This research focuses on the security vulnerabilities of websites hosted on cloud technical platforms in the D.R.C., dealing with local issues such as recurrent power outages, high network latencies, etc. We applied the quantitative model CloudRisk-AF v2.0 to a selection of 35 strategic sites in Kinshasa (AWS, Azure, GCP), coming from various sectors: e-government, banks, and SMEs. The hybrid methodology uses automated analysis tools such as OWASP ZAP, Nmap, and CloudSploit, field audits that include 15 interviews with IT managers, and then integrates the analysis results to derive a comprehensive understanding. The results reveal that 78% of the sites are at critical risk (average CR-AF scores = 8.1), with a strong dominance of IAM vulnerabilities (62%) and exposure to public storage (35%). The model exceeds international standards (ROC-AUC 0.92) and recommends the gradual adoption of Zero Trust and the strengthening of IT skills, for an anticipated risk reduction of 47%.