Boldo joins the 2026 Radar of French cybersecurity startups

Boldo now features among the companies listed in the 2026 Radar of French cybersecurity startups, published by Wavestone in partnership with Bpifrance. Our presence in this landscape, within the Governance, Risk & Compliance category, marks an important milestone for our teams and recognises the contribution of enterprise architecture to securing information systems.

A reference landscape for the cyber ecosystem
For its eighth consecutive edition, the Wavestone and Bpifrance Radar has established itself as one of the most comprehensive maps of the French cyber ecosystem. Published this year at VivaTech, the study lists 234 startups and 43 scale-ups, representing nearly 6,000 jobs across the country. It also highlights a dynamic sector, driven by 304 million euros raised over the period and by the growing integration of artificial intelligence into security offerings.
Beyond the figures, this annual work is a valuable reference point for decision-makers, investors and organisations seeking to find their way in a fast-growing market. It reflects the vitality of a sector that is strategic for French digital sovereignty, one in which we are proud to take our place.
Why an enterprise architecture platform in a cyber radar?
Seeing Boldo, the publisher of an enterprise architecture platform, appear in a radar devoted to cybersecurity may seem surprising at first glance. Yet this connection says something essential about how governance and compliance challenges are evolving: you can only properly protect what you know precisely.
Governance, risk management and compliance rest on a prerequisite that is often underestimated: an up-to-date map of the information system. Applications, data flows, technical dependencies, service providers, business processes, so many elements that must be identified, documented and kept up to date so that security measures can rely on a trustworthy foundation. Without this overall view, compliance efforts risk remaining theoretical, disconnected from the operational reality of the information system.
This is precisely the role of enterprise architecture: to provide a clear, structured and dynamic representation of the organisation's information assets. This continuous picture becomes the common foundation on which security, compliance and business teams can talk to each other, prioritise risks and document their decisions.
DORA, NIS2: compliance starts with knowing your information system
The entry into force of regulations such as DORA, in the financial sector, and NIS2, for a wide range of essential and important entities, reinforces this requirement. These texts require organisations to better understand their risk exposure, to master their chain of dependencies, including with their third-party providers, and to demonstrate the robustness of their security posture.
Meeting these obligations first requires having a reliable inventory of one's assets and understanding how they fit together. How can you assess the risk carried by a critical supplier without knowing which applications depend on it? How can you prove operational resilience without a consolidated view of the processes and systems that support them? Compliance cannot be decreed: it is built on a detailed and up-to-date knowledge of the information system.
By making this map accessible, usable and shared among stakeholders, enterprise architecture turns a regulatory exercise, sometimes perceived as a constraint, into a genuine steering tool. It makes it possible to move from compliance endured to governance mastered, where documentation becomes a living asset rather than a one-off obligation.
A recognition that commits us
Joining this radar alongside recognised players in French cybersecurity reinforces our conviction: tomorrow's security and compliance will be decided upstream, in organisations' ability to know and master their information system. This conviction guides the development of our platform and the support we offer our clients.
We extend our thanks to Wavestone and Bpifrance for the quality and consistency of this reference work, as well as our congratulations to all the teams and players featured in this edition. This is a demanding, innovative and meaningful ecosystem, serving European digital sovereignty, that we are proud to help grow.
Ready to turn compliance into governance you control?
See how Boldo helps you build a reliable, up-to-date map of your information system to meet DORA, NIS2, and GRC requirements.
Schedule your personalized demo
Let's talk about your governance, risk and compliance challenges.