Ongoing support

vCISO services and Compliance-as-a-Service

Need security leadership without a full-time appointment? An external or virtual CISO (vCISO) is a specialist who fulfils agreed leadership responsibilities with defined capacity. We work remotely; any on-site presence is agreed around the work required. We assess the required work, applicability and independence before combining roles. Legal accountability remains with your management body.

Compliance-as-a-Service (CaaS): ongoing compliance support

The review ends, but the obligations remain. We maintain agreed cybersecurity and ICT-risk compliance work: deadlines, evidence, gaps and reporting. Other specialist functions, including a data protection officer, are scoped separately according to applicability, capacity and independence. This service suits recurring responsibilities where an internal team needs expert capacity and coordination.

What we agree for each month

Calendar and changes
Review agreed requirements and deadlines; assess whether a change affects the organisation.
Evidence
Review selected records, their validity and missing confirmations; maintain an index linking to them.
Risks and actions
Update priorities, accountable people and deadlines; track assigned corrective actions.
Management reporting
What was checked, what remains unverified and which decisions or resources are needed.

Before starting, we define the entities, applicable areas, sources, access, monthly capacity and review frequency. The monthly plan selects tasks according to risk and available hours. Each report identifies completed work, evidence and deferred tasks. The activities listed are not a promise that the smallest subscription covers them all.

An example monthly result

A customer review is approaching. We review an agreed set of evidence, identify outdated records, assign an accountable person to each gap and prepare a short report of decisions required from management. This is an illustrative scope; document volumes and required capacity are agreed in advance.

How do CaaS and an external CISO / vCISO differ?

CaaS organises ongoing compliance work. An external CISO, also called a vCISO (virtual CISO), is a named specialist providing agreed security leadership: priorities, risk, management reporting and coordination. The two can be combined after assessing workload and independence, but a monthly fee does not provide unlimited responsibilities.

Management decisions and legal accountability remain with the client. Certification, independent audit, legal representation, round-the-clock response and technical implementation are not automatically included. Availability, response times and additional work are agreed in writing. We do not promise a successful audit or regulatory acceptance.

Monthly capacity starts at €1 400 for one expert day (8 hours), with a limited agreed scope. Further tiers and terms appear below. Addressing an initial backlog may require a separate project.

The first conversation is free. After we clarify your needs, you receive a written proposal covering scope, outputs, capacity and responsibilities.

Discuss monthly compliance support

CaaS scope worksheet (TXT) · How to compare external CISO capacity and cost

Ongoing supportWhat it rests onLaw, standard or organisational choice
External support to the ICT risk control functionDORA Art. 6(4) requires covered non-micro financial entities to assign management and oversight of ICT risk to a control function with an appropriate level of independence. Art. 6(10) permits outsourcing of compliance-verification tasks; the entity retains the function, oversight and full responsibility. Art. 16 cases are checked separately.Law
Cybersecurity officer (NIS2)Cybersecurity Act (ЗКС) and its ordinance on minimum measures — whether a designated person is required is confirmed for your entity typeLaw
Data protection officerGDPR Art. 37 — required for public authorities except courts acting judicially, and where core activities involve large-scale regular and systematic monitoring or large-scale processing of special-category or criminal-offence data; may be external and must be free of conflictsLaw
Information security responsibilitiesISO/IEC 27001 clause 5.3 requires roles and responsibilities to be assigned and communicated — a requirement of the standard, not a named statutory postStandard
AI governance ownerISO/IEC 42001 — responsibilities assigned under the standard. The EU AI Act places duties on the organisation: Art. 26 on deployers, other articles on providers; it does not create a named “AI officer” postStandard
Third-party / ICT risk responsibilityFor covered non-micro financial entities, DORA Art. 5(3) requires a role to monitor ICT-provider arrangements or assigns that responsibility to senior management. The job title and operating model are agreed for the organisation. NIS2 also requires proportionate supply-chain security measures.Law
Business continuity responsibilitiesISO 22301 requires assigned responsibilities. For covered non-micro financial entities, DORA Art. 11(7) also requires a crisis-management function. Art. 16 cases are checked separately. The regulation does not prescribe a particular job title.Law
Incident-reporting coordinatorNIS2, DORA and CRA set statutory reporting deadlines; a coordinator who runs the playbook is an organisational choiceOrganisational choice
Whistleblowing channel — receipt and registrationDirective (EU) 2019/1937 and the Bulgarian ЗЗЛПСПОИН: private employers with 50+ staff, and regardless of headcount where the activity falls under the EU acts listed in the Act’s annex (e.g. financial services, AML) — Art. 12(1). Per КЗЛД guidance an external party may only receive and register written reports; examination stays with an internal designated employeeLaw
Interim cover for your own officerContinuity of a mandated role while you recruitOrganisational choice

Law Legal duty in defined casesStandard Required by a standard you choose to certify againstOrganisational choice Organisational choice — the duties exist, the named role does not

The engagement model depends on the function, responsibilities, workload and independence required. We may decline an under-resourced scope.

These tiers cover ongoing senior work in security and ICT risk governance. DPO and other specialist functions are scoped and priced separately according to the capacity and independence required.

Combining functions. Whether one person may hold several functions depends on conflicts of interest and on capacity: a data protection officer, for example, may not also decide the purposes and means of processing. We assess this for your organisation and quote accordingly.

Monthly support has a defined allowance

Monthly support includes an agreed allowance of senior time, not unlimited availability. We publish it so that you can compare the service clearly.

A monthly engagement includes a planned allowance, the agreed response window and the published rollover terms. An individually booked day is a scheduled piece of work and does not by itself establish ongoing response availability. Named substitute arrangements must be confirmed in the agreement.

Monthly optionPer monthIncluded
1 day per month€1 4008 hours of senior work
2 days per month€2 60016 hours of senior work
4 days per month€4 90032 hours of senior work
Published day rate€1 300 

One expert day is eight hours of senior time, usable in parts — preparation, analysis, meetings, written responses and agreed coordination all count towards it. There is no unlimited work between meetings.

Outside the agreed service window, the standard retainer provides no committed immediate response or technical containment. Use your organisation’s arranged incident route. The agreement defines hours, time zone and escalation; a meeting in another time zone does not extend the window.

Compare the responsibilities, not just the hours. An IT provider may already perform some security tasks. We identify what is covered, what remains with management and where extra leadership or independent review is useful. If recurring work exceeds the agreed capacity, we discuss a larger allowance or an internal role. Compare cost and responsibilities →

  • Unused time rolls over for one month, up to half of that month’s allowance; carried-over time is used first and expires at the end of that next month.
  • Before additional days are used, we confirm in writing whether they remain a one-off day or whether a larger monthly option applies, and from which month. Where the larger option costs less for the requested capacity, we propose it.
  • Response to a critical issue within 4 working hours during the agreed service window means acknowledgement and first guidance, not resolution of the incident; one business day otherwise. The service window, contact channel and a named substitute are set in the contract.
  • No 24/7 promise in the standard service. Where you need round-the-clock cover, we arrange it separately with a vetted partner once availability is confirmed. Who receives an incident alert, when, and what Dyasol does is set out under incident help.
  • 30 days’ notice to cancel, at any time.

What Tier 1 actually looks like in the first 90 days

Month 1Appointment letter and role description; inventory of what the role owns; a register of the decisions and deadlines that recur.
Month 2The first documented cycle: the standing review, the supplier or incident log kept current, the first board-readable note.
Month 3Cadence in place — one day a month is a review rhythm, not a full-time officer. If the workload consistently exceeds the tier, we say so and you move up or hire.

How the included time may be used

Illustrative allocation for a limited agreed scope. This is not a guaranteed deliverable list for every role.

TierExample
1 — 8 hours2h preparation, 1h working meeting, 3h review of a selected topic, 2h written note and update to the agreed register.
2 — 16 hours3h preparation, 2h meetings, 7h agreed reviews, 4h documentation and follow-up.

The allocation changes with the work required. A new issue or incident may displace a planned activity. Technical implementation and management decisions remain with the parties assigned in the agreement.

WhoDoes what
DyasolAnalyses, recommends and documents the agreed work.
The clientMakes the management decisions and ensures execution.
Independent assessorPerforms the applicable independent verification.
Independence. Where we support your ICT risk control function or perform outsourced compliance-verification tasks, we do not act as your ICT auditor; the financial entity retains the function, oversight and responsibility; where we build your management system, the certification or independent assessment is done by another body. Checking that our own fixes work remains part of accepting the work. We state the arrangement in writing before you engage us.

Specimens and preparation for commissioning

These specimens and worksheets show how outputs, your participation and acceptance are recorded. Specific terms are completed and agreed for the engagement.