Suspect a breach? Report it immediately — response within 1 hour.Report an incident

PASSI Qualification (Morocco)

The PASSI qualification (Information Systems Security Audit Provider) is issued by DGSSI to audit providers, under implementing decree 2-21-406 of Law 05-20.

Last updatedAugust 22, 2026

Who's affected

Relevant to providers seeking to perform security audits on behalf of critical infrastructure operators or administrations subject to DNSSI, and to any organization wanting to verify an audit provider's qualification before engaging it.

What the framework requires

The qualification is issued to the provider, while each auditor is individually evaluated and receives an attestation specifying the audit domain covered, the qualification level, the validity period, and the auditor's attachment to the qualified provider. To become qualified, a provider must in particular have an organizational structure dedicated exclusively to security audit, be qualified in at least 3 of the 6 audit domains defined by the framework, have at least one qualified auditor per domain, and, for Class A, demonstrate majority Moroccan-owned capital and auditors of Moroccan nationality. The process has two stages: dossier review, followed by evaluation by a body designated by DGSSI.

Compliance steps

01

Request a copy of the audit provider's qualification attestation

02

Verify the audit domain(s) covered by the qualification

03

Verify the attestation's validity date

04

Verify that the auditor assigned to the engagement is attached to the qualified provider

05

If in doubt, consult the list of qualified providers published by DGSSI

Common mistakes

  • Confusing an individually-issued PASSI auditor attestation with a company-level PASSI qualification
  • Not verifying the audit domain covered before engaging a provider
  • Not verifying the attestation's validity date before starting the engagement

Cross-mapping to other frameworks (UCM)

FrameworkCovered
loi-05-20-dgssi

Downloadable resource

Get the checklist by email.

Frequently asked questions

What is the PASSI qualification?

A qualification issued by DGSSI to information systems security audit providers, under decree 2-21-406 implementing Law 05-20.

Is EBH Security PASSI qualified?

Our team includes an auditor who holds a PASSI auditor attestation issued under the DGSSI framework. Our audit methodologies are aligned with the PASSI qualification requirements framework (V2.1).

How can I verify that a provider is genuinely PASSI qualified?

By requesting a copy of its qualification attestation, verifying the audit domains covered and the validity date, and, if needed, consulting the list of qualified providers published by DGSSI.

What is the difference between a PASSI auditor attestation and a company-level PASSI qualification?

A PASSI auditor attestation is issued individually to an auditor evaluated on a given domain. A company-level PASSI qualification is issued to the provider itself, following a separate process covering its organizational structure and its coverage of several audit domains.

Does an audit performed by a non-PASSI-qualified provider still have value if my organization is not subject to Law 05-20?

Yes, an audit can retain methodological and operational value outside the regulated scope. The PASSI qualification becomes necessary when the audit is specifically required under Law 05-20.