An ISMS that someone actually runs.
Maintenance of the risk register, action plan, and policies in day-to-day operation — on fixed dates rather than in bursts shortly before the audit.
NIS2, ISO 27001, and TISAX® all ask for the same thing: a designated, reachable, properly resourced responsibility for information security. In companies between twenty and two hundred employees there is rarely a suitable position for it — so the task lands with the head of IT, who already holds a full-time role. We take on the engagement: as your designated information security officer, with a fixed reporting line to your executive management.
Not out of negligence — but because for most companies it is too big to do on the side and too small to justify a position of its own.
Whoever is responsible for operations cannot assess them independently. That dual role surfaces in the audit at the latest — and it means security work always ends up behind day-to-day business.
An externally produced policy package does not pass an audit if nobody maintains it. Assessors do not check whether an ISMS exists, but whether it is lived — certifications fail on that more often than on technology.
Section 38 BSIG requires approval and oversight by executive management. Without someone reporting to them regularly and in a structured way, that duty is practically impossible to fulfill — and, in case of doubt, impossible to prove.
Security questionnaires, audit requests, and supply chain reviews need an addressee with subject expertise. Without one, these requests wander through the company and get answered too slowly or too vaguely.
The question is rarely whether the role is needed — but in which form it fits the size of the company.
| Employed internally | External retainer (vCISO) | On the side, by IT | |
|---|---|---|---|
| Available in | three to nine months of searching | two to four weeks | immediately — nominally |
| Cost | full-time position plus training | a fraction of that, tied to actual demand | hidden — in overtime and neglected operations |
| Independence | given, provided it does not report into IT | structurally given | not given — operations assess themselves |
| Certification experience | depends on the individual | from many procedures, not from one | usually none |
| Scales under audit pressure | no — the position stays the same size | yes — scope is adjusted | no — operations suffer first |
| Makes sense from | around 200 employees | around 20 to 200 employees | only as an interim solution |
The market confirms this calculation: according to the State of the vCISO Report 2025, the share of managed service providers offering a vCISO service rose from 21 to 67 percent within a single year. Not because the model is new — but because regulation is now reaching company sizes that could never have afforded a security department of their own.
Not advice on request, but a role with fixed dates, fixed deliverables, and a fixed reporting line.
Maintenance of the risk register, action plan, and policies in day-to-day operation — on fixed dates rather than in bursts shortly before the audit.
A quarterly report to executive management: risk position, status of measures, open decisions — documented, and therefore usable as evidence of the oversight duty under Section 38 BSIG.
Preparation for and support through ISO 27001 certifications and TISAX® assessments, handling of nonconformities, and communication with auditors — from a lead auditor's perspective.
A rehearsed response to security incidents including the NIS2 reporting chain with its 24-hour initial notification — prepared before it is needed, not improvised while things are burning.
Handling of security questionnaires and supply chain requests from your customers, plus review of the security clauses in contracts before they are signed.
Awareness across the workforce and the training for executive management that NIS2 requires — documented, because the documentation is part of the duty too.
Most vCISO retainers stop at the edge of the technology: a policy gets written, and someone else owes its implementation. On Apple fleets we shorten that path — what the ISMS demands is enforced through Mosyle MDM and is retrievable as evidence in the next audit.
In practice, both terms describe the same thing from two angles. “External information security officer” is the term the German frameworks use — it describes the designated role that ISO 27001, the VDA ISA catalog, and a NIS2 implementation presuppose organizationally. “vCISO” is the market term for the same retainer, usually with somewhat more weight on strategy, budget advice, and management communication. We deliver both in one engagement and set the emphasis according to whether you are heading into an audit or running a security program over several years.
No — and any provider promising that should make you suspicious. Section 38 BSIG expressly assigns the approval of risk management measures and the oversight of their implementation to executive management; a waiver of claims for damages is excluded by law. What an external information security officer delivers is something different and practically decisive: they put executive management in a position to meet its oversight duty in the first place — through regular, documented reports, clear decision papers, and traceable risk assessments. It is exactly this evidence that counts when it matters.
The typical scope runs between one and four days per month. A company with around fifty employees and an existing ISMS usually manages on one to two days in normal operation. During certification, a TISAX® assessment, or an acute security incident, the demand rises sharply — and falls again afterwards. This elasticity is the core of the model: you cannot let a permanent position breathe, but you can let a retainer.
Yes. The VDA ISA catalog requires that responsibility for information security is clearly designated, resourced, and anchored in the organization — it does not require that the person be employed by the company. What matters to assessors is that the role is reachable, actually prepares decisions, and is connected to the management level through a documented reporting line. An external retainer satisfies that, provided it is contractually clean and reflected in the ISMS.
Then it is an orderly handover, not a fresh start. Everything created during the retainer — policies, risk register, action plans, reporting lines, audit records — belongs to you and sits in your systems, not ours. Many companies use the retainer exactly this way: as a build-up phase until the organization is large enough for its own position. We hand over to the internal successor and support the onboarding if that is wanted.
The regulatory frame that makes this role necessary in many companies in the first place.
Gap analysis, ISMS build-out, and support all the way to the certificate.
The day-to-day operations the security measures are built on.
Zero-trust, risk assessment, and security awareness as standalone projects.