XMCO
XMCO is a French sovereign cybersecurity consulting firm providing penetration testing, incident response, and audit services to over 450 enterprise and public-sector clients, including more than half of CAC40 and SBF120 companies.
- Company typePrivate
- Founded2002
- HeadquartersParis, France
- Headcount51–100
- GTM typeB2B
- OfferingServices
What XMCO does
XMCO is a French sovereign cybersecurity consulting firm founded in 2002 by Marc Behar and headquartered in Paris, with two additional offices in Nantes and Labège. The firm operates CERT-XMCO, an accredited computer emergency response team recognized by CERT-FR, TF-CSIRT, and Trusted Introducer, and serves as a trusted third party for the cybersecurity of French enterprises and public institutions. XMCO holds two of the most demanding European credentials in the field — PASSI qualification on all five scopes since 2020 and QSA certification since 2009 — making it a credentialed auditor of payment systems and a broadly qualified penetration testing provider for regulated buyers.
XMCO's service catalog spans intrusion testing, red team engagements, incident response, configuration audits, source code audits, and a newly introduced AI/LLM Security Audit service line. Underpinning these services are five proprietary platforms: Yuno (vulnerability intelligence), Serenety (Continuous Threat Exposure Management), IAMBuster (Active Directory auditing), Scanly (network vulnerability scanning), and Concerto (audit due diligence). These tools convert two decades of accumulated security engineering and incident data into productized, repeatable assets rather than purely manual consulting.
Commercially, XMCO operates on a mission-based consulting model, executing more than 700 audit missions per year across approximately 450 active enterprise clients and 110 CERT subscribers. More than half of CAC40 and SBF120 companies are clients, alongside public-sector buyers reached via the CAIH and UGAP government frameworks. The firm employs approximately 120 people, holds an 8-year average consultant tenure, and has been funded through two minority private equity rounds (Initiative & Finance in 2017, Entrepreneur Invest in 2024), retaining founder-led control under a sovereign-French positioning.
XMCO firmographics
Firmographics- Name
- XMCO
- Legal name
- XMCO
- Website
- https://xmco.fr
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- XMCO is a French sovereign cybersecurity consulting firm providing penetration testing, incident response, and audit services to over 450 enterprise and public-sector clients, including more than half of CAC40 and SBF120 companies.
- Ownership category
- akta.pro rank
XMCO industry classification
Industry- Product category
- Cybersecurity Consulting & Managed Security Services
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
Keywords
Where XMCO is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices3 records
Markets served
XMCO business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Services - Audit & Consulting: Project-based consulting engagements including penetration tests, Red Team operations, architecture audits, compliance assessments (PCI DSS, ISO 27001), and organizational GRC audits. Priced per mission, with engagements including kickoff meeting, technical delivery, debrief, deliverables, and presentation. XMCO maintains no reselling or material integration businesses.
- Managed Services - Yuno (Vulnerability Intelligence): Subscription-based vulnerability monitoring platform providing daily qualified alerts, CVE tracking, and ticketing. Delivered as a managed service with a collaborative client portal.
- Managed Services - Serenety (CTEM): Continuous Threat Exposure Management service with modules for EASM, Data Leak, Dark Web Intelligence, and Brand Monitoring. Billed on a managed services subscription model.
- Managed Services - IAMBuster (AD Auditing): Active Directory security audit tool delivered as a managed service engagement.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Quote-based engagement model — no public pricing |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
XMCO product offering
Product offeringCore offering
XMCO delivers cybersecurity consulting and managed services through three Business Units: Audit & Conseil (40+ audit/pentest types), the Factory (proprietary tools Yuno, Serenety, IamBuster, Scanly, Concerto), and Managed Services (Yuno vulnerability intelligence, Serenety CTEM, CERT-XMCO incident response). The firm also conducts PCI DSS QSA certification audits and holds PASSI qualification across all five scopes for compliance-driven engagements.
Product overview
XMCO is a French sovereign cybersecurity consulting firm founded in 2002, operating as a single unified practice organized into three Business Units: Audit & Conseil, the Factory, and Managed Services. The portfolio is anchored by two proprietary platforms — Yuno (vulnerability intelligence and threat monitoring with a built-in remediation ticketing API) and Serenety (Continuous Threat Exposure Management covering EASM, Data Leak Detection, Dark Web Intelligence, and Brand Monitoring) — complemented by sub-tools IamBuster (Active Directory auditing) and Scanly (internal scanning). The service layer encompasses over 40 distinct audit and pentest types including Red Team, phishing simulation, PCI DSS QSA certification, CI/CD security, ICS/OT, Mainframe, and AI/LLM audits, all delivered by PASSI-qualified consultants with a proprietary methodology rooted in ISO 19011. The CERT-XMCO operates as the firm's internal CSIRT, feeding the managed services and enriching the Yuno knowledge base.
Differentiator
Problem solved
Functional benefit
Brands
- Yuno: Vulnerability and cyber threat monitoring platform that centralizes sources, filters relevant alerts, and provides manually qualified vulnerability analysis with actionable recommendations.
- Serenety
- IamBuster
- Scanly
Quantifiable outcome
- 120 consultants with average 8 years tenure delivering 700+ audit missions per year
- +3 more outcomes
Companies that use XMCO
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
XMCO technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
XMCO partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information)coreXMCO's CERT-XMCO is officially recognized by the French government CERT-FR, facilitated through ANSSI's national cybersecurity framework. XMCO also holds PASSI qualification from ANSSI. ANSSI's logo appears on XMCO's website.
- Trusted IntroducercoreCERT-XMCO is recognized by the Trusted Introducer, enabling it to collaborate with other European CERTs and receive threat intelligence from the Trusted Introducer network.
- TF-CSIRT (Task Force on Computer Emergency Response Teams)coreCERT-XMCO is a member of TF-CSIRT, the European task force for computer emergency response teams, facilitating cross-border threat intelligence sharing.
- InterCERT FrancecoreCERT-XMCO participates in InterCERT France, the French national CERT network, which coordinates incident response and threat intelligence across French organizations. XMCO's logo appears alongside InterCERT France on its website.
- Aston Martin RacingminorAston Martin Racing is listed as a partner since 2019 on XMCO's LinkedIn content. The partnership involves brand association and presence at racing events (Aston Martin F1 team).
- CANUTminorCANUT (cyber resilience center) logo appears on XMCO's website, suggesting a cooperative relationship within the French cybersecurity ecosystem.
- CAIH ( Centrale d'Achat de l'Informatique Hospitalière)minorCAIH (Central purchasing body for hospital IT) logo appears on XMCO's website, indicating XMCO is an approved vendor on the CAIH framework for healthcare cybersecurity services.
- UGAP (Union des Groupements d'Achats Publics)minorUGAP (French public procurement central purchasing body) logo appears on XMCO's website, indicating XMCO is an approved vendor on the UGAP framework for public sector cybersecurity services.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
XMCO competitors and assessment
Company assessmentBroad incumbents
- Devoteam: European IT and digital transformation consultancy with a dedicated cybersecurity practice covering GRC, cloud security, and offensive testing. Serves overlapping CAC40 and mid-market French clients but competes as a broader transformation vendor rather than a cybersecurity pure-player.
- Sopra Steria: Large European IT services firm with a cybersecurity division delivering security audits, identity management, and managed security to French banks, public sector, and defense. Overlaps with XMCO on pentest and ISO/PCI compliance work but operates at much greater scale.
- Thales (Cybersecurity): French sovereign defense and cybersecurity group offering consulting, compliance, and managed security services, including Cipher/Datacryptor product lines. Competes with XMCO for sovereign, defense, and critical-infrastructure cybersecurity engagements.
- Capgemini (Cybersecurity): Global systems integrator with a sizable cybersecurity consulting arm covering GRC, identity, cloud security, and SOC services. Competes with XMCO for CAC40 enterprise security mandates, typically embedded in larger transformation programs.
Direct peers
- Advens: French cybersecurity pure-player focused on managed detection, SOC, and offensive security for large French enterprises. Comparable in size and customer profile to XMCO and competes head-to-head on pentest, CTI, and SOC contracts.
- Orange Cyberdefense: French MSSP arm of Orange, providing managed detection, incident response, threat intelligence, and pentest services across France and Europe. Directly competes with XMCO's Serenety CTEM and CERT-XMCO offerings into the same enterprise buyer base, with the added leverage of Orange's telecom and sovereign identity.
- CS Group: French cybersecurity and mission-critical systems integrator serving defense, space, and critical-infrastructure clients. Comparable in sovereign positioning and in scope of cyber audit, ICS/OT, and CERT-adjacent services.
- Wavestone: French-headquartered consultancy with a major cybersecurity and digital trust practice serving CAC40/SBF120 clients. Closest direct competitor in the French enterprise cybersecurity consulting market, with a broader transformation footprint but overlapping pentest, GRC, and cyber resilience offerings.
Emerging players
- Gatewatcher: French cybersecurity vendor offering NDR (network detection) and CTEM-adjacent technologies, recognized as a sovereign provider. Adjacent rather than head-to-head: a potential partner for XMCO managed services rather than a direct consulting peer.
- Sekoia.io: French CTEM/SOC platform vendor offering threat intelligence, EASM, and managed detection SaaS. Overlaps conceptually with XMCO's Serenety and Yuno offerings but competes from a product/SaaS angle rather than consulting.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
XMCO social profiles
Digital presenceXMCO compliance and trust
Trust signalCompliance6 records
XMCO financial estimates
Financial estimateRevenue estimate
Valuation estimate
XMCO leadership team
Management profileNumber of profiles
Profiles2 records
XMCO subsidiaries and ownership
Company hierarchySubsidiaries1 record
XMCO funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
XMCO M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about XMCO
What does XMCO do?
XMCO delivers cybersecurity consulting and managed services through three Business Units: Audit & Conseil (40+ audit/pentest types), the Factory (proprietary tools Yuno, Serenety, IamBuster, Scanly, Concerto), and Managed Services (Yuno vulnerability intelligence, Serenety CTEM, CERT-XMCO incident response). The firm also conducts PCI DSS QSA certification audits and holds PASSI qualification across all five scopes for compliance-driven engagements.
Is XMCO a public or private company?
XMCO is a private company. It is classified as venture growth investor backed and is currently operating.
When was XMCO founded?
XMCO was founded in 2002. It employs 51 to 100 people.
Where is XMCO based?
XMCO is headquartered in Paris, France, in the Europe region.
How does XMCO make money?
Four revenue lines are on record. Professional Services - Audit & Consulting is the primary driver. The others are managed Services - Yuno (Vulnerability Intelligence), managed Services - Serenety (CTEM) and managed Services - IAMBuster (AD Auditing).
Who are XMCO's main competitors?
Broad incumbents on record are Devoteam, Sopra Steria, Thales (Cybersecurity) and Capgemini (Cybersecurity). Direct peers are Advens, Orange Cyberdefense, CS Group and Wavestone. Emerging players are Gatewatcher and Sekoia.io.
Does XMCO have an API?
Yes. The Yuno platform includes an API that allows synchronization with clients' internal systems for alert ticket management — enabling organizations to assign, track, and close remediation actions directly from the platform with full traceability of decisions taken.
What industry is XMCO in?
XMCO's product category is Cybersecurity Consulting & Managed Security Services. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 541519 and its SIC code is 7370.