Bundles
69 curated bundles drawing on 100 products, grouped by the job they do rather than the order they were built in. Every one is priced below the sum of its parts — and never below its dearest component, so a bundle is always the cheaper way to own the set and never a cheaper way to own one thing.
Most run at the house 25% discount. A few sit at 20%, and those say so on the page: where one product is several times the price of the others, a quarter off the pair would cost less than the largest component on its own.
Compliance
20Audit-ready compliance frameworks and checklists
CRA Governance + Reporting
EU Cyber Resilience Act Workbook + CRA 24-Hour Reporting Clock — the governance half and the operational half of the CRA in one purchase. 14% off buying them separately. For the conformity artefacts as well, see the CRA Manufacturer Set.
Disclosure & Consent Pack
What you have to tell people about the automated and synthetic systems you point at them — the ADMT pre-use notice and opt-out California requires, and the labels, provenance and likeness releases synthetic media requires. One notice-and-consent practice, two regimes. 15% off buying separately.
Article 50, Both Sides
The duty and the discharge. The AI Act tells you disclosure applies; the synthetic-media kit is how you actually do it — caption, platform label, C2PA credentials, consent and a register — across every regime that asks. 15% off buying separately.
Healthcare Provider Risk
The billing company holds your cardholder data and your PHI, and the MSP holds the admin rights over both. Assess the payment side and the provider that runs it. 15% off buying separately.
CRA Manufacturer Set
The whole CRA line in one purchase — scope the obligation, run the Article 14 clock that is already live, and produce the technical file, SBOM and CE declaration for December 2027. 19% off buying the three separately.
EU AI Act + Risk Register Pack
The clock that tells you which date binds each AI system, and the register that holds them once they are scored. Classify against the Act, then keep the answer somewhere an auditor can read it. 15% off buying separately.
Product Security Complete
Everything a product vendor owes the EU and the crypto clock in one purchase — the CRA scope test, the Article 14 reporting runbook, the technical file with SBOM and CE declaration, and the post-quantum inventory and migration plan. 19% off buying the four separately.
AI Program Complete
Classify your AI against the law, fence the agents that can act on your estate, and hold the risk somewhere an auditor can read it. The three halves of an AI programme that most organisations buy one incident at a time. 19% off buying separately.
EU Regulatory Estate
The two EU regimes that reach almost every regulated business at once — operational resilience and third-party risk under DORA and NIS2, and the AI Act obligations arriving on top of them. 14% off buying separately.
Utility Board Package
The regime calendar an operator is judged against, and the twelve questions a director should be asking about it. What management owes the regulator, and what the board records having asked. 15% off buying separately.
Both Sides of the MSP
The duties a UK managed service provider owes, and the assessment its customers are about to run on it. Read your own regime and your customers’ checklist in one purchase. 14% off buying separately.
Defense Supplier Pack
The CMMC self-assessment and SPRS score you are certifying to, the provider holding your admin rights, and the federal incident clock underneath both. What a DIB contractor is actually accountable for while Phase 2 is suspended. 19% off buying separately.
Compliance Program Starter
The Pillar 01 operating system plus the two workbooks most first programs actually need — SOC 2 Readiness and the NIST CSF 2.0 Self-Assessment — with both PDF readiness checklists included. 24% off buying separately.
Privacy Dual Coverage Bundle
2026 US state privacy program + EU GDPR/DPIA — every SaaS selling to US and EU customers needs both. 14% off list.
Healthcare Now & Next
The whole HIPAA programme, the Security Rule change coming in 2027, and the payment side neither covers. Three products across the compliance a healthcare organisation is actually assessed on. 19% off buying separately.
Federal Contractor Pack
CMMC 2.0 + NIST CSF 2.0 + PCI DSS for defense and federal contractors — built for DoD, GSA, and agency RFP responses. 19% off list.
Healthcare Security Pack
HIPAA + SOC 2 + Ransomware Readiness for healthcare SaaS and digital health. Healthcare ransomware is 31% of all attacks. 19% off list.
Compliance Trifecta Bundle
SOC 2 + HIPAA + ISO 27001:2022 readiness in one bundle — the three certifications every enterprise buyer asks for. 19% off list.
Global SaaS Compliance Pack
SOC 2 + ISO 27001 + GDPR/DPIA for B2B SaaS going international — US enterprise + EU data subjects in one bundle. 19% off list.
Compliance Big 5 Bundle
SOC 2 + HIPAA + ISO 27001 + PCI DSS + CMMC 2.0 — every major compliance framework an auditor or regulator will ask about. 25% off list.
Governance
12Policies, procedures, and board reporting templates
Synthetic Media & Agents
The agents that can publish, and the disclosure regime that lands the moment they do. Fence what the agent may post, then discharge the labelling, provenance and consent obligations that attach to it. 14% off buying separately.
Board Package
What the board asks, the numbers behind the answers, and the exercise it should watch. The director layer plus the two management tools a board actually sees output from. 19% off buying separately.
First 100 Days + Quantum
The kit for the job you just took, and the answer to the question the board will ask in your first quarter. 14% off buying them separately.
New CISO Starter
The First 100 Days Kit + the Cyber Insurance Application Readiness Kit + the First 72 Hours Command Kit — the plan, the fastest honest baseline, and the crisis card. The same first month. 19% off buying them separately.
Board Preparation Bundle
CISO Budget Workbook + CISO Board Reporting Pack + NIST CSF 2.0 — everything a CISO needs for the quarterly board cycle. 19% off list.
vCISO Starter Pack
vCISO Client-in-a-Box + NIST CSF 2.0 Assessment + CISO Board Reporting Pack — drop-in kit for fractional CISOs running concurrent clients. 19% off list.
Fractional CISO Practice Pack
The Pillar 06 operating system plus the two workbooks that run it — vCISO Client-in-a-Box for the portfolio and the CISO 90-Day Onboarding Workbook for every new engagement. 19% off buying separately.
New CISO Starter Pack
CISO 90-Day Onboarding + NIST CSF 2.0 Assessment + CISO Budget Workbook + Board Reporting Pack — your Day-90 board meeting in a bundle. 19% off list.
CISO Executive Suite
CISO 90-Day Onboarding + Budget + Board Pack + NIST CSF 2.0 + Tabletop Exercise Pack — the most complete CISO toolkit in the catalog. 25% off list.
vCISO Ops Bundle
vCISO Client-in-a-Box + Shadow AI Inventory + CISO Budget Workbook — the three tools every vCISO needs to run a full program. 19% off individual pricing.
Critical Infrastructure Complete
The plant, the regulators above it, the federal reporting duty, the drill and the board layer — five products covering an operator end to end, from the vendor VPN that should already be off to the evidence log a director keeps. 25% off buying separately.
vCISO Complete Practice
vCISO Client-in-a-Box + CISO 90-Day Onboarding + NIST CSF 2.0 + Budget + SOC 2 + Board Pack — complete vCISO practice toolkit. 24% off list.
Security Program Pillars
10The CISO Marketplace AI Security Department pillars, rebuilt as open-source DIY guides — the real architecture we run, written so you can build it on your own estate, with the managed version available if you would rather not
Operator on a Box
The Operator's Manual plus SOC in a Box — the command layer and the hardened machine to run it on. Sovereign by construction: your vault, your gates, your hardware. 14% off buying separately.
Compliance: Method & Machine
Pillar 01 — The Compliance Operating System, plus The Living ISMS. Read the method, then build the system that runs it. 15% off buying separately.
Self-Host Starter
C2 — The Operator's Manual plus the Operator Node DIY Build. The operating model and the box it runs on. 15% off buying separately.
DevSecOps + PTaaS Bundle
Pillars 02 and 03 together — the always-on risk register that finds patterns, and the authorized offense lane that proves them. 14% off buying separately.
Pillar 04 — AI-SOC Complete
The whole AI-SOC pillar — the operating system that reduces your alerts, the reference architecture that designs the system underneath it, and the hardware build guide that lands it on one machine you hold. 19% off buying separately.
AI Risk Register Pack
Pillar 06 — The Fractional CISO Operating System, plus The 2026 AI Risk Register. The practice and the system: own the register and know how to run it. 15% off buying separately.
Register & Machine
The Enterprise Risk Register plus The Living ISMS. The register asks whether a risk is treated by control X; the control graph answers whether X is real. Both sides of the seam. 14% off buying separately.
Phase 0 + Shadow AI Pack
The assessment that finds every AI system in your estate, paired with the workbook that inventories and scores them. Map the footprint, then govern it. 14% off buying separately.
The Register Family
Pillar 06 plus both registers — The Enterprise Risk Register as the hub and The 2026 AI Risk Register as the AI stream. The hub, the stream, and the practice that owns them. 19% off buying separately.
Complete Security Program Pillars
The whole programme — the Phase 0 assessment that scopes it, all six pillars, and the C2 command layer that conducts them — the compliance operating system, the DevSecOps risk register, the Bug-Hunter discovery layer, the PTaaS proof lane, both halves of the AI-SOC pillar, and the Fractional CISO operating system they all report into. Discovery to detection to remediation as one program, and the operator node it all runs on. 29% off buying separately.
Architecture & Build
7The ten-volume Build Series — open-source construction guides for each security capability, with the framework clauses each build satisfies, a validation harness that catches silent failure, and dated currency notes
Build Series Foundation Bundle
Volumes 02, 01 and 06 — inventory, detection and identity. The three everything else depends on.
Open SOC Architecture + Build Foundation
The Open SOC Reference Architecture plus Build Series Volumes 02, 01 and 06 — the system-level design, then the three planes everything else depends on.
SOC 2 + Build Foundation
SOC 2 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
ISO 27001 + Build Foundation
ISO 27001:2022 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
HIPAA + Build Foundation
HIPAA Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
Complete Build Series
All ten volumes in reading order — a security department built out of open source, with control mappings, validation harnesses and honest buy lines throughout. 24% off buying separately.
Open SOC Architecture + Complete Build Series
The reference architecture and all ten build volumes — the whole system-level design plus every plane built end to end, in the recommended build order. 25% off buying separately.
Incident Response
4Playbooks, runbooks, and IR planning templates
IR Stack Bundle
Ransomware Readiness Workbook + Tabletop Exercise Pack — prepare, practice, and survive a ransomware incident. 15% off individual pricing.
The Regime Clocks
Four regulators, four clocks, one incident — the First 72 Hours Command Kit plus the CIRCIA, SEC 8-K and NYDFS Part 500 kits. The problem is sequencing: the confidential federal report precedes the public 8-K, and only the SEC clock waits for a materiality determination. 19% off buying them separately.
Risk & Readiness Pack
Ransomware Readiness + Tabletop Exercise Pack + Cyber Insurance Workbook + Shadow AI Inventory — show underwriters and your CEO your program maturity. 19% off list.
Phase 0 + Risk & Readiness Pack
The front-door assessment plus the four workbooks that prove readiness to the people who ask — ransomware, tabletop, cyber insurance and shadow AI. 24% off buying separately.
Security Awareness
4Practical security guides for families, remote workers, individuals, and small businesses — home networks, elder fraud, career planning, and more
Family Cyber Safety Pack
Everything your family needs to be cyber-safe in 2026 — Home Network Audit, Family Online Safety Contract (AI/deepfake-aware), 3-scenario Cyber Drill with fillable Safe Word card, and IR Runbook for account compromise. 16% off individual.
Elder Fraud Recovery Pack
Built for the worst week — Senior Cyber Safety Workbook, Identity Theft Recovery Binder (FCRA §605B), and Family IR Runbook, plus a 2-page triage guide that tells you which workbook to open first based on what you discovered. 18% off individual.
Business & Financial Cyber Pack
Lock down your accounts, protect your money, recover from identity theft, and pass your cyber insurance application — Password Manager Workbook, Cyber Insurance Checklist, Identity Theft Recovery Binder (FCRA §605B), and SMB Starter Kit. 19% off individual.
Complete Cyber Library
The entire consumer catalog — 10 products covering family safety, financial protection, career planning, and small business documentation. 54 pages, scenario-based bundle index showing what to open first for any situation. 25% off individual.
Vendor Risk
4Third-party risk assessment and management tools
Infrastructure Providers Pack
The two parties that run your estate for you — the MSP with delegated admin, and the facility where the data physically sits. Same assessment discipline applied to both. 15% off buying separately.
Provider Risk Pack
The vendor programme, and a deep assessment of the vendor that holds your admin rights. Run every supplier properly, then run your MSP properly — because one row in a register does not cover the party with delegated admin on your tenant. 14% off buying separately.
Vendor Risk Complete
The TPRM Program Kit + the Vendor Risk Operations Kit — design the programme, then actually run it. Tiering, questionnaires and clauses on one side; dossiers, scorecards, exit tests and the Register of Information on the other.
Resilience Estate Pack
Where the estate sits, what you do the morning it is encrypted, and what the insurer will ask before either. Assess the facility, rehearse the incident, evidence the controls. 19% off buying separately.
Due Diligence
3M&A and VC cyber diligence workbooks for deal teams and investors
M&A Diligence Complete
The M&A Cyber Due Diligence Kit + the M&A Cyber Diligence Workbook — the engagement method and the deal model together. Run the diligence with one, price the findings with the other. 15% off buying them separately.
Both Sides of the Deal
The M&A Cyber Due Diligence Kit + the Sell-Side Cyber Exit Readiness Kit — the same eight-domain method run as a buyer and as a seller. The disclosure schedules are structured around the buyer reps, so the two kits answer each other. 15% off buying them separately.
Deal-Cycle Pack
M&A Cyber Diligence + VC Startup Due Diligence + Enterprise Questionnaire Response Kit — for deal advisors, corp dev, and VCs running cyber DD. 19% off list.
Threat Intelligence
2Stand up and run a CTI program on open-source tooling — a scored maturity assessment, the build workbook, feed and scoring tools, analyst runbooks, and the policy pack that governs it
CTI Essentials
The three products that get a program running — the build workbook, the maturity assessment, and the feed matrix. 19% off buying separately.
Threat Intelligence Starter Kit
All six CTI products — assessment, auto-scoring tool, the build workbook, the feed matrix, eighteen analyst runbooks and the policy pack. 24% off buying separately.
Cyber Insurance
2Insurance prep, workbooks, and documentation
Cyber Insurance Complete
The Application Readiness Kit + the Cyber Insurance Workbook — get bound, then stay insurable. The kit runs the application and builds the evidence binder; the workbook is the standing programme between renewals. 15% off buying them separately.
Before & After
The Cyber Insurance Application Readiness Kit + the First 72 Hours Command Kit — qualify for the cover, then know not to void it at 6 a.m. 15% off buying them separately.
Cyber Range
1Build and operate a cyber range you own — isolation and reset architecture, a curated adversary corpus, a fresh-CVE reproduction pipeline, detection validation, and scored purple-team exercises
Looking for a single product instead? Browse all 181, or start from the categories. Working to a date? The compliance calendar lists what lands when.