Coralium
Coralium is a French cybersecurity consulting firm founded in 2020, part of ADVANS Group, serving SMBs, healthcare organizations, and local governments with security audits, penetration testing, EBIOS RM risk analysis, managed SOC, compliance support, and cybersecurity training.
- Company typePrivate
- Founded2020
- HeadquartersParis, France
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Coralium does
Coralium is a French cybersecurity consulting firm (SAS) founded in 2020 and headquartered in Paris at 10 Rue de Penthièvre. It is a subsidiary of ADVANS Group and serves primarily small and medium-sized enterprises (TPE/PME) in France, with extensions into mid-sized companies (ETI), healthcare organizations, and local government entities. The company operates a portfolio organized around four pillars: Protection (security audits including Audit Flash, maturity audits, and 360° group assessments), Offensive Security (external/internal penetration testing, phishing simulation, OSINT), Process & Documentation (EBIOS RM risk analysis, PSSI/PRA/PCA plans, shared CISO/RSSI), and a Training Academy. It also offers a Micro-SOC managed security service and extensive compliance/certification support spanning ISO 27001/27017/27018/27701, GDPR, SOC 2, PCI DSS, CMMC, ANSSI SecNumCloud, and healthcare-specific frameworks.
The underlying technology stack is methodology-driven rather than proprietary-software-driven. Coralium applies established frameworks including OWASP for penetration testing and the ANSSI-developed EBIOS RM for risk analysis, with consultants certified as CEH, CREST, and ISO 27001 Lead Implementers. The Micro-SOC offering layers human expert validation on top of third-party EDR solutions rather than proprietary AI/ML detection engines. There is no public API, no disclosed SDK, and no AI-specific capabilities; the competitive product is the certified expertise of its consultants.
Commercially, Coralium bills via a Taux Journalier Moyen (TJM) daily-rate model with mission durations typically of 5-20 days and occasional complex engagements of up to ~100 days. Go-to-market is sales-led and primarily direct, supported by content marketing (a cybersecurity blog), a website-based diagnostic tool, and LinkedIn. The company reportedly secured over 60 clients by 2021, with named customers spanning startups (Angelaw, HappyPal), SMBs (Exaqtworld, Evermaps), and larger enterprises (Cyber Group Studios, SMEDAR) across technology, media, and industrial sectors. No external funding or disclosed revenue figures are available, and equity capital is the statutory €3,000 SAS minimum.
Coralium firmographics
Firmographics- Name
- Coralium
- Legal name
- CORALIUM
- Website
- https://coralium.fr
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Coralium is a French cybersecurity consulting firm founded in 2020, part of ADVANS Group, serving SMBs, healthcare organizations, and local governments with security audits, penetration testing, EBIOS RM risk analysis, managed SOC, compliance support, and cybersecurity training.
- Ownership category
- akta.pro rank
Coralium industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Compliance, Risk & Audit Management (SOC 2/ISO/PCI) (HDABANAK), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
Keywords
Where Coralium is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
Coralium business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Consulting Services: Coralium bills clients using a Taux Journalier Moyen (TJM) model, where daily rates are generally fixed and total cost depends on the number of days required for the mission. Classic missions range from 5 to 20 days, with more exceptional engagements reaching around 100 days. Pricing varies based on the architecture and complexity of the IT system being tested and/or mapped.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Standard consulting missions (5-20 days) |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels3 records
Coralium product offering
Product offeringCore offering
Coralium provides cybersecurity consulting services to French VSEs, SMEs, mid-sized companies, hospitals, and local governments. Its offering spans security audits (Audit Flash, maturity audits, 360° group audits), offensive security (external/internal penetration testing, phishing simulation, OSINT), process and documentation work (EBIOS RM risk analysis, PSSI/PRA/PCA, shared CISO), compliance support (ISO 27001, GDPR, CMMC, PCI DSS, SOC 2, SecNumCloud), a managed Micro-SOC service, and a training academy for employees and executives.
Product overview
Coralium is a French cybersecurity services company (a SAS, part of ADVANS Group) founded in 2020, offering a comprehensive portfolio of security services organized around four main poles: Protection (security audits including Audit Flash, maturity audits, and 360° assessments), Offensive Security (penetration testing with external/internal tests, phishing simulations, OSINT, and configuration reviews), Academy (cybersecurity training programs), and Process & Documentation services (EBIOS RM risk analysis, PRA, PSSI, PCA, and shared CISO services). The company also provides a Micro-SOC managed security service and extensive compliance/certification support including ISO 27001, GDPR, CMMC, PCI DSS, SOC 2, SecNumCloud, and healthcare-specific certifications (IEC 82304-1, IEC 62304, ISO/IEEE 11073). Their consultants hold CEH, CREST, and ISO 27001 Lead Implementer certifications.
Differentiator
Problem solved
Functional benefit
Products and services
- Audit SSI (Information System Security Audit) A suite of security maturity audits covering the organization's information system, including rapid Audit Flash assessments, comprehensive maturity audits with remediation plans, 360° audits for groups and subsidiaries, and structured cyber maturity journeys combining organizational and technical assessments. Targeted at French VSEs, SMEs, ETIs, and multi-entity groups needing a structured evaluation of their cybersecurity posture.
- Audit technique (Penetration Testing) Offensive security testing services using the OWASP methodology, with Black Box, Grey Box, and White Box modes. Includes external penetration testing of internet-facing systems, internal penetration testing within the corporate network, phishing simulations to test employee susceptibility, and OSINT-driven external exposure analysis. Designed for French SMEs, technology vendors, and larger organizations needing to identify exploitable vulnerabilities before attackers do.
- Micro-SOC (Managed Security Operations Center) A managed Security Operations Center service providing continuous monitoring, automated threat detection via EDR solutions, and human expert response validation. Designed to give SMEs, mid-sized enterprises, hospitals, and local governments access to SOC-grade capabilities without building an in-house security operations function.
- Compliance and Certification Consulting End-to-end consulting support for organizations pursuing security and compliance certifications, including ISO 27001 implementation, GDPR (RGPD) compliance, Trusted Partner Network (TPN), ISO/IEC 20000-1, ISO 27017, ISO 27018, CMMC for U.S. Department of Defense contractors, healthcare certifications (IEC 82304-1, IEC 62304, ISO/IEEE 11073), ISO 27701 for privacy, PCI DSS for payments, SOC 2 for service organizations, VP2 for video production security, and ANSSI SecNumCloud qualification for trusted cloud providers.
- Process and Documentation (Governance) Services Strategic governance and documentation services comprising EBIOS RM risk analysis using the ANSSI methodology, drafting of Information System Security Policies (PSSI), Business Continuity Plans (PCA), Business Recovery Plans (PRA), and shared part-time CISO (RSSI) engagements providing ongoing governance, security roadmap development, and security management for organizations without a full-time CISO.
- Cybersecurity Training and Awareness (Academy) A catalog of training courses for different audiences, including essential cybersecurity for employees, cybersecurity for executives, cyber risk management, secure development, secure information system design, becoming an SSI referent, GDPR compliance, secure project management, beginner hacking awareness, ISO 27001 implementation, cyber crisis management, and PSSI drafting. Targeted at building security culture and skills across technical and non-technical staff.
- Atelier Phishing (Phishing Awareness Workshop) A standalone hands-on workshop that teaches participants to think like attackers in order to recognize phishing attempts and social engineering techniques. Designed for employees and teams as a practical complement to broader awareness training.
Quantifiable outcome
- Secured over 60 companies in 2021
- +1 more outcomes
Companies that use Coralium
Customer profileNamed customers6 records
Segments4 records
Ideal customer profiles3 records
Coralium technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Coralium partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- ADVANS Groupparent companyCoralium is identified as a company of ADVANS Group, with the company logo displaying 'une société d'ADVANS Group'. ADVANS Group appears to be the parent company of Coralium.
Scale indicators3 records
Recent moves5 records
Expansion highlights5 records
Coralium competitors and assessment
Company assessmentDirect peers
- Advens: French-origin cybersecurity consulting and managed detection firm specializing in SOC, pentest, GRC and compliance for mid-market and large enterprises. Closest direct competitor to Coralium in geography, service mix, and SME/ETI focus.
- Hervé Schauer Consultants (HSC): Long-standing French cybersecurity consultancy offering penetration testing, security audits, training, and incident response. Directly comparable to Coralium in service mix, French SME/mid-market positioning, and consulting-only business model.
- XMCO: French cybersecurity boutique focused on penetration testing, audits, and managed security services. Targets a similar French SME/ETI customer base with comparable EBIOS RM and compliance expertise.
Broad incumbents
- Orange Cyberdefense: Subsidiary of Orange, one of France's largest cybersecurity service providers offering pentesting, SOC, consulting, and threat intelligence across EMEA. Overlaps heavily with Coralium's portfolio but at much greater scale and broader geographic reach.
- Wavestone: French-listed consulting firm with a large cybersecurity and digital trust practice covering audits, risk, compliance, and transformation. Competes with Coralium for mid-market and enterprise compliance/cybersecurity mandates in France.
- Devoteam: European IT consulting group with a substantial cybersecurity practice (Devoteam Cyber Trust) covering audits, risk, compliance, and managed security. Competes with Coralium on multi-sector compliance and transformation mandates.
- Capgemini Engineering / Cybersecurity: Global IT services giant with a large cybersecurity practice offering GRC, IAM, SOC, and pentest services. Represents the global incumbent against which Coralium's localized French SME offering is positioned.
- Sopra Steria Cybersecurity: Large European IT services group with a dedicated cybersecurity division covering audits, compliance, SOC, and identity services. Competes for the same French public-sector and enterprise compliance work as Coralium.
Emerging players
- Sekoia.io: French cybersecurity SaaS/MSSP providing a CTI-driven SOC platform and managed detection services. Comparable to Coralium in French-market focus and SOC/security operations offerings, but product-led rather than purely consulting-led.
- YesWeHack: French bug bounty and vulnerability management platform with adjacent offensive-security services. Comparable in French market and offensive-security focus, though more product/platform oriented than pure consulting.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights7 records
Customer concentration
Coralium social profiles
Digital presenceCoralium compliance and trust
Trust signalCompliance16 records
Coralium financial estimates
Financial estimateRevenue estimate
Valuation estimate
Coralium leadership team
Management profileNumber of profiles
Profiles3 records
Coralium funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Coralium M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Coralium
What does Coralium do?
Coralium provides cybersecurity consulting services to French VSEs, SMEs, mid-sized companies, hospitals, and local governments. Its offering spans security audits (Audit Flash, maturity audits, 360° group audits), offensive security (external/internal penetration testing, phishing simulation, OSINT), process and documentation work (EBIOS RM risk analysis, PSSI/PRA/PCA, shared CISO), compliance support (ISO 27001, GDPR, CMMC, PCI DSS, SOC 2, SecNumCloud), a managed Micro-SOC service, and a training academy for employees and executives.
Is Coralium a public or private company?
Coralium is a private company. It is classified as corporate owned and is currently operating.
When was Coralium founded?
Coralium was founded in 2020. It employs 1 to 10 people.
Where is Coralium based?
Coralium is headquartered in Paris, France, in the Europe region.
How does Coralium make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are Coralium's main competitors?
Direct peers on record are Advens, Hervé Schauer Consultants (HSC) and XMCO. Broad incumbents are Orange Cyberdefense, Wavestone, Devoteam, Capgemini Engineering / Cybersecurity and Sopra Steria Cybersecurity. Emerging players are Sekoia.io and YesWeHack.
Does Coralium have an API?
No public API is recorded for Coralium.
What industry is Coralium in?
Coralium's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of HDABANAK, Compliance, Risk & Audit Management (SOC 2/ISO/PCI). Its NAICS code is 561621 and its SIC code is 7381.