Stop building from scratch.
Start from done.
Professional-grade PowerPoint, Word, and Excel templates for CISOs, security managers, and compliance teams. Download, customize, deploy.
Featured Templates
View all →Build Series Vol. 01 — Detection & Monitoring
Wazuh, Suricata and Zeek assembled into a stack one person can operate, with the tuning and detection validation that almost every deployment skips.
Build Series Vol. 02 — Asset Inventory & Discovery
Discovery tells you what is out there. The source of truth holds what you have decided about it. The control lives in the reconciliation between them, not in either list.
EU Cyber Resilience Act Workbook
Article 14 reporting readiness and the road to December 2027 — the scope test, the reporting clocks, Annex I requirements mapped to controls, the technical documentation set, and conformity assessment routes. Neither DORA nor NIS2 covers this.
Build Series Foundation Bundle
Volumes 02, 01 and 06 — inventory, detection and identity. The three everything else depends on.
Complete Build Series
All ten volumes in reading order — a security department built out of open source, with control mappings, validation harnesses and honest buy lines throughout. 29% off buying separately.
RA-01 + Foundation
The Open SOC Reference Architecture plus Build Series Volumes 02, 01 and 06 — the system-level design, then the three planes everything else depends on.
RA-01 + Complete Build Series
The reference architecture and all ten build volumes — the whole system-level design plus every plane built end to end, in the recommended build order. 30% off buying separately.
SOC 2 + Build Foundation
SOC 2 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
CTI Program Maturity Assessment
Nine domains, forty-five statements, and two ceiling rules that stop you scoring yourself a three. The front door to the line — find out where the program actually is before spending anything.
Build Your Own Threat Intelligence Program
The anchor. Ten sections taking a small team from no capability to a running CTI program in ninety days, on MISP and the open-source CIRCL stack — with an honest ceiling on what a DIY program can ever do.
CTI Analyst Runbook Library
Eighteen procedures for the things that actually land in an analyst queue. One page each, each ending in a decision rather than a suggestion — with an escalation matrix and an execution log.
Threat Intel Policy & Governance Pack
Six adoptable documents covering marking, handling, sharing, retention, membership, and machine access — with DORA Article 45, NIS2 Article 29 and ISO 27001 mappings. The governance a sharing programme is required to have and almost never does.
Threat Intelligence Starter Kit
All six CTI products — assessment, auto-scoring tool, the build workbook, the feed matrix, eighteen analyst runbooks and the policy pack. 39% off buying separately.
R01 — Range Foundations
The anchor volume: hardware sizing with an honest cost model, Proxmox and Ludus as the substrate, three-zone isolation, and the four-tier reset architecture that decides whether your range gets used daily or becomes a museum. Includes the Range Build Planner.
R03 — The Fresh Vulnerability Pipeline
The flagship: from a KEV/NVD/EUVD identifier to a reproduced environment, a validated detection, and a remediation check — as a repeatable six-stage pipeline rather than a heroic weekend. Written for the post-2026 reality where four in five CVEs arrive un-enriched. Includes the CVE Repro Template.
Complete Range Line
All five volumes plus both build tools and the Range Runbook Library — the whole facility, from isolation architecture to scored purple-team exercises. 34% off buying separately.
RA-01 — The Open SOC Reference Architecture
The open-source SOC diagram everyone shares has two commercial products on it. This is the corrected version — six planes, 24 components with verified licenses and named replacements, an AI analyst plane with a defensible autonomy ceiling, and three sized builds with honest hour counts.
Cyber Insurance Workbook
Everything you need to prepare, apply for, and manage cyber insurance — 8 tabs, 167 live formulas, built for security teams who need to hold their own with brokers and underwriters.
Shadow AI Inventory & Risk Scoring Workbook
Discover, inventory, and score every unapproved AI tool in your environment — 10 tabs, 589 formulas, pre-seeded with 15 real-world shadow AI tools and a defensible 10-factor risk model.
vCISO Client-in-a-Box
27 tabs, 1,565 formulas — a complete client management system for solo vCISOs and small teams. NIST CSF 2.0 assessments, risk registers, roadmaps, and a portfolio dashboard for 20 clients. Includes the 584-paragraph Practitioner User Guide.
M&A Cyber Diligence Workbook
The active cyber diligence workbook for M&A deal teams — auto-generated deal recommendations, cost modeling, and deal-term mechanism mapping across a 10-day sprint framework.
VC Cyber Diligence Workbook
Stage-aware VC diligence for Pre-Seed through Series B+ — founder assessment, investment thesis scoring, pipeline tracking, cap table analysis, and IC memo output. 16 tabs built around the question: what would have to go right for 10x?
Tabletop Exercise Pack
10 research-calibrated IR scenarios, a 13-tab program management system, and a 687-paragraph facilitator guide — plus an ecosystem map that turns every buyer into a full IR practice.
2026 CISO Budget Workbook
Input five values on the Assumptions tab — revenue, IT budget, headcount, industry, maturity — and the entire workbook calculates itself. Three budget-sizing methods, 50+ line items, CRQ for boards, and board talking points with your actual numbers.
SOC 2 Readiness Accelerator
20-tab SOC 2 program covering assessment through Type 2 audit — 100+ controls, 35 required policies, 7 pre-populated operational logs, and an executive dashboard with three auto-calculated readiness metrics.
HIPAA Readiness Accelerator
23-tab HIPAA compliance workbook built for the 2026 Final Rule — covers all current safeguards plus the 12 new mandatory requirements, IoMT risk, BAA management, breach notification matrix, and a dedicated 2026 gap analysis tab.
Enterprise Questionnaire Response Kit
14-tab operational efficiency toolkit for responding to security questionnaires — 400+ pre-written answers mapped to CAIQ v4, SIG, VSA, and HECVAT, AI governance supplements, deal pipeline tracking, and a trust portal content planner.
ISO 27001:2022 Readiness Accelerator
20-tab ISMS implementation workbook for ISO 27001:2022 — all 93 Annex A controls across 4 themes, 11 new 2022 controls, Clauses 4–10 ISMS framework, transition gap analysis from 2013, and policy library.
PCI DSS v4.0.1 Readiness Accelerator
12-tab PCI DSS v4.0.1 workbook — all 12 requirement domains, SAQ type selector, 51 future-dated requirements tracker, e-commerce script security controls, and QSA-ready evidence register. Built for the March 2025 mandatory transition.
CMMC 2.0 Readiness Accelerator
12-tab CMMC 2.0 workbook — all 110 NIST 800-171 practices with DoD SPRS weights, auto-calculated SPRS score, Level determination decision tree, SSP builder, POA&M tracker, and C3PAO readiness checklist. Built for the November 2026 Phase 2 deadline.
DORA + NIS2 EU Compliance Workbook
14-tab EU regulatory compliance workbook covering all 5 DORA pillars, NIS2 Article 21 measures, dual framework applicability decision tree, penalty calculator (2% DORA / €10M NIS2), and cross-framework mapping across 17 control domains.
CISO Board Reporting Pack
Everything you need to brief the board on cybersecurity — editable Excel metrics workbook, 25-slide PowerPoint deck template, and a user guide covering what boards actually want to hear and how to answer the questions you will get.
NIST CSF 2.0 Self-Assessment Workbook
14-tab NIST CSF 2.0 workbook — all 106 Subcategories with verbatim NIST.CSWP.29 outcome statements, Current/Target tier dropdowns, Organizational Profile Generator, heatmap, gap analysis pre-seeded with 12 high-gap 2026 scenarios, and crosswalks to SP 800-53r5, SP 800-171r3, CIS Controls v8.1, and ISO 27001:2022.
GDPR & DPIA Compliance Workbook
20-tab GDPR compliance workbook — Controller ROPA, Processor ROPA, DSR log with 30-day SLA tracking, 72-hour breach deadline calculator, TIA template, DPF certification tracker, and DPIA template with WP29 9-factor trigger test. Updated for April 2026 research baseline.
2026 US Privacy Program Workbook
17-tab US state privacy compliance workbook covering the 20-state wave — CCPA/CPRA, MODPA, VCDPA, CPA, and 16 more — with auto-generated obligation matrix, DSR tracker, consent management log, ADMT register, and enforcement reference.
CISO 90-Day Onboarding Workbook
The structured first-90-days playbook for new CISOs — stakeholder mapping, program gap assessment, quick-win tracker, board briefing builder, and 30/60/90-day milestone framework. For FTE CISOs, vCISOs starting new engagements, and interim security leaders.
Incident Response Runbook Library
18 runbooks × 3 formats (54 files) — complete IR runbook library covering every major 2026 threat scenario, from ransomware multi-extortion to vishing to Magecart. ZIP delivery with Word, PDF, and Markdown versions of every runbook.
Compliance Trifecta Bundle
SOC 2 + HIPAA + ISO 27001:2022 readiness in one bundle — the three certifications every enterprise buyer asks for. 17% off list.
Compliance Big 5 Bundle
SOC 2 + HIPAA + ISO 27001 + PCI DSS + CMMC 2.0 — every major compliance framework an auditor or regulator will ask about. 22% off list.
New CISO Starter Pack
CISO 90-Day Onboarding + NIST CSF 2.0 Assessment + CISO Budget Workbook + Board Reporting Pack — your Day-90 board meeting in a bundle. 20% off list.
vCISO Starter Pack
vCISO Client-in-a-Box + NIST CSF 2.0 Assessment + CISO Board Reporting Pack — drop-in kit for fractional CISOs running concurrent clients. 20% off list.
IR Stack Bundle
Ransomware Readiness Workbook + Tabletop Exercise Pack — prepare, practice, and survive a ransomware incident. 25% off individual pricing.
vCISO Ops Bundle
vCISO Client-in-a-Box + Shadow AI Inventory + CISO Budget Workbook — the three tools every vCISO needs to run a full program. 18% off individual pricing.
Browse by Category
Part of the CISO Marketplace
How it works
One CISO Marketplace account works across every site — sign in once, pay your way, and your purchases follow you in the member portal.
Sign in once
One CISO Marketplace login (email magic-link, password, or SSO) across ciso.diy and the whole ecosystem.
Pay your way
Checkout by card, or with your membership credits ($1 = 1 credit) — allowance + top-up.
Instant delivery
Download links are emailed immediately and saved to your account — no waiting, no re-purchasing.
Your central library
Every purchase shows in your member portal — Finance, licenses & saved reports.
Part of the CyberAdX ecosystem
More tools for security teams
Explore our other properties built to accelerate security work.