The operating system for vCISO engagements

A client's full security program, drafted in an afternoon.

CISO Doc replaces blank-page drafting with guided interview workflows that generate a complete, audit-ready documentation suite — policies, plans, risk registers, and board reports — tailored to each client engagement.

01

Information Security Policy

  • 01.1Purpose & Scope
  • 01.2Roles & Responsibilities
  • 01.3Acceptable Use
  • 01.4Review Cycle
02

Risk Register

  • 02.1Asset Inventory
  • 02.2Threat & Likelihood
  • 02.3Impact Rating
  • 02.4Treatment Plan
03

Board Report

  • 03.1Program Maturity
  • 03.2Open Risks
  • 03.3Remediation Status
  • 03.4Next Quarter

Output mapped to the frameworks your clients are audited against

SOC 2ISO 27001GDPRHIPAANIST CSF+18 more

The vCISO time tax

Every new client costs you a week of policy drafting before the strategic work begins.

Each engagement demands 20–40 bespoke documents — tailored to the client's industry, size, compliance obligations, and stack. Generic templates buy you a head start but still consume 40–80 hours per engagement.

80h
saved per engagement
40+
documents generated
23
frameworks mapped

The platform

Four layers. One engagement OS.

CISO Doc unifies the workflow that's currently scattered across templates, spreadsheets, and slide decks.

01

Client Intelligence Engine

Capture comprehensive client context through structured intake — the single source of truth every downstream document draws from.

02

Document Generation Engine

Apply context to a library of intelligent templates that produce specific, accurate first drafts — editable from minute one.

03

Compliance & Program Tracker

Map documents and controls to frameworks, track remediation, and maintain a living compliance calendar.

04

Reporting & Delivery Layer

Generate board reports, maturity scorecards, and audit evidence packages from live document and metrics data.

Capabilities

Everything a vCISO ships, in one place.

From the first intake call to the quarterly board update — CISO Doc covers the full surface area of a security engagement.

Guided intake interviews

Eight domain modules covering Governance, Risk, Policies, Compliance, IR, BCDR, Architecture, and Awareness.

Connected document graph

Update a control once — every policy, plan, and report that references it stays in sync automatically.

Framework crosswalk

Map controls to SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF, NIST 800-53, NIST RMF, FedRAMP, NIST AI RMF, EU AI Act, GDPR, DORA, NIS2, MITRE ATLAS, CMMC, NERC CIP, CIS Controls v8, OWASP Top 10 2025, OWASP GenAI Top 10 2026, OWASP Agentic Top 10 2026, OWASP GenAI Data Security 2026, and OWASP Agentic Skills Top 10 2026 simultaneously.

Client portal & approvals

Give stakeholders scoped read or edit access. Capture acknowledgments and approvals as audit evidence.

Board-ready reporting

Auto-generate maturity scorecards, risk heatmaps, and quarterly board decks from live engagement data.

Multi-tenant by design

Strict client isolation, SSO, role-based access, and a shared template library across your practice.

Coverage

One source of truth. Every framework.

Every generated document carries traceable control mappings. When an auditor asks for evidence, the package is one click away.

Security

SOC 2
ISO 27001
NIST CSF
NIST 800-53

Privacy & regulatory

HIPAA
PCI DSS
GDPR
DORA

AI governance

NIST AI RMF
EU AI Act
ISO 42001
MITRE ATLAS

Intake flows

Every framework, backed by a guided intake.

Each control area opens with a structured interview that captures exactly what the downstream policies, registers, and reports need — nothing more, nothing less.

GDPR

Records of Processing Activities (ROPA)

Catalog every processing activity, purpose, lawful basis, data categories, recipients, transfers, and retention — Article 30 ready.

28 guided questions
  • ROPA register
  • Controller/processor matrix
  • Retention schedule
GDPR

Data Protection Impact Assessment (DPIA)

Walk through necessity, proportionality, risk to data subjects, and mitigations for any high-risk processing activity.

34 guided questions
  • DPIA report
  • Risk register entries
  • Consultation log
GDPR

Data Subject Rights (DSAR) workflow

Capture intake, identity verification, scope, and fulfillment evidence for access, rectification, erasure, and portability requests.

18 guided questions
  • DSAR procedure
  • Response templates
  • Verification log
GDPR

International data transfer assessment

Map cross-border flows, document SCCs / adequacy decisions, and run the transfer impact analysis required post-Schrems II.

22 guided questions
  • TIA report
  • SCC register
  • Subprocessor agreements
GDPR

Breach notification playbook

Operationalize the 72-hour clock: severity scoring, supervisory authority notification, and data subject communication templates.

16 guided questions
  • Breach response plan
  • Notification templates
  • Decision log
CIS v8

Enterprise asset inventory (IG1–IG3)

Onboard hardware, cloud instances, IoT, and mobile assets with owner, sensitivity, location, and decommission tracking.

24 guided questions
  • Asset register
  • CMDB import
  • Lifecycle policy
CIS v8

Software & SaaS inventory

Capture authorized software, SaaS subscriptions, unsupported components, and the allow/deny-list governance behind them.

19 guided questions
  • Software inventory
  • SaaS register
  • Allowlisting policy
CIS v8

Secure configuration baselines

Document hardening standards by platform (workstation, server, cloud, network) and the deviation approval process.

21 guided questions
  • Configuration standard
  • Deviation register
  • Image build SOP
CIS v8

Account & access management

Joiner/mover/leaver, privileged access, MFA coverage, and service account governance across identity providers.

26 guided questions
  • Access control policy
  • JML procedure
  • Privileged access register
CIS v8

Continuous vulnerability management

Scanning cadence, SLAs by severity, exception governance, and remediation evidence collection.

17 guided questions
  • Vuln mgmt policy
  • Remediation SLA matrix
  • Exception register
CIS v8

Audit log management

Define log sources, retention, time sync, centralized collection, and detection use cases mapped to CIS Control 8.

15 guided questions
  • Logging standard
  • Retention schedule
  • Detection catalog
CIS v8 & GDPR

Data protection inventory

Classify data, map storage and flows, and align encryption, DLP, and minimization to both CIS Control 3 and GDPR Article 32.

23 guided questions
  • Data classification
  • Data flow diagrams
  • Encryption standard

Pricing

Aligned to your practice's growth.

Start solo, scale to a multi-CISO firm. Move between tiers without losing engagement history. Every plan includes a 14-day free trial with two sample engagements already loaded.

Starter

For an independent vCISO running a first handful of engagements.

$299/mo
  • 1 vCISO user
  • Up to 3 active engagements
  • Full document library
  • All intake modules
  • Basic compliance tracker
  • Email support
Start free trial
Most popular

Professional

For growing vCISO firms and MSSPs standardizing across a team.

$799/mo
  • 3 vCISO users
  • Up to 10 active engagements
  • Everything in Starter
  • Client portal
  • Phase 1 integrations
  • Priority support
  • Custom branding
Start free trial

Team

For established consultancies running a full engagement portfolio.

$1,499/mo
  • 10 vCISO users
  • Up to 30 active engagements
  • Everything in Professional
  • Template authoring
  • API access
  • Phase 2 integrations
  • Dedicated CSM
Start free trial

Enterprise

For consultancies, MSSPs, and advisory practices at scale.

Custom
  • Unlimited users & engagements
  • All features, all tiers
  • Custom data residency
  • SSO (SAML / OIDC)
  • Custom integrations
  • SLA guarantees
Talk to sales