VARVICO ADVISORY · FIXED PRICE · REMOTE

Scope, readiness and a security lead — without hiring one

Fixed-price time from the practicing CISO who builds the VARVICO kits, for teams facing the Cyber Resilience Act, NIS2 or DORA. The work is mine, not subcontracted.

REMOTE
Calls on Google Meet, CET business hours
ENGLISH
Calls, proposals and every deliverable
REPLY
Within two business days; proposal within three
CONTRACT
Named entity, VAT number and liability cap stated in every proposal

The offers

START HERE

Scope & Obligation Snapshot

€750 fixed
Two calls, delivered within five working days
WHEN

You ran the scope check or opened the kit and are not sure which role or category you fall into — or you need the answer in writing before a customer, an auditor or a supervisor asks for it.

Covers the Cyber Resilience Act, NIS2 and DORA. If you already know your scope, go straight to the engagement that fits.

YOU GET
Your scope record from the kit, completed with you on the call
A two-page memo: which obligations apply, with the article references
Where your member state's law sets the rule — registration, deadlines, the national authority — the memo says so
The points your counsel should look at, listed
NOT
A legal opinion on scope
A notified-body procedure

Invoiced on delivery, not in advance. If the memo does not answer your scope question, there is no invoice. Credited in full against a Readiness Review started within 90 days.

BEFORE A DEADLINE

Readiness Review

From €4,500 fixed
Four calendar weeks, remote
WHEN

An obligation date 6–18 months out, a customer questionnaire, or a letter from a supervisor or a notified body. Three variants, one per regulation.

CRA: Annex I and the Article 14 reporting duties. NIS2: the Article 21 measures as your member state's law applies them. DORA: the ICT risk-management framework at the depth that applies to you — the simplified framework of Article 16 only for the entity types it names — plus the register of information.

YOU GET
A gap register scored 0–3 per requirement, mapped to the kit's control list and the article it answers to
The evidence that is missing, item by item
A management summary and a six-month plan
The relevant kit, tailored to what the review found
NOT
An audit opinion or attestation
Contact with authorities or notified bodies on your behalf

€4,500 covers one entity, one regulation, up to six interviews, one evidence sample agreed at kickoff and two review rounds on the deliverables. Anything beyond that is priced in the proposal before you commit.

ENGINEERING

Secure Development Review

From €3,000 fixed
Two calendar weeks, remote, at most six interviews
WHEN

An enterprise security questionnaire, an investor's due diligence, or the secure-development evidence the Cyber Resilience Act asks of manufacturers (Annex I, Part I).

Method: OWASP SAMM across its practice areas, with NIST SSDF as an optional second lens. Written for the engineers who have to act on it and the leadership that has to fund it.

YOU GET
A maturity heatmap across the OWASP SAMM practice areas
A prioritised findings register your engineers can act on
An executive summary and a 30/60/90-day roadmap
NOT
A penetration test
A code audit
Any certificate

€3,000 for one product or platform; urgent or due-diligence timelines are priced in the proposal.

ONGOING

Fractional Security Lead

Monthly, hours-capped, business hours CET
WHEN

You have had a review and need someone to keep the risk register, the policies and the management reporting alive — without hiring a full-time security lead yet.

Each month follows your compliance calendar: register of information and supervisor deadlines for DORA, registration and reporting duties for NIS2, vulnerability-handling and reporting drills for the CRA.

YOU GET
A monthly report and a decision log
Risk register and control calendar kept current
Policy and vendor-questionnaire reviews within the hours cap
A quarterly management pack
NOT
A CISO of record
On-call incident command
Representation before a regulator

Three tiers below. Three- or six-month minimum term.

Read a sample scope memo, three findings and a management summary — fictional organisations, the real method. The same sample pages, plus pages from the engagement type you ask about, come with every proposal.

Three things with a date on them

Short, fixed-price pieces of work tied to obligations that are live now or land next. Each one is complete in itself; where it says so, the fee also counts toward the matching Readiness Review.

CRA Article 14 reporting drill

€2,900 fixed · Two weeks
FOR

For manufacturers of products with digital elements, and the importers who coordinate reporting with them.

WHY NOW

Reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026: early warning within 24 hours, notification within 72 hours, then the final report, through ENISA's single reporting platform.

YOU GET

Your coordinated-disclosure and vulnerability-handling procedure checked against Annex I, Part II; the reporting runbook filled in with your contacts and platform access; one timed tabletop against the 24-hour and 72-hour clocks, with the gaps written up.

Fee credited against a CRA Readiness Review started within 90 days.

NIS2 supplier evidence pack

€1,900 fixed · Two weeks
FOR

For suppliers that are not in scope themselves but sell to entities that are.

WHY NOW

Your in-scope customers must manage supply-chain security (Article 21(2)(d)) and are sending you questionnaires at onboarding and renewal.

YOU GET

A reusable answer set and evidence index for customer questionnaires, the policies they most often ask for adapted from the NIS2 kit, and a one-page statement of your security posture you can hand over. Complete in itself — no further engagement implied.

DORA register pre-submission check

€1,900 fixed · One week
FOR

For financial entities preparing the 2027 submission; registers up to 25 ICT providers at this price, larger ones quoted.

WHY NOW

The next register of information cycle takes the 31 December 2026 reference date, with submissions in the first quarter of 2027. Supervisors have said validation is stricter than in the first cycle.

YOU GET

Your register — in the ESA template layout, Excel or CSV — run against the ESA validation rules before you submit: identifiers, mandatory fields, cross-sheet consistency, closed-list values. Every failing row listed with the fix stated, and one re-check of the corrected file included.

Fee credited against a DORA Readiness Review started within 90 days.

Fractional Security Lead — tiers

ADVISOR
€1,500 / month
8 h / month
Two business days, written
Minimum term 3 months
LEAD
€2,800 / month
16 h / month
One business day; two calls a month
Minimum term 6 months
EMBEDDED
€4,800 / month
30 h / month
Same business day; weekly call
Minimum term 6 months
Offered when capacity allows; confirmed in the proposal

Hours do not roll over; extra work is agreed in advance as a priced block. No on-call at any tier. On-site only in the Embedded tier, at most one day a quarter, booked three weeks ahead, travel at cost. An Advisor term costs about the same as one Readiness Review; most teams start with the review and add the retainer afterwards.

How an engagement runs

  1. 01
    Email or the form
    Say what you need and when. The buttons prefill the subject; the form below asks for nothing confidential.
  2. 02
    20-minute call
    To confirm the fit and the timing. No preparation needed; you can keep the organisation's name back until the NDA if you prefer.
  3. 03
    Written proposal
    Within three working days: scope in and out, deliverables, dates, a fixed price. It becomes part of the contract.
  4. 04
    Mutual NDA
    Signed before anything confidential changes hands. The proposal that follows carries my CV and the contracting entity's details.
  5. 05
    Engagement letter
    Fixed scope, written change control, deliverables yours to use inside your organisation, liability capped at the fee. Half on acceptance, half on delivery; retainers monthly in advance.

Sold by written proposal, invoiced directly — not through the store. Not legal advice; no audit opinion.

WHAT THIS IS NOT

Legal advice — your counsel reviews anything that carries legal weight
An audit, an attestation or any form of sign-off
A penetration test or a code audit
Contact with regulators or notified bodies on your behalf
A CISO of record or an on-call incident commander

WHAT YOU PROVIDE

One point of contact who can open doors and answer within a day
An index of what exists: policies, registers, contracts, previous audits
Two to six short interviews, scheduled in the first week
Read access to the evidence the proposal names — nothing more
A decision-maker for the closing call

Client material stays in a workspace created for the engagement and is deleted 90 days after the final invoice, except the signed deliverable and the contract.

Questions, answered plainly

Usually within two weeks of accepting the proposal; the proposal states the date. I run a small number of engagements at a time so each one gets the attention it needs, and the intro call tells you where the next slot is.

Send an inquiry

Say what you need and roughly when. You get a reply within two business days, and a call slot if it fits. Or email contact@varvico.com.

Reply by:
or email contact@varvico.com

Kept as correspondence under the privacy notice. No newsletter, no sequence.