Virtual CISO
What a vCISO Actually Does in Month 1, Month 3, and Month 12 — A Timeline Your Board Can Hold Us To
What a virtual CISO actually delivers in month 1, month 3, and month 12 — a concrete milestone timeline SMB and mid-market boards can hold any provider to.

A virtual CISO retainer for a European mid-market company runs €2,500–8,500 a month in 2026 — real money for a 50–500-person business, and a fraction of the €150,000–300,000 a full-time hire costs all-in. The economics are not the hard part. The hard part is knowing what you are supposed to receive for it. “Strategic security leadership” appears in every proposal and is verifiable in none of them.
So this article does something providers rarely do: it publishes the delivery timeline. Not our marketing calendar — the actual sequence of work, with the deliverable that should land on your desk at each milestone and the question that tells you whether it is real. We sell this service, so read what follows as a commitment, not a brochure. Before the engagement starts, you should also be asking the ten hiring questions we published in June — this piece begins where that one ends, on the first Monday of month one.
The question nobody asks in the sales meeting
Buyers ask about certifications, references and price. Almost nobody asks: “Show me, month by month, what I will have in hand that I do not have today.” That question matters more now than it did a year ago, because the regulatory clock is running — just not at the same speed in every country, which is the part most boards get wrong.
In Belgium, the date has already passed. Since 18 April 2026, essential entities have had to be able to demonstrate that they are effectively implementing cybersecurity risk-management measures, by one of three routes: a CyberFundamentals verification at Basic or Important level — obtained, actively in progress, or covered by a signed agreement with an accredited assessment body; ISO 27001, with the certification scope, Statement of Applicability and most recent internal audit report submitted, and full certification due by April 2027; or a self-assessment with a formal request for direct inspection, a route the CCB notes may lead straight to supervisory measures. The CCB describes the deadline as a binding regulatory obligation, not a procedural formality.
In France, the obligation has not started — though the preparation has. The transposing bill, the loi résilience, cleared the Sénat in March 2025 and the Assemblée nationale’s commission spéciale in September 2025, has never reached a plenary vote, and on 8 July 2026 the European Commission referred France to the Court of Justice, seeking both a lump sum and daily penalties. ANSSI is explicit that NIS2 applies in France only once the law, its decrees and its ministerial orders have all been promulgated. In the meantime it has published the Référentiel Cyber France (ReCyF) and opened voluntary pre-registration on MesServicesCyber — the portal that has absorbed MonEspaceNIS2 — where you can test your eligibility today. Registration becomes an obligation on promulgation, not before. This is a timing reprieve, not an exemption.
That asymmetry is why the month you start is a risk decision rather than a calendar preference. A Belgian entity engaging now is building evidence for a supervisor who can already ask for it. A French one is buying the twelve months before a regime arrives — and when the decrees land, the companies that start after them will be doing month-1 work under supervision, which is the expensive way to do month 1.
| Milestone | What lands on your desk | The question to ask |
|---|---|---|
| Month 1 | Baseline assessment, asset and access inventory, programme charter | “What did you find that we didn’t tell you?” |
| Month 3 | Quantified risk register, prioritised 12-month roadmap, first policy set | “Which risk did you tell us not to fix yet, and why?” |
| Month 12 | Audit-ready evidence file, metrics trendline, annual review with a keep/change/stop recommendation | “What would an auditor find tomorrow?” |
Month 1 — Listen, inventory, baseline
The first month is deliberately unglamorous. A competent vCISO spends it listening and counting: interviews with the executive team and whoever runs IT, an inventory of systems, data, vendors and access rights, and a review of whatever policies and controls already exist. The output is an honest baseline — where you actually stand against the obligations and threats that apply to your company, not a generic maturity wheel.
Two things should be true at day 30. First, you hold a written baseline and a one-page programme charter: scope, governance, who reports what to whom, and a reporting cadence your board signs off. Second — and this is the tell — nobody has asked you to buy anything yet. A provider who arrives with a tooling shopping list in week two is solving their margin, not your risk. Month 1 produces knowledge, not invoices.
Month 3 — The risk register your board can actually read
By day 90 the baseline has become a decision tool: a risk register written in business language — revenue, contracts, regulatory exposure, director liability — with each risk quantified, owned by a named person, and sorted into fix now, fix this year, and accept and document. Alongside it sits the prioritised 12-month roadmap and the first tranche of policies — the handful you genuinely need first, not a 25-document library dumped in a shared drive.
The month 3 question — “which risk did you tell us not to fix yet?” — is the sharpest test of the whole engagement. A real risk register contains explicit, argued decisions to defer. If everything is urgent, nothing has been prioritised, and you are reading a sales document. This is also when quick wins ship: the MFA gap closed, the offboarding hole plugged, the one vendor contract that needed an immediate security clause. Visible movement by day 90 is what earns the programme its second year.
Months 4 to 11 — Where the real work hides
The middle months are execution, and they resist headlines: roadmap projects delivered in order, an incident response plan written and then actually exercised with your leadership team around a table, vendor reviews folded into procurement, awareness training that targets your real attack surface, and a quarterly board report that shows the trendline, not a weather forecast. For companies in scope of NIS2, this is where our NIS2 compliance services typically dock into the programme — the register of measures, incident reporting readiness and management-body training land in these months, sequenced against whichever national calendar actually applies to you — which, as above, is not one calendar.
Month 12 — The annual review: what “working” looks like
Month 12 is not a celebration deck. It is three artefacts. An evidence file: controls mapped to obligations, with proof an auditor could walk through tomorrow — many of our clients put this to the test with an independent internal audit before a certification or supervisory visit. A metrics trendline: incidents, patch latency, training completion, vendor coverage — twelve months of direction, not a snapshot. And an annual review with a recommendation: what to keep, what to change, and — said out loud — whether you still need us at the same intensity. A vCISO who cannot name the conditions under which you outgrow them is optimising for their renewal, not your programme.
The timeline test
You do not need to remember the whole map. Take the three questions into your next review meeting: what did you find that we didn’t tell you (month 1), what did you tell us not to fix (month 3), what would an auditor find tomorrow (month 12). Any provider doing the job answers all three in plain language, with documents on the table. If the answers are fog, the timeline above is what you are missing — and twelve months from now, the only deliverable will be twelve invoices.
If you want to see what this timeline looks like scoped to your company — including an honest view on which month you should start, given where the enforcement calendar sits — our Virtual CISO service runs exactly this map, and we are happy to be held to it.
The three milestones: what a vCISO is doing, what lands on your desk, and the question to ask at each one.
Nine checks, three milestones: is your vCISO on track — or just on retainer?
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.


