For EMI, PI and CASP leadership teams
vCISO for
EU-Licensed Fintechs
A named ICT-risk owner in place in 90 days, DORA-ready, from €3,000 a month. Fixed scope, fixed price.
CyAdvisoled by Andrey Gubarev, Founder & vCISOCISM, CDPSE, SABSA
Who this is for. Leadership at an EU-licensed EMI, Payment Institution or CASP that does not have a named person owning ICT-risk governance under DORA, and is not ready to make a €150-260K full-time hire with a 3-6 month search attached to it.
What this produces. A named ICT-risk owner, a board-approved ICT-risk framework, a current evidence index, an incident-classification workflow, a third-party ICT-supplier register, and a monthly reporting cadence to your management body, delivered on the fixed-scope 90-day programme and maintained on the retainer that follows it.
Does this sound like your situation?
- You already know what a vCISO is. You have read the explainers. What you actually need now is who does it, what it costs, and how fast.
- Your board, or an incoming supervisory review, is asking who owns ICT risk under DORA Articles 5-16, and the honest answer today is “nobody named.”
- You priced a full-time CISO hire: €150-260K before equity, plus a 3-6 month search, and the exposure continues the whole time you are looking.
- You run GRC software. It manages evidence collection. It does not write the framework, brief the board, or make a classification call when an incident happens.
- You want someone who has actually run this function at EU-licensed fintechs under supervision, not a generalist consultant learning DORA on your engagement.
Run a 15-minute scoping call, the fastest way to find out what applies to you →
What you're actually buying
Four things, owned continuously under DORA Articles 5-16, not a one-time document:
Management-body reporting (Art. 5(4))
Dedicated ICT-risk reporting to your board on a defined cadence, separate from compliance reporting: material risks, open remediation items, supplier changes, incident status.
ICT incident classification (Art. 17-19)
When an incident happens, someone owns the DORA severity classification, drives response governance, and ensures the board and, where a major incident triggers it, the NCA, are notified on time.
Third-party ICT provider oversight (Art. 28-30)
The register of ICT providers, concentration-risk assessment, contract review on renewal, subcontracting-chain checks.
ICT security and testing support (Art. 9-10, 24-27)
Review of your ICT security control framework and coordination of the DORA testing programme, including vulnerability assessment and threat-led penetration-test planning where applicable.
Not a compliance-officer replacement, and not a GRC tool. A compliance officer covers regulatory monitoring and breach-notification obligations; a vCISO owns the ICT-risk framework and reports to the board on it. The two run in parallel, not instead of each other (full comparison →). GRC software collects and organises control evidence; it does not interpret the risk picture or make a board-facing governance call (full comparison →).
What each part gets you
| What you get | What it means for you |
|---|---|
| A named ICT-risk owner | One person your board and your next supervisory review can point to, not “the compliance officer covers it.” |
| Board-approved framework | Documentation your management body has actually seen and signed off, not a template nobody read. |
| Current evidence index | The artefact NCAs ask for first: proof the function operates continuously, not just that a policy exists. |
| Incident-classification workflow | Someone who can classify an incident under DORA's severity taxonomy the day it happens, not after a scramble. |
| Third-party ICT register | Your concentration risk mapped before a supplier failure becomes your incident. |
From gap to audit-ready in 90 days
-
1Day 1
Self-check or scoping call
Free. No commitment. A clear read on where you stand.
-
2Weeks 1-2
Deep gap analysis and roadmap
Full gap against DORA's 5 pillars. Prioritised remediation plan with timelines and costs. Board-ready summary.
-
3Weeks 3-10
Build and implement
Policies, procedures, controls, tailored. Evidence packs structured for external review. Your team: 2-4 hrs/week.
-
4Weeks 10-12
Test and validate
Resilience testing, tabletops, incident-response drills. You know your systems work before the regulator asks.
-
5Month 4+
Ongoing retainer
Monthly compliance, board reporting, regulator liaison. Your vCISO stays on the line.
“We had fragmented evidence and couldn’t explain our controls under review. Within 90 days, our framework was documented, defensible, and the regulator stopped repeating the same control questions.”
What changes once someone owns this
-
Before. A supervisory question about ICT-risk ownership gets a compliance officer answering outside their function, or no answer. An incident happens and classification is improvised. Your board sees ICT risk as a line item, not a report.
-
After the 90-day programme. A named owner, a board-approved framework, and an evidence index exist. Your board has seen and signed off the framework.
-
After the retainer starts (month 4+). The cadence runs itself: monthly register review and incident-status check, quarterly board report and supplier-register review, on-trigger incident governance and NCA-notice preparation, annual continuity-plan review.
Already done, for EU-licensed fintechs
Three anonymised, published engagements: a DORA gap analysis for an EMI, an incident-reporting register build for a Payment Institution, MiCA + DORA readiness for a CASP (read the case studies →).
Your alternatives, honestly compared
Each is a real route an EU-licensed fintech takes, and where each one leaves a gap the NCA can see.
| Criteria | CyAdviso vCISO |
Full-time CISO |
Big 4 / Law Firm |
GRC Platform |
Compliance officer |
Do Nothing |
|---|---|---|---|---|---|---|
| Annual cost | €36-60K | €150-260K+ | €80-200K | €5-15K | €0 incremental | €0* |
| DORA expertise | Deep | Depends | Legal yes | SOC2/ISO27001** · DORA gaps | Wrong domain | None |
| Technical implementation | Full | Full | Advisory only | Self-service | Out of scope | None |
| Board reporting | Included | Included | Extra cost | No | Legal flavour | No |
| Time to compliance | 90 days | 3-6 mo | 3-12 mo | Depends | Indefinite | Never |
| Ongoing support | Retained | Permanent | Project | Platform | Wrong domain | None |
| Risk exposure | Managed | Managed | Partial | Partial | False confidence | You ARE the risk |
*Not zero: the cost of doing nothing is the supervisory exposure itself, not a line item. **Most GRC platforms are strong on SOC2/ISO27001 evidence collection; DORA-specific gaps remain.
- Helps
- Deep DORA expertise, full technical implementation, board reporting included, 90-day time to compliance, retained ongoing support, at €36-60K a year.
- Gap
- Risk exposure is managed, not eliminated. No vendor removes all ICT risk.
- Choose if
- You want a named ICT-risk owner with DORA expertise, technical delivery, and board reporting, in place within 90 days.
- Helps
- Full technical implementation and board reporting, with permanent, in-house ongoing support.
- Gap
- €150-260K+ a year before equity, plus a 3-6 month hiring window with exposure continuing the whole time.
- Choose if
- Budget and headcount both allow a permanent hire and you can absorb the search window.
- Helps
- Legal expertise and a recognised name on a report.
- Gap
- Advisory only, no technical implementation; board reporting is extra cost.
- Choose if
- You need a legal opinion, not the framework built and operated.
- Helps
- Low annual cost (€5-15K), organises evidence collection.
- Gap
- Self-service implementation, no board reporting, DORA-specific gaps beyond SOC2/ISO27001 evidence.
- Choose if
- You already have someone to interpret the risk picture and just need the tooling.
- Helps
- No incremental cost, already on staff for legal/AML monitoring.
- Gap
- ICT risk is the wrong domain: out of scope technically, legal-flavoured reporting at best, false confidence at worst.
- Choose if
- Never, as a substitute for ICT-risk ownership; the two functions run in parallel.
- Helps
- No spend today.
- Gap
- No expertise, no implementation, no reporting, indefinite time to compliance. The cost is the supervisory exposure itself.
- Choose if
- Never, once a board or supervisor has asked the ownership question.
Frequently asked questions
Scope, cost and how it works
Is a vCISO different from a compliance officer who already covers cyber?
Yes. DORA Articles 5-16 require continuous ICT-risk ownership: framework, board reporting, incident classification. A compliance officer's function is regulatory monitoring and breach notification. The two run in parallel. Full comparison →
We already run GRC software. Do we still need a vCISO?
The tool collects and organises control evidence. It does not interpret the risk picture, write the framework, or make the board-facing governance call. Full comparison →
Should we start with a one-off gap assessment or the retainer?
It depends on whether you already have a framework. If nothing exists yet, the 90-day programme builds it first; the retainer maintains it from month 4. Retainer vs. project, compared →
What's the minimum engagement?
3 months on the retainer model. The 90-day fixed-scope programme is exactly that. Single-engagement scopes start at 4-8 weeks.
How is this different from a Big 4 audit?
Big 4 tells you what's wrong and hands you a report. We fix it: build the framework, write the policies, train your team, and stay on retainer to keep it running. You get a vCISO, not a PDF.
What if a review still finds gaps after the engagement?
No serious CISO promises a reviewer will never find another issue. The 90-day programme creates the defensible floor: named ownership, board-approved framework, current evidence index, incident workflow, supplier view, remediation tracker. If a review finds something, you can show what was known, who owned it, and how it was being managed.
Can’t find your question? Ask on a 15-minute call, or email info@cyadviso.com.
The sources this page relies on
The scope in the “What you're actually buying” section above maps to Regulation (EU) 2022/2554 (DORA), Articles 5, 5(4), 8, 9-10, 11-12, 17-19, 24-27 and 28-30.
Show the source
-
DORA: Regulation (EU) 2022/2554, Articles 5, 5(4), 8, 9-10, 11-12, 17-19, 24-27, 28-30. Management-body reporting, ICT security and testing, business continuity, incident classification and reporting, and third-party ICT-provider oversight, the four deliverables above map directly to these articles.
A related article covering this scope in full is drafted and not yet live on the blog.
What this engagement is, and what it is not
Fixed tiers, published up front. What you get, and what stays with your own team.
Building the ICT-risk framework, policies and evidence index (90-day programme); ongoing governance of that framework under DORA Articles 5-16 (retainer, month 4+): board reporting, incident classification, third-party oversight, security/testing coordination.
The compliance function itself: regulatory monitoring, NCA liaison on compliance matters, breach-notification obligations stay with your compliance officer; the vCISO and compliance officer work in parallel, not instead of each other. Day-to-day IT infrastructure operations and hands-on managed security services: the vCISO is a governance function, reviewing whether controls are appropriate and operating, not running your IT department.
Fixed tiers, published up front
Most engagements follow the same path: free scoping call, then a single engagement or the 90-day programme, then ongoing vCISO retainer. All engagements include monthly board-report packs and evidence your regulator can accept. Minimum commitment 3 months. 30-day exit clause after month 3.
Single Engagement
A defined, bounded question (e.g. one policy, one review).
90-Day Programme
Building the framework from a gap to audit-ready.
vCISO Retainer
Ongoing governance once the framework exists.
A named ICT-risk owner for your fintech, in 90 days.
Or email info@cyadviso.com · No commitment. No sales pressure.