Scope, readiness and a security lead — without hiring one
Fixed-price time from the practicing CISO who builds the VARVICO kits, for teams facing the Cyber Resilience Act, NIS2 or DORA. The work is mine, not subcontracted.
The offers
Scope & Obligation Snapshot
You ran the scope check or opened the kit and are not sure which role or category you fall into — or you need the answer in writing before a customer, an auditor or a supervisor asks for it.
Covers the Cyber Resilience Act, NIS2 and DORA. If you already know your scope, go straight to the engagement that fits.
Invoiced on delivery, not in advance. If the memo does not answer your scope question, there is no invoice. Credited in full against a Readiness Review started within 90 days.
Readiness Review
An obligation date 6–18 months out, a customer questionnaire, or a letter from a supervisor or a notified body. Three variants, one per regulation.
CRA: Annex I and the Article 14 reporting duties. NIS2: the Article 21 measures as your member state's law applies them. DORA: the ICT risk-management framework at the depth that applies to you — the simplified framework of Article 16 only for the entity types it names — plus the register of information.
€4,500 covers one entity, one regulation, up to six interviews, one evidence sample agreed at kickoff and two review rounds on the deliverables. Anything beyond that is priced in the proposal before you commit.
Secure Development Review
An enterprise security questionnaire, an investor's due diligence, or the secure-development evidence the Cyber Resilience Act asks of manufacturers (Annex I, Part I).
Method: OWASP SAMM across its practice areas, with NIST SSDF as an optional second lens. Written for the engineers who have to act on it and the leadership that has to fund it.
€3,000 for one product or platform; urgent or due-diligence timelines are priced in the proposal.
Fractional Security Lead
You have had a review and need someone to keep the risk register, the policies and the management reporting alive — without hiring a full-time security lead yet.
Each month follows your compliance calendar: register of information and supervisor deadlines for DORA, registration and reporting duties for NIS2, vulnerability-handling and reporting drills for the CRA.
Three tiers below. Three- or six-month minimum term.
Read a sample scope memo, three findings and a management summary — fictional organisations, the real method. The same sample pages, plus pages from the engagement type you ask about, come with every proposal.
Three things with a date on them
Short, fixed-price pieces of work tied to obligations that are live now or land next. Each one is complete in itself; where it says so, the fee also counts toward the matching Readiness Review.
CRA Article 14 reporting drill
For manufacturers of products with digital elements, and the importers who coordinate reporting with them.
Reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026: early warning within 24 hours, notification within 72 hours, then the final report, through ENISA's single reporting platform.
Your coordinated-disclosure and vulnerability-handling procedure checked against Annex I, Part II; the reporting runbook filled in with your contacts and platform access; one timed tabletop against the 24-hour and 72-hour clocks, with the gaps written up.
Fee credited against a CRA Readiness Review started within 90 days.
NIS2 supplier evidence pack
For suppliers that are not in scope themselves but sell to entities that are.
Your in-scope customers must manage supply-chain security (Article 21(2)(d)) and are sending you questionnaires at onboarding and renewal.
A reusable answer set and evidence index for customer questionnaires, the policies they most often ask for adapted from the NIS2 kit, and a one-page statement of your security posture you can hand over. Complete in itself — no further engagement implied.
DORA register pre-submission check
For financial entities preparing the 2027 submission; registers up to 25 ICT providers at this price, larger ones quoted.
The next register of information cycle takes the 31 December 2026 reference date, with submissions in the first quarter of 2027. Supervisors have said validation is stricter than in the first cycle.
Your register — in the ESA template layout, Excel or CSV — run against the ESA validation rules before you submit: identifiers, mandatory fields, cross-sheet consistency, closed-list values. Every failing row listed with the fix stated, and one re-check of the corrected file included.
Fee credited against a DORA Readiness Review started within 90 days.
Fractional Security Lead — tiers
Hours do not roll over; extra work is agreed in advance as a priced block. No on-call at any tier. On-site only in the Embedded tier, at most one day a quarter, booked three weeks ahead, travel at cost. An Advisor term costs about the same as one Readiness Review; most teams start with the review and add the retainer afterwards.
How an engagement runs
- 01Email or the formSay what you need and when. The buttons prefill the subject; the form below asks for nothing confidential.
- 0220-minute callTo confirm the fit and the timing. No preparation needed; you can keep the organisation's name back until the NDA if you prefer.
- 03Written proposalWithin three working days: scope in and out, deliverables, dates, a fixed price. It becomes part of the contract.
- 04Mutual NDASigned before anything confidential changes hands. The proposal that follows carries my CV and the contracting entity's details.
- 05Engagement letterFixed scope, written change control, deliverables yours to use inside your organisation, liability capped at the fee. Half on acceptance, half on delivery; retainers monthly in advance.
Sold by written proposal, invoiced directly — not through the store. Not legal advice; no audit opinion.
WHAT THIS IS NOT
WHAT YOU PROVIDE
Client material stays in a workspace created for the engagement and is deleted 90 days after the final invoice, except the signed deliverable and the contract.
Questions, answered plainly
Send an inquiry
Say what you need and roughly when. You get a reply within two business days, and a call slot if it fits. Or email contact@varvico.com.