ExpertCyber Monaco: Vetting IT Firms
Digital Strategy·7 min read·30 July 2026

ExpertCyber Monaco: Vetting IT Firms

Monaco now has an official label for cybersecurity and IT service providers. Here's how ExpertCyber Monaco works and how to use it when you hire.

The Hardest Purchase a Small Business Makes

Ask a Monaco business owner how they chose their IT provider and you usually get the same answer: someone recommended them, or they were already there when the company started. Nobody audited them. Nobody asked to see evidence that the person with domain-admin rights over the company's systems actually knows how to secure them.

That is not carelessness — it is a genuine information problem. Cybersecurity is one of the few purchases where the buyer has almost no way to assess the seller. You cannot evaluate a firewall configuration. You cannot tell a competent incident responder from a confident one until something goes wrong, at which point the assessment is expensive.

Monaco has now built a formal answer to that problem. The Principality has established ExpertCyber Monaco, a label for IT service companies that can demonstrate real cybersecurity expertise, run under the authority of the AMSN — the Agence Monégasque de Sécurité Numérique, Monaco's national digital security agency. It is a small piece of infrastructure, but it changes a decision that most companies currently make on instinct.

What the Label Actually Is

ExpertCyber Monaco rests on two texts published in July 2025: Sovereign Ordinance No. 11.325 of 10 July 2025, which gives the AMSN the power to label providers, and Ministerial Order No. 2025-342 of 3 July 2025, which sets the assessment criteria and how the scheme is administered.

The mechanics are worth understanding, because they explain why the label carries weight:

  • The AMSN owns the scheme. Its director grants the label, maintains the register of labelled providers, and can suspend or withdraw the label if a provider stops meeting the requirements.
  • AFNOR Certification carries out the conformity checks against the published requirements, so the assessment is not self-declared by the provider.
  • Individual staff working under the label are subject to security clearance, renewed on a three-year cycle, and the provider must keep an up-to-date register of who is authorised.

The last point is the one most buyers miss. The label is not just a company badge — it attaches to named people. That is a meaningfully higher bar than a marketing claim on a website.

What a Provider Has to Prove

The assessment is not a single exam. Broadly, a candidate provider is examined on four fronts:

  1. Administrative and regulatory compliance, including how it handles personal data. In Monaco that means Law No. 1.565 of 3 December 2024 and the supervision of the APDP — not the EU's GDPR, which does not apply to Monaco directly.
  2. The quality of the security services it offers — what it actually sells, how it is scoped, and how incidents are handled.
  3. The competence of its staff, evaluated individually rather than at company level.
  4. Technical skill, tested under time pressure rather than described on paper.

The subject matter covered includes recognising and characterising cyberattacks, securing the architecture of an information system, analysing software vulnerabilities and security tooling, and understanding which legal frameworks and jurisdictions apply when an incident becomes a criminal matter.

The scope is deliberately practical for smaller organisations. It covers professional information systems, business telephony, and the administration and protection of websites — which is to say, the three things a typical Monaco SME actually depends on day to day.

Who This Is Aimed At

ExpertCyber Monaco targets IT service companies serving professional clients: the firms that install systems, maintain them, and get called when something breaks. In other words, the exact category of supplier that most small and mid-sized Monaco businesses rely on and have the least ability to evaluate.

If you run a company with somewhere between five and a hundred people — a professional services firm, an agency, a retailer, a family office, a hospitality group — you almost certainly have one of these providers, and they almost certainly hold more access to your business than anyone outside it.

It is worth distinguishing this from the other Monaco scheme you may have heard about. The PINH qualification for cloud computing and hosting providers, set out in Ministerial Order No. 2026-59 of February 2026, covers where your data lives. ExpertCyber Monaco covers who touches your systems. Different questions, different registers, both maintained by the AMSN. A well-run business ends up caring about both.

How to Use It When You Hire

The label only helps if you actually put it into a procurement conversation. Some practical ways to do that:

Check the register before you sign, not after. The AMSN maintains the list of labelled providers, and AFNOR publishes information about the scheme. Verify directly at the source rather than trusting a logo on a supplier's homepage — labels can be displayed after they have lapsed.

Ask which named individuals are covered. Because the label attaches to cleared staff, "our company is labelled" and "the engineer assigned to your account is covered" are not the same statement. Ask for the second one.

Do not treat an unlabelled provider as disqualified. The scheme is young and the register is still filling out. Plenty of competent people in Monaco have not gone through it yet. The label is strong positive evidence; its absence is simply a prompt to ask harder questions.

Use it as a structure for your own questions even if you stay with your current supplier. The four assessment areas above make a decent agenda for an annual review: who has access, how incidents are handled, what happens to personal data, and who on the team is actually qualified.

Separate the roles. The firm that manages your network is rarely the right firm to build and secure your public-facing site. If your website handles enquiries, bookings, or client data, its security belongs with whoever does your web development and website maintenance — with clear, written ownership of updates, backups, and access.

Where This Sits in the Bigger Picture

Monaco is steadily building a set of official reference points that let businesses check claims instead of trusting them: the APDP as an active data protection authority under Law No. 1.565, the PINH qualification for cloud and hosting, and now a label for the people who look after your systems. None of these is a compliance obligation you have to meet. All of them are tools that shift the balance of information toward the buyer.

That matters more in Monaco than in a larger market. The supplier pool is small, relationships are long, and switching is socially awkward. An objective external standard gives you a neutral reason to ask a direct question, which is often the harder part.

One caveat worth stating plainly: schemes like this evolve, registers change, and the details of eligibility and renewal are administered by the AMSN. If a supplier decision or a compliance question turns on the specifics, verify with the AMSN directly and take professional advice — this article is orientation, not legal counsel.

If you would like help working out which parts of your digital estate need this level of scrutiny — and which are fine as they are — get in touch. We can look at your site, your data handling under APDP rules, and where your digital strategy and your supplier relationships need to be tightened up.

cybersecurityexpertcyberamsnmonaco businessmonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch