LSTI
LSTI is a France-based Conformity Assessment Body and subsidiary of Apave Group, providing ANSSI qualifications, ISO certifications, eIDAS trust services, and individual competency certifications to cybersecurity, digital trust, and information security organizations and professionals across Europe.
- Company typePrivate
- Founded2004
- HeadquartersSaint Malo, France
- Headcount11–50
- GTM typeB2B and B2C
- OfferingServices
What LSTI does
LSTI is a France-based Conformity Assessment Body (CAB/OEC) specializing in cybersecurity, digital trust, and information security certification. Founded in 2004 as an entity of the Apave Group, the company operates from Saint-Malo with a team of 11-50 employees and is the first historical OEC authorized by ANSSI to assess companies for PASSI qualification. LSTI holds COFRAC accreditation under ISO/IEC 17024 and maintains ANSSI habilitation across multiple qualification frameworks (PASSI, SecNumCloud, PRIS, PDIS, PACS, PVID).
The company delivers a two-pillar certification portfolio. The enterprise pillar covers ANSSI qualifications, ISO standards (27001, 27701, 20000, 22301, 42001), eIDAS trust services (including eIDAS v2 products like EUDI Wallet and Qualified Electronic Archiving), and HDS health data hosting certification. The individual pillar provides competency certifications for professionals including ISO 27001 Lead Auditor/Implementer, Risk Manager EBIOS, and Risk Manager ISO 27005, delivered through an online examination platform with 130 sessions per year. LSTI has certified 300+ organizations and 2,500 individuals, with 90 ANSSI VISA companies and 60 digital trust providers among its track record.
Revenue is generated through quote-based enterprise certification projects and tariff-based individual examination fees (document DT057 V.18). Distribution combines direct enterprise sales with a self-serve online examination channel and a network of 9 approved training organizations that funnel candidates into LSTI exams. LSTI is wholly owned by Apave Group, a French risk management and technical supervision conglomerate, which provides brand, capital, and cross-sell reach.
LSTI firmographics
Firmographics- Name
- LSTI
- Legal name
- LSTI SAS
- Website
- https://lsti-certification.fr
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- LSTI is a France-based Conformity Assessment Body and subsidiary of Apave Group, providing ANSSI qualifications, ISO certifications, eIDAS trust services, and individual competency certifications to cybersecurity, digital trust, and information security organizations and professionals across Europe.
- Ownership category
- akta.pro rank
LSTI industry classification
Industry- Product category
- Cybersecurity and Information Security Certification Services
- NAICS
- Testing Laboratories and Services (541380), Testing Laboratories and Services (54138)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Certification & Licensing Exam Management Platforms (EDAFADAG)
Keywords
Where LSTI is headquartered
LocationHeadquarters
- HQ city
- Saint Malo
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
LSTI business model
Business model- GTM type
- B2B and B2C
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Enterprise Certification Services: Revenue from certification and qualification assessments for enterprises and organizations. Includes PASSI, SecNumCloud, PDIS, PRIS, PACS, PVID qualifications, ISO certifications (27001, 27701, 20000, 22301, 42001), eIDAS certification, and HDS certification. Fees are quote-based and project-specific.
- Competency Certification (Personnel): Revenue from online examination and certification of individual professionals. Covers Implementer ISO 27001, Auditor/Lead Auditor ISO 27001, Risk Manager ISO 27005, and EBIOS Risk Manager certifications. Pricing available via downloadable tariff document DT057 V.18.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | Professional Competency Certifications |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
LSTI product offering
Product offeringCore offering
LSTI is a Conformity Assessment Body (CAB/OEC) that audits, qualifies, and certifies organizations and individuals across cybersecurity, digital trust, and information security domains. For organizations it delivers ANSSI qualifications (PASSI, SecNumCloud, PDIS, PRIS, PACS, PVID), ISO certifications (27001, 27701, 20000, 22301, 42001), eIDAS trust service certifications, and HDS health data hosting certification. For individuals it issues ISO/IEC 17024-accredited competency certifications through an online examination platform.
Product overview
LSTI is a Conformity Assessment Body (CAB) and certification organization offering a comprehensive portfolio of cybersecurity, digital trust, and information security certifications. The portfolio is organized into two main categories: (1) Enterprise/Service Qualifications and Certifications for organizations including ANSSI qualifications (PASSI, PACS, PRIS, PDIS, SecNumCloud, PVID), international standards (ISO 27001, ISO 27701, ISO 20000, ISO 22301, ISO 42001, eIDAS), and sector-specific certifications (HDS for health data hosting); and (2) Individual Competency Certifications for professionals including Auditor/Lead Auditor ISO 27001, Implementer ISO 27001/27701, Risk Manager EBIOS, and Risk Manager ISO 27005. The company serves over 300 organizations in France and Europe, functioning as an evaluation center for ANSSI qualifications and an ISO/IEC 17024 accredited certification body for persons.
Differentiator
Problem solved
Functional benefit
Products and services
- PASSI Qualification ANSSI qualification assessment for security audit service providers, evaluating competencies and methodologies against ANSSI's cybersecurity standards. Designed for organizations seeking PASSI (Prestataires d'Audit en Sécurité des Systèmes d'Information) qualification.
- SecNumCloud Qualification ANSSI qualification for cloud service providers, delivering the highest level of security certification for maximum trust in cloud services.
- PDIS Qualification ANSSI qualification for incident detection service providers, assessing capabilities to detect and respond to security incidents.
- PACS Qualification ANSSI qualification for cybersecurity consulting framework, evaluating consulting expertise and advisory services.
- PRIS Qualification ANSSI qualification for incident resolution service providers, certifying capabilities to resolve security incidents.
- ISO/IEC 27001 Certification International standard certification for Information Security Management Systems (ISMS), guaranteeing protection, improvement and performance of information systems.
- ISO/IEC 27701 Certification Privacy Information Management System (PIMS) certification extending ISO 27001 for GDPR and data protection compliance.
- ISO/IEC 20000 Certification IT service management certification for organizations to certify their service delivery and ITSM processes.
- ISO 22301 Certification Business Continuity Management System (BCMS) certification ensuring organizational resilience and recovery capabilities.
- ISO/IEC 42001 Certification Artificial Intelligence Management System (AIMS) certification for responsible AI development and use, aligned with EU AI Act requirements.
- HDS Certification Health Data Host certification mandatory in France for organizations hosting personal health data, based on ISO 27001 with healthcare-specific requirements.
- eIDAS Certification European regulation certification for digital trust services including electronic signatures, seals, time stamps, qualified electronic archiving, and EUDI Wallet.
- PVID Certification Remote identity verification certification compliant with ANSSI's PVID standard for French regulatory requirements.
- PSCe Certification Electronic certification services for trust and authenticity of digital transactions, under the PSCe framework.
- Auditor/Lead Auditor ISO 27001 Certification Personal certification for information security professionals demonstrating knowledge and skills for ISO 27001 compliance and internal audits.
- Implementer ISO/IEC 27001:2022 Certification Personal certification validating skills in implementing and managing an Information Security Management System (ISMS) per ISO 27001 requirements.
- Implementer ISO/IEC 27701:2019 Certification Personal certification for privacy management and PIMS implementation extending ISO 27001 for GDPR compliance.
- Risk Manager EBIOS Certification ANSSI-based certification for digital risk assessment using the EBIOS Risk Manager methodology, validating ability to identify APTs and define remediation strategies.
- Risk Manager ISO/IEC 27005:2022 Certification Personal certification validating mastery of ISO 27005 risk management process for information security threat analysis.
Quantifiable outcome
- 90 companies received ANSSI VISA qualified or assessed by LSTI
- +3 more outcomes
Companies that use LSTI
Customer profileNamed customers1 record
Segments4 records
Ideal customer profiles4 records
LSTI technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
LSTI partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered core and minor.
- COFRAC (Comité Français d'Accréditation)coreCOFRAC accreditation is essential for LSTI's operations as a certification body. HDS certification specifically requires certification bodies to be accredited by COFRAC or its European equivalent. COFRAC accreditation validates LSTI's competence to perform certification activities according to international standards.
- ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information)coreANSSI is the French national cybersecurity agency that establishes qualification frameworks (PASSI, SecNumCloud, PRIS, PDIS, PACS, PVID) that LSTI is authorized to assess. ANSSI qualifications require evaluation by qualified certification bodies, and LSTI serves as a reference evaluation center for these qualifications.
- ANS (Agence Numérique en Santé)coreANS (formerly ASIP Santé) oversees the Health Data Host (HDS) certification framework in France. LSTI conducts HDS certification audits according to the ANS reference framework, which is based on ISO 27001 with healthcare-specific requirements.
- Club EBIOSminorClub EBIOS is the organization that oversees the EBIOS Risk Manager method, a French cybersecurity risk management approach. LSTI provides EBIOS Risk Manager certification based on ANSSI standards supervised by Club EBIOS.
- Centrale Supelec / Université Paris SaclayminorApproved training organization since 2016 providing information security and cybersecurity training with LSTI certification exams. Located in Rennes, France. Contact: [email protected], Tel: +33 (0)2 99 84 45 00.
- Orsys FormationminorApproved training organization since 2008 offering information security training with LSTI certification exams. Contact: [email protected], Tel: +33(0) 1 49 07 73 73.
- AFNOR CompétencesminorApproved training organization since 2010 providing training aligned with LSTI certification exams. Contact: [email protected], Tel: +33(0) 1 41 62 76 22.
- EduGroupeminorApproved training organization since 2020 offering information security training with LSTI exams. Contact: [email protected], Tel: +33 (0) 1 71 19 70 30.
- AdacisminorApproved training organization since 2017 providing cybersecurity training aligned with LSTI certifications. Contact: [email protected], Tel: +33(0) 6 71 83 84 61.
- PolarisminorApproved training organization since 2018 providing information security training with LSTI exams. Contact: [email protected], Tel: +33 (0)4 78 74 50 80.
- NL ConsultingminorApproved training organization since 2021 offering cybersecurity training with LSTI certification exams. Contact: [email protected], Tel: +33 (0)6 25 57 58 14.
- We are CyberminorApproved training organization since 2025 providing cybersecurity training with LSTI certification exams. Contact: [email protected], Tel: +33 (0)6 16 57 28 13.
- SysDreamminorApproved training organization providing cybersecurity training with LSTI certification exams. Contact: Tel: +33 1 78 76 58 00.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
LSTI competitors and assessment
Company assessmentBroad incumbents
- DNV: Norwegian-headquartered certification body with strong ISO 27001, ISO 42001, and maritime/energy-adjacent cybersecurity certifications. Competes with LSTI for European enterprise ISO certifications and brings significant international scale.
- Bureau Veritas: Global testing, inspection, and certification (TIC) giant offering ISO 27001, cybersecurity audits, and managed certification services across 140+ countries. Directly competes with LSTI in France and Europe for enterprise ISO and cybersecurity certifications but operates across a far broader portfolio (marine, commodities, construction).
- TÜV Rheinland: Global TIC conglomerate providing ISO 27001, TÜV-issued cybersecurity certifications, and AI/ISO 42001 services. Competes with LSTI in European enterprise cybersecurity certification with deeper international bench and broader portfolio (industrial, automotive, medical).
- BSI Group: UK-headquartered certification body and originator of ISO 27001 with strong cybersecurity certification portfolio (ISO 27001, ISO 42001, NIS2 readiness). Competes with LSTI across European enterprise deals and is significantly larger in headcount and geographic reach.
- DEKRA Certification: German-headquartered TIC conglomerate providing ISO 27001, ISO 42001, automotive cybersecurity, and AI certification services. Competes with LSTI for European enterprise cybersecurity certifications across multiple verticals.
Direct peers
- AFNOR Certification: French national standards body (AFNOR) operating a certification subsidiary that issues ISO 27001, ISO 27701, ISO 42001, HDS-equivalent certifications, and ISO/IEC 17024-accredited personnel certifications in direct competition with LSTI in France. Closest functional peer given shared French regulatory base and overlapping catalog.
Others
- Apave Group: Parent conglomerate of LSTI, a French risk-management and technical-supervision group founded in 1867. Not a direct competitor, but adjacent — Apave's broader risk and conformity services overlap with parts of LSTI's catalog and provide cross-sell opportunities.
Emerging players
- Coalfire: US-based cybersecurity advisory and assessment firm providing ISO 27001 certification, SOC 2, FedRAMP, and HITRUST audits. Comparable to LSTI's cybersecurity audit practice, though US-centric and more advisory-heavy than pure certification body.
- Schellman: US-based certification body accredited to issue ISO 27001, SOC 2, PCI DSS, and FedRAMP authorizations. Comparable to LSTI as a focused certification practice, though operating in a different (North American) regulatory regime.
Regional players
- Certifying Authority (ANSSI-listed): Other ANSSI-accredited Conformity Assessment Bodies (e.g., other PASSI-qualified OECs) operating in France. Direct competitors for French national cybersecurity qualifications, though smaller in scale than LSTI's first-mover install base.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat4 records
Key risks7 records
Key highlights7 records
Customer concentration
LSTI social profiles
Digital presenceLSTI financial estimates
Financial estimateRevenue estimate
Valuation estimate
LSTI leadership team
Management profileNumber of profiles
Profiles1 record
LSTI funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
LSTI M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about LSTI
What does LSTI do?
LSTI is a Conformity Assessment Body (CAB/OEC) that audits, qualifies, and certifies organizations and individuals across cybersecurity, digital trust, and information security domains. For organizations it delivers ANSSI qualifications (PASSI, SecNumCloud, PDIS, PRIS, PACS, PVID), ISO certifications (27001, 27701, 20000, 22301, 42001), eIDAS trust service certifications, and HDS health data hosting certification. For individuals it issues ISO/IEC 17024-accredited competency certifications through an online examination platform.
Is LSTI a public or private company?
LSTI is a private company. It is classified as corporate owned and is currently operating.
When was LSTI founded?
LSTI was founded in 2004. It employs 11 to 50 people.
Where is LSTI based?
LSTI is headquartered in Saint Malo, France, in the Europe region.
How does LSTI make money?
Two revenue lines are on record. Enterprise Certification Services are the primary driver. The others are competency Certification (Personnel).
Who are LSTI's main competitors?
Broad incumbents on record are DNV, Bureau Veritas, TÜV Rheinland, BSI Group and DEKRA Certification. AFNOR Certification is listed as a direct peer. Apave Group is listed as an others. Emerging players are Coalfire and Schellman. Certifying Authority (ANSSI-listed) is listed as a regional player.
Does LSTI have an API?
No public API is recorded for LSTI.
What industry is LSTI in?
LSTI's product category is Cybersecurity and Information Security Certification Services. Its primary akta.pro industry code is EDAFADAG, Certification & Licensing Exam Management Platforms. Its NAICS code is 541380 and its SIC code is 8734.