pace of innovation is measured by credential and scope expansion (ISO 27001:2022 recertification, PASSI qualification) rather than shipped features; steady but not fast-moving.
Delivers a defined menu of audit, pentest, and ISMS implementation services with documented methodology, but has no proprietary platform or automation layer that would materially reduce customer operational burden beyond the consulting engagement itself.
Growth is visible through ANSSI PASSI qualification and membership in the Hexatrust French cybersecurity trade cluster, but there is no independently reported revenue, funding, or headcount growth data to confirm trajectory beyond a small, stable practice.
A traditional audit and consulting model; it does not introduce new technology or a materially different delivery approach relative to other ANSSI-qualified French security consultancies.
ANSSI PASSI qualification is a real, independently administered accreditation requiring documented methodology and periodic reassessment, which is a meaningful efficacy signal for audit quality, though no named client outcomes were independently verifiable.
GDPR, NIS2, PCI DSS, and DSP2 compliance pressure keeps demand for qualified French audit firms steady, but the firm's relevance is geographically bounded to the French/EU regulatory market rather than global.
Why CISOs Should Care
CISOs operating under French regulatory regimes (NIS2, HDS, ANSSI-qualified audit requirements) get a locally accredited, vendor-neutral auditor rather than a product pitch.
What Makes It Different
ANSSI PASSI qualification distinguishes it from generic security consultancies by certifying its audit methodology meets the French government's own bar for regulated engagements.
The Matrix Verdict
42/100 — EMERGING / UNRANKED
A credible, narrowly-scoped compliance and audit consultancy for the French market; useful for regulatory assurance work but not a technology or category disruptor.
Editorial Note: Claims vs. Verified Findings
ANSSI PASSI qualification and ISO 27001:2022 certification are independently verifiable third-party accreditations. Employee count, revenue, and growth figures are drawn from directory estimates (not independently audited) rather than company-disclosed financials.
Sources
Alternatives to ACG Cybersecurity
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…