The PASSI qualification (Information Systems Security Audit Provider) is issued by DGSSI to audit providers, under implementing decree 2-21-406 of Law 05-20.
Last updated — August 22, 2026
Relevant to providers seeking to perform security audits on behalf of critical infrastructure operators or administrations subject to DNSSI, and to any organization wanting to verify an audit provider's qualification before engaging it.
The qualification is issued to the provider, while each auditor is individually evaluated and receives an attestation specifying the audit domain covered, the qualification level, the validity period, and the auditor's attachment to the qualified provider. To become qualified, a provider must in particular have an organizational structure dedicated exclusively to security audit, be qualified in at least 3 of the 6 audit domains defined by the framework, have at least one qualified auditor per domain, and, for Class A, demonstrate majority Moroccan-owned capital and auditors of Moroccan nationality. The process has two stages: dossier review, followed by evaluation by a body designated by DGSSI.
Deadlines
The framework does not set a single timeline applicable to all providers: the validity period of a qualification is specified in the attestation issued at the end of the evaluation process, and renewal follows the terms set by DGSSI.
Sanctions
A non-qualified provider cannot claim the PASSI qualification. For a client organization, engaging a non-qualified provider for an audit required under Law 05-20 exposes it to non-compliance with its own regulatory obligations.
Request a copy of the audit provider's qualification attestation
Verify the audit domain(s) covered by the qualification
Verify the attestation's validity date
Verify that the auditor assigned to the engagement is attached to the qualified provider
If in doubt, consult the list of qualified providers published by DGSSI
| Framework | Covered |
|---|---|
| loi-05-20-dgssi | ✓ |
Get the checklist by email.
A qualification issued by DGSSI to information systems security audit providers, under decree 2-21-406 implementing Law 05-20.
Our team includes an auditor who holds a PASSI auditor attestation issued under the DGSSI framework. Our audit methodologies are aligned with the PASSI qualification requirements framework (V2.1).
By requesting a copy of its qualification attestation, verifying the audit domains covered and the validity date, and, if needed, consulting the list of qualified providers published by DGSSI.
A PASSI auditor attestation is issued individually to an auditor evaluated on a given domain. A company-level PASSI qualification is issued to the provider itself, following a separate process covering its organizational structure and its coverage of several audit domains.
Yes, an audit can retain methodological and operational value outside the regulated scope. The PASSI qualification becomes necessary when the audit is specifically required under Law 05-20.