vCISO services and Compliance-as-a-Service
Need security leadership without a full-time appointment? An external or virtual CISO (vCISO) is a specialist who fulfils agreed leadership responsibilities with defined capacity. We work remotely; any on-site presence is agreed around the work required. We assess the required work, applicability and independence before combining roles. Legal accountability remains with your management body.
Compliance-as-a-Service (CaaS): ongoing compliance support
The review ends, but the obligations remain. We maintain agreed cybersecurity and ICT-risk compliance work: deadlines, evidence, gaps and reporting. Other specialist functions, including a data protection officer, are scoped separately according to applicability, capacity and independence. This service suits recurring responsibilities where an internal team needs expert capacity and coordination.
What we agree for each month
- Calendar and changes
- Review agreed requirements and deadlines; assess whether a change affects the organisation.
- Evidence
- Review selected records, their validity and missing confirmations; maintain an index linking to them.
- Risks and actions
- Update priorities, accountable people and deadlines; track assigned corrective actions.
- Management reporting
- What was checked, what remains unverified and which decisions or resources are needed.
Before starting, we define the entities, applicable areas, sources, access, monthly capacity and review frequency. The monthly plan selects tasks according to risk and available hours. Each report identifies completed work, evidence and deferred tasks. The activities listed are not a promise that the smallest subscription covers them all.
An example monthly result
A customer review is approaching. We review an agreed set of evidence, identify outdated records, assign an accountable person to each gap and prepare a short report of decisions required from management. This is an illustrative scope; document volumes and required capacity are agreed in advance.
How do CaaS and an external CISO / vCISO differ?
CaaS organises ongoing compliance work. An external CISO, also called a vCISO (virtual CISO), is a named specialist providing agreed security leadership: priorities, risk, management reporting and coordination. The two can be combined after assessing workload and independence, but a monthly fee does not provide unlimited responsibilities.
Management decisions and legal accountability remain with the client. Certification, independent audit, legal representation, round-the-clock response and technical implementation are not automatically included. Availability, response times and additional work are agreed in writing. We do not promise a successful audit or regulatory acceptance.
Monthly capacity starts at €1 400 for one expert day (8 hours), with a limited agreed scope. Further tiers and terms appear below. Addressing an initial backlog may require a separate project.
The first conversation is free. After we clarify your needs, you receive a written proposal covering scope, outputs, capacity and responsibilities.
Discuss monthly compliance support
CaaS scope worksheet (TXT) · How to compare external CISO capacity and cost
| Ongoing support | What it rests on | Law, standard or organisational choice |
|---|---|---|
| External support to the ICT risk control function | DORA Art. 6(4) requires covered non-micro financial entities to assign management and oversight of ICT risk to a control function with an appropriate level of independence. Art. 6(10) permits outsourcing of compliance-verification tasks; the entity retains the function, oversight and full responsibility. Art. 16 cases are checked separately. | Law |
| Cybersecurity officer (NIS2) | Cybersecurity Act (ЗКС) and its ordinance on minimum measures — whether a designated person is required is confirmed for your entity type | Law |
| Data protection officer | GDPR Art. 37 — required for public authorities except courts acting judicially, and where core activities involve large-scale regular and systematic monitoring or large-scale processing of special-category or criminal-offence data; may be external and must be free of conflicts | Law |
| Information security responsibilities | ISO/IEC 27001 clause 5.3 requires roles and responsibilities to be assigned and communicated — a requirement of the standard, not a named statutory post | Standard |
| AI governance owner | ISO/IEC 42001 — responsibilities assigned under the standard. The EU AI Act places duties on the organisation: Art. 26 on deployers, other articles on providers; it does not create a named “AI officer” post | Standard |
| Third-party / ICT risk responsibility | For covered non-micro financial entities, DORA Art. 5(3) requires a role to monitor ICT-provider arrangements or assigns that responsibility to senior management. The job title and operating model are agreed for the organisation. NIS2 also requires proportionate supply-chain security measures. | Law |
| Business continuity responsibilities | ISO 22301 requires assigned responsibilities. For covered non-micro financial entities, DORA Art. 11(7) also requires a crisis-management function. Art. 16 cases are checked separately. The regulation does not prescribe a particular job title. | Law |
| Incident-reporting coordinator | NIS2, DORA and CRA set statutory reporting deadlines; a coordinator who runs the playbook is an organisational choice | Organisational choice |
| Whistleblowing channel — receipt and registration | Directive (EU) 2019/1937 and the Bulgarian ЗЗЛПСПОИН: private employers with 50+ staff, and regardless of headcount where the activity falls under the EU acts listed in the Act’s annex (e.g. financial services, AML) — Art. 12(1). Per КЗЛД guidance an external party may only receive and register written reports; examination stays with an internal designated employee | Law |
| Interim cover for your own officer | Continuity of a mandated role while you recruit | Organisational choice |
Law Legal duty in defined casesStandard Required by a standard you choose to certify againstOrganisational choice Organisational choice — the duties exist, the named role does not
The engagement model depends on the function, responsibilities, workload and independence required. We may decline an under-resourced scope.
These tiers cover ongoing senior work in security and ICT risk governance. DPO and other specialist functions are scoped and priced separately according to the capacity and independence required.
Monthly support has a defined allowance
Monthly support includes an agreed allowance of senior time, not unlimited availability. We publish it so that you can compare the service clearly.
A monthly engagement includes a planned allowance, the agreed response window and the published rollover terms. An individually booked day is a scheduled piece of work and does not by itself establish ongoing response availability. Named substitute arrangements must be confirmed in the agreement.
| Monthly option | Per month | Included |
|---|---|---|
| 1 day per month | €1 400 | 8 hours of senior work |
| 2 days per month | €2 600 | 16 hours of senior work |
| 4 days per month | €4 900 | 32 hours of senior work |
| Published day rate | €1 300 |
One expert day is eight hours of senior time, usable in parts — preparation, analysis, meetings, written responses and agreed coordination all count towards it. There is no unlimited work between meetings.
Outside the agreed service window, the standard retainer provides no committed immediate response or technical containment. Use your organisation’s arranged incident route. The agreement defines hours, time zone and escalation; a meeting in another time zone does not extend the window.
Compare the responsibilities, not just the hours. An IT provider may already perform some security tasks. We identify what is covered, what remains with management and where extra leadership or independent review is useful. If recurring work exceeds the agreed capacity, we discuss a larger allowance or an internal role. Compare cost and responsibilities →
- Unused time rolls over for one month, up to half of that month’s allowance; carried-over time is used first and expires at the end of that next month.
- Before additional days are used, we confirm in writing whether they remain a one-off day or whether a larger monthly option applies, and from which month. Where the larger option costs less for the requested capacity, we propose it.
- Response to a critical issue within 4 working hours during the agreed service window means acknowledgement and first guidance, not resolution of the incident; one business day otherwise. The service window, contact channel and a named substitute are set in the contract.
- No 24/7 promise in the standard service. Where you need round-the-clock cover, we arrange it separately with a vetted partner once availability is confirmed. Who receives an incident alert, when, and what Dyasol does is set out under incident help.
- 30 days’ notice to cancel, at any time.
What Tier 1 actually looks like in the first 90 days
How the included time may be used
Illustrative allocation for a limited agreed scope. This is not a guaranteed deliverable list for every role.
| Tier | Example |
|---|---|
| 1 — 8 hours | 2h preparation, 1h working meeting, 3h review of a selected topic, 2h written note and update to the agreed register. |
| 2 — 16 hours | 3h preparation, 2h meetings, 7h agreed reviews, 4h documentation and follow-up. |
The allocation changes with the work required. A new issue or incident may displace a planned activity. Technical implementation and management decisions remain with the parties assigned in the agreement.
| Who | Does what |
|---|---|
| Dyasol | Analyses, recommends and documents the agreed work. |
| The client | Makes the management decisions and ensures execution. |
| Independent assessor | Performs the applicable independent verification. |
Specimens and preparation for commissioning
These specimens and worksheets show how outputs, your participation and acceptance are recorded. Specific terms are completed and agreed for the engagement.