Roles-as-a-Service

Some seats the law requires you to fill. We can sit in them.

Regulation increasingly names a person, not just a control — an officer, an owner, a designated contact. Most of those regimes expressly allow that person to be external. We take the seat with a named professional, a defined cadence, and documentation your regulator will accept.

ICT Risk Control-Function Owner

Non-microenterprise CIFs, crypto-asset service providers, fund managers, trading venues

DORA requires this function to be independent of ICT operations. In a firm of 25 people the IT manager cannot credibly be both operator and overseer — and Art. 6(10) expressly permits appointing an external undertaking.

Basis: DORA Art. 6(4) and 6(10) · CySEC Circular C751 Portal designation

from €2,500/mo

Cybersecurity Officer (NIS2)

Essential and important entities across the 18 NIS2 sectors, including every Bulgarian municipality

The seat the law obliges you to fill. We hold it, run the cadence, own the reporting clocks, and brief your management body on the training it is separately required to complete.

Basis: Bulgarian Cybersecurity Act Art. 21 · equivalents in Hungary (IBF) and Romania

from €1,500/mo · shared municipal cluster from €900/mo

Data Protection Officer

Any organisation meeting the Article 37 triggers

A registered contact point for your supervisory authority and your data subjects, records of processing kept current, DPIAs run when needed, and breach notification handled to the clock.

Basis: GDPR Art. 37(6) — expressly permits an external DPO under a service contract

from €200/mo (10–50 staff)

Information Security Officer

SaaS vendors under enterprise due diligence; organisations holding or seeking ISO 27001

Owns the management system between audits — the part most organisations let lapse the week after certification.

Basis: ISO/IEC 27001 Clause 5.3 role assignment · customer and insurer requirements

from €1,500/mo

AI Governance Officer

Organisations building or deploying AI, especially those meeting ISO 42001 in tenders

Maintains the AI inventory and risk classification, keeps transparency obligations satisfied, and answers the AI-governance questions now appearing in enterprise procurement.

Basis: ISO/IEC 42001 management responsibility · EU AI Act Art. 26 deployer duties

from €1,200/mo

Third-Party / ICT Risk Manager

Financial entities and the ICT vendors who serve them

Keeps the Register of Information submission-ready for the annual February deadline, remediates supplier contracts, and maps the subcontracting chain.

Basis: DORA Arts. 28–30 — Register of Information, contractual requirements, concentration risk

from €1,000/mo

Business Continuity Manager

Regulated entities and critical suppliers

Plans that have been tested rather than filed — including the exercise programme auditors ask to see evidence of.

Basis: ISO 22301 · DORA Arts. 11–12 · NIS2 Art. 22 continuity measure

from €900/mo

Incident Reporting Coordinator

Any in-scope entity — somebody has to own the clock before the clock starts

Classification decisions documented at the moment of detection, not reconstructed afterwards, and notifications filed on time in the right format.

Basis: NIS2 24h/72h/1-month · DORA 4h/72h/1-month · CRA 24h to ENISA

from €600/mo, or bundled

Whistleblowing / Speak-Up Officer

Employers above the Directive thresholds

An external channel is often more trusted than an internal one, and the Directive was written to allow exactly this. A genuinely unserved adjacent obligation.

Basis: EU Directive 2019/1937 — permits an impartial third party to receive and handle reports

from €400/mo

Interim cover for your own officer

Organisations that already have an officer but cannot leave the seat empty

Parental leave, a resignation, or the six months it takes to recruit a replacement. The obligation does not pause while you hire.

Basis: Continuity of a mandated role during absence or between hires

day rate or short fixed term
Roles bundle — and should. A Cybersecurity Officer, a Data Protection Officer and an Incident Reporting Coordinator are one person, one cadence and three obligations discharged. We price bundles at a visible discount rather than stacking three retainers.
One rule we will not break: where we build or run something, we will not also audit it. If we hold your ICT risk control-function seat, we will not act as your ICT auditor. If we build your management system, we will not assess it. That separation costs us a second retainer and protects you — the body that built a system must not be the body that certifies it works. Your regulator expects to see exactly this boundary, and we state it in writing before you engage us.
Discuss which seat you need filled