// vCISO Support

YOUR GUIDE FROM
DAY ONE - AND EVERY DAY AFTER.

Whether you are starting from scratch or already certified, vCISO support is how you get a security lead without hiring one. Starting out? We guide you through certification and keep you covered once you are through. Already certified? This is what comes next. Plain English, fixed price, no jargon - either way.

FIXED MONTHLY FEEROLLING MONTHLY AFTER 3 MONTHSUK-BASED
// Why You Need This

MOST SMALL BUSINESSES DON'T NEED A FULL-TIME CISO

They need someone to call before a problem becomes a breach, a lapsed certificate, or a lost tender. A vCISO - sometimes called a fractional CISO - gives you that person, without the £80,000+ salary.

Certificates expire every 12 months

Without someone managing renewal, businesses miss deadlines and lose tender eligibility. Your certificate does not renew itself.

Security policies go stale

MFA rules, access controls, and patching policies written once and never revisited are the most common reason businesses fail their CE+ retest.

Pen test findings get forgotten

A report is a point-in-time snapshot. Without ongoing management, the same class of vulnerability quietly reappears within a year.

DCC obligations don't end at assessment

Supply chain requirements under DEFCON 658 are reviewed on an ongoing basis, not just at onboarding.

Tenders keep asking security questions

Procurement questionnaires, supply chain due diligence, and insurance renewals all expect answers you may not have in-house.

Cyber insurance needs ongoing evidence

Insurers are asking harder questions at renewal. Up-to-date policies, patching evidence, and current certifications are increasingly required to maintain cover.

// Who This Is For

BUILT FOR BUSINESSES THAT CAN'T AFFORD TO LET COMPLIANCE SLIP

  • STARTING FROM SCRATCH

    Businesses wanting one guide through certification and beyond - not a different supplier at every stage.

  • SMALL BUSINESSES

    No in-house IT security lead, but tenders and clients are asking security questions. Foundation plan provides the cover you need.

  • LAW FIRMS & SOLICITORS

    SRA guidance, client confidentiality obligations, and supply chain due diligence all require ongoing security management.

  • HEALTHCARE & CLINICAL PROVIDERS

    NHS DSPT submissions, UK GDPR Article 32, and clinical data obligations require regular testing and documented security governance.

  • SCHOOLS & MATs

    DfE requirements, safeguarding-linked data, and multi-site complexity make ongoing security oversight essential.

  • MOD & ENTERPRISE SUPPLY CHAIN

    DEFCON 658, DCC Level 0, and enterprise procurement all require ongoing security posture management beyond the point of certification.

vCISO advisory session - a security consultant discussing cyber security compliance and certification requirements with UK business owners around a meeting table
// One Relationship

NOT FOUR DIFFERENT SUPPLIERS

Every VCD service - Cyber Essentials, CE+, DCC Level 0, and pen testing - integrates with your vCISO plan. Direct lead contact from day one. No handoffs, no account managers, no starting from scratch at every renewal.

// Your Security Journey

EVERY SERVICE BUILDS TOWARD THE SAME GOAL

Proving you are secure today, and staying secure after.

vCISO SUPPORT
CYBER ESSENTIALS
CE PLUS
DCC LEVEL 0
PEN TESTING

Starting from nothing?

A vCISO plan can begin before your first certification. We scope your setup, get you audit-ready, guide you through CE, CE+, and DCC Level 0 as they become relevant, and keep going once you are certified. One point of contact for the whole journey, instead of a new supplier at every stage.

Already certified?

The moment your CE+ certificate is issued, or your pen test report lands, the clock starts running on the next twelve months - new vulnerabilities, new starters and leavers, new devices, new tenders asking the same questions again. vCISO support is how our clients stop starting from scratch every renewal cycle.

// What's Included

EVERY PLAN INCLUDES

Annual recertification - managed

CE and CE+ renewal managed start to finish so it never lapses. We handle the process; you sign the declaration. Certification fees are billed separately at standard pricing.

Continuous patch & vulnerability monitoring (up to 8 devices)

Ongoing visibility of your patch posture and new vulnerability exposure - plain English, not a raw scan dump.

Security policy pack - maintained

MFA, access control, acceptable use, and incident response policies written, kept current, and ready to share with auditors or insurers.

Email advisory support

A business-hours email channel for security questions arising from your certification, policies, or a specific tender. Not a general IT helpdesk or emergency line. Response time varies by plan - see pricing for details.

Named point of contact - direct

Your lead contact from day one - no account managers, no handoffs. The person who onboards you is the person you call. One relationship across every certification, renewal, and review.

Cyber insurance readiness

Current certifications, up-to-date policies, and patching evidence maintained and ready to share at insurer renewal - so you are not scrambling to evidence your controls when the question lands.

// How It Works

FOUR STEPS, ONE ONGOING RELATIONSHIP

1

SCOPING CALL

We understand your current setup, certifications held, and what's driving the requirement. We recommend the right plan and confirm the starting point.

2

ONBOARDING

If you are already certified, we review your setup and open gaps. If you are starting fresh, we map your route through CE, CE+, and DCC Level 0.

3

ONGOING SUPPORT

Quarterly reviews, email advisory, policy maintenance, and renewal management - running in the background so you do not have to think about it.

4

YEAR-ROUND COVER

You stay certified, tender-ready, and audit-prepared. When tenders ask security questions, you have answers. When renewal is due, we handle it.

// Pricing

THREE FIXED MONTHLY PLANS

No hidden fees. 3-month minimum term, then rolling monthly - cancel any time after. Already a VCD client? Mention it and we skip straight to what we already know about your setup.

FOUNDATION
£195/month + VAT

For businesses that want to stay certified, stay compliant, and have someone to call - without the overhead of a larger retainer.

  • Annual CE/CE+ recertification managed for you (cert fee billed separately)
  • Security policy pack maintained
  • Continuous patch & vulnerability monitoring (up to 8 devices)
  • Email advisory - response within 2 business days
Get Started →
Most Popular
STANDARD
£345/month + VAT

For businesses with active pen testing requirements or reporting up to senior leadership. Everything in Foundation, plus:

  • Tender & procurement questionnaire support
  • Pentest scoping & remediation coordination
  • Quarterly risk review, written summary
  • Priority email advisory - response within 1 business day
  • 5% discount on all certifications & testing
Get Started →
ELEVATED
£495/month + VAT

For businesses in regulated or higher-risk sectors needing hands-on support. Everything in Standard, plus:

  • Monthly vCISO call
  • Incident response readiness planning
  • DCC Level 0 process managed for you
  • Annual board-level risk report
  • IASME Cyber Assurance roadmap
  • 10% discount on all certifications & testing
Get Started →

Certifications and testing are billed separately at standard pricing. Your vCISO plan covers the scoping, coordination, and remediation management around them.

Not sure which plan fits? A 15-minute scoping call will confirm the right level - no obligation.

// Scope Boundary

WHAT'S NOT INCLUDED

A clear scope means no surprises. These fall outside every plan - additional advisory time is available at £199/hour if needed.

Day-to-day IT support

IT helpdesk queries, day-to-day device management, patching, and software upgrades sit with your IT provider or MSP - we advise on what needs doing, not the doing itself.

Technical incident response

IR sits with your cyber insurer's panel. We prepare you for that call - we are not on it. The same applies to 24/7 monitoring and SOC coverage; a vCISO is an advisory role, not a managed detection service.

Legal or contract review

We answer security questions in procurement documents. Legal interpretation stays with your solicitor.

Implementation work

Configuring firewalls, deploying MDM, installing security tools, or running penetration tests is implementation - not advisory. We scope and coordinate; delivery sits with your IT team or a specialist third party.

Security awareness training

Staff training programmes, phishing simulations, and e-learning platforms are not part of a vCISO plan. We can recommend providers; delivery sits elsewhere.

Acting as DPO or GDPR lead

A vCISO manages your security posture, not your data protection compliance programme. If you need a Data Protection Officer, that is a separate appointment.

// FAQ

VCISO SUPPORT FAQ

No. You can start a vCISO plan before your first certification - we will guide you through Cyber Essentials, CE+, and DCC Level 0 as part of the plan, then keep you covered once you are through. Or add vCISO support any time after you are already certified.
Book a scoping call. We will assess where you stand, recommend which certifications apply to you, and build a plan that takes you from zero to certified to continuously maintained - one relationship, not four separate suppliers.
The recertification fee on its own is less. What you are paying for is the ongoing management, policy maintenance, quarterly reviews, and advisory access - so renewal happens without you chasing it, your policies do not go stale between audits, and you are not scrambling when a tender lands. If you only need recertification, we offer that as a standalone service.
No. We do not manage your day-to-day IT - we manage your security posture, compliance, and certification. We are happy to work alongside your existing IT provider or MSP.
Our plans run on a 3-month minimum term, then rolling monthly. Ask about short-term tender support if you need something time-boxed.
Yes, any time. Most businesses start on Foundation and move to Standard once they have active pen testing requirements or need to report up to senior leadership.
Every plan includes monitoring for up to 8 devices as standard. Additional devices are added at a fixed rate of +£8/month each on any tier, so your bill stays predictable as your estate grows - whether you are on Foundation, Standard, or Elevated. Most small teams stay within the 8-device limit comfortably - this mainly applies to larger estates or multiple-device-per-person setups.
Plans do not cover day-to-day IT support, patching, or software upgrades (these sit with your IT provider or MSP); technical incident response or 24/7 SOC monitoring (IR sits with your cyber insurer's panel); legal or contract review; implementation work such as configuring firewalls, deploying MDM, or running penetration tests; security awareness training or phishing simulations; or acting as your DPO or GDPR lead. Email advisory covers questions arising from your certification, policies, or a specific tender - not general IT queries. Additional advisory time beyond the plan scope is available at £199/hour if needed; most clients never need this. DCC Level 0 process management is included in the Elevated plan; Foundation and Standard clients requiring DCC can add this as a standalone service or upgrade. Out-of-hours and emergency response are not covered - plans operate on business-hours email advisory.
Most businesses start on Foundation - it covers CE/CE+ recertification management, security policy maintenance, continuous monitoring for up to 8 devices, and email advisory. Move to Standard if you have active pen testing requirements, need to respond to regular tender and procurement questionnaires, or need to report security posture to senior leadership. Elevated suits regulated sectors, MOD supply chain clients who need DCC Level 0 process management, or businesses that want a monthly vCISO call and an annual board-level risk report. If you are unsure, a 15-minute scoping call will confirm the right level - no obligation.
No. The monthly plan fee covers the management, advisory, and compliance work your vCISO does around certification - not the certification fee itself. CE, CE Plus, DCC Level 0, and pen testing are billed separately at standard pricing when they fall due. Standard plan clients receive a 5% discount and Elevated plan clients receive a 10% discount on all certifications and testing billed separately. Your plan cost is predictable month to month - certification fees only land when a renewal or new engagement is due.
Yes, depending on your plan. The Elevated plan includes full DCC Level 0 process management - we coordinate the CE prerequisite, prepare your scoping statement and evidence documentation, and manage the assessment through to certification. Foundation and Standard clients can add DCC Level 0 as a standalone engagement at standard pricing, or upgrade to Elevated. If you are in the MOD supply chain and need to certify ahead of the Eleanor Fairford December 2026 deadline, a scoping call will confirm the quickest route. Note that Cyber Essentials is a mandatory prerequisite for DCC Level 0 - if you do not yet hold a current CE certificate, that must be obtained first.

CERTIFIED OR STARTING OUT. WE'VE GOT YOU EITHER WAY.

Talk to our UK-based team. No jargon, no hard sell - just clear, fixed-price support.

// Blog & Guides

LATEST INSIGHTS

View All Articles →