“SPAC Alliance provides a bridge for knowledge and expertise between the logical and physical security worlds, which were previously largely disconnected. It therefore made perfect sense for us to contribute to this initiative by sharing our experience in compliance.”
Jean-Luc Garnier - CEO, Trust & Cie
Could you tell us about your business and development priorities?
Trust & Cie is an audit and consulting firm specialising in cybersecurity. Qualified as a PASSI (Information Systems Security Audit Service Provider) by ANSSI in 2025, the firm can demonstrate the rigour of its practices, the breadth of its auditors’ expertise and the quality of its procedures, serving companies of all sizes. As an independent firm committed to strict ethical standards, Trust & Cie enables organisations to approach their compliance process with complete confidence. We are qualified to conduct “Organisational and Physical Audits” (with a focus on governance), “Architecture Audits” (covering proprietary, hybrid and cloud systems) and “Configuration Audits” (to ensure that security measures are relevant and effective).
Why did you join SPAC Alliance and its ecosystem of European stakeholders?
The “physical security” dimension is becoming increasingly important in compliance assessments, while access control systems now go far beyond simple “open / closed” mechanisms. SPAC Alliance has fully understood this new dimension and provides a bridge for knowledge and expertise between the “logical” and “physical” security worlds, which were previously largely disconnected. It was therefore highly relevant for us to contribute to this initiative by sharing our experience in compliance. We are also frequently consulted on issues relating to the forthcoming implementation of the CRA (Cyber Resilience Act), which covers all products “with digital elements”. The Alliance’s ecosystem is naturally particularly concerned by these issues, as well as by the impact that the NIS 2 Directive may have on its activities.
What benefits can the SSCP protocol bring to the security market?
Any solution that strengthens security in organisations’ day-to-day activities should be promoted! As an open protocol with CSPN security certification, SSCP is an ideal candidate for building resilient, interoperable and easily auditable systems. We take the same view of SSCP as we do of TLS, SSH, SFTP and other open protocols whose security can be demonstrated.
What does this mean for you as a PASSI auditor?
As mentioned above, an auditor will value the use of a secure and auditable protocol within the audited organisation’s infrastructure. The evidence that we may collect from an access control system running SSCP can be readily compared against regulatory requirements. The systems themselves can be audited using trusted tools, and some have even obtained CSPN certification in their own right, which will greatly facilitate our assessment!
How do you view standards and certifications in the security market?
As PASSI auditors, standards and certifications are the fundamental building blocks of our work! We conduct daily regulatory monitoring to maintain a thorough understanding of the various texts, the areas in which they overlap, their possible interpretations in different business contexts and the wide range of possible implementations. Although they can sometimes be complex to comply with, they undeniably provide a beneficial framework for the widespread adoption of security practices in a world where security is constantly being tested by criminal organisations. Complying with the regulations applicable to your field means choosing to engage a consulting firm at an early stage, rather than calling in a remediation provider once your systems have been compromised!
