Outsourced CISO

Outsourced CISO pricing: how much does it cost?

All the pricing models, the price drivers and the comparison with an in-house CISO to make the right choice.

3 pricing models to choose from

Monthly subscription (shared time)

All-inclusive monthly fee for ongoing SME/mid-cap steering: dedicated CISO, Data Comply One steering platform and recurring follow-up.

Custom quote

Per day

Billing per day for one-off missions, flash audits or reinforcement on a specific project.

Custom quote

Per project (flat fee)

NIS 2 compliance, DORA scoping, ISP / BCP / DRP drafting, pentests: custom pricing by scope.

Custom quote

4 factors driving the price

Size and IS perimeter

Number of critical systems, sites, users and sub-processors.

Cyber maturity level

The lower your maturity, the heavier the initial projects.

Industry sector

Healthcare (HDS), finance (DORA), critical operators (NIS2) impose reinforced requirements.

Level of support

Shared time (1-2 days/month), intensive (4-8 days/month) or full-management.

Outsourced vs in-house CISO: direct comparison

Outsourced CISO (typical SME/mid-cap)

  • • Price: custom quote, all-inclusive subscription
  • • Steering platform included
  • • Start: within 15 days
  • • Multi-sector expertise

Senior in-house CISO

  • • Gross annual salary: €85-120k
  • • Loaded cost: ~€130-180k
  • • Recruitment: 3-9 months (talent shortage)
  • • Often single-sector expertise

→ The outsourced CISO brings immediately operational expertise at a controlled overall cost, without recruitment or talent shortage.

Notre approche

Une méthodologie éprouvée, alignée sur les référentiels

Nous appliquons les standards reconnus (ISO 27001, EBIOS RM, NIST CSF, ANSSI) et adaptons notre accompagnement à vos enjeux sectoriels : banque, assurance, santé, industrie, services, public.

Un expert dédié

Un expert dédié

Votre interlocuteur unique, présent à chaque COPIL et disponible en cas de crise.

Méthodologie cadrée

Méthodologie cadrée

Livrables standardisés, planning explicite, points réguliers — vous savez où vous en êtes.

Sectoriel adapté

Sectoriel adapté

Banque, santé, industrie, public : on adapte les mesures à vos obligations spécifiques.

Disponibilité

Disponibilité

Assistance réactive, gestion de crise, accompagnement lors des contrôles des autorités.

Référentiels appliqués dans nos missions

ISO 27001 ISO 27005 EBIOS RM NIST CSF ANSSI NIS 2 DORA TIBER-EU / TLPT