Cybervize
A vCISO mandate for NIS-2, DORA and ISO 27001

Outsourced CISO (vCISO): the CISO function filled, without creating the post

Cybervize fills the CISO role in your organisation. We implement whatever applies to you, whether NIS-2, DORA or ISO 27001, and keep the evidence for it, from €3,600/month. The work runs on our security platform OdySecure, which is included in the mandate.

Schedule vCISO Consultation Now

What you get with the vCISO

An experienced CISO takes over the steering of your information security and reports to management. Risks, measures and evidence are kept in OdySecure, so the current status can be checked at any time.

The filled function

  • Steering information security and prioritising measures
  • Reporting to management and the board
  • Support through audits and assessments

Evidence in OdySecure

  • Automated risk assessment and action recommendations
  • Ongoing tracking of measures and compliance status
  • Central management of all security processes

Ongoing or fixed-term

Ongoing
We fill the CISO function for as long as you do not want to appoint your own CISO. The vCISO packages apply, from €3,600/month.
Fixed-term
We fill the function until a successor is appointed or until handover to your team. This runs as an interim mandate and is billed on a project basis. More on Interim CISO

Three situations, three routes

Organisations need a CISO function for different reasons. The situation decides which route fits.

Meeting regulatory requirements

NIS-2, DORA, ISO 27001 or a customer audit call for measures, clear responsibilities and evidence that holds up. That is what the vCISO is for: ongoing, from €3,600/month.

See the vCISO packages

Vacancy or fixed-term cover

Your CISO is leaving, the successor is not yet in place, or an implementation project needs leadership for a limited period. That is the job of the Interim CISO, billed on a project basis.

Go to Interim CISO

After an acquisition or a carve-out

After closing, the acquired company often has no named security function. After a carve-out, the new entity needs its own ISMS before the Transitional Service Agreement expires. We fill the function and build up security.

Go to M&A support

Our vCISO Packages at a Glance

Option 1: Basic Package

€3,600 per month

Services (about 2 days, up to 16 hours per month):

  • Analysis of current security situation
  • NIS-2 Gap Analysis
  • Assessment of central risks, with measures
  • Weekly reports via dashboard or email
  • Monthly C-level meeting
  • Consulting within the contingent

Goal:

Basic assumption of the CISO function with continuous security management. Ideal for companies that want to take the first step towards a fully integrated Virtual CISO.

Option 2: Standard Package

€4,900 per month

Services (about 3 days, up to 24 hours per month):

  • All services of the Basic Package
  • Detailed analysis of IT and business processes
  • Development and maintenance of a compliance catalog
  • Two brief alignment meetings per week
  • Two C-level meetings per month
  • Ad-hoc support on security and compliance issues

Goal:

Broader, more intensive support of the Virtual CISO function with a quantitative increase in supported hours. Designed for companies that need deeper strategic integration and operational control.

Option 3: Senior Package

Around €8,500 per month

Services (5 to 6 days, up to 48 hours per month):

  • All services of the Standard Package
  • Daily security updates and alignments
  • Additional C-level and specialist team meetings as needed
  • Integration into security processes (crisis response, business continuity)
  • Individualized management reporting with KPIs

Goal:

Full and customized assumption of the CISO function for companies with the highest security requirements and complex challenges. Offers maximum flexibility and individual adaptation.

*Price per month, minimum contract period 6 months. Upgrade to the next higher level possible at the end of each month.
More about the vCISO

Your Virtual CISO: An outsourced CISO with a verifiable result

Virtual CISO (vCISO) and external or outsourced CISO name the same service: the CISO function is filled from outside rather than by an in-house hire. Our vCISO delivers a result: a security function that is filled and requirements that are demonstrably met. We steer the implementation and are still there at the next audit. Mid-market companies without an in-house CISO get the function from €3,600/month. For corporates we bill on a project basis at a daily rate, with the corporate modules of OdySecure.

How the CISO role differs from the operational security officer is covered in our article on the difference between a CISO and an ISO.

Senior CISO on the mandate
From €3,600/month
OdySecure included

CISO and ISB: who does what

In German organisations the operational role is often called Informationssicherheitsbeauftragter (ISB), the information security officer. The ISB keeps processes running and the evidence complete. The CISO sets priorities, reports to management and prepares its decisions.

In the vCISO mandate we fill the CISO function. If your company has an ISB, we work with them: they stay in charge of day-to-day operations, we steer and report. If the role is vacant, we agree in the initial call who takes it on. CISO and ISB compared

What the vCISO does and what stays with you

The vCISO leads the implementation and keeps management informed throughout. Duties and accountability remain with the organisation and its management. For entities under NIS-2, management's duty is set out in § 38 BSIG: it must implement the risk management measures and oversee their implementation.

What the vCISO takes on

  • Planning and prioritising measures and steering their implementation
  • Keeping risks, measures and evidence in OdySecure
  • Reports and decision papers for management
  • Preparing for and accompanying audits and assessments

What stays with you

  • The decision which risks your company accepts
  • Budget and approval for the measures
  • The requirements of NIS-2, DORA or ISO 27001 and accountability for them

Two levels, one vCISO

Available

The OdySecure Navigator works inside the platform: information from your real data, with source and metric, read-only. The human vCISO sits above that layer: judgement, prioritization, decision papers for management, audit and crisis leadership. The assistant makes your vCISO faster; it does not replace them.

The assistant answers "where do we stand". The vCISO answers "what do we do now and who does it".

The Benefits of Virtual CISO at a Glance

Expertise
Expertise without Full-Time Costs
An experienced CISO takes on the function without you having to create a full-time post.
Plattform
OdySecure included
Risk assessment, compliance checks and tracking of open measures run inside OdySecure instead of spreadsheets. The platform is included in the mandate.
Flexibilität
Adjustable month by month
Six-month minimum term, then cancellable monthly. You can move up to the next tier at the end of any month.

vCISO vs. Full-time CISO vs. IT Manager

Criterion: Cost per year

vCISOFrom €43,200 (€3,600/month)
Full-time CISO€135,000 to €200,000 cost of employment
IT Manager€110,000 to €160,000 cost of employment

Criterion: Flexibility

vCISO
Full-time CISO
IT Manager

Criterion: Expertise Level

vCISOEnterprise-Grade
Full-time CISOVaries
IT ManagerBasic

Criterion: Availability

vCISOAs needed
Full-time CISOFull-time
IT ManagerFull-time

Criterion: Industry Experience

vCISOCross-industry
Full-time CISOLimited
IT ManagerLimited

Ongoing employer cost of employment in the mid-market, as of 2026: base salary plus employer contributions, workplace and training. Within that, a CISO base salary sits at 110,000 to 160,000 EUR and an IT lead at 85,000 to 125,000 EUR (sources: Hays IT salary report 2025, StepStone, Robert Half 2026). In the first year, recruitment costs of 25 to 33 % of target annual salary are added (BDU 2024: 27.5 %). Large enterprises and highly regulated sectors sit above these figures.

Who fills the function

We fill the CISO function from our own audit and implementation practice.

Auditor acceptance
Our vCISOs bring several years of experience in information security. Evidence is built the way auditors read it.
One methodology for every mandate
We run every mandate with the same methodology and the same templates in OdySecure, so each one stands up to auditors in the same way.

How to assess an outsourced CISO

Five questions any provider should be able to answer.

How much time is agreed?
The scope is set by the package: around two days a month in Basic, five to six in Senior.
How long are you committed?
A six-month minimum term, then cancellable monthly.
What does it cost, and what is included?
From €3,600/month. Included are the platform licence, the NIS-2 gap check, reporting to management and steering of the ISMS.
Where is the evidence produced?
In OdySecure, the platform included in the mandate. The current status can be checked there at any time.
Who decides in the end?
Your management. We lead the implementation and provide the basis for its decisions.

Frequently Asked Questions about vCISO Service

A vCISO (Virtual CISO) is an external Chief Information Security Officer who fills a company's CISO function on a mandate instead of as a full-time hire. At Cybervize the mandate is ongoing, covers two to six days a month and starts at €3,600/month, with the OdySecure platform included. The vCISO carries out the security work and keeps management informed on an ongoing basis. Duties and accountability stay with your company and its management.

Cybervize offers vCISO packages from €3,600/month (basic retainer with about 2 days per month) up to roughly €8,500/month (senior retainer with 5-6 days per month). Hourly rates for spot engagements run €200-350/hour. Published retainers for external CISO and ISO mandates in the DACH region range from under €1,000/month for narrow ISO packages to around €8,000/month for full vCISO mandates; typical day rates for senior security advisory sit at €1,600 to €2,500 (own survey of public price lists, August 2026). Our pricing is transparent. The full cost comparison is in the post Virtual CISO costs.

For an example scenario at roughly 200 employees the standard package at €4,900/month is usually the fit. It covers two C-level meetings per month, two brief alignment meetings per week, weekly reports via dashboard or email, building and maintaining a compliance catalogue, and access to the OdySecure security platform. Compared to a full-time CISO at €135,000 to €200,000 annual cost of employment, the vCISO retainer at €58,800/year is well under half the cost, without losing C-level cybersecurity leadership. Detailed calculation is in the pricing pillar post.

Smaller and mid-market companies have four lower-cost alternatives to a full-time CISO: (1) vCISO (Virtual CISO), external CISO on retainer, from €3,600/month; (2) Fractional CISO, partial CISO function, often 1-2 days per month; (3) Interim CISO, temporary full-time coverage during vacancies; (4) vCISO with its own ISMS platform, which is how Cybervize works: the OdySecure platform is part of the mandate and the evidence is built there. For most SMEs the vCISO model is the most cost-effective alternative: you get C-level cybersecurity leadership without the €135,000 to €200,000 annual cost of employment of a permanent CISO.

CISO (Chief Information Security Officer) is the strategic cybersecurity leadership role at C-level, traditionally as a permanent hire. vCISO (Virtual CISO) is the same role delivered as an external, flexible service on a retainer, typically remote, often cross-industry. ISO (Information Security Officer / Informationssicherheitsbeauftragter in German) is the operational role under BSI-IT-Grundschutz and ISO 27001, usually one level below the CISO and more focused on implementation than on strategy. Cybervize delivers both vCISO and ISO/ISB mandates depending on the scope you need.

The vCISO service is particularly suitable for medium-sized companies that need cybersecurity expertise at C-level but don't want to finance a full-time position. The service is also ideal for companies in growth phases or with temporary increased security needs.

Access to the OdySecure platform is part of the mandate, with no separate licence to pay. The platform supports your vCISO's work: it assists with risk assessments, keeps track of compliance requirements and proposes measures. Your vCISO uses it to steer the ISMS and the reporting to management.

Our vCISO service typically starts within the first week after contract signature. After a structured onboarding with baseline assessment, measures are prioritised and the platform is configured to your requirements.

We have experience in numerous industries, including financial services, healthcare, manufacturing, public sector, and technology companies. Our expertise covers industry-specific security requirements and compliance regulations.

A full-time CISO is a permanent position with an ongoing cost of employment of €135,000 to €200,000 per year. A vCISO (Virtual CISO) provides the same strategic cybersecurity leadership at C-level, but as a flexible, external service. You get an experienced CISO on demand who manages your security strategy without the fixed costs of a permanent hire. This makes it the cost-effective alternative, especially for mid-market companies.

An external CISO brings cross-industry experience from numerous companies and is immediately available without lengthy recruitment. As an external leader, they act independently and objectively in security assessments and audits. Especially during vacancies, while searching for a permanent CISO, or when facing urgent compliance requirements like NIS-2 or ISO 27001, an external CISO is the fastest solution.

Yes. The vCISO is not limited to mid-market. Corporates use the same mandate: we fill the CISO function on a permanent basis, with the OdySecure platform included. What changes is the scope: corporate modules of the platform (multi-entity rollout, auditor-accepted group reporting, multi-country) and a project-based daily rate instead of the €/month retainer. If you only need to bridge a short-term vacancy, Interim CISO is the right choice, not vCISO.

The vCISO is a permanent mandate: we fill your CISO function on an ongoing monthly basis, with the OdySecure platform included in the mandate. The Interim CISO is a short-term bridge across a specific vacancy or crisis (CISO departure, audit preparation, post-incident stabilisation), project-based, usually without the platform, no lock-in. Both lines are standalone: you can start with Interim CISO and switch to vCISO later, or book vCISO directly.

Ready for your Virtual CISO?

We fill your CISO function from €3,600/month. OdySecure is included in the mandate.

Schedule a consultation now

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT