The operating system for vCISO engagements

A client's full security program, drafted in an afternoon.

CISO Doc replaces blank-page drafting with guided interview workflows that generate a complete, audit-ready documentation suite — policies, plans, risk registers, and board reports — tailored to each client engagement.

SOC 2 · ISO 27001 · HIPAA · PCI DSS · GDPR · NIST CSF · NIST 800-53 · NIST RMF · DORA · NIS2 · MITRE ATLAS · CMMC · NERC CIP · CIS Controls v8 · OWASP Top 10 2025 · OWASP GenAI Top 10 2026 · OWASP Agentic Top 10 2026 · OWASP GenAI Data Security 2026 · NIST AI RMF · EU AI Act · ISO 42001 · FedRAMP · OWASP Agentic Skills Top 10 2026

Document graph showing connected security policies and controls

Output mapped to the frameworks your clients are audited against

SOC 2ISO 27001HIPAAPCI DSSNIST CSFNIST 800-53NIST RMFGDPRDORANIS2MITRE ATLASCMMCNERC CIPCIS Controls v8OWASP Top 10 2025OWASP GenAI Top 10 2026OWASP Agentic Top 10 2026OWASP GenAI Data Security 2026NIST AI RMFEU AI ActISO 42001FedRAMPOWASP Agentic Skills Top 10 2026

The vCISO time tax

Every new client costs you a week of policy drafting before the strategic work begins.

Each engagement demands 20–40 bespoke documents — tailored to the client's industry, size, compliance obligations, and stack. Generic templates buy you a head start but still consume 40–80 hours per engagement.

80h
saved per engagement
40+
documents generated
23
frameworks mapped

The platform

Four layers. One engagement OS.

CISO Doc unifies the workflow that's currently scattered across templates, spreadsheets, and slide decks.

01

Client Intelligence Engine

Capture comprehensive client context through structured intake — the single source of truth every downstream document draws from.

02

Document Generation Engine

Apply context to a library of intelligent templates that produce specific, accurate first drafts — editable from minute one.

03

Compliance & Program Tracker

Map documents and controls to frameworks, track remediation, and maintain a living compliance calendar.

04

Reporting & Delivery Layer

Generate board reports, maturity scorecards, and audit evidence packages from live document and metrics data.

Capabilities

Everything a vCISO ships, in one place.

From the first intake call to the quarterly board update — CISO Doc covers the full surface area of a security engagement.

Guided intake interviews

Eight domain modules covering Governance, Risk, Policies, Compliance, IR, BCDR, Architecture, and Awareness.

Connected document graph

Update a control once — every policy, plan, and report that references it stays in sync automatically.

Framework crosswalk

Map controls to SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF, NIST 800-53, NIST RMF, FedRAMP, NIST AI RMF, EU AI Act, GDPR, DORA, NIS2, MITRE ATLAS, CMMC, NERC CIP, CIS Controls v8, OWASP Top 10 2025, OWASP GenAI Top 10 2026, OWASP Agentic Top 10 2026, OWASP GenAI Data Security 2026, and OWASP Agentic Skills Top 10 2026 simultaneously.

Client portal & approvals

Give stakeholders scoped read or edit access. Capture acknowledgments and approvals as audit evidence.

Board-ready reporting

Auto-generate maturity scorecards, risk heatmaps, and quarterly board decks from live engagement data.

Multi-tenant by design

Strict client isolation, SSO, role-based access, and a shared template library across your practice.

Coverage

One source of truth. Every framework.

Every generated document carries traceable control mappings. When an auditor asks for evidence, the package is one click away.

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF
NIST 800-53
NIST RMF
GDPR
DORA
NIS2
MITRE ATLAS
CMMC
NERC CIP
CIS Controls v8
OWASP Top 10 2025
OWASP GenAI Top 10 2026
OWASP Agentic Top 10 2026
OWASP GenAI Data Security 2026
NIST AI RMF
EU AI Act
ISO 42001
FedRAMP
OWASP Agentic Skills Top 10 2026

Intake flows

Every framework, backed by a guided intake.

Each control area opens with a structured interview that captures exactly what the downstream policies, registers, and reports need — nothing more, nothing less.

GDPR

Records of Processing Activities (ROPA)

Catalog every processing activity, purpose, lawful basis, data categories, recipients, transfers, and retention — Article 30 ready.

28 guided questions
  • ROPA register
  • Controller/processor matrix
  • Retention schedule
GDPR

Data Protection Impact Assessment (DPIA)

Walk through necessity, proportionality, risk to data subjects, and mitigations for any high-risk processing activity.

34 guided questions
  • DPIA report
  • Risk register entries
  • Consultation log
GDPR

Data Subject Rights (DSAR) workflow

Capture intake, identity verification, scope, and fulfillment evidence for access, rectification, erasure, and portability requests.

18 guided questions
  • DSAR procedure
  • Response templates
  • Verification log
GDPR

International data transfer assessment

Map cross-border flows, document SCCs / adequacy decisions, and run the transfer impact analysis required post-Schrems II.

22 guided questions
  • TIA report
  • SCC register
  • Subprocessor agreements
GDPR

Breach notification playbook

Operationalize the 72-hour clock: severity scoring, supervisory authority notification, and data subject communication templates.

16 guided questions
  • Breach response plan
  • Notification templates
  • Decision log
CIS v8

Enterprise asset inventory (IG1–IG3)

Onboard hardware, cloud instances, IoT, and mobile assets with owner, sensitivity, location, and decommission tracking.

24 guided questions
  • Asset register
  • CMDB import
  • Lifecycle policy
CIS v8

Software & SaaS inventory

Capture authorized software, SaaS subscriptions, unsupported components, and the allow/deny-list governance behind them.

19 guided questions
  • Software inventory
  • SaaS register
  • Allowlisting policy
CIS v8

Secure configuration baselines

Document hardening standards by platform (workstation, server, cloud, network) and the deviation approval process.

21 guided questions
  • Configuration standard
  • Deviation register
  • Image build SOP
CIS v8

Account & access management

Joiner/mover/leaver, privileged access, MFA coverage, and service account governance across identity providers.

26 guided questions
  • Access control policy
  • JML procedure
  • Privileged access register
CIS v8

Continuous vulnerability management

Scanning cadence, SLAs by severity, exception governance, and remediation evidence collection.

17 guided questions
  • Vuln mgmt policy
  • Remediation SLA matrix
  • Exception register
CIS v8

Audit log management

Define log sources, retention, time sync, centralized collection, and detection use cases mapped to CIS Control 8.

15 guided questions
  • Logging standard
  • Retention schedule
  • Detection catalog
CIS v8 & GDPR

Data protection inventory

Classify data, map storage and flows, and align encryption, DLP, and minimization to both CIS Control 3 and GDPR Article 32.

23 guided questions
  • Data classification
  • Data flow diagrams
  • Encryption standard

Pricing

Aligned to your practice's growth.

Start solo, scale to a multi-CISO firm. Move between tiers without losing engagement history.

Solo Practitioner

For independent vCISOs running up to three concurrent engagements.

$249/mo
  • Up to 3 client engagements
  • Full template library
  • All framework crosswalks
  • PDF & Word export
Start free trial
Most popular

Practice

For growing vCISO firms and MSSPs standardizing across a team.

$799/mo
  • Up to 15 engagements, 5 seats
  • Shared template library
  • Client portal & approvals
  • Board reporting & scorecards
  • SSO (SAML / OIDC)
Start free trial

Enterprise

For consultancies, MSSPs, and advisory practices at scale.

Custom
  • Unlimited engagements & seats
  • Custom templates & branding
  • Audit log & DLP integrations
  • Dedicated success manager
Talk to sales

Stop drafting. Start advising.

Join the early-access program and onboard your first client engagement this week.