Stop building from scratch.
Start from done.
Build guides, workbooks and reference architectures for CISOs, security engineers and compliance teams — including the six-pillar security programme, published so you can build it yourself.
The AI Security Department, DIY
Six pillars. Build them yourself — or have them run for you.
These are the same pillars CISO Marketplace runs as a managed programme, published as build guides with the real architecture in them. Each stands alone; together they are one programme, where every stream feeds a register a human owns.
Compliance
Map controls once, satisfy every framework — driven from your registry, not a platform’s integrations.
Get Pillar 01 →DevSecOps
Discovery, scanning and AI triage across 100+ apps, in one self-healing risk register.
Get Pillar 02 →PTaaS
An authorized, sandboxed lane that proves the bug and drafts the patch, under a human gate.
Get Pillar 03 →AI-SOC
A reducer over your existing stack: read every alert, resolve the routine, escalate the few.
Get Pillar 04 →Incident Response
The response capability the other pillars hand off to. Publishing shortly.
See the managed pillar →Fractional CISO
The capstone hub — every stream above feeds one register a human owns, conducted out to the board.
Get Pillar 06 →Take the whole programme
5 pillars published so far, plus their companions, in one purchase at 20% off — and every future edition as the remaining pillar lands.
Featured
Browse and search all 112 →Pillar 04 — The AI-SOC Operating System
Read every alert, resolve the routine, escalate only what needs a human. A reducer that overlays your existing SIEM, EDR, identity and cloud — human-gated, auditable, and capped at an autonomy level you can defend.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
Compliance Program Starter
The Pillar 01 operating system plus the two workbooks most first programs actually need — SOC 2 Readiness and the NIST CSF 2.0 Self-Assessment — with both PDF readiness checklists included. 30% off buying separately.
Pillar 06 — The Fractional CISO Operating System
The capstone hub: a human-owned register that aggregates every security stream into board-legible, quantified risk. The 2026 pricing ladder, the first 90 days, the five-page board deck, and the layer the AI vCISO platforms structurally cannot replace.
Fractional CISO Practice Pack
The Pillar 06 operating system plus the two workbooks that run it — vCISO Client-in-a-Box for the portfolio and the CISO 90-Day Onboarding Workbook for every new engagement. 25% off buying separately.
Pillar 02 — AI-Augmented DevSecOps Risk Register
Run a continuous, AI-triaged security program across 100+ apps as a solo engineer. Platform-first discovery, SAST/SCA/secrets/DAST, a self-healing risk register, and tiered Claude triage — on free and near-free parts.
Browse by Category
Part of the CISO Marketplace
How it works
One CISO Marketplace account works across every site — sign in once, pay your way, and your purchases follow you in the member portal.
Sign in once
One CISO Marketplace login (email magic-link, password, or SSO) across ciso.diy and the whole ecosystem.
Pay your way
Checkout by card, or with your membership credits ($1 = 1 credit) — allowance + top-up.
Instant delivery
Download links are emailed immediately and saved to your account — no waiting, no re-purchasing.
Your central library
Every purchase shows in your member portal — Finance, licenses & saved reports.
Part of the CyberAdX ecosystem
More tools for security teams
Explore our other properties built to accelerate security work.