Whether you are starting from scratch or already certified, vCISO support is how you get a security lead without hiring one. Starting out? We guide you through certification and keep you covered once you are through. Already certified? This is what comes next. Plain English, fixed price, no jargon - either way.
They need someone to call before a problem becomes a breach, a lapsed certificate, or a lost tender. A vCISO - sometimes called a fractional CISO - gives you that person, without the £80,000+ salary.
Without someone managing renewal, businesses miss deadlines and lose tender eligibility. Your certificate does not renew itself.
MFA rules, access controls, and patching policies written once and never revisited are the most common reason businesses fail their CE+ retest.
A report is a point-in-time snapshot. Without ongoing management, the same class of vulnerability quietly reappears within a year.
Supply chain requirements under DEFCON 658 are reviewed on an ongoing basis, not just at onboarding.
Procurement questionnaires, supply chain due diligence, and insurance renewals all expect answers you may not have in-house.
Insurers are asking harder questions at renewal. Up-to-date policies, patching evidence, and current certifications are increasingly required to maintain cover.
Businesses wanting one guide through certification and beyond - not a different supplier at every stage.
No in-house IT security lead, but tenders and clients are asking security questions. Foundation plan provides the cover you need.
SRA guidance, client confidentiality obligations, and supply chain due diligence all require ongoing security management.
NHS DSPT submissions, UK GDPR Article 32, and clinical data obligations require regular testing and documented security governance.
DfE requirements, safeguarding-linked data, and multi-site complexity make ongoing security oversight essential.
DEFCON 658, DCC Level 0, and enterprise procurement all require ongoing security posture management beyond the point of certification.

Every VCD service - Cyber Essentials, CE+, DCC Level 0, and pen testing - integrates with your vCISO plan. Direct lead contact from day one. No handoffs, no account managers, no starting from scratch at every renewal.
Proving you are secure today, and staying secure after.
A vCISO plan can begin before your first certification. We scope your setup, get you audit-ready, guide you through CE, CE+, and DCC Level 0 as they become relevant, and keep going once you are certified. One point of contact for the whole journey, instead of a new supplier at every stage.
The moment your CE+ certificate is issued, or your pen test report lands, the clock starts running on the next twelve months - new vulnerabilities, new starters and leavers, new devices, new tenders asking the same questions again. vCISO support is how our clients stop starting from scratch every renewal cycle.
CE and CE+ renewal managed start to finish so it never lapses. We handle the process; you sign the declaration. Certification fees are billed separately at standard pricing.
Ongoing visibility of your patch posture and new vulnerability exposure - plain English, not a raw scan dump.
MFA, access control, acceptable use, and incident response policies written, kept current, and ready to share with auditors or insurers.
A business-hours email channel for security questions arising from your certification, policies, or a specific tender. Not a general IT helpdesk or emergency line. Response time varies by plan - see pricing for details.
Your lead contact from day one - no account managers, no handoffs. The person who onboards you is the person you call. One relationship across every certification, renewal, and review.
Current certifications, up-to-date policies, and patching evidence maintained and ready to share at insurer renewal - so you are not scrambling to evidence your controls when the question lands.
We understand your current setup, certifications held, and what's driving the requirement. We recommend the right plan and confirm the starting point.
If you are already certified, we review your setup and open gaps. If you are starting fresh, we map your route through CE, CE+, and DCC Level 0.
Quarterly reviews, email advisory, policy maintenance, and renewal management - running in the background so you do not have to think about it.
You stay certified, tender-ready, and audit-prepared. When tenders ask security questions, you have answers. When renewal is due, we handle it.
No hidden fees. 3-month minimum term, then rolling monthly - cancel any time after. Already a VCD client? Mention it and we skip straight to what we already know about your setup.
For businesses that want to stay certified, stay compliant, and have someone to call - without the overhead of a larger retainer.
For businesses with active pen testing requirements or reporting up to senior leadership. Everything in Foundation, plus:
For businesses in regulated or higher-risk sectors needing hands-on support. Everything in Standard, plus:
Certifications and testing are billed separately at standard pricing. Your vCISO plan covers the scoping, coordination, and remediation management around them.
Not sure which plan fits? A 15-minute scoping call will confirm the right level - no obligation.
A clear scope means no surprises. These fall outside every plan - additional advisory time is available at £199/hour if needed.
IT helpdesk queries, day-to-day device management, patching, and software upgrades sit with your IT provider or MSP - we advise on what needs doing, not the doing itself.
IR sits with your cyber insurer's panel. We prepare you for that call - we are not on it. The same applies to 24/7 monitoring and SOC coverage; a vCISO is an advisory role, not a managed detection service.
We answer security questions in procurement documents. Legal interpretation stays with your solicitor.
Configuring firewalls, deploying MDM, installing security tools, or running penetration tests is implementation - not advisory. We scope and coordinate; delivery sits with your IT team or a specialist third party.
Staff training programmes, phishing simulations, and e-learning platforms are not part of a vCISO plan. We can recommend providers; delivery sits elsewhere.
A vCISO manages your security posture, not your data protection compliance programme. If you need a Data Protection Officer, that is a separate appointment.
Talk to our UK-based team. No jargon, no hard sell - just clear, fixed-price support.
Every certification and test below can be scoped, coordinated, and renewed through your vCISO plan - one relationship instead of four separate suppliers.
Annual renewal managed start to finish across all plans. Certification fee billed separately at standard pricing. Free cyber liability insurance up to £25,000 for eligible UK organisations.
Explore CE →// All PlansTechnical audit renewal coordinated through your plan. Pre-Assessment Check included as standard before every CE Plus audit to reduce failure risk.
Explore CE Plus →// ElevatedFull DCC Level 0 process management included in Elevated - scoping, evidence, annual attestation. Foundation and Standard clients can add DCC as a standalone engagement.
Explore DCC Level 0 →// Standard & ElevatedScoping and remediation coordination included in Standard and Elevated. Pen test execution billed separately. Free 30-day retest included as standard with every engagement.
Explore Pen Testing →