{
  "$schema": "https://schema.org/Product",
  "site": "https://ciso.diy",
  "name": "ciso.diy",
  "description": "Cybersecurity workbooks, build guides and governance packs sold as one-time downloads. Excel, Word, PowerPoint, PDF and ZIP deliverables for CISOs, vCISOs, compliance teams, MSPs and MSSPs, deal teams and families.",
  "generated": "2026-09-04T04:33:53.422Z",
  "currency": "USD",
  "priceNote": "Prices are in US cents. `priceFrom` is what is charged today; `listPriceFrom` is before any promotion.",
  "launchDiscount": 0.2,
  "returnPolicy": {
    "days": 30,
    "url": "https://ciso.diy/refunds",
    "note": "Full refund within 30 days, no reason required."
  },
  "licensing": {
    "url": "https://ciso.diy/eula",
    "note": "One-time purchase, permanent licence. Tiers differ by scope of use, not by content — every file ships at every tier."
  },
  "count": 149,
  "categories": [
    {
      "id": "compliance",
      "label": "Compliance",
      "description": "Audit-ready compliance frameworks and checklists",
      "count": 14,
      "url": "https://ciso.diy/categories/compliance"
    },
    {
      "id": "incident-response",
      "label": "Incident Response",
      "description": "Playbooks, runbooks, and IR planning templates",
      "count": 7,
      "url": "https://ciso.diy/categories/incident-response"
    },
    {
      "id": "vendor-risk",
      "label": "Vendor Risk",
      "description": "Third-party risk assessment and management tools",
      "count": 3,
      "url": "https://ciso.diy/categories/vendor-risk"
    },
    {
      "id": "cyber-insurance",
      "label": "Cyber Insurance",
      "description": "Insurance prep, workbooks, and documentation",
      "count": 3,
      "url": "https://ciso.diy/categories/cyber-insurance"
    },
    {
      "id": "governance",
      "label": "Governance",
      "description": "Policies, procedures, and board reporting templates",
      "count": 9,
      "url": "https://ciso.diy/categories/governance"
    },
    {
      "id": "awareness",
      "label": "Security Awareness",
      "description": "Practical security guides for families, remote workers, individuals, and small businesses — home networks, elder fraud, career planning, and more",
      "count": 20,
      "url": "https://ciso.diy/categories/awareness"
    },
    {
      "id": "due-diligence",
      "label": "Due Diligence",
      "description": "M&A and VC cyber diligence workbooks for deal teams and investors",
      "count": 4,
      "url": "https://ciso.diy/categories/due-diligence"
    },
    {
      "id": "architecture",
      "label": "Architecture & Build",
      "description": "The ten-volume Build Series — open-source construction guides for each security capability, with the framework clauses each build satisfies, a validation harness that catches silent failure, and dated currency notes",
      "count": 10,
      "url": "https://ciso.diy/categories/architecture"
    },
    {
      "id": "cyber-range",
      "label": "Cyber Range",
      "description": "Build and operate a cyber range you own — isolation and reset architecture, a curated adversary corpus, a fresh-CVE reproduction pipeline, detection validation, and scored purple-team exercises",
      "count": 8,
      "url": "https://ciso.diy/categories/cyber-range"
    },
    {
      "id": "threat-intelligence",
      "label": "Threat Intelligence",
      "description": "Stand up and run a CTI program on open-source tooling — a scored maturity assessment, the build workbook, feed and scoring tools, analyst runbooks, and the policy pack that governs it",
      "count": 6,
      "url": "https://ciso.diy/categories/threat-intelligence"
    },
    {
      "id": "program-pillars",
      "label": "Security Program Pillars",
      "description": "The CISO Marketplace AI Security Department pillars, rebuilt as open-source DIY guides — the real architecture we run, written so you can build it on your own estate, with the managed version available if you would rather not",
      "count": 15,
      "url": "https://ciso.diy/categories/program-pillars"
    },
    {
      "id": "bundle",
      "label": "Bundles",
      "description": "Curated product bundles at a discount — more tools, less spend",
      "count": 50,
      "url": "https://ciso.diy/categories/bundle"
    }
  ],
  "products": [
    {
      "slug": "phase-0-ai-risk-assessment",
      "title": "Phase 0 — The Enterprise AI Risk Assessment",
      "description": "The front-door methodology: map the whole AI and security footprint — sanctioned and shadow — against the frameworks that matter, then produce a current-state map, a future-state design, and a sequenced six-pillar build plan. Scoped assessment, not a build guide.",
      "url": "https://ciso.diy/templates/phase-0-ai-risk-assessment",
      "image": "https://ciso.diy/images/og/phase-0-ai-risk-assessment.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "Phase 0",
        "risk assessment",
        "AI risk",
        "NIST AI RMF",
        "shadow AI",
        "current-state map",
        "front door",
        "enterprise",
        "methodology"
      ],
      "keyFacts": [
        "**You cannot architect a security department for an organisation you have not mapped.** Phase 0 lays out the whole current ecosystem so the six pillars snap into real infrastructure instead of assumptions.",
        "Nothing downstream gets a number until Phase 0 is delivered.",
        "After Phase 0 each pillar is a scoped piece of work you can start independently — AI-SOC this quarter, PTaaS next, an IR capability because a cyber-insurance renewal requires it."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 24,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 19900,
      "listPriceFrom": 19900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 19900,
          "listPrice": 19900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 44900,
          "listPrice": 44900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 94900,
          "listPrice": 94900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "phase-0-shadow-ai-pack",
      "title": "Phase 0 + Shadow AI Pack",
      "description": "The assessment that finds every AI system in your estate, paired with the workbook that inventories and scores them. Map the footprint, then govern it. 20% off buying separately.",
      "url": "https://ciso.diy/templates/phase-0-shadow-ai-pack",
      "image": "https://ciso.diy/images/og/phase-0-shadow-ai-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "Phase 0",
        "shadow AI",
        "AI governance",
        "risk assessment",
        "bundle",
        "EU AI Act",
        "NIST AI RMF"
      ],
      "keyFacts": [
        "**Run Phase 0 first, then fill the AI section of it with this.** Phase 0 asks what AI is running here, sanctioned and shadow; the inventory answers it with a defensible score."
      ],
      "formats": [
        "pdf",
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 31900,
      "listPriceFrom": 39900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 79900,
          "listPrice": 99900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 111900,
          "listPrice": 139900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "phase-0-ai-risk-assessment",
          "title": "Phase 0 — The Enterprise AI Risk Assessment",
          "url": "https://ciso.diy/templates/phase-0-ai-risk-assessment"
        },
        {
          "slug": "shadow-ai-inventory",
          "title": "Shadow AI Inventory & Risk Scoring Workbook",
          "url": "https://ciso.diy/templates/shadow-ai-inventory"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "phase-0-risk-readiness-pack",
      "title": "Phase 0 + Risk & Readiness Pack",
      "description": "The front-door assessment plus the four workbooks that prove readiness to the people who ask — ransomware, tabletop, cyber insurance and shadow AI. 25% off buying separately.",
      "url": "https://ciso.diy/templates/phase-0-risk-readiness-pack",
      "image": "https://ciso.diy/images/og/phase-0-risk-readiness-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "Phase 0",
        "risk assessment",
        "ransomware",
        "tabletop",
        "cyber insurance",
        "shadow AI",
        "bundle",
        "readiness"
      ],
      "keyFacts": [
        "**Assess once, then evidence it four ways** — to an underwriter, a board, an auditor and your own roadmap."
      ],
      "formats": [
        "pdf",
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 58300,
      "listPriceFrom": 72900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 58300,
          "listPrice": 72900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 139900,
          "listPrice": 174900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 259900,
          "listPrice": 324900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "phase-0-ai-risk-assessment",
          "title": "Phase 0 — The Enterprise AI Risk Assessment",
          "url": "https://ciso.diy/templates/phase-0-ai-risk-assessment"
        },
        {
          "slug": "ransomware-readiness",
          "title": "2026 Ransomware Readiness Workbook",
          "url": "https://ciso.diy/templates/ransomware-readiness"
        },
        {
          "slug": "tabletop-exercise-pack",
          "title": "Tabletop Exercise Pack",
          "url": "https://ciso.diy/templates/tabletop-exercise-pack"
        },
        {
          "slug": "cyber-insurance-workbook",
          "title": "Cyber Insurance Workbook",
          "url": "https://ciso.diy/templates/cyber-insurance-workbook"
        },
        {
          "slug": "shadow-ai-inventory",
          "title": "Shadow AI Inventory & Risk Scoring Workbook",
          "url": "https://ciso.diy/templates/shadow-ai-inventory"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "operators-manual-c2",
      "title": "The Operator's Manual — C2 Command Layer",
      "description": "The capstone above all six pillars: one seat that conducts the whole department. Intake from four employee doorways, visible approval gates, one living risk register, and observability into every AI channel — with the agent layer and MCP wiring that runs it.",
      "url": "https://ciso.diy/templates/operators-manual-c2",
      "image": "https://ciso.diy/images/og/operators-manual-c2.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "C2",
        "command layer",
        "operator",
        "orchestration",
        "agent framework",
        "MCP",
        "agent wallets",
        "OpenClaw",
        "risk register",
        "vCISO",
        "capstone"
      ],
      "keyFacts": [
        "**The capstone above all six pillars — not a seventh pillar, the seat that conducts them.**",
        "**Agent wallets are why spend becomes a control.** The 2026 shift is that agents hold wallets and spend autonomously, which turns budget into a gated security control rather than a finance concern.",
        "One pane, the whole department: an intake queue where reports from every doorway land, triaged and ready for action behind a gate.",
        "Runs on hardware you hold if you want sovereignty — Qubes laptops and Linux NUCs with hardware tokens."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 24,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 22900,
      "listPriceFrom": 22900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 22900,
          "listPrice": 22900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 49900,
          "listPrice": 49900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 99900,
          "listPrice": 99900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "incident-response-operating-system",
      "title": "Pillar 05 — The Incident Response Operating System",
      "description": "An operating system for the worst day — the right people in one room, on one clock, with 90% of the hardest choices already made. Built on NIST 800-61 Rev. 3, with the offline runbook, the notification clocks and a ready-to-run tabletop.",
      "url": "https://ciso.diy/templates/incident-response-operating-system",
      "image": "https://ciso.diy/images/og/incident-response-operating-system.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "incident response",
        "pillar 05",
        "IR",
        "NIST 800-61",
        "tabletop",
        "ransomware",
        "breach notification",
        "SEC 8-K",
        "DFIR retainer"
      ],
      "keyFacts": [
        "**Built on NIST 800-61 Rev. 3 — the 2025 rewrite most guides missed.** If your plan still follows the retired revision, it is describing a lifecycle that no longer matches the current framework.",
        "**90% of incident response is preparation**, and the guide is structured that way.",
        "Pre-grant emergency isolation authority, so nobody is hunting for permission at 2am.",
        "An operating system for the worst day: the right people in one room, on one clock, with 90% of the hardest choices already made before the incident lands."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 24,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 18900,
      "listPriceFrom": 18900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 18900,
          "listPrice": 18900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 41900,
          "listPrice": 41900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 87900,
          "listPrice": 87900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ai-soc-operating-system",
      "title": "Pillar 04 — The AI-SOC Operating System",
      "description": "Read every alert, resolve the routine, escalate only what needs a human. A reducer that overlays your existing SIEM, EDR, identity and cloud — human-gated, auditable, and capped at an autonomy level you can defend.",
      "url": "https://ciso.diy/templates/ai-soc-operating-system",
      "image": "https://ciso.diy/images/og/ai-soc-operating-system.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "AI SOC",
        "pillar 04",
        "agentic SOC",
        "alert triage",
        "alert fatigue",
        "SOC automation",
        "SIEM overlay",
        "detection as code",
        "MDR alternative"
      ],
      "keyFacts": [
        "**Teams field 960 to 5,000 alerts a day, and between 40% and 67% of them are never investigated at all.**",
        "71% of SOC analysts report burnout and roughly 28% turn over.",
        "The winning move in 2026 is not a better detector — it is **a reducer with a human gate** that turns 5,000 raw alerts into a few confirmed threats and can prove how it got there.",
        "The rip-and-replace pitch costs roughly 18 months and seven figures; the overlay model shows alert reduction **within 30 days**."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 24,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 17900,
      "listPriceFrom": 17900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 17900,
          "listPrice": 17900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 39900,
          "listPrice": 39900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 84900,
          "listPrice": 84900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "compliance-operating-system",
      "title": "Pillar 01 — The Compliance Operating System",
      "description": "Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.",
      "url": "https://ciso.diy/templates/compliance-operating-system",
      "image": "https://ciso.diy/images/og/compliance-operating-system.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "compliance",
        "pillar 01",
        "SOC 2",
        "ISO 27001",
        "HIPAA",
        "PCI DSS",
        "CMMC",
        "DORA",
        "NIS2",
        "ISO 42001",
        "EU AI Act",
        "evidence",
        "audit readiness"
      ],
      "keyFacts": [
        "One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.",
        "**A readiness dashboard can read 98% while the auditor’s fieldwork disagrees**, because completion percentage is not evidence quality.",
        "Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 24,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 16900,
      "listPriceFrom": 16900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 16900,
          "listPrice": 16900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 37900,
          "listPrice": 37900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 79900,
          "listPrice": 79900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "living-isms",
      "title": "Pillar 01 Companion — The Living ISMS",
      "description": "The database behind the control register. A homegrown ISMS with automatic evidence decay, an eleven-prompt agent layer and an MCP interface — the engineered companion to Pillar 01. Ships with the schema, the prompt library and all eleven JSON Schemas.",
      "url": "https://ciso.diy/templates/living-isms",
      "image": "https://ciso.diy/images/og/living-isms.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "ISMS",
        "pillar 01",
        "compliance",
        "GRC",
        "control graph",
        "evidence decay",
        "ISO 27001",
        "SOC 2",
        "privacy",
        "ROPA",
        "DSAR",
        "MCP",
        "AI agents"
      ],
      "keyFacts": [
        "One change — MFA enforcement now covers contractors — touches an access policy, a SOC 2 narrative, an ISO Annex A mapping, three questionnaire answers and a customer commitment.",
        "All eleven prompts ship as **JSON Schema** — ten output contracts plus the P0 input contract — so your code rejects malformed responses instead of trusting them.",
        "**P6 is the one that pays for the guide.** A questionnaire responder grounded strictly in your own store that says *cannot answer* rather than producing the industry-typical answer — and every cannot-answer writes back as a gap."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": 40,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 18300,
      "listPriceFrom": 22900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 18300,
          "listPrice": 22900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 39900,
          "listPrice": 49900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 87900,
          "listPrice": 109900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "compliance-method-and-machine",
      "title": "Compliance: Method & Machine",
      "description": "Pillar 01 — The Compliance Operating System, plus The Living ISMS. Read the method, then build the system that runs it. 25% off buying separately.",
      "url": "https://ciso.diy/templates/compliance-method-and-machine",
      "image": "https://ciso.diy/images/og/compliance-method-and-machine.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "compliance",
        "pillar 01",
        "ISMS",
        "GRC",
        "bundle",
        "control graph",
        "evidence"
      ],
      "keyFacts": [
        "**Why the pair:** the two overlap deliberately at the control-mapping seam. Read the method, then build the system that runs it."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 52700,
          "listPrice": 65900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 114300,
          "listPrice": 142900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "compliance-operating-system",
          "title": "Pillar 01 — The Compliance Operating System",
          "url": "https://ciso.diy/templates/compliance-operating-system"
        },
        {
          "slug": "living-isms",
          "title": "Pillar 01 Companion — The Living ISMS",
          "url": "https://ciso.diy/templates/living-isms"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "compliance-program-starter",
      "title": "Compliance Program Starter",
      "description": "The Pillar 01 operating system plus the two workbooks most first programs actually need — SOC 2 Readiness and the NIST CSF 2.0 Self-Assessment — with both PDF readiness checklists included. 30% off buying separately.",
      "url": "https://ciso.diy/templates/compliance-program-starter",
      "image": "https://ciso.diy/images/og/compliance-program-starter.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "compliance",
        "pillar 01",
        "SOC 2",
        "NIST CSF",
        "bundle",
        "audit readiness",
        "evidence"
      ],
      "keyFacts": [
        "Read the operating system for the method, run SOC 2 with the accelerator, baseline against NIST CSF, and **use the checklists as the pre-fieldwork sanity pass**."
      ],
      "formats": [
        "pdf",
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 41500,
      "listPriceFrom": 51900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 41500,
          "listPrice": 51900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 101500,
          "listPrice": 126900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 242300,
          "listPrice": 302900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "compliance-operating-system",
          "title": "Pillar 01 — The Compliance Operating System",
          "url": "https://ciso.diy/templates/compliance-operating-system"
        },
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        },
        {
          "slug": "soc2-readiness-checklist",
          "title": "SOC 2 Readiness Checklist (Type I & II)",
          "url": "https://ciso.diy/templates/soc2-readiness-checklist"
        },
        {
          "slug": "hipaa-compliance-checklist",
          "title": "HIPAA Compliance Checklist 2026",
          "url": "https://ciso.diy/templates/hipaa-compliance-checklist"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "fractional-ciso-operating-system",
      "title": "Pillar 06 — The Fractional CISO Operating System",
      "description": "The capstone hub: a human-owned register that aggregates every security stream into board-legible, quantified risk. The 2026 pricing ladder, the first 90 days, the five-page board deck, and the layer the AI vCISO platforms structurally cannot replace.",
      "url": "https://ciso.diy/templates/fractional-ciso-operating-system",
      "image": "https://ciso.diy/images/og/fractional-ciso-operating-system.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "fractional CISO",
        "vCISO",
        "virtual CISO",
        "pillar 06",
        "board reporting",
        "risk register",
        "cyber risk quantification",
        "MSP",
        "security leadership"
      ],
      "keyFacts": [
        "The senior version — the one worth 00K-equivalent leadership — is aggregating every stream into one register a human owns, and conducting it to the board in the one language the board acts on: **money**.",
        "The answer when a prospect asks why they need you if the platform writes the policies: **the platform writes policies, but it cannot be accountable to your board for whether your .2M exposure is acceptable.**",
        "The 2026 pricing ladder places a client by risk rather than hope — Core Program at ,000–2,000/month for 12–20 hours is where most engagements land."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 23,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 19900,
      "listPriceFrom": 19900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 19900,
          "listPrice": 19900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 44900,
          "listPrice": 44900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 89900,
          "listPrice": 89900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ai-risk-register-build-system",
      "title": "Pillar 06 Companion — The 2026 AI Risk Register",
      "description": "The register that inventories every AI system, model and agent in your business, classifies it against the 2026 regulatory map, scores it on autonomy and blast radius, and routes remediation to real suppliers. Full schema, five classification rule tables, 41 build prompts.",
      "url": "https://ciso.diy/templates/ai-risk-register-build-system",
      "image": "https://ciso.diy/images/og/ai-risk-register-build-system.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "AI risk register",
        "pillar 06",
        "AI governance",
        "EU AI Act",
        "NIST AI RMF",
        "ISO 42001",
        "TRAIGA",
        "shadow AI",
        "AI inventory",
        "agentic AI risk",
        "air-gapped GRC",
        "vCISO"
      ],
      "keyFacts": [
        "**The Digital Omnibus on AI entered into force 27 July 2026** and pushed the high-risk regime for stand-alone Annex III systems out to 2 December 2027, with embedded Annex I systems following on 2 August 2028.",
        "What survived every amendment: **Article 50 transparency, the Article 4 AI-literacy duty, and the 2 December 2026 marking obligation** for systems already on the market.",
        "The line to use with your board: the high-risk regime moved by sixteen months, and **a team that restarts this work in mid-2027 restarts it with fifteen months less evidence history** than a team that never stopped.",
        "Texas TRAIGA has been enforceable since 1 January 2026 with **no revenue or compute threshold**, and carries an enforcement safe harbor for substantial compliance with the NIST AI RMF."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": 27,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 20700,
      "listPriceFrom": 25900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 20700,
          "listPrice": 25900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 45500,
          "listPrice": 56900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 91100,
          "listPrice": 113900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ai-risk-register-pack",
      "title": "AI Risk Register Pack",
      "description": "Pillar 06 — The Fractional CISO Operating System, plus The 2026 AI Risk Register. The practice and the system: own the register and know how to run it. 20% off buying separately.",
      "url": "https://ciso.diy/templates/ai-risk-register-pack",
      "image": "https://ciso.diy/images/og/ai-risk-register-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "AI risk register",
        "pillar 06",
        "fractional CISO",
        "vCISO",
        "AI governance",
        "bundle",
        "EU AI Act"
      ],
      "keyFacts": [
        "**Why the pair:** the pillar tells you what the register is for and how to charge for conducting it; the companion tells you how to build one that survives an acquirer’s diligence."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 29200,
      "listPriceFrom": 36500,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 29200,
          "listPrice": 36500,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 65200,
          "listPrice": 81500,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 130300,
          "listPrice": 162900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "fractional-ciso-operating-system",
          "title": "Pillar 06 — The Fractional CISO Operating System",
          "url": "https://ciso.diy/templates/fractional-ciso-operating-system"
        },
        {
          "slug": "ai-risk-register-build-system",
          "title": "Pillar 06 Companion — The 2026 AI Risk Register",
          "url": "https://ciso.diy/templates/ai-risk-register-build-system"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "enterprise-risk-register-build-system",
      "title": "Pillar 06 Companion — The Enterprise Risk Register",
      "description": "Seed to sale for risk: from the engagement that found it to the purchase order that closes it. Offensive scoping, a coverage matrix that knows what has gone stale, treatment as a budgeted project, and priced solutions with the ROI attached.",
      "url": "https://ciso.diy/templates/enterprise-risk-register-build-system",
      "image": "https://ciso.diy/images/og/enterprise-risk-register-build-system.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "enterprise risk register",
        "pillar 06",
        "risk register",
        "coverage matrix",
        "MITRE ATT&CK",
        "OWASP WSTG",
        "NIST 800-115",
        "remediation ROI",
        "vCISO",
        "third-party risk",
        "GRC",
        "multi-entity"
      ],
      "keyFacts": [
        "Four methodology packs ship **as data** — MITRE ATT&CK, OWASP WSTG, NIST 800-115 and a generic assessment pack — 141 entries carrying their own decay windows.",
        "The seed is a populated enterprise risk register with a coverage map: 8 assets, 4 engagements, 116 coverage rows, 11 scored risks, 6 solution options."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": 32,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 51900,
          "listPrice": 64900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 103900,
          "listPrice": 129900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "register-family",
      "title": "The Register Family",
      "description": "Pillar 06 plus both registers — The Enterprise Risk Register as the hub and The 2026 AI Risk Register as the AI stream. The hub, the stream, and the practice that owns them. 25% off buying separately.",
      "url": "https://ciso.diy/templates/register-family",
      "image": "https://ciso.diy/images/og/register-family.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "enterprise risk register",
        "AI risk register",
        "pillar 06",
        "fractional CISO",
        "vCISO",
        "bundle",
        "risk register"
      ],
      "keyFacts": [
        "The three registers that share one seam — and **buy the parts separately and you assemble the same thing for more**."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 45500,
      "listPriceFrom": 56900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 45500,
          "listPrice": 56900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 99900,
          "listPrice": 124900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 199900,
          "listPrice": 249900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "fractional-ciso-operating-system",
          "title": "Pillar 06 — The Fractional CISO Operating System",
          "url": "https://ciso.diy/templates/fractional-ciso-operating-system"
        },
        {
          "slug": "enterprise-risk-register-build-system",
          "title": "Pillar 06 Companion — The Enterprise Risk Register",
          "url": "https://ciso.diy/templates/enterprise-risk-register-build-system"
        },
        {
          "slug": "ai-risk-register-build-system",
          "title": "Pillar 06 Companion — The 2026 AI Risk Register",
          "url": "https://ciso.diy/templates/ai-risk-register-build-system"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "register-and-machine",
      "title": "Register & Machine",
      "description": "The Enterprise Risk Register plus The Living ISMS. The register asks whether a risk is treated by control X; the control graph answers whether X is real. Both sides of the seam. 25% off buying separately.",
      "url": "https://ciso.diy/templates/register-and-machine",
      "image": "https://ciso.diy/images/og/register-and-machine.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "enterprise risk register",
        "ISMS",
        "control graph",
        "GRC",
        "bundle",
        "risk register",
        "evidence"
      ],
      "keyFacts": [
        "**Run the register without a control graph and you type an effectiveness figure that nothing backs; run the control graph without a register and you know your controls are real but not what they are protecting you from.**"
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 31900,
      "listPriceFrom": 39900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 68700,
          "listPrice": 85900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 143900,
          "listPrice": 179900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "enterprise-risk-register-build-system",
          "title": "Pillar 06 Companion — The Enterprise Risk Register",
          "url": "https://ciso.diy/templates/enterprise-risk-register-build-system"
        },
        {
          "slug": "living-isms",
          "title": "Pillar 01 Companion — The Living ISMS",
          "url": "https://ciso.diy/templates/living-isms"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "fractional-ciso-practice-pack",
      "title": "Fractional CISO Practice Pack",
      "description": "The Pillar 06 operating system plus the two workbooks that run it — vCISO Client-in-a-Box for the portfolio and the CISO 90-Day Onboarding Workbook for every new engagement. 25% off buying separately.",
      "url": "https://ciso.diy/templates/fractional-ciso-practice-pack",
      "image": "https://ciso.diy/images/og/fractional-ciso-practice-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "fractional CISO",
        "vCISO",
        "pillar 06",
        "bundle",
        "board reporting",
        "practice",
        "MSP"
      ],
      "keyFacts": [
        "Read the operating system, run the portfolio in the workbook, and **onboard every new client the same way**."
      ],
      "formats": [
        "pdf",
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 59800,
      "listPriceFrom": 74700,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 59800,
          "listPrice": 74700,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 152700,
          "listPrice": 190900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 323900,
          "listPrice": 404900,
          "formats": [
            "pdf",
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "fractional-ciso-operating-system",
          "title": "Pillar 06 — The Fractional CISO Operating System",
          "url": "https://ciso.diy/templates/fractional-ciso-operating-system"
        },
        {
          "slug": "vciso-client-in-a-box",
          "title": "vCISO Client-in-a-Box",
          "url": "https://ciso.diy/templates/vciso-client-in-a-box"
        },
        {
          "slug": "ciso-90-day-onboarding",
          "title": "CISO 90-Day Onboarding Workbook",
          "url": "https://ciso.diy/templates/ciso-90-day-onboarding"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "devsecops-risk-register-guide",
      "title": "Pillar 02 — AI-Augmented DevSecOps Risk Register",
      "description": "Run a continuous, AI-triaged security program across 100+ apps as a solo engineer. Platform-first discovery, SAST/SCA/secrets/DAST, a self-healing risk register, and tiered Claude triage — on free and near-free parts.",
      "url": "https://ciso.diy/templates/devsecops-risk-register-guide",
      "image": "https://ciso.diy/images/og/devsecops-risk-register-guide.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "DevSecOps",
        "risk register",
        "AI triage",
        "SAST",
        "DAST",
        "Semgrep",
        "AppSec",
        "solo security team",
        "vCISO",
        "pillar 02"
      ],
      "keyFacts": [
        "AI triage took roughly **6,000 flat findings down to 44 ranked criticals** — and escalated dozens of buried “highs” *up* to critical — for about **0 of one-time API spend**.",
        "Run a credible, continuous, AI-triaged security programme across 100+ apps as a solo engineer, for roughly the cost of a streaming subscription.",
        "**A pagination bug in that enumeration once hid 80% of our own estate.**",
        "Seven build steps, each with the architecture, the exact tooling decisions, and the failure modes we hit on a ~150-property estate."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 18,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 14900,
      "listPriceFrom": 14900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 14900,
          "listPrice": 14900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 34900,
          "listPrice": 34900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 74900,
          "listPrice": 74900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ptaas-lane-guide",
      "title": "Pillar 03 — AI-Augmented PTaaS Lane",
      "description": "An authorized, sandboxed autonomous offense lane that proves bugs — a crashing proof-of-vulnerability or live exploit chain, paired with a candidate patch, under the same register and human gate as Pillar 02. Design-stage guide, published before the build.",
      "url": "https://ciso.diy/templates/ptaas-lane-guide",
      "image": "https://ciso.diy/images/og/ptaas-lane-guide.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "PTaaS",
        "autonomous pentest",
        "cyber reasoning system",
        "AIxCC",
        "Buttercup",
        "PentAGI",
        "exploit chain",
        "red team",
        "pillar 03"
      ],
      "keyFacts": [
        "**Status: design and roadmap, not yet shipped — and the cover says so, not the fine print.**",
        "Pillar 02 is the always-on health monitor with a read-only blast radius; **Pillar 03 is scheduled, consented surgery** — a fuzzer that crashes the target, tooling that pops a real injection.",
        "The 2026 field is crowded with **39+ AI-pentest agents**, so evaluate before committing: the integration contract matters more than which tool you pick."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 19,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 17900,
      "listPriceFrom": 17900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 17900,
          "listPrice": 17900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 39900,
          "listPrice": 39900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 84900,
          "listPrice": 84900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "bug-hunter-automation",
      "title": "Bug-Hunter Automation",
      "description": "The continuous discovery layer between Pillars 02 and 03 — shift-left source analysis, autonomous runtime testing, and a validation gate in the middle that files findings instead of noise. Ten sections, eight working appendices.",
      "url": "https://ciso.diy/templates/bug-hunter-automation",
      "image": "https://ciso.diy/images/og/bug-hunter-automation.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "bug bounty",
        "bug hunting",
        "discovery",
        "agentic AI",
        "AppSec",
        "runtime testing",
        "validation gate",
        "authorization",
        "pillar 02 add-on"
      ],
      "keyFacts": [
        "**One continuous loop, not three disconnected tools.** Most teams bolt on security that never talks to itself: a static scanner in CI, a scanner-of-the-week against production, and a folder of write-ups nobody re-reads.",
        "**A validation gate in the middle that files findings instead of noise** — source analysis on the left, autonomous runtime testing on the right.",
        "Ten sections and eight working appendices, sitting between Pillar 02 (where findings come to rest) and Pillar 03 (which proves the deployed asset)."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 19,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 19900,
      "listPriceFrom": 19900,
      "onSale": false,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 19900,
          "listPrice": 19900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 44900,
          "listPrice": 44900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 89900,
          "listPrice": 89900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ai-soc-pillar-bundle",
      "title": "Pillar 04 — AI-SOC Complete",
      "description": "The whole AI-SOC pillar — the operating system that reduces your alerts, the reference architecture that designs the system underneath it, and the hardware build guide that lands it on one machine you hold. 20% off buying separately.",
      "url": "https://ciso.diy/templates/ai-soc-pillar-bundle",
      "image": "https://ciso.diy/images/og/ai-soc-pillar-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "AI-SOC",
        "pillar 04",
        "SOC",
        "bundle",
        "Wazuh",
        "hardware",
        "architecture"
      ],
      "keyFacts": [
        "Read the architecture for the shape of the system, **then build it on hardware you own**."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 27100,
      "listPriceFrom": 33900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 27100,
          "listPrice": 33900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 41500,
          "listPrice": 51900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 70300,
          "listPrice": 87900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ai-soc-operating-system",
          "title": "Pillar 04 — The AI-SOC Operating System",
          "url": "https://ciso.diy/templates/ai-soc-operating-system"
        },
        {
          "slug": "open-soc-architecture",
          "title": "Pillar 04 Companion — The Open SOC Reference Architecture",
          "url": "https://ciso.diy/templates/open-soc-architecture"
        },
        {
          "slug": "soc-in-a-box",
          "title": "Pillar 04 Companion — SOC in a Box",
          "url": "https://ciso.diy/templates/soc-in-a-box"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "operator-node-diy-build",
      "title": "C2 Companion — The Operator Node DIY Build",
      "description": "The box the security department runs on. Self-host the living risk register, the ISMS and the evidence vault on one hardened machine — zero inbound, hardware-rooted, on your keys, severable in one step. Ships with the scoping module and the AI data-handling annex as editable templates.",
      "url": "https://ciso.diy/templates/operator-node-diy-build",
      "image": "https://ciso.diy/images/og/operator-node-diy-build.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "operator node",
        "C2",
        "self-hosted",
        "infrastructure",
        "zero trust",
        "Tailscale",
        "BYOK",
        "hardware root",
        "homelab",
        "NUC",
        "evidence vault",
        "ISMS"
      ],
      "keyFacts": [
        "Deploy the register and ISMS as version-controlled documents, framework-mapped on a NIST CSF 2.0 baseline with SOC 2 and ISO 27001 overlays, and **wire report generation to the live source rather than to a copy**.",
        "If your answer to *whose data is on this box* is “a client’s, heading into diligence”, Part 4 says so plainly.",
        "Phase 0 maps the estate; **this is where that map becomes a running configuration**."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": 24,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 10300,
      "listPriceFrom": 12900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 10300,
          "listPrice": 12900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 51900,
          "listPrice": 64900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "self-host-starter",
      "title": "Self-Host Starter",
      "description": "C2 — The Operator's Manual plus the Operator Node DIY Build. The operating model and the box it runs on. 25% off buying separately.",
      "url": "https://ciso.diy/templates/self-host-starter",
      "image": "https://ciso.diy/images/og/self-host-starter.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "operator node",
        "C2",
        "self-hosted",
        "homelab",
        "bundle",
        "zero trust",
        "infrastructure"
      ],
      "keyFacts": [
        "**Why the pair:** the manual assumes infrastructure it does not tell you how to build; the build guide produces infrastructure without telling you how to operate it.",
        "The cheapest complete way into the programme — the operating model and the machine it runs on."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 21500,
      "listPriceFrom": 26900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 21500,
          "listPrice": 26900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 47900,
          "listPrice": 59900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 99100,
          "listPrice": 123900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "operators-manual-c2",
          "title": "C2 — The Operator's Manual",
          "url": "https://ciso.diy/templates/operators-manual-c2"
        },
        {
          "slug": "operator-node-diy-build",
          "title": "C2 Companion — The Operator Node DIY Build",
          "url": "https://ciso.diy/templates/operator-node-diy-build"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "operator-on-a-box",
      "title": "Operator on a Box",
      "description": "The Operator's Manual plus SOC in a Box — the command layer and the hardened machine to run it on. Sovereign by construction: your vault, your gates, your hardware. 18% off buying separately.",
      "url": "https://ciso.diy/templates/operator-on-a-box",
      "image": "https://ciso.diy/images/og/operator-on-a-box.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "C2",
        "operator",
        "bundle",
        "hardware",
        "sovereign",
        "Nitrokey",
        "coreboot",
        "agent framework"
      ],
      "keyFacts": [
        "**Why they pair:** the C2 guide’s containment guarantee is that the AI layer can be severed in one click with production untouched — and this is the box that makes that severable."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 21500,
      "listPriceFrom": 26900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 21500,
          "listPrice": 26900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 39100,
          "listPrice": 48900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 71900,
          "listPrice": 89900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "operators-manual-c2",
          "title": "C2 — The Operator's Manual",
          "url": "https://ciso.diy/templates/operators-manual-c2"
        },
        {
          "slug": "soc-in-a-box",
          "title": "Pillar 04 Companion — SOC in a Box",
          "url": "https://ciso.diy/templates/soc-in-a-box"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "security-pillars-complete",
      "title": "Complete Security Program Pillars",
      "description": "The whole programme — the Phase 0 assessment that scopes it, all six pillars, and the C2 command layer that conducts them — the compliance operating system, the DevSecOps risk register, the Bug-Hunter discovery layer, the PTaaS proof lane, both halves of the AI-SOC pillar, and the Fractional CISO operating system they all report into. Discovery to detection to remediation as one program, and the operator node it all runs on. 25% off buying separately.",
      "url": "https://ciso.diy/templates/security-pillars-complete",
      "image": "https://ciso.diy/images/og/security-pillars-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "DevSecOps",
        "PTaaS",
        "bug hunting",
        "AI-SOC",
        "bundle",
        "AppSec",
        "pillars",
        "AI security"
      ],
      "keyFacts": [
        "Phase 0, all six pillars, their companions and the C2 seat above them. **Bought apart, you assemble that integration yourself.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 123900,
      "listPriceFrom": 154900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 123900,
          "listPrice": 154900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 259100,
          "listPrice": 323900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 519900,
          "listPrice": 649900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "phase-0-ai-risk-assessment",
          "title": "Phase 0 — The Enterprise AI Risk Assessment",
          "url": "https://ciso.diy/templates/phase-0-ai-risk-assessment"
        },
        {
          "slug": "compliance-operating-system",
          "title": "Pillar 01 — The Compliance Operating System",
          "url": "https://ciso.diy/templates/compliance-operating-system"
        },
        {
          "slug": "devsecops-risk-register-guide",
          "title": "Pillar 02 — AI-Augmented DevSecOps Risk Register",
          "url": "https://ciso.diy/templates/devsecops-risk-register-guide"
        },
        {
          "slug": "bug-hunter-automation",
          "title": "Bug-Hunter Automation",
          "url": "https://ciso.diy/templates/bug-hunter-automation"
        },
        {
          "slug": "ptaas-lane-guide",
          "title": "Pillar 03 — AI-Augmented PTaaS Lane",
          "url": "https://ciso.diy/templates/ptaas-lane-guide"
        },
        {
          "slug": "ai-soc-operating-system",
          "title": "Pillar 04 — The AI-SOC Operating System",
          "url": "https://ciso.diy/templates/ai-soc-operating-system"
        },
        {
          "slug": "open-soc-architecture",
          "title": "Pillar 04 Companion — The Open SOC Reference Architecture",
          "url": "https://ciso.diy/templates/open-soc-architecture"
        },
        {
          "slug": "soc-in-a-box",
          "title": "Pillar 04 Companion — SOC in a Box",
          "url": "https://ciso.diy/templates/soc-in-a-box"
        },
        {
          "slug": "incident-response-operating-system",
          "title": "Pillar 05 — The Incident Response Operating System",
          "url": "https://ciso.diy/templates/incident-response-operating-system"
        },
        {
          "slug": "fractional-ciso-operating-system",
          "title": "Pillar 06 — The Fractional CISO Operating System",
          "url": "https://ciso.diy/templates/fractional-ciso-operating-system"
        },
        {
          "slug": "operators-manual-c2",
          "title": "C2 — The Operator's Manual",
          "url": "https://ciso.diy/templates/operators-manual-c2"
        },
        {
          "slug": "operator-node-diy-build",
          "title": "C2 Companion — The Operator Node DIY Build",
          "url": "https://ciso.diy/templates/operator-node-diy-build"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "devsecops-ptaas-bundle",
      "title": "DevSecOps + PTaaS Bundle",
      "description": "Pillars 02 and 03 together — the always-on risk register that finds patterns, and the authorized offense lane that proves them. 15% off buying separately.",
      "url": "https://ciso.diy/templates/devsecops-ptaas-bundle",
      "image": "https://ciso.diy/images/og/devsecops-ptaas-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "DevSecOps",
        "PTaaS",
        "bundle",
        "AppSec",
        "AI triage",
        "autonomous pentest",
        "pillars"
      ],
      "keyFacts": [
        "**Together they share one register, one human gate, and one append-only audit trail where the machine suggests and a person decides.**",
        "Pillar 03 assumes Pillar 02 rather than standing beside it. Buy them apart and you assemble that integration yourself."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-01",
      "priceCurrency": "USD",
      "priceFrom": 22300,
      "listPriceFrom": 27900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 22300,
          "listPrice": 27900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 51100,
          "listPrice": 63900,
          "formats": [
            "pdf"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 108700,
          "listPrice": 135900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "devsecops-risk-register-guide",
          "title": "Pillar 02 — AI-Augmented DevSecOps Risk Register",
          "url": "https://ciso.diy/templates/devsecops-risk-register-guide"
        },
        {
          "slug": "ptaas-lane-guide",
          "title": "Pillar 03 — AI-Augmented PTaaS Lane",
          "url": "https://ciso.diy/templates/ptaas-lane-guide"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-01-detection-monitoring",
      "title": "Build Series Vol. 01 — Detection & Monitoring",
      "description": "Wazuh, Suricata and Zeek assembled into a stack one person can operate, with the tuning and detection validation that almost every deployment skips.",
      "url": "https://ciso.diy/templates/build-01-detection-monitoring",
      "image": "https://ciso.diy/images/og/build-01-detection-monitoring.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "detection",
        "SIEM",
        "Wazuh",
        "Suricata",
        "Zeek",
        "monitoring",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**Current as of August 2026.** Security Onion 2.4 reaches end of life on 1 October 2026, and 3.x replaced Wazuh with Elastic Agent — so running both platforms means two agent fleets and two rule languages.",
        "Stack: Wazuh 4.14.x · Security Onion 3.x · Suricata · Zeek · Atomic Red Team.",
        "This is a document, not a service contract — **Section 8 tells you plainly where the buy line is.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-02-asset-inventory",
      "title": "Build Series Vol. 02 — Asset Inventory & Discovery",
      "description": "Discovery tells you what is out there. The source of truth holds what you have decided about it. The control lives in the reconciliation between them, not in either list.",
      "url": "https://ciso.diy/templates/build-02-asset-inventory",
      "image": "https://ciso.diy/images/og/build-02-asset-inventory.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "asset inventory",
        "CMDB",
        "NetBox",
        "osquery",
        "discovery",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**Current as of August 2026.** runZero Community Edition is free to 100 assets and is **not** open source; the fully open path is Nmap with Netdisco.",
        "This is a document, not a service contract — Section 8 tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-03-vulnerability-management",
      "title": "Build Series Vol. 03 — Vulnerability Management",
      "description": "Finding what is exploitable, fixing what matters, and proving both — with a prioritisation model that still works when the severity score is missing.",
      "url": "https://ciso.diy/templates/build-03-vulnerability-management",
      "image": "https://ciso.diy/images/og/build-03-vulnerability-management.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "vulnerability management",
        "OpenVAS",
        "KEV",
        "EPSS",
        "DefectDojo",
        "patching",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**NIST stopped enriching most CVEs on 15 April 2026** — everything unenriched before 1 March 2026 moved to “Not Scheduled”.",
        "This is a document, not a service contract — Section 8 tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-04-incident-response-lab",
      "title": "Build Series Vol. 04 — Incident Response Lab",
      "description": "The capability to investigate, contain and report — built before you need it, including the reporting clocks measured in hours rather than days.",
      "url": "https://ciso.diy/templates/build-04-incident-response-lab",
      "image": "https://ciso.diy/images/og/build-04-incident-response-lab.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "incident response",
        "DFIR",
        "Velociraptor",
        "DFIR-IRIS",
        "CIRCIA",
        "forensics",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**The decision this volume is really about:** who may authorise containment at 2am, and collecting evidence before anyone remediates.",
        "**Current as of August 2026.** TheHive has been a commercial product since 2022; DFIR-IRIS is the open path.",
        "CIRCIA’s 72-hour incident and 24-hour ransom-payment clocks are statutory and **have not moved through four years of delays**.",
        "Tier 1 is 15–25 hours to build, then 2–4 hours a month plus exercises."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-05-backup-recovery",
      "title": "Build Series Vol. 05 — Backup & Recovery",
      "description": "Copies an attacker holding domain admin cannot reach, and restores you have actually performed and timed — including the full-estate rebuild nobody plans for.",
      "url": "https://ciso.diy/templates/build-05-backup-recovery",
      "image": "https://ciso.diy/images/og/build-05-backup-recovery.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "backup",
        "recovery",
        "ransomware",
        "Restic",
        "immutability",
        "RPO",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**Restic reads its repository index on every run, so it cannot be write-only** — the correct pattern is a deny-delete credential policy, not a read-only one.",
        "This is a document, not a service contract — Section 8 tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-06-identity-access",
      "title": "Build Series Vol. 06 — Identity & Access",
      "description": "One front door, authenticators that survive phishing, privileged identities separated from daily work, and access that genuinely ends when people do.",
      "url": "https://ciso.diy/templates/build-06-identity-access",
      "image": "https://ciso.diy/images/og/build-06-identity-access.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "identity",
        "IAM",
        "Keycloak",
        "passkeys",
        "FIDO2",
        "MFA",
        "SSO",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**NIST SP 800-63-4 is final and superseded 800-63-3 on 1 August 2025**, with synced passkeys explicitly accommodated.",
        "Stack: Keycloak · Authentik · Zitadel · OpenBao · Vaultwarden · FIDO2 and passkeys."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-07-endpoint-hardening",
      "title": "Build Series Vol. 07 — Endpoint Hardening & Configuration",
      "description": "Baselines per system class, enforced continuously and measured for drift, across a fleet that includes machines you do not manage and cannot reach on a network.",
      "url": "https://ciso.diy/templates/build-07-endpoint-hardening",
      "image": "https://ciso.diy/images/og/build-07-endpoint-hardening.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "endpoint hardening",
        "CIS Benchmarks",
        "OpenSCAP",
        "baseline",
        "drift",
        "Ansible",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**The Windows Production PCA 2011 Secure Boot certificate expires on 19 October 2026.** Devices without the 2023 certificates keep booting but stop receiving boot-level protections.",
        "This is a document, not a service contract — Section 8 tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-08-network-segmentation",
      "title": "Build Series Vol. 08 — Network Segmentation & Zero Trust",
      "description": "The containment substrate the rest of the series assumes: isolating a host, keeping a compromised endpoint away from the backups, restricting an unmanaged device to a narrow slice.",
      "url": "https://ciso.diy/templates/build-08-network-segmentation",
      "image": "https://ciso.diy/images/og/build-08-network-segmentation.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "segmentation",
        "zero trust",
        "WireGuard",
        "OPNsense",
        "NIST 1800-35",
        "network",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**NIST SP 1800-35 was finalised on 10 June 2025** and frames zero trust as crawl, walk, run.",
        "This is a document, not a service contract — Section 8 tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-09-cloud-saas-posture",
      "title": "Build Series Vol. 09 — Cloud & SaaS Security Posture",
      "description": "The control plane where the estate actually lives — misconfiguration, privilege graphs, public exposure, and the SaaS tenants nobody has ever baselined.",
      "url": "https://ciso.diy/templates/build-09-cloud-saas-posture",
      "image": "https://ciso.diy/images/og/build-09-cloud-saas-posture.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "cloud security",
        "CSPM",
        "SaaS",
        "Prowler",
        "Steampipe",
        "Checkov",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**There is no open-source SSPM, and this volume says so** rather than pretending otherwise — written tenant baselines beat a scanner you do not have.",
        "**ScoutSuite has been unmaintained since May 2024** while remaining on nearly every recommendation list published since."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-10-email-domain-defense",
      "title": "Build Series Vol. 10 — Email & Domain Defense",
      "description": "Domain authentication all the way to enforcement, transport security, portfolio hygiene, and the monitoring that tells you when someone is impersonating you.",
      "url": "https://ciso.diy/templates/build-10-email-domain-defense",
      "image": "https://ciso.diy/images/og/build-10-email-domain-defense.png",
      "category": "architecture",
      "categoryLabel": "Architecture & Build",
      "type": "product",
      "tags": [
        "email security",
        "DMARC",
        "SPF",
        "DKIM",
        "MTA-STS",
        "domain",
        "phishing",
        "build series",
        "open source"
      ],
      "keyFacts": [
        "**DMARC became an IETF Proposed Standard in May 2026 as RFC 9989, and the pct tag is gone** — the protocol’s only staged-rollout mechanism.",
        "This is a document, not a service contract — Section 8 tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 7,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cra-workbook",
      "title": "EU Cyber Resilience Act Workbook",
      "description": "Article 14 reporting readiness and the road to December 2027 — the scope test, the reporting clocks, Annex I requirements mapped to controls, the technical documentation set, and conformity assessment routes. Neither DORA nor NIS2 covers this.",
      "url": "https://ciso.diy/templates/cra-workbook",
      "image": "https://ciso.diy/images/og/cra-workbook.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "CRA",
        "Cyber Resilience Act",
        "EU",
        "compliance",
        "Article 14",
        "product security",
        "regulation"
      ],
      "keyFacts": [
        "**Article 14 reporting is live from 11 September 2026.** Actively exploited vulnerabilities and severe incidents in products with digital elements carry reporting clocks measured in hours, to ENISA and your national CSIRT.",
        "**DORA covers financial entities; NIS2 covers essential and important entities by sector. Neither covers a manufacturer of a product with digital elements** — which is what the CRA regulates.",
        "The road to December 2027 is laid out as a dated sequence rather than a cliff, so the work can be planned across budget cycles.",
        "Harmonised standards and notified-body designations are still landing through 2027; the workbook says which parts of the position are settled and which are still moving, with a dated currency note on each."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 7,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-foundation-bundle",
      "title": "Build Series Foundation Bundle",
      "description": "Volumes 02, 01 and 06 — inventory, detection and identity. The three everything else depends on.",
      "url": "https://ciso.diy/templates/build-foundation-bundle",
      "image": "https://ciso.diy/images/og/build-foundation-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "The three volumes everything else depends on: **everything scopes from the inventory**, detection pays dividends into four later volumes at no marginal cost, and **in a remote-first estate identity is where incidents actually begin**."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 19900,
      "listPriceFrom": 24900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 19900,
          "listPrice": 24900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "build-series-complete",
      "title": "Complete Build Series",
      "description": "All ten volumes in reading order — a security department built out of open source, with control mappings, validation harnesses and honest buy lines throughout. 29% off buying separately.",
      "url": "https://ciso.diy/templates/build-series-complete",
      "image": "https://ciso.diy/images/og/build-series-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "**The volumes are numbered by subject and read in a different order — 02 → 01 → 06 → 05 → 03 → 10 → 04 → 07 → 09 → 08.**",
        "Every volume prints the exact SOC 2, ISO 27001:2022, NIST CSF 2.0, CIS v8.1, CMMC, PCI DSS v4.0.1 and HIPAA clauses the build satisfies **before any installation step**.",
        "**Ships without support, deliberately.** The failure mode for a technical DIY line is a support queue nobody priced for — so every volume tells you plainly where the buy line is."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 55900,
      "listPriceFrom": 69900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 55900,
          "listPrice": 69900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        },
        {
          "slug": "build-05-backup-recovery",
          "title": "Vol. 05 — Backup & Recovery",
          "url": "https://ciso.diy/templates/build-05-backup-recovery"
        },
        {
          "slug": "build-03-vulnerability-management",
          "title": "Vol. 03 — Vulnerability Management",
          "url": "https://ciso.diy/templates/build-03-vulnerability-management"
        },
        {
          "slug": "build-10-email-domain-defense",
          "title": "Vol. 10 — Email & Domain Defense",
          "url": "https://ciso.diy/templates/build-10-email-domain-defense"
        },
        {
          "slug": "build-04-incident-response-lab",
          "title": "Vol. 04 — Incident Response Lab",
          "url": "https://ciso.diy/templates/build-04-incident-response-lab"
        },
        {
          "slug": "build-07-endpoint-hardening",
          "title": "Vol. 07 — Endpoint Hardening & Configuration",
          "url": "https://ciso.diy/templates/build-07-endpoint-hardening"
        },
        {
          "slug": "build-09-cloud-saas-posture",
          "title": "Vol. 09 — Cloud & SaaS Security Posture",
          "url": "https://ciso.diy/templates/build-09-cloud-saas-posture"
        },
        {
          "slug": "build-08-network-segmentation",
          "title": "Vol. 08 — Network Segmentation & Zero Trust",
          "url": "https://ciso.diy/templates/build-08-network-segmentation"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ra01-foundation-bundle",
      "title": "Open SOC Architecture + Build Foundation",
      "description": "The Open SOC Reference Architecture plus Build Series Volumes 02, 01 and 06 — the system-level design, then the three planes everything else depends on.",
      "url": "https://ciso.diy/templates/ra01-foundation-bundle",
      "image": "https://ciso.diy/images/og/ra01-foundation-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "Read the architecture first for the shape of the system, **then build in the order 02 → 01 → 06**."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 27900,
      "listPriceFrom": 34900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 27900,
          "listPrice": 34900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "open-soc-architecture",
          "title": "Pillar 04 — The Open SOC Reference Architecture",
          "url": "https://ciso.diy/templates/open-soc-architecture"
        },
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ra01-build-series-complete",
      "title": "Open SOC Architecture + Complete Build Series",
      "description": "The reference architecture and all ten build volumes — the whole system-level design plus every plane built end to end, in the recommended build order. 30% off buying separately.",
      "url": "https://ciso.diy/templates/ra01-build-series-complete",
      "image": "https://ciso.diy/images/og/ra01-build-series-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "The architecture for the shape of the system, then all ten volumes in build order — **segmentation last, because it depends on both the inventory and the identity work being real**."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 63900,
      "listPriceFrom": 79900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "open-soc-architecture",
          "title": "Pillar 04 — The Open SOC Reference Architecture",
          "url": "https://ciso.diy/templates/open-soc-architecture"
        },
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        },
        {
          "slug": "build-05-backup-recovery",
          "title": "Vol. 05 — Backup & Recovery",
          "url": "https://ciso.diy/templates/build-05-backup-recovery"
        },
        {
          "slug": "build-03-vulnerability-management",
          "title": "Vol. 03 — Vulnerability Management",
          "url": "https://ciso.diy/templates/build-03-vulnerability-management"
        },
        {
          "slug": "build-10-email-domain-defense",
          "title": "Vol. 10 — Email & Domain Defense",
          "url": "https://ciso.diy/templates/build-10-email-domain-defense"
        },
        {
          "slug": "build-04-incident-response-lab",
          "title": "Vol. 04 — Incident Response Lab",
          "url": "https://ciso.diy/templates/build-04-incident-response-lab"
        },
        {
          "slug": "build-07-endpoint-hardening",
          "title": "Vol. 07 — Endpoint Hardening & Configuration",
          "url": "https://ciso.diy/templates/build-07-endpoint-hardening"
        },
        {
          "slug": "build-09-cloud-saas-posture",
          "title": "Vol. 09 — Cloud & SaaS Security Posture",
          "url": "https://ciso.diy/templates/build-09-cloud-saas-posture"
        },
        {
          "slug": "build-08-network-segmentation",
          "title": "Vol. 08 — Network Segmentation & Zero Trust",
          "url": "https://ciso.diy/templates/build-08-network-segmentation"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "soc2-build-pairing",
      "title": "SOC 2 + Build Foundation",
      "description": "SOC 2 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.",
      "url": "https://ciso.diy/templates/soc2-build-pairing",
      "image": "https://ciso.diy/images/og/soc2-build-pairing.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "The framework workbook plus the three builds that answer most of it. **Each build volume prints the exact clauses it satisfies before any installation step, so the work lands in your evidence pack rather than beside it.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 39100,
      "listPriceFrom": 48900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 39100,
          "listPrice": 48900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "iso27001-build-pairing",
      "title": "ISO 27001 + Build Foundation",
      "description": "ISO 27001:2022 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.",
      "url": "https://ciso.diy/templates/iso27001-build-pairing",
      "image": "https://ciso.diy/images/og/iso27001-build-pairing.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "The framework workbook plus the three builds that answer most of it. **Each build volume prints the exact clauses it satisfies before any installation step, so the work lands in your evidence pack rather than beside it.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 41500,
      "listPriceFrom": 51900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 41500,
          "listPrice": 51900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "iso27001-readiness",
          "title": "ISO 27001:2022 Readiness Accelerator",
          "url": "https://ciso.diy/templates/iso27001-readiness"
        },
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "hipaa-build-pairing",
      "title": "HIPAA + Build Foundation",
      "description": "HIPAA Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.",
      "url": "https://ciso.diy/templates/hipaa-build-pairing",
      "image": "https://ciso.diy/images/og/hipaa-build-pairing.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "build series",
        "bundle",
        "open source",
        "security programme"
      ],
      "keyFacts": [
        "The framework workbook plus the three builds that answer most of it. **Each build volume prints the exact clauses it satisfies before any installation step, so the work lands in your evidence pack rather than beside it.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 43900,
      "listPriceFrom": 54900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 43900,
          "listPrice": 54900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "hipaa-readiness-accelerator",
          "title": "HIPAA Readiness Accelerator",
          "url": "https://ciso.diy/templates/hipaa-readiness-accelerator"
        },
        {
          "slug": "build-02-asset-inventory",
          "title": "Vol. 02 — Asset Inventory & Discovery",
          "url": "https://ciso.diy/templates/build-02-asset-inventory"
        },
        {
          "slug": "build-01-detection-monitoring",
          "title": "Vol. 01 — Detection & Monitoring",
          "url": "https://ciso.diy/templates/build-01-detection-monitoring"
        },
        {
          "slug": "build-06-identity-access",
          "title": "Vol. 06 — Identity & Access",
          "url": "https://ciso.diy/templates/build-06-identity-access"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cti-maturity-assessment",
      "title": "CTI Program Maturity Assessment",
      "description": "Nine domains, forty-five statements, and two ceiling rules that stop you scoring yourself a three. The front door to the line — find out where the program actually is before spending anything.",
      "url": "https://ciso.diy/templates/cti-maturity-assessment",
      "image": "https://ciso.diy/images/og/cti-maturity-assessment.png",
      "category": "threat-intelligence",
      "categoryLabel": "Threat Intelligence",
      "type": "product",
      "tags": [
        "threat intelligence",
        "CTI",
        "maturity assessment",
        "MISP",
        "self-assessment",
        "gap analysis"
      ],
      "keyFacts": [
        "**Nine domains, forty-five statements**, scored 0–4 with a per-domain Level 3 anchor so “3” means the same thing in every domain rather than whatever the room feels like that afternoon.",
        "**If the programme is person-dependent — it works because one analyst knows things nobody wrote down — you are capped at Level 1** regardless of what the other domains say.",
        "If the room disagrees about the answers, you are capped at Level 2, because a capability nobody can describe consistently is not a capability.",
        "**A programme with no written requirements is not immature, it is a sophisticated noise generator** — so the whole score is capped at Domain 1 plus one."
      ],
      "formats": [
        "pdf",
        "docx"
      ],
      "deliverables": 23,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 5500,
      "listPriceFrom": 6900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 5500,
          "listPrice": 6900,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 27600,
          "listPrice": 34500,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cti-maturity-autoscoring",
      "title": "CTI Maturity Assessment — Auto-Scoring",
      "description": "The same forty-five statements as a spreadsheet that applies both ceiling rules and ranks your gaps for you — six tabs, 98 formulas, nothing hardcoded.",
      "url": "https://ciso.diy/templates/cti-maturity-autoscoring",
      "image": "https://ciso.diy/images/og/cti-maturity-autoscoring.png",
      "category": "threat-intelligence",
      "categoryLabel": "Threat Intelligence",
      "type": "product",
      "tags": [
        "threat intelligence",
        "CTI",
        "maturity assessment",
        "scoring",
        "spreadsheet",
        "gap analysis"
      ],
      "keyFacts": [
        "The size-based target profiles from the assessment, so you see the gap **against a realistic goal rather than against Level 4**."
      ],
      "formats": [
        "xlsx"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 3900,
      "listPriceFrom": 4900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 3900,
          "listPrice": 4900,
          "formats": [
            "xlsx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 19600,
          "listPrice": 24500,
          "formats": [
            "xlsx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "threat-intel-program-workbook",
      "title": "Build Your Own Threat Intelligence Program",
      "description": "The anchor. Ten sections taking a small team from no capability to a running CTI program in ninety days, on MISP and the open-source CIRCL stack — with an honest ceiling on what a DIY program can ever do.",
      "url": "https://ciso.diy/templates/threat-intel-program-workbook",
      "image": "https://ciso.diy/images/og/threat-intel-program-workbook.png",
      "category": "threat-intelligence",
      "categoryLabel": "Threat Intelligence",
      "type": "product",
      "tags": [
        "threat intelligence",
        "CTI",
        "MISP",
        "CIRCL",
        "feeds",
        "warninglists",
        "program build"
      ],
      "keyFacts": [
        "**Section 1 comes before installation, and that ordering is the whole argument.**",
        "**Section 10 states the honest ceiling** — no attribution, no finished intelligence, no off-hours cover.",
        "The companion Feed Selection Matrix applies the same rubric to 62 real sources."
      ],
      "formats": [
        "pdf",
        "docx"
      ],
      "deliverables": 21,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 10300,
      "listPriceFrom": 12900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 10300,
          "listPrice": 12900,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 51600,
          "listPrice": 64500,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "feed-selection-matrix",
      "title": "Feed Selection Matrix",
      "description": "Sixty-two open sources pre-scored on the six criteria that are the same for everyone — you supply the two that are not. Six tabs, 411 formulas, an eight-criterion rubric and a cut line at 18 of 40.",
      "url": "https://ciso.diy/templates/feed-selection-matrix",
      "image": "https://ciso.diy/images/og/feed-selection-matrix.png",
      "category": "threat-intelligence",
      "categoryLabel": "Threat Intelligence",
      "type": "product",
      "tags": [
        "threat intelligence",
        "CTI",
        "feeds",
        "OSINT",
        "feed selection",
        "MISP",
        "scoring"
      ],
      "keyFacts": [
        "“Should we take this feed?” answered with a rubric instead of an opinion, applied to **62 real, publicly available sources across twelve categories**.",
        "**Eight criteria, 1–5 each, 40 maximum, cut threshold at 18.** Six of the eight are properties of the source itself and identical for every buyer, so they come pre-scored.",
        "**A source earns direct detection use only at 25+ points *and* a low false-positive score.**",
        "The criterion people read backwards is called out explicitly: low FP risk is scored so that 5 is *good*."
      ],
      "formats": [
        "xlsx"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 4700,
      "listPriceFrom": 5900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 4700,
          "listPrice": 5900,
          "formats": [
            "xlsx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 23600,
          "listPrice": 29500,
          "formats": [
            "xlsx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cti-analyst-runbook-library",
      "title": "CTI Analyst Runbook Library",
      "description": "Eighteen procedures for the things that actually land in an analyst queue. One page each, each ending in a decision rather than a suggestion — with an escalation matrix and an execution log.",
      "url": "https://ciso.diy/templates/cti-analyst-runbook-library",
      "image": "https://ciso.diy/images/og/cti-analyst-runbook-library.png",
      "category": "threat-intelligence",
      "categoryLabel": "Threat Intelligence",
      "type": "product",
      "tags": [
        "threat intelligence",
        "CTI",
        "runbooks",
        "SOC",
        "analyst",
        "procedures",
        "escalation"
      ],
      "keyFacts": [
        "**Eighteen procedures for the things that actually land in an analyst queue on a Tuesday** — not a taxonomy of threat intelligence.",
        "**One page each, and each ends in a decision rather than a suggestion**, with an escalation matrix and an execution log.",
        "Covers intake (KEV entries, edge-device CVEs, the bulk PDF with forty indicators in it), exposure (infostealer credentials for your domain, leak-site mentions, lookalike domains) and data quality (false-positive investigation, decay audit, source onboarding)."
      ],
      "formats": [
        "pdf",
        "docx"
      ],
      "deliverables": 25,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 59600,
          "listPrice": 74500,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "threat-intel-policy-pack",
      "title": "Threat Intel Policy & Governance Pack",
      "description": "Six adoptable documents covering marking, handling, sharing, retention, membership, and machine access — with DORA Article 45, NIS2 Article 29 and ISO 27001 mappings. The governance a sharing programme is required to have and almost never does.",
      "url": "https://ciso.diy/templates/threat-intel-policy-pack",
      "image": "https://ciso.diy/images/og/threat-intel-policy-pack.png",
      "category": "threat-intelligence",
      "categoryLabel": "Threat Intelligence",
      "type": "product",
      "tags": [
        "threat intelligence",
        "CTI",
        "policy",
        "governance",
        "TLP",
        "PAP",
        "DORA",
        "NIS2",
        "ISO 27001",
        "AI governance"
      ],
      "keyFacts": [
        "Both **DORA Article 45 and NIS2 Article 29 make joining *and leaving* an information-sharing arrangement separately notifiable** to your competent authority.",
        "Information marking and handling covers TLP 2.0 and PAP — the two systems governing what you may do with intelligence you received, and what your machines may do with it.",
        "Mapped to DORA, NIS2 and ISO 27001 **so the documents can be cited in an audit rather than merely existing**."
      ],
      "formats": [
        "pdf",
        "docx"
      ],
      "deliverables": 18,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 79600,
          "listPrice": 99500,
          "formats": [
            "pdf",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "threat-intelligence-starter-kit",
      "title": "Threat Intelligence Starter Kit",
      "description": "All six CTI products — assessment, auto-scoring tool, the build workbook, the feed matrix, eighteen analyst runbooks and the policy pack. 39% off buying separately.",
      "url": "https://ciso.diy/templates/threat-intelligence-starter-kit",
      "image": "https://ciso.diy/images/og/threat-intelligence-starter-kit.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "threat intelligence",
        "CTI",
        "bundle",
        "MISP",
        "runbooks",
        "policy"
      ],
      "keyFacts": [
        "**Assess, build, govern** — the maturity assessment and its auto-scoring, the build workbook with 62 pre-scored sources, and six adoptable policy documents mapped to DORA, NIS2 and ISO 27001.",
        "Bought separately, you assemble that mapping yourself."
      ],
      "formats": [
        "pdf",
        "docx",
        "xlsx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 31900,
      "listPriceFrom": 39900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "pdf",
            "docx",
            "xlsx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 159600,
          "listPrice": 199500,
          "formats": [
            "pdf",
            "docx",
            "xlsx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "cti-maturity-assessment",
          "title": "CTI Program Maturity Assessment",
          "url": "https://ciso.diy/templates/cti-maturity-assessment"
        },
        {
          "slug": "cti-maturity-autoscoring",
          "title": "CTI Maturity Assessment — Auto-Scoring",
          "url": "https://ciso.diy/templates/cti-maturity-autoscoring"
        },
        {
          "slug": "threat-intel-program-workbook",
          "title": "Build Your Own Threat Intelligence Program",
          "url": "https://ciso.diy/templates/threat-intel-program-workbook"
        },
        {
          "slug": "feed-selection-matrix",
          "title": "Feed Selection Matrix",
          "url": "https://ciso.diy/templates/feed-selection-matrix"
        },
        {
          "slug": "cti-analyst-runbook-library",
          "title": "CTI Analyst Runbook Library",
          "url": "https://ciso.diy/templates/cti-analyst-runbook-library"
        },
        {
          "slug": "threat-intel-policy-pack",
          "title": "Threat Intel Policy & Governance Pack",
          "url": "https://ciso.diy/templates/threat-intel-policy-pack"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cti-essentials",
      "title": "CTI Essentials",
      "description": "The three products that get a program running — the build workbook, the maturity assessment, and the feed matrix. 30% off buying separately.",
      "url": "https://ciso.diy/templates/cti-essentials",
      "image": "https://ciso.diy/images/og/cti-essentials.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "threat intelligence",
        "CTI",
        "bundle",
        "MISP",
        "runbooks",
        "policy"
      ],
      "keyFacts": [
        "**Run the assessment first; it names the workbook sections that close each gap.**"
      ],
      "formats": [
        "pdf",
        "docx",
        "xlsx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 14300,
      "listPriceFrom": 17900,
      "onSale": true,
      "licences": [
        {
          "id": "single",
          "name": "Individual Practitioner",
          "price": 14300,
          "listPrice": 17900,
          "formats": [
            "pdf",
            "docx",
            "xlsx"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 71600,
          "listPrice": 89500,
          "formats": [
            "pdf",
            "docx",
            "xlsx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "threat-intel-program-workbook",
          "title": "Build Your Own Threat Intelligence Program",
          "url": "https://ciso.diy/templates/threat-intel-program-workbook"
        },
        {
          "slug": "cti-maturity-assessment",
          "title": "CTI Program Maturity Assessment",
          "url": "https://ciso.diy/templates/cti-maturity-assessment"
        },
        {
          "slug": "feed-selection-matrix",
          "title": "Feed Selection Matrix",
          "url": "https://ciso.diy/templates/feed-selection-matrix"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "range-foundations",
      "title": "R01 — Range Foundations",
      "description": "The anchor volume: hardware sizing with an honest cost model, Proxmox and Ludus as the substrate, three-zone isolation, and the four-tier reset architecture that decides whether your range gets used daily or becomes a museum. Includes the Range Build Planner.",
      "url": "https://ciso.diy/templates/range-foundations",
      "image": "https://ciso.diy/images/og/range-foundations.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "Proxmox",
        "Ludus",
        "isolation",
        "homelab",
        "detection engineering",
        "purple team"
      ],
      "keyFacts": [
        "**A cyber range is attack infrastructure.** It contains software with known, unpatched, pre-authentication remote code execution, and every architectural decision here is downstream of keeping that contained.",
        "**“A cyber range” is four different machines** depending on what you want out of it — exploit reproduction, attack path practice, detection validation, exercise delivery — and they size very differently.",
        "**The four-tier reset architecture decides whether your range gets used daily or becomes a museum.**",
        "Proxmox and Ludus as the substrate, three-zone isolation, and an honest hardware cost model. Includes the Range Build Planner."
      ],
      "formats": [
        "pdf",
        "xlsx"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "pdf",
            "xlsx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "adversary-environment-corpus",
      "title": "R02 — The Adversary Environment Corpus",
      "description": "What to put in the range and how to curate what you maintain — the GOAD family for Active Directory, Vulhub for per-CVE containers, cloud and IaC targets, organised into five handling tiers by reset cost and risk, with the maintenance treadmill made explicit.",
      "url": "https://ciso.diy/templates/adversary-environment-corpus",
      "image": "https://ciso.diy/images/og/adversary-environment-corpus.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "GOAD",
        "Active Directory",
        "Vulhub",
        "CVE",
        "corpus",
        "vulnerable infrastructure"
      ],
      "keyFacts": [
        "**The 180-day evaluation licence clock is the single largest recurring cost in the corpus, and the most common reason a range quietly dies.**",
        "Vulhub as the backbone, run as Tier 0 container work on one Linux VM you should be least precious about.",
        "**Tier E is optional and the rules are stricter:** its own VLAN with no route to any other zone, zero egress with no build-time window, no shared storage, and a Tier 2 reset every time."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "fresh-vulnerability-pipeline",
      "title": "R03 — The Fresh Vulnerability Pipeline",
      "description": "The flagship: from a KEV/NVD/EUVD identifier to a reproduced environment, a validated detection, and a remediation check — as a repeatable six-stage pipeline rather than a heroic weekend. Written for the post-2026 reality where four in five CVEs arrive un-enriched. Includes the CVE Repro Template.",
      "url": "https://ciso.diy/templates/fresh-vulnerability-pipeline",
      "image": "https://ciso.diy/images/og/fresh-vulnerability-pipeline.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "CVE",
        "KEV",
        "EPSS",
        "detection engineering",
        "Sigma",
        "vulnerability management",
        "MCP"
      ],
      "keyFacts": [
        "**The vulnerability data ecosystem changed structurally between 2024 and 2026** — and the CVE program came within a day of a funding lapse in April 2025."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "range-defend-side",
      "title": "R04 — The Defend Side",
      "description": "Instrument the range so a detection test actually means something. Log fidelity first, then Wazuh or Elastic with Velociraptor, Suricata and Zeek, driven by Atomic Red Team and Caldera, with detections written as portable Sigma and validated in CI against the corpus.",
      "url": "https://ciso.diy/templates/range-defend-side",
      "image": "https://ciso.diy/images/og/range-defend-side.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "Wazuh",
        "Elastic",
        "Sigma",
        "Atomic Red Team",
        "Caldera",
        "detection engineering",
        "purple team"
      ],
      "keyFacts": [
        "**Volumes 01 through 03 all ended at the same handoff: *and then you detect it*. This is where that happens.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 5,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "exercise-design-purple-team",
      "title": "R05 — Exercise Design & Purple Team Operations",
      "description": "The capstone: turn the validated stack into scored exercises. Time-to-detect and time-to-contain as the primary metrics, ATT&CK coverage mapping, evidence capture and after-action reporting — bridging the tabletop most teams already run into a live run against instrumented infrastructure.",
      "url": "https://ciso.diy/templates/exercise-design-purple-team",
      "image": "https://ciso.diy/images/og/exercise-design-purple-team.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "purple team",
        "tabletop",
        "ATT&CK",
        "exercise",
        "TTD",
        "after-action report"
      ],
      "keyFacts": [
        "The technical spine is an ordered ATT&CK path mapped to your corpus and emulation, **with the predicted detection outcome per step taken from R04’s coverage matrix — that prediction is what makes the result meaningful**.",
        "**The solo-operator collapse:** running this alone you are white cell, red and observer, the blue team is the R04 stack and its triage layer, and the exercise measures the controls rather than the humans."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 5,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "range-safety-pack",
      "title": "Range Safety & Authorization Pack",
      "description": "The governance layer that lets the range ship — nine fill-and-sign documents so a security leader can stand up a defensible posture in an afternoon rather than discovering the need for it during an incident. Word to edit, PDF to sign.",
      "url": "https://ciso.diy/templates/range-safety-pack",
      "image": "https://ciso.diy/images/og/range-safety-pack.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "governance",
        "policy",
        "attestation",
        "authorization",
        "rules of engagement",
        "isolation"
      ],
      "keyFacts": [
        "**The governance has to be as real as the tooling — and it has to exist *before* the range does**, not after something goes wrong.",
        "Nine fill-and-sign documents: five policies, two signable attestations, and the rest of the paper trail — **a defensible posture in an afternoon**.",
        "Includes the Defensive-Only Charter that states in writing what the range is and is not for, and an Isolation Attestation recording zones, VLAN IDs and the egress rules in force.",
        "Word to edit, PDF to sign."
      ],
      "formats": [
        "docx",
        "pdf"
      ],
      "deliverables": 15,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7100,
      "listPriceFrom": 8900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7100,
          "listPrice": 8900,
          "formats": [
            "docx",
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "range-build-planner",
      "title": "Range Build Planner",
      "description": "The live calculator that catches the wrong hardware call before you buy it — seven working tabs and 86 formulas covering purpose weighting, VM inventory with linked-clone math, host fit analysis, a three-year on-prem-vs-cloud cost model with payback, VLAN plan and reset-time log.",
      "url": "https://ciso.diy/templates/range-build-planner",
      "image": "https://ciso.diy/images/og/range-build-planner.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "hardware sizing",
        "cost model",
        "calculator",
        "Proxmox",
        "capacity planning"
      ],
      "keyFacts": [
        "**A GOAD-Light row of 4 GB × 5 VMs at 60 GB disk with a 25% clone delta computes to 20 GB effective RAM and 120 GB effective disk, not 300.**",
        "The sample build correctly flags vCores OVER — 22 needed against 16 available — with the overcommit caveat, while RAM and storage pass.",
        "**The 3-year cost model includes your own maintenance hours at your billing rate: the line everyone omits, and usually the largest.**",
        "Rank the four range purposes and it derives your dominant purpose, substrate bias and reset tier via live INDEX/MATCH."
      ],
      "formats": [
        "xlsx"
      ],
      "deliverables": 7,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 3900,
      "listPriceFrom": 4900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 3900,
          "listPrice": 4900,
          "formats": [
            "xlsx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "scenario-card-deck",
      "title": "Range Scenario Card Deck",
      "description": "Printable attack-and-defend scenario cards for running range exercises away from a screen — a ready deck of scenarios you can deal onto a table for a tabletop, a training session, or the warm-up before a live purple-team run.",
      "url": "https://ciso.diy/templates/scenario-card-deck",
      "image": "https://ciso.diy/images/og/scenario-card-deck.png",
      "category": "cyber-range",
      "categoryLabel": "Cyber Range",
      "type": "product",
      "tags": [
        "cyber range",
        "tabletop",
        "scenario cards",
        "exercise",
        "printable",
        "security awareness"
      ],
      "keyFacts": [
        "**The cheapest possible version of the exercise progression in R05** — no range, no instrumentation.",
        "The format that gets non-technical participants engaged in a security exercise for the first time."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 2300,
      "listPriceFrom": 2900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 2300,
          "listPrice": 2900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "complete-range-line",
      "title": "Complete Range Line",
      "description": "All five volumes plus both build tools and the Range Runbook Library — the whole facility, from isolation architecture to scored purple-team exercises. 34% off buying separately.",
      "url": "https://ciso.diy/templates/complete-range-line",
      "image": "https://ciso.diy/images/og/complete-range-line.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "cyber range",
        "bundle",
        "purple team",
        "detection engineering",
        "GOAD",
        "Sigma"
      ],
      "keyFacts": [
        "**Build order: R01 and the Planner first, then R02, then the Safety Pack, then R03 (give it the most time), then R04, R05 and the Runbook Library.**"
      ],
      "formats": [
        "pdf",
        "xlsx",
        "docx",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 43900,
      "listPriceFrom": 54900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 43900,
          "listPrice": 54900,
          "formats": [
            "pdf",
            "xlsx",
            "docx",
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "range-foundations",
          "title": "R01 — Range Foundations",
          "url": "https://ciso.diy/templates/range-foundations"
        },
        {
          "slug": "adversary-environment-corpus",
          "title": "R02 — The Adversary Environment Corpus",
          "url": "https://ciso.diy/templates/adversary-environment-corpus"
        },
        {
          "slug": "fresh-vulnerability-pipeline",
          "title": "R03 — The Fresh Vulnerability Pipeline",
          "url": "https://ciso.diy/templates/fresh-vulnerability-pipeline"
        },
        {
          "slug": "range-defend-side",
          "title": "R04 — The Defend Side",
          "url": "https://ciso.diy/templates/range-defend-side"
        },
        {
          "slug": "exercise-design-purple-team",
          "title": "R05 — Exercise Design & Purple Team Operations",
          "url": "https://ciso.diy/templates/exercise-design-purple-team"
        },
        {
          "slug": "range-safety-pack",
          "title": "Range Safety & Authorization Pack",
          "url": "https://ciso.diy/templates/range-safety-pack"
        },
        {
          "slug": "range-build-planner",
          "title": "Range Build Planner",
          "url": "https://ciso.diy/templates/range-build-planner"
        },
        {
          "slug": "range-runbook-library",
          "title": "Range Runbook Library",
          "url": "https://ciso.diy/templates/range-runbook-library"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "open-soc-architecture",
      "title": "Pillar 04 Companion — The Open SOC Reference Architecture",
      "description": "The open-source SOC diagram everyone shares has two commercial products on it. This is the corrected version — six planes, 24 components with verified licenses and named replacements, an AI analyst plane with a defensible autonomy ceiling, and three sized builds with honest hour counts.",
      "url": "https://ciso.diy/templates/open-soc-architecture",
      "image": "https://ciso.diy/images/og/open-soc-architecture.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "SOC",
        "AI-SOC",
        "pillar 04",
        "open source",
        "architecture",
        "Wazuh",
        "detection engineering",
        "vCISO",
        "MSSP"
      ],
      "keyFacts": [
        "**The license truth table is the section to read first.** All 24 components carry a license, a version and a currency note, verified with dates in August 2026.",
        "Entries that fail carry a named replacement: TheHive 5 is proprietary and drops to read-only without a StrangeBee license → DFIR-IRIS (LGPLv3). OTRS Community Edition lost security fixes on 1 January 2021 with eight days’ notice → Znuny or OTOBO.",
        "The conventional four-column layout hides the plane where the difficulty lives: **Pipeline, where 40–70% of raw volume is cut before it reaches paid storage**, does not appear on it at all."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 10,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "soc-in-a-box",
      "title": "Pillar 04 Companion — SOC in a Box",
      "description": "The Open SOC reference architecture landed on one machine you can hold — a coreboot NUC with the Management Engine disabled, Nitrokey as the root of trust, three disks mapped to three storage tiers, and a 14-test acceptance suite you run before pointing a single agent at it.",
      "url": "https://ciso.diy/templates/soc-in-a-box",
      "image": "https://ciso.diy/images/og/soc-in-a-box.png",
      "category": "program-pillars",
      "categoryLabel": "Security Program Pillars",
      "type": "product",
      "tags": [
        "SOC",
        "AI-SOC",
        "pillar 04",
        "hardware",
        "coreboot",
        "Nitrokey",
        "build guide",
        "self-hosted",
        "Wazuh"
      ],
      "keyFacts": [
        "**Three configurations — Watch, Work and Seed** — sized from a Tier 1 deployment under 100 endpoints through the first node of a multi-tenant practice, with CPU, memory, disk, retention and AI ceiling specified for each.",
        "Boot key: FIDO2 hmac-secret unlock of the LUKS2 volumes, protecting evidence at rest, with the availability tradeoff spelled out and three options to pick deliberately.",
        "Admin key: resident FIDO2 SSH plus git commit signing, so **every detection rule change carries a hardware-backed identity that survives an employee leaving**.",
        "**Tests 2, 3 and 14 are the ones people skip, and they are the three that cause the outages.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-08-31",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cyber-insurance-workbook",
      "title": "Cyber Insurance Workbook",
      "description": "Everything you need to prepare, apply for, and manage cyber insurance — 8 tabs, 167 live formulas, built for security teams who need to hold their own with brokers and underwriters.",
      "url": "https://ciso.diy/templates/cyber-insurance-workbook",
      "image": "https://ciso.diy/images/og/cyber-insurance-workbook.png",
      "category": "cyber-insurance",
      "categoryLabel": "Cyber Insurance",
      "type": "product",
      "tags": [
        "insurance",
        "cyber insurance",
        "risk",
        "compliance",
        "underwriting"
      ],
      "keyFacts": [
        "A control questionnaire of **35 questions across 12 categories** — MFA, endpoint, backups, email security, access, vulnerability management, IR, training, network, third party, data protection and logging.",
        "An evidence register of **20 pre-seeded items (EV-001–EV-020)** cross-referenced to the questionnaire.",
        "8 tabs and 167 live formulas, built for a security team managing insurance as an ongoing programme rather than a one-off application."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 6300,
      "listPriceFrom": 7900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 6300,
          "listPrice": 7900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "shadow-ai-inventory",
      "title": "Shadow AI Inventory & Risk Scoring Workbook",
      "description": "Discover, inventory, and score every unapproved AI tool in your environment — 10 tabs, 589 formulas, pre-seeded with 15 real-world shadow AI tools and a defensible 10-factor risk model.",
      "url": "https://ciso.diy/templates/shadow-ai-inventory",
      "image": "https://ciso.diy/images/og/shadow-ai-inventory.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "shadow AI",
        "AI governance",
        "risk scoring",
        "EU AI Act",
        "NIST AI RMF",
        "vCISO"
      ],
      "keyFacts": [
        "Pre-seeded with **15 real tools** — ChatGPT, Claude, Copilot, M365 Copilot, Gemini, Notion AI, Grammarly, Perplexity, Jasper, Otter.ai, Fireflies, Cursor, custom GPTs, Zapier AI, ElevenLabs — so you recognise your own environment immediately.",
        "A **10-factor weighted risk model summing to 100**: data sensitivity (25), training on data (15), account type (12), retention (10), SSO (8), access scope (8), user count (6), criticality (6), regulatory (6), agentic (4).",
        "A 5×4 heatmap of data sensitivity against risk tier, showing **where shadow AI concentrates** rather than just that it exists.",
        "Governance tier scored MATURE / DEVELOPING / AD-HOC / REACTIVE / AT RISK, with a live top-10 highest-risk tools list and recommended actions."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 10,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 24000,
      "listPriceFrom": 29999,
      "onSale": true,
      "licences": [
        {
          "id": "single-company",
          "name": "Organization License",
          "price": 24000,
          "listPrice": 29999,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "practitioner",
          "name": "vCISO / MSSP License",
          "price": 64000,
          "listPrice": 79999,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vciso-client-in-a-box",
      "title": "vCISO Client-in-a-Box",
      "description": "27 tabs, 1,565 formulas — a complete client management system for solo vCISOs and small teams. NIST CSF 2.0 assessments, risk registers, roadmaps, and a portfolio dashboard for 20 clients. Includes the 584-paragraph Practitioner User Guide.",
      "url": "https://ciso.diy/templates/vciso-client-in-a-box",
      "image": "https://ciso.diy/images/og/vciso-client-in-a-box.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "vCISO",
        "client management",
        "NIST CSF 2.0",
        "MSSP",
        "white-label",
        "portfolio dashboard"
      ],
      "keyFacts": [
        "Run a professional vCISO practice **without paying $10K–$40K a month** for platforms like Cynomi, GetCybr or Drata.",
        "**One data flow end to end:** score a client’s 22 NIST CSF 2.0 categories → maturity rolls up to the portfolio dashboard → hours roll up to utilisation → retainer rolls into MRR.",
        "All 22 NIST CSF 2.0 categories crosswalked to SOC 2 TSC, ISO 27001:2022 Annex A, HIPAA Security Rule (164.xxx), PCI DSS 4.0.1 and CIS Controls v8.",
        "Client register pre-seeded with 6 realistic examples across healthcare, SaaS, legal, manufacturing, education and real estate, so the pattern is visible immediately."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 27,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 40000,
      "listPriceFrom": 49999,
      "onSale": true,
      "licences": [
        {
          "id": "single-practitioner",
          "name": "Individual Practitioner",
          "price": 40000,
          "listPrice": 49999,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "team",
          "name": "Team License",
          "price": 104000,
          "listPrice": 129999,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "unlimited",
          "name": "vCISO / MSSP License",
          "price": 200000,
          "listPrice": 249999,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ma-cyber-diligence",
      "title": "M&A Cyber Diligence Workbook",
      "description": "The active cyber diligence workbook for M&A deal teams — auto-generated deal recommendations, cost modeling, and deal-term mechanism mapping across a 10-day sprint framework.",
      "url": "https://ciso.diy/templates/ma-cyber-diligence",
      "image": "https://ciso.diy/images/og/ma-cyber-diligence.png",
      "category": "due-diligence",
      "categoryLabel": "Due Diligence",
      "type": "product",
      "tags": [
        "M&A",
        "cyber diligence",
        "deal team",
        "mergers acquisitions",
        "PE",
        "due diligence"
      ],
      "keyFacts": [
        "Opens with the acquirer’s psychology directly: **the $350M Verizon–Yahoo price cut, 73% who would walk from an undisclosed breach, 40% who find issues post-close, and fewer than 10% of deals that include cyber diligence today.**",
        "A 10-day sprint plan, day by day: kickoff and DRL, OSINT, document review, target interview, control assessment, vendor and regulatory, findings consolidation, remediation cost, synthesis, delivery.",
        "Findings register with 13 columns per finding, including **deal impact rating, recommended deal-term mechanism and estimated remediation cost**.",
        "15 independent OSINT validation checks: breach databases, dark web, Shodan/Censys, SSL Labs, DMARC, GitHub secrets, exposed cloud storage, SEC filings and more."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 13,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "single-deal",
          "name": "Individual Practitioner",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "practitioner",
          "name": "Organization License",
          "price": 47900,
          "listPrice": 59900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "portfolio",
          "name": "vCISO / MSSP License",
          "price": 119900,
          "listPrice": 149900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vc-diligence",
      "title": "VC Cyber Diligence Workbook",
      "description": "Stage-aware VC diligence for Pre-Seed through Series B+ — founder assessment, investment thesis scoring, pipeline tracking, cap table analysis, and IC memo output. 16 tabs built around the question: what would have to go right for 10x?",
      "url": "https://ciso.diy/templates/vc-diligence",
      "image": "https://ciso.diy/images/og/vc-diligence.png",
      "category": "due-diligence",
      "categoryLabel": "Due Diligence",
      "type": "product",
      "tags": [
        "VC",
        "venture capital",
        "founder assessment",
        "investment thesis",
        "due diligence",
        "cap table"
      ],
      "keyFacts": [
        "**M&A asks “what risks am I buying?” VC asks “what would have to go right for 10x?”** That mindset shift drives the entire tool.",
        "The investment thesis comes first: before any deal evaluation you define the fund’s screening criteria across 40+ fields.",
        "**Founder assessment is the flagship tab** — 30+ dimensions across background, team dynamics, execution, vision, character and coachability, with a flag column running None / Monitor / Concern / Dealbreaker.",
        "An auto-calculated overall founder score with a five-tier interpretation from HIGH CONVICTION to PASS."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 16,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "single-user",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "fund",
          "name": "Organization License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "multi-fund",
          "name": "vCISO / MSSP License",
          "price": 79900,
          "listPrice": 99900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "tabletop-exercise-pack",
      "title": "Tabletop Exercise Pack",
      "description": "The IR exercise programme management system for a security team — 10 research-calibrated scenarios, 13 tabs of maturity scorecard, gap tracker and executive dashboard, and a 687-paragraph facilitator guide. For maturing your own IR practice over time; if you need a single ninety-minute session for a room of executives, the Executive Tabletop Exercise Kit is that.",
      "url": "https://ciso.diy/templates/tabletop-exercise-pack",
      "image": "https://ciso.diy/images/og/tabletop-exercise-pack.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "tabletop exercise",
        "incident response",
        "IR scenarios",
        "TTX",
        "MSSP",
        "board reporting",
        "facilitator guide"
      ],
      "keyFacts": [
        "**10 scenarios, each researched and calibrated for realistic escalation** — S1 ransomware with exfiltration runs a $4.2M→$6.8M ransom escalation, backup corruption discovered at hour 24, and a journalist tip-off.",
        "S2 BEC and wire fraud: a $847K unauthorised wire, attacker with IMAP access for three weeks, and two more fraudulent wires already in the queue.",
        "A 13-tab programme management system with a maturity scorecard and gap tracker — **for a security team maturing its own IR practice over time**.",
        "If you need a single ninety-minute session for a room of executives, the Executive Tabletop Exercise Kit is that instead."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 13,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "single-user",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "team",
          "name": "Team License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 79900,
          "listPrice": 99900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ciso-budget-workbook",
      "title": "2026 CISO Budget Workbook",
      "description": "Input five values on the Assumptions tab — revenue, IT budget, headcount, industry, maturity — and the entire workbook calculates itself. Three budget-sizing methods, 50+ line items, CRQ for boards, and board talking points with your actual numbers.",
      "url": "https://ciso.diy/templates/ciso-budget-workbook",
      "image": "https://ciso.diy/images/og/ciso-budget-workbook.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "CISO budget",
        "security budget",
        "financial model",
        "board presentation",
        "cyber risk quantification",
        "budget planning",
        "2026"
      ],
      "keyFacts": [
        "Three independent benchmarks side by side: **IT × 12% (Gartner), revenue × 0.75% (IANS 2026), and $2,700 per employee (Deloitte 2026)**.",
        "**Converts “I need $1.2M for security” into “our baseline expected annual loss is $1.4M; this $1.2M reduces it to $309K — net benefit $1.1M a year, payback in 13 months.” Boards fund the second statement.**",
        "A board talking-points tab of 10 pre-written sentences that pull your actual numbers into complete spoken sentences via Excel TEXT() formulas."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 16,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 159900,
          "listPrice": 199900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ransomware-readiness",
      "title": "2026 Ransomware Readiness Workbook",
      "description": "18 tabs of operational crisis preparedness — 80-control readiness assessment, 8 pre-built IR playbook cards with DO NOT lists, ransom decision framework with OFAC gate, and regulatory matrix covering all 2026 mandates.",
      "url": "https://ciso.diy/templates/ransomware-readiness",
      "image": "https://ciso.diy/images/og/ransomware-readiness.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "ransomware",
        "incident response",
        "IR playbook",
        "ransom decision",
        "OFAC",
        "readiness",
        "2026",
        "NIST IR"
      ],
      "keyFacts": [
        "**The thing you prepare so you have something to open at 2am when the Slack messages start.**",
        "**A readiness program built on 2023 assumptions has blind spots in all five of the shifts since.**",
        "8 pre-built IR playbook cards for specific incident moments — first 15 minutes, first hour, containment, scope, ransom demand received, external communications, restoration, after-action.",
        "**Card 1: declare the incident on suspicion — do not wait for certainty.**"
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 18,
      "version": "1.0",
      "updated": "2026-04-17",
      "priceCurrency": "USD",
      "priceFrom": 19900,
      "listPriceFrom": 24900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 19900,
          "listPrice": 24900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 47900,
          "listPrice": 59900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 119900,
          "listPrice": 149900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "soc2-readiness",
      "title": "SOC 2 Readiness Accelerator",
      "description": "20-tab SOC 2 program covering assessment through Type 2 audit — 100+ controls, 35 required policies, 7 pre-populated operational logs, and an executive dashboard with three auto-calculated readiness metrics.",
      "url": "https://ciso.diy/templates/soc2-readiness",
      "image": "https://ciso.diy/images/og/soc2-readiness.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "SOC 2",
        "compliance",
        "Type 2",
        "AICPA",
        "TSC",
        "evidence collection",
        "audit readiness"
      ],
      "keyFacts": [
        "**SOC 2 has three distinct phases — readiness assessment, observation period, audit — and this workbook serves all three**, as a point-in-time assessment and an ongoing 3–12 month tracker.",
        "100+ controls across CC1–CC9, each with its CC reference, family, description, evidence type, score and owner.",
        "Plus 34 optional TSC controls across Availability, Confidentiality, Processing Integrity and Privacy."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 20,
      "version": "1.0",
      "updated": "2026-04-18",
      "priceCurrency": "USD",
      "priceFrom": 31900,
      "listPriceFrom": 39900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 79900,
          "listPrice": 99900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 199900,
          "listPrice": 249900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "hipaa-readiness-accelerator",
      "title": "HIPAA Readiness Accelerator",
      "description": "23-tab HIPAA compliance workbook built for the 2026 Final Rule — covers all current safeguards plus the 12 new mandatory requirements, IoMT risk, BAA management, breach notification matrix, and a dedicated 2026 gap analysis tab.",
      "url": "https://ciso.diy/templates/hipaa-readiness-accelerator",
      "image": "https://ciso.diy/images/og/hipaa-readiness-accelerator.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "HIPAA",
        "compliance",
        "2026 Final Rule",
        "healthcare",
        "PHI",
        "BAA",
        "OCR",
        "IoMT"
      ],
      "keyFacts": [
        "The 2026 HIPAA Security Rule Final Rule is the biggest HIPAA update since 2013: **it eliminates “addressable” entirely and adds 12 new mandatory requirements**, mapped here against current state with auto-scored status.",
        "**Healthcare breach average 0M** (IBM 2026, up from .42M).",
        "**31% of all ransomware attacks hit healthcare; 96% involve data exfiltration; 93% of US healthcare organisations experienced at least one attack.**",
        "2025 OCR fines exceeded .6M, with individual fines up to M."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 23,
      "version": "1.0",
      "updated": "2026-04-18",
      "priceCurrency": "USD",
      "priceFrom": 39900,
      "listPriceFrom": 49900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 39900,
          "listPrice": 49900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 103900,
          "listPrice": 129900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 183900,
          "listPrice": 229900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "enterprise-questionnaire-kit",
      "title": "Enterprise Questionnaire Response Kit",
      "description": "14-tab operational efficiency toolkit for responding to security questionnaires — 400+ pre-written answers mapped to CAIQ v4, SIG, VSA, and HECVAT, AI governance supplements, deal pipeline tracking, and a trust portal content planner.",
      "url": "https://ciso.diy/templates/enterprise-questionnaire-kit",
      "image": "https://ciso.diy/images/og/enterprise-questionnaire-kit.png",
      "category": "vendor-risk",
      "categoryLabel": "Vendor Risk",
      "type": "product",
      "tags": [
        "security questionnaire",
        "CAIQ",
        "SIG",
        "VSA",
        "HECVAT",
        "vendor risk",
        "trust portal",
        "AI governance"
      ],
      "keyFacts": [
        "**Manual completion at 5–20 hours per week is a direct tax on your sales cycle**, and a mid-stage B2B SaaS company might receive 50–200 questionnaires a year.",
        "The 2026 landscape mapped: **CAIQ v4 (261 questions, 17 domains, CCM v4 mapped, free)** against **SIG Core (~850 questions, 18 risk domains, 35+ regulatory frameworks, licensed at $6,500+/year)**."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 14,
      "version": "1.0",
      "updated": "2026-04-18",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 159900,
          "listPrice": 199900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "iso27001-readiness",
      "title": "ISO 27001:2022 Readiness Accelerator",
      "description": "20-tab ISMS implementation workbook for ISO 27001:2022 — all 93 Annex A controls across 4 themes, 11 new 2022 controls, Clauses 4–10 ISMS framework, transition gap analysis from 2013, and policy library.",
      "url": "https://ciso.diy/templates/iso27001-readiness",
      "image": "https://ciso.diy/images/og/iso27001-readiness.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "ISO 27001",
        "ISO 27001:2022",
        "ISMS",
        "compliance",
        "Annex A",
        "certification",
        "information security",
        "gap analysis",
        "2022 transition"
      ],
      "keyFacts": [
        "**Organisations still operating on ISO 27001:2013 are out of compliance**, and new certifications must use 2022 with the 2024 environmental amendment.",
        "Built specifically for 2022 — **not a patched 2013 template**.",
        "**Clause 6.3 is new:** changes must be planned, documented, and evidence retained.",
        "Carries the five new control attributes introduced for taxonomy — control type, CIA properties, NIST CSF concepts, operational capabilities and security domains."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 20,
      "version": "1.0",
      "updated": "2026-04-18",
      "priceCurrency": "USD",
      "priceFrom": 35900,
      "listPriceFrom": 44900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 35900,
          "listPrice": 44900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 87900,
          "listPrice": 109900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 215900,
          "listPrice": 269900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "pci-dss-readiness",
      "title": "PCI DSS v4.0.1 Readiness Accelerator",
      "description": "12-tab PCI DSS v4.0.1 workbook — all 12 requirement domains, SAQ type selector, 51 future-dated requirements tracker, e-commerce script security controls, and QSA-ready evidence register. Built for the March 2025 mandatory transition.",
      "url": "https://ciso.diy/templates/pci-dss-readiness",
      "image": "https://ciso.diy/images/og/pci-dss-readiness.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "PCI DSS",
        "PCI DSS 4.0.1",
        "compliance",
        "payment card",
        "SAQ",
        "QSA",
        "e-commerce",
        "cardholder data"
      ],
      "keyFacts": [
        "**All PCI DSS v4.0 requirements became fully mandatory on 31 March 2025.**",
        "A focused view of the **51 future-dated requirements** that became mandatory in March 2025, each with a plain-English “what it requires” and an effort estimate.",
        "All 12 domains with 160+ control items, a future-dated flag per requirement, and formula-driven summary counts.",
        "A 12-question SAQ type selector with a formula-driven recommendation."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 12,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 31900,
      "listPriceFrom": 39900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 79900,
          "listPrice": 99900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 199900,
          "listPrice": 249900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cmmc-readiness",
      "title": "CMMC 2.0 Readiness Accelerator",
      "description": "12-tab CMMC 2.0 workbook — all 110 NIST 800-171 practices with DoD SPRS weights, auto-calculated SPRS score, Level determination decision tree, SSP builder, POA&M tracker, and C3PAO readiness checklist. Built for the November 2026 Phase 2 deadline.",
      "url": "https://ciso.diy/templates/cmmc-readiness",
      "image": "https://ciso.diy/images/og/cmmc-readiness.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "CMMC",
        "CMMC 2.0",
        "DoD",
        "NIST 800-171",
        "SPRS",
        "CUI",
        "defense contractors",
        "compliance"
      ],
      "keyFacts": [
        "**Phase 2 begins 10 November 2026** — third-party CMMC Level 2 certification for most contractors handling CUI.",
        "Phase 1 (10 November 2025) already requires Level 1 and Level 2 self-assessments as pre-award conditions for new contracts.",
        "**The most common early mistake: treating FCI-only contracts as requiring CMMC Level 2.** A 7-question decision tree produces the Level 1 / L2-Self / L2-C3PAO / L3 recommendation.",
        "All 110 NIST 800-171 practices across 14 families, each carrying its DoD Assessment Methodology SPRS weight (48 × 5pt, 15 × 3pt, 47 × 1pt)."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 12,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 35900,
      "listPriceFrom": 44900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 35900,
          "listPrice": 44900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 87900,
          "listPrice": 109900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 215900,
          "listPrice": 269900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "dora-nis2-readiness",
      "title": "DORA + NIS2 EU Compliance Workbook",
      "description": "14-tab EU regulatory compliance workbook covering all 5 DORA pillars, NIS2 Article 21 measures, dual framework applicability decision tree, penalty calculator (2% DORA / €10M NIS2), and cross-framework mapping across 17 control domains.",
      "url": "https://ciso.diy/templates/dora-nis2-readiness",
      "image": "https://ciso.diy/images/og/dora-nis2-readiness.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "DORA",
        "NIS2",
        "EU compliance",
        "financial entities",
        "ICT risk",
        "incident reporting",
        "resilience testing",
        "European Union"
      ],
      "keyFacts": [
        "**DORA entered into force 17 January 2025 with no transitional period** — as the ESAs stated on 4 December 2024, DORA does not provide for one.",
        "A dual decision tree of 32 questions: 14 DORA entity types, 17 NIS2 sectors and the size thresholds.",
        "**Correctly handles lex specialis:** DORA entities receive a “DORA takes precedence” NIS2 output.",
        "DORA incident reporting as the 4-hour / 72-hour / 1-month three-stage timeline, with 7 classification criteria and a 15-point readiness tracker."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 14,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 35900,
      "listPriceFrom": 44900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 35900,
          "listPrice": 44900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 87900,
          "listPrice": 109900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 215900,
          "listPrice": 269900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "board-reporting",
      "title": "CISO Board Reporting Pack",
      "description": "Everything you need to brief the board on cybersecurity — editable Excel metrics workbook, 25-slide PowerPoint deck template, and a user guide covering what boards actually want to hear and how to answer the questions you will get.",
      "url": "https://ciso.diy/templates/board-reporting",
      "image": "https://ciso.diy/images/og/board-reporting.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "board reporting",
        "CISO",
        "board presentation",
        "governance",
        "metrics",
        "PowerPoint",
        "executive communication"
      ],
      "keyFacts": [
        "**Most board security presentations fail for the same reason: they lead with technical controls and hope the board connects the dots to business risk.**",
        "**Boards want to know three things** — are we better than last year, how do we compare to our peers, and what are we doing about the biggest threats. The pack is built around those three questions.",
        "An Excel metrics workbook that auto-populates board-ready KPIs from your programme data — risk posture score, control maturity trend, incident metrics, compliance status, budget utilisation — with year-over-year comparison.",
        "Plus a 25-slide deck template and a guide to the questions you will actually get."
      ],
      "formats": [
        "xlsx",
        "pptx",
        "docx"
      ],
      "deliverables": 25,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "xlsx",
            "pptx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "xlsx",
            "pptx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 159900,
          "listPrice": 199900,
          "formats": [
            "xlsx",
            "pptx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "nist-csf-assessment",
      "title": "NIST CSF 2.0 Self-Assessment Workbook",
      "description": "14-tab NIST CSF 2.0 workbook — all 106 Subcategories with verbatim NIST.CSWP.29 outcome statements, Current/Target tier dropdowns, Organizational Profile Generator, heatmap, gap analysis pre-seeded with 12 high-gap 2026 scenarios, and crosswalks to SP 800-53r5, SP 800-171r3, CIS Controls v8.1, and ISO 27001:2022.",
      "url": "https://ciso.diy/templates/nist-csf-assessment",
      "image": "https://ciso.diy/images/og/nist-csf-assessment.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "NIST CSF",
        "NIST CSF 2.0",
        "self-assessment",
        "cybersecurity framework",
        "gap analysis",
        "heatmap",
        "Organizational Profile"
      ],
      "keyFacts": [
        "Built around the **26 February 2024 final publication of NIST CSF 2.0 (NIST.CSWP.29)**.",
        "**All 106 Subcategories with verbatim outcome statements, not paraphrases** — plus a nested-IF gap calculation that works across all Excel versions.",
        "Includes the Organizational Profile Generator — the new-in-2.0 concept most vendors fail to implement well."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 14,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 79900,
          "listPrice": 99900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "gdpr-dpia-workbook",
      "title": "GDPR & DPIA Compliance Workbook",
      "description": "20-tab GDPR compliance workbook — Controller ROPA, Processor ROPA, DSR log with 30-day SLA tracking, 72-hour breach deadline calculator, TIA template, DPF certification tracker, and DPIA template with WP29 9-factor trigger test. Updated for April 2026 research baseline.",
      "url": "https://ciso.diy/templates/gdpr-dpia-workbook",
      "image": "https://ciso.diy/images/og/gdpr-dpia-workbook.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "GDPR",
        "DPIA",
        "data protection",
        "EU privacy",
        "ROPA",
        "data transfers",
        "DPF",
        "TIA",
        "privacy"
      ],
      "keyFacts": [
        "Controller and Processor ROPAs **pre-seeded with 13 vendor DPAs** across cloud infrastructure, analytics, email, CRM, support and AI/LLM.",
        "Transfer register and TIA template following **post-Schrems II methodology and EDPB Recommendations 01/2020**, updated for the post-Latombe DPF reality.",
        "A WP29-compliant 9-factor necessity test with risk matrix and mitigations register.",
        "Enforcement reference covers the **Meta €1.2B, Uber €290M and LinkedIn €310M** precedents."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 20,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 35900,
      "listPriceFrom": 44900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 35900,
          "listPrice": 44900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 87900,
          "listPrice": 109900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 215900,
          "listPrice": 269900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "us-privacy-program",
      "title": "2026 US Privacy Program Workbook",
      "description": "17-tab US state privacy compliance workbook covering the 20-state wave — CCPA/CPRA, MODPA, VCDPA, CPA, and 16 more — with auto-generated obligation matrix, DSR tracker, consent management log, ADMT register, and enforcement reference.",
      "url": "https://ciso.diy/templates/us-privacy-program",
      "image": "https://ciso.diy/images/og/us-privacy-program.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "US privacy",
        "CCPA",
        "CPRA",
        "state privacy law",
        "MODPA",
        "DSR",
        "privacy program",
        "2026"
      ],
      "keyFacts": [
        "A 20-state wave table mapping each state’s effective date, thresholds, opt-out mechanisms and unique requirements.",
        "**DSR log with state-specific response windows enforced** — 45 days California, Virginia and Colorado, 60 days Maryland — with overdue conditional formatting per applicable deadline.",
        "Carries an ADMT register pre-seeded with the common scenarios: hiring screening, credit scoring, insurance underwriting, content personalisation."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 17,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 159900,
          "listPrice": 199900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ccpa-audit-risk-assessment-kit",
      "title": "CCPA Cybersecurity Audit & Privacy Risk Assessment Kit",
      "description": "The assessment kit and audit workplan California actually asks for — applicability calculator, per-activity risk assessment template and register, ADMT addendum, the 18-component audit workplan with auditor-independence checklist, report skeleton, and the §7124 certification cover. Assessments for existing processing are due 31 December 2027.",
      "url": "https://ciso.diy/templates/ccpa-audit-risk-assessment-kit",
      "image": "https://ciso.diy/images/og/ccpa-audit-risk-assessment-kit.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "CCPA",
        "CPPA",
        "California privacy",
        "cybersecurity audit",
        "privacy risk assessment",
        "ADMT",
        "11 CCR",
        "vCISO"
      ],
      "keyFacts": [
        "California is the first US state to require a cybersecurity audit and documented privacy risk assessments **by regulation rather than by contract**. Assessments for processing already under way are due **31 December 2027**; first certifications and submissions **1 April 2028**.",
        "All **18 components** §7123(b) enumerates, with readiness scoring and the twelve-point auditor-independence checklist from §7122.",
        "ADMT ships **inside** the kit rather than as an add-on: it is one of the six §7150(b) triggers, and an assessment that stops short of it is incomplete.",
        "The crosswalk maps the 18 components to NIST CSF 2.0, ISO 27001:2022 and SOC 2 — including **what a SOC 2 typically does not cover** — so you reuse evidence you already hold."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 10,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 39900,
          "listPrice": 49900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "circia-reporting-readiness",
      "title": "CIRCIA 72/24 Reporting Readiness Pack",
      "description": "Know in ten minutes whether CIRCIA covers you, decide in one call whether an incident is reportable, and have the report drafted inside the first day — the two-gate covered-entity worksheet, the four-prong decision tree, the 72/24 clock runbook, and a report pre-fill with a JSON Schema twin for your SOAR. Built on the NPRM, with a free update when the final rule publishes.",
      "url": "https://ciso.diy/templates/circia-reporting-readiness",
      "image": "https://ciso.diy/images/og/circia-reporting-readiness.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "CIRCIA",
        "CISA",
        "incident reporting",
        "72-hour",
        "ransomware payment",
        "critical infrastructure",
        "6 CFR 226",
        "vCISO"
      ],
      "keyFacts": [
        "CISA estimates roughly **300,000 covered entities** across the 16 sectors, and most do not think of themselves as critical infrastructure — water utilities, clinics, food and agriculture, regional transport, mid-size manufacturers and their MSPs.",
        "The hard part is not the report. It is knowing whether you owe one **at 2 a.m. while the incident is still running** — a two-gate covered-entity test, then four prongs and the exclusions.",
        "**72 hours** for a substantial incident, **24 hours** for a ransom payment, with a report pre-fill so Section A is complete before anything happens.",
        "Built on the NPRM and honest about it: everything still open is marked “verify final” rather than presented as settled, and **the updated edition is free when the final rule publishes**."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cra-reporting-clock",
      "title": "CRA 24-Hour Reporting Clock",
      "description": "The clock starts 11 September 2026. The runbook for the 24 hours after you learn a vulnerability in your product is being exploited — the actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a CVD policy you can publish as-is.",
      "url": "https://ciso.diy/templates/cra-reporting-clock",
      "image": "https://ciso.diy/images/og/cra-reporting-clock.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "CRA",
        "Cyber Resilience Act",
        "EU",
        "Article 14",
        "vulnerability disclosure",
        "ENISA",
        "PSIRT",
        "incident reporting"
      ],
      "keyFacts": [
        "**The clock starts 11 September 2026.** 24 hours to an early warning, 72 hours to full notification, and a final report **14 days after a fix is available**.",
        "That last clock is the most misread sentence in Article 14: it does **not** run from awareness. A vulnerability you cannot fix for six months does not start its 14-day clock for six months.",
        "The CRA trigger is **product** security, not operational — a US SaaS or IoT vendor with EU customers is squarely in scope and usually has no process for it at all.",
        "The runbook opens with pre-flight, because the platform work happens **before** the deadline: register submitters during ENISA’s test period and determine your coordinator CSIRT."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 7,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ciso-90-day-onboarding",
      "title": "CISO 90-Day Onboarding Workbook",
      "description": "The 12-tab assessment workbook for a CISO joining a company — stakeholder mapping, a deep program gap assessment against the frameworks that organization cares about, quick-win tracker, board briefing builder, and the 30/60/90-day milestone framework. For the employed CISO who needs the analysis in depth; if you are arriving fractionally, on an interim basis, or into a seat nobody has held before, start with The First 100 Days Kit.",
      "url": "https://ciso.diy/templates/ciso-90-day-onboarding",
      "image": "https://ciso.diy/images/og/ciso-90-day-onboarding.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "CISO onboarding",
        "new CISO",
        "90-day plan",
        "vCISO",
        "stakeholder mapping",
        "program assessment",
        "board reporting"
      ],
      "keyFacts": [
        "Most new CISOs spend their first 90 days in reactive mode — firefighting, attending every meeting, and producing a board deck that reflects no real analysis.",
        "**The 5 questions every new CISO should answer in the first 30 days before making any commitments.**",
        "A structured program gap analysis against the frameworks the organisation actually cares about, plus risk register initialisation and quick-win identification.",
        "If you are arriving fractionally, on an interim basis, or into a seat nobody has held before, **The First 100 Days Kit is the better starting point** — this is the depth tool for a CISO joining a company."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": 12,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 159900,
          "listPrice": 199900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ir-runbook-library",
      "title": "Incident Response Runbook Library",
      "description": "18 runbooks × 3 formats (54 files) — complete IR runbook library covering every major 2026 threat scenario, from ransomware multi-extortion to vishing to Magecart. ZIP delivery with Word, PDF, and Markdown versions of every runbook.",
      "url": "https://ciso.diy/templates/ir-runbook-library",
      "image": "https://ciso.diy/images/og/ir-runbook-library.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "incident response",
        "runbook",
        "IR playbook",
        "ransomware",
        "BEC",
        "account takeover",
        "NIST 800-61",
        "vCISO"
      ],
      "keyFacts": [
        "**eSentire’s 2026 Cyberthreat Landscape Report found a 389% year-over-year increase in identity-based account compromise.** Most of these runbooks lead with identity and access context rather than malware detection.",
        "18 runbooks × 3 formats = 54 files, plus a catalog index with usage tiers and a 26-page user guide.",
        "Each runbook carries 6 role definitions, a 4-tier severity matrix, 8–12 indicators of compromise, 5 NIST SP 800-61 phase checklists totalling 50–70 action items, and 3–4 communication templates."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 18,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "single-user",
          "name": "Individual Practitioner",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "team",
          "name": "Team License",
          "price": 39900,
          "listPrice": 49900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 103900,
          "listPrice": 129900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cyber-insurance-checklist",
      "title": "Cyber Insurance Readiness Checklist",
      "description": "A concise checklist covering the controls underwriters check before quoting — MFA, backups, endpoint, email security, and IR — with a quick self-scoring mechanism to spot coverage red flags before you talk to a broker.",
      "url": "https://ciso.diy/templates/cyber-insurance-checklist",
      "image": "https://ciso.diy/images/og/cyber-insurance-checklist.png",
      "category": "cyber-insurance",
      "categoryLabel": "Cyber Insurance",
      "type": "product",
      "tags": [
        "cyber insurance",
        "checklist",
        "underwriting",
        "readiness",
        "PDF"
      ],
      "keyFacts": [
        "The **15 controls underwriters consistently screen for**, with Yes/No/Partial scoring and a Red Flag column marking answers likely to trigger exclusions or premium increases.",
        "**Best used 4–6 weeks before starting an application** — early enough that a red flag is still fixable."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "soc2-readiness-checklist",
      "title": "SOC 2 Readiness Checklist (Type I & II)",
      "description": "The key controls, evidence items, and policy gaps auditors check at every SOC 2 engagement — organized by Trust Service Criteria with a pre-audit readiness rating.",
      "url": "https://ciso.diy/templates/soc2-readiness-checklist",
      "image": "https://ciso.diy/images/og/soc2-readiness-checklist.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "SOC 2",
        "compliance",
        "checklist",
        "Type I",
        "Type II",
        "audit readiness",
        "PDF"
      ],
      "keyFacts": [
        "The controls, evidence artifacts and policy items **auditors consistently focus on across CC1–CC9**, with a Ready / Needs Work / Gap rating per line.",
        "A pre-audit checklist for Type I or Type II — best used before you commit to an observation window."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "hipaa-compliance-checklist",
      "title": "HIPAA Compliance Checklist 2026",
      "description": "Updated for the 2026 Security Rule Final Rule — covers all 12 new mandatory requirements plus the core Administrative, Physical, and Technical safeguards in a single actionable checklist.",
      "url": "https://ciso.diy/templates/hipaa-compliance-checklist",
      "image": "https://ciso.diy/images/og/hipaa-compliance-checklist.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "HIPAA",
        "compliance",
        "checklist",
        "2026 Final Rule",
        "healthcare",
        "PDF"
      ],
      "keyFacts": [
        "All three safeguard categories — Administrative, Physical, Technical — plus the 2026 additions.",
        "Carries a **priority flag for the items with the tightest OCR enforcement history**, so remediation starts where the fines actually land."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ransomware-prep-checklist",
      "title": "Ransomware Preparation Checklist",
      "description": "The pre-incident checklist for ransomware preparedness — backup validation, identity hardening, IR contacts, communication templates, and the ransom decision questions to answer before an attack hits.",
      "url": "https://ciso.diy/templates/ransomware-prep-checklist",
      "image": "https://ciso.diy/images/og/ransomware-prep-checklist.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "ransomware",
        "checklist",
        "incident response",
        "preparation",
        "PDF"
      ],
      "keyFacts": [
        "The **five areas that determine whether an organisation recovers in days or weeks**: backup resilience (3-2-1-1-0 validation), identity hardening, detection capability, IR plan readiness and communication pre-work."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "college-cyber-privacy-guide",
      "title": "College Cyber Privacy Guide",
      "description": "A practical privacy and security guide for college students — accounts, devices, campus Wi-Fi, social media, AI tools, and identity protection covered in plain language.",
      "url": "https://ciso.diy/templates/college-cyber-privacy-guide",
      "image": "https://ciso.diy/images/og/college-cyber-privacy-guide.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "college",
        "privacy",
        "students",
        "personal security",
        "PDF"
      ],
      "keyFacts": [
        "The privacy and security topics every college student actually encounters: accounts and devices, **campus and public Wi-Fi**, social media settings, AI tools (what gets stored, what gets trained), financial accounts, and what to do if an account is compromised.",
        "**Written for students, not security professionals. No jargon, no acronyms.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1600,
      "listPriceFrom": 1999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1600,
          "listPrice": 1999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "pre-teen-cyber-checklist",
      "title": "Pre-Teen Cyber Privacy Checklist",
      "description": "A simple online safety and privacy checklist for pre-teens (ages 9–12) and the parents reviewing it with them — covering apps, gaming, passwords, and what to share online.",
      "url": "https://ciso.diy/templates/pre-teen-cyber-checklist",
      "image": "https://ciso.diy/images/og/pre-teen-cyber-checklist.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "children",
        "privacy",
        "online safety",
        "parents",
        "pre-teen",
        "PDF"
      ],
      "keyFacts": [
        "The online safety decisions most relevant to **ages 9–12**: which apps are age-appropriate, gaming platform settings, password basics, what should never be shared, and what to do if something feels wrong."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "teen-cyber-privacy-playbook",
      "title": "Teen Cyber Privacy Playbook",
      "description": "A comprehensive digital privacy and online safety guide for teenagers — social media, gaming, AI tools, relationships, identity protection, and what your data is actually worth.",
      "url": "https://ciso.diy/templates/teen-cyber-privacy-playbook",
      "image": "https://ciso.diy/images/og/teen-cyber-privacy-playbook.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "teens",
        "privacy",
        "online safety",
        "social media",
        "PDF"
      ],
      "keyFacts": [
        "The decisions that matter most at **ages 13–18**: platform-by-platform social media privacy, gaming and streaming account security, AI tool data handling, digital reputation, and recognising manipulation and scams aimed at teens.",
        "**Written directly for teenagers — peer tone, real examples, no corporate language.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1600,
      "listPriceFrom": 1999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1600,
          "listPrice": 1999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "smart-home-iot-checklist",
      "title": "Smart Home & IoT Security Checklist",
      "description": "Device hardening and network segmentation checklist for smart home setups — routers, cameras, smart speakers, thermostats, and everything else on your home network.",
      "url": "https://ciso.diy/templates/smart-home-iot-checklist",
      "image": "https://ciso.diy/images/og/smart-home-iot-checklist.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "IoT",
        "smart home",
        "home security",
        "checklist",
        "PDF"
      ],
      "keyFacts": [
        "Router hardening, then **device by device** — cameras, smart speakers, thermostats, locks, TVs, baby monitors — plus network segmentation basics.",
        "**Includes what to do when a device stops receiving security updates**, which is the question most smart-home guides skip."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "social-media-privacy-ai",
      "title": "Social Media Privacy & AI Workbook",
      "description": "Platform-by-platform privacy settings guide for major social networks plus an AI tool awareness section — what each platform does with your data and how to tighten it.",
      "url": "https://ciso.diy/templates/social-media-privacy-ai",
      "image": "https://ciso.diy/images/og/social-media-privacy-ai.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "social media",
        "privacy",
        "AI tools",
        "data protection",
        "PDF"
      ],
      "keyFacts": [
        "Platform by platform with screenshots and step counts: Instagram, TikTok, Facebook, X/Twitter, LinkedIn, Snapchat, YouTube.",
        "Plus an AI section on **ChatGPT, Google Gemini, Meta AI and Copilot — what each does with your data, what gets stored, and what opt-outs exist**.",
        "**Settings current as of 2026**, which is the part that dates fastest in every other guide."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1600,
      "listPriceFrom": 1999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1600,
          "listPrice": 1999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "password-manager-migration",
      "title": "Password Manager Migration Workbook",
      "description": "A step-by-step guide to evaluating, selecting, and migrating to a password manager — comparison framework, migration checklist, and post-migration hardening steps.",
      "url": "https://ciso.diy/templates/password-manager-migration",
      "image": "https://ciso.diy/images/og/password-manager-migration.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "password manager",
        "migration",
        "personal security",
        "1Password",
        "Bitwarden",
        "PDF"
      ],
      "keyFacts": [
        "An evaluation framework comparing **1Password, Bitwarden, Dashlane, LastPass, Keeper, Apple Keychain and Google Password Manager** before you commit.",
        "Migration steps for each major platform, what to prioritise moving first, and family sharing setup.",
        "**Post-migration hardening is the half most people skip:** removing saved passwords from browsers, enabling emergency access, and putting 2FA on the vault itself."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1600,
      "listPriceFrom": 1999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1600,
          "listPrice": 1999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "digital-legacy-workbook",
      "title": "Digital Legacy Workbook",
      "description": "Document your digital accounts, assets, subscriptions, and access wishes for estate planning — so your family can act quickly and nothing is permanently lost.",
      "url": "https://ciso.diy/templates/digital-legacy-workbook",
      "image": "https://ciso.diy/images/og/digital-legacy-workbook.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "digital legacy",
        "estate planning",
        "personal security",
        "accounts",
        "PDF"
      ],
      "keyFacts": [
        "An account inventory across email, financial, social, subscriptions, cloud storage and crypto — with access instructions for each.",
        "Legacy contact designations and platform-specific guidance for memorialisation or closure.",
        "**Designed to be completed once and updated annually**, with a checklist for where to keep it and how to make sure your executor can actually find it."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 1600,
      "listPriceFrom": 1999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1600,
          "listPrice": 1999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "security-awareness-training",
      "title": "Security Awareness Training Deck",
      "description": "25-slide editable PowerPoint security awareness training deck — phishing, passwords, social engineering, AI threats, and incident reporting. Compatible with Google Slides, Keynote, and LibreOffice.",
      "url": "https://ciso.diy/templates/security-awareness-training",
      "image": "https://ciso.diy/images/og/security-awareness-training.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "security awareness",
        "training",
        "phishing",
        "PowerPoint",
        "employees",
        "pptx"
      ],
      "keyFacts": [
        "Designed for a **45–60 minute all-hands delivery** or self-paced async review."
      ],
      "formats": [
        "pptx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 3200,
      "listPriceFrom": 3999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 3200,
          "listPrice": 3999,
          "formats": [
            "pptx"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "home-network-security-audit-checklist",
      "title": "Home Network Security Audit Checklist",
      "description": "2-page printable audit for your home Wi-Fi — router hardening, WPA3, network segmentation (Main / Guest / IoT), DNS filtering, IoT device inventory, and a 90-day re-audit cycle. The average home has 22+ connected devices; most routers ship insecure.",
      "url": "https://ciso.diy/templates/home-network-security-audit-checklist",
      "image": "https://ciso.diy/images/og/home-network-security-audit-checklist.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "home network",
        "Wi-Fi security",
        "router",
        "IoT",
        "smart home",
        "WPA3",
        "DNS filtering",
        "printable",
        "PDF"
      ],
      "keyFacts": [
        "**The average household in 2026 has 22+ connected devices, and 67% of smart home devices ship with at least one critical vulnerability.**",
        "Walk through it with your router admin page open; re-run it every 90 days."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 2,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 400,
      "listPriceFrom": 499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 400,
          "listPrice": 499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "password-manager-migration-workbook",
      "title": "Password Manager Migration Workbook",
      "description": "4-page printable workbook to inventory, prioritize, and migrate all your accounts to a password manager — 30+ account types pre-listed in 4 priority tiers, 2FA migration tracker, lockout prevention checklist. Works with Bitwarden, 1Password, Proton Pass, and more.",
      "url": "https://ciso.diy/templates/password-manager-migration-workbook",
      "image": "https://ciso.diy/images/og/password-manager-migration-workbook.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "password manager",
        "Bitwarden",
        "1Password",
        "2FA",
        "account security",
        "printable",
        "PDF"
      ],
      "keyFacts": [
        "**Nobody remembers 200 unique passwords, so people reuse — which is exactly how most account compromises happen.**",
        "The structured **2–4 hour project** that fixes it for good.",
        "Works with any manager: Bitwarden · 1Password · Proton Pass · Apple Passwords · Dashlane · KeePass."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 4,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 400,
      "listPriceFrom": 499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 400,
          "listPrice": 499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "family-online-safety-contract",
      "title": "Family Online Safety Contract",
      "description": "4-page two-way family internet agreement updated for 2026 — AI chatbots, deepfakes, sextortion, and gaming strangers addressed in age-appropriate language. Parents promise things too (the two-column design is why teens actually sign it). Ages 8-17.",
      "url": "https://ciso.diy/templates/family-online-safety-contract",
      "image": "https://ciso.diy/images/og/family-online-safety-contract.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "family",
        "online safety",
        "kids",
        "teens",
        "internet agreement",
        "deepfake",
        "sextortion",
        "AI chatbot",
        "parenting",
        "PDF"
      ],
      "keyFacts": [
        "Updated for 2026 to address **AI chatbots, deepfakes and sextortion** in age-appropriate ways.",
        "**15 kid promises and 15 parent promises**, both sides signed — the parent column is the half most contracts leave out.",
        "Privacy settings for Instagram, TikTok, Snapchat, Discord, Roblox, YouTube, Apple/Google and iMessage, plus 7 conversation starters that actually work.",
        "Emergency resources on the page: FBI tip line, NCMEC CyberTipline, Take It Down, 988."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 4,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 400,
      "listPriceFrom": 499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 400,
          "listPrice": 499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "personal-cyber-insurance-checklist",
      "title": "Personal Cyber Insurance Checklist",
      "description": "2-page before-you-buy checklist for personal cyber insurance — 10 coverage questions, 8 fine-print red flags, and a side-by-side quote comparison worksheet. Includes the #1 most-excluded coverage type that most buyers never think to ask about.",
      "url": "https://ciso.diy/templates/personal-cyber-insurance-checklist",
      "image": "https://ciso.diy/images/og/personal-cyber-insurance-checklist.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "cyber insurance",
        "personal",
        "identity theft",
        "fraud protection",
        "insurance checklist",
        "PDF"
      ],
      "keyFacts": [
        "**Social engineering — “authorized transfer” fraud — is the most common personal cyber loss in 2026, and the most commonly excluded coverage.**",
        "**That one question alone has saved buyers from filing $10K+ claims that would have been denied.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 2,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 500,
      "listPriceFrom": 650,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 500,
          "listPrice": 650,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "family-ir-runbook-account-compromise",
      "title": "Family Incident Response Runbook",
      "description": "Fillable 4-page playbook for when an account gets hacked — pre-fill family contacts and fraud hotlines now, then follow the First 60 Minutes / Next 24 Hours / Cleanup Week checklists when it happens. 24 fillable fields + 30 priority-ordered checkboxes.",
      "url": "https://ciso.diy/templates/family-ir-runbook-account-compromise",
      "image": "https://ciso.diy/images/og/family-ir-runbook-account-compromise.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "incident response",
        "hacked account",
        "account recovery",
        "family",
        "fillable PDF",
        "cyber emergency",
        "PDF"
      ],
      "keyFacts": [
        "**The first 60 minutes are everything — and most people freeze or do the wrong things.**",
        "A pre-fill page to complete **now, before anything happens**: family member info, fraud hotlines, recovery key locations.",
        "Then first 60 minutes, next 24 hours and cleanup week as ordered 10-step checklists — including *do not delete evidence* and *change passwords from a clean device*.",
        "24 fillable text fields and 30 fillable checkboxes, with account recovery URLs for Google, Apple, Meta and the banks."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 4,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 700,
      "listPriceFrom": 900,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 700,
          "listPrice": 900,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cybersecurity-career-planner",
      "title": "Cybersecurity Career Planner & Study Tracker 2026",
      "description": "8-page fillable career planner covering 16 certifications — Cert Decision Framework (8 scenarios), 2026 cost reference (Sec+ $404, CISSP $749, OSCP $1,649+), Domain Mastery Tracker, Practice Exam Score Log with \"Am I Ready?\" rubric, and weekly study tracker. Updated for SY0-701 and April 2026 CISSP CBK.",
      "url": "https://ciso.diy/templates/cybersecurity-career-planner",
      "image": "https://ciso.diy/images/og/cybersecurity-career-planner.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "cybersecurity career",
        "Security+",
        "CISSP",
        "OSCP",
        "cert study",
        "SY0-701",
        "career planner",
        "study tracker",
        "PDF"
      ],
      "keyFacts": [
        "**16 certifications covered and verified for 2026** — CompTIA A+, Network+, Security+ SY0-701, CySA+ CS0-003, PenTest+ PT0-003, SSCP, CISSP, CCSP, CISM, CRISC, SC-200, SC-100, AZ-500, AWS Security Specialty, OSCP and GIAC GCIH.",
        "**The practice exam rule: hit 85%+ consistently across three different providers before booking.** One source can be “easy”; three matched providers cannot."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 800,
      "listPriceFrom": 999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 800,
          "listPrice": 999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "family-cyber-drill-tabletop-pack",
      "title": "Family Cyber Drill — Tabletop Pack",
      "description": "8-page printable with 3 dinner-table scenarios (smishing, AI voice cloning, gaming scam) plus a fillable Family Safe Word Card — the #1 defense against AI voice clone scams. Each scenario is 20 minutes with discussion questions tuned for ages 8-17.",
      "url": "https://ciso.diy/templates/family-cyber-drill-tabletop-pack",
      "image": "https://ciso.diy/images/og/family-cyber-drill-tabletop-pack.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "family",
        "tabletop",
        "AI voice cloning",
        "phishing",
        "safe word",
        "kids",
        "cyber drill",
        "smishing",
        "printable",
        "PDF"
      ],
      "keyFacts": [
        "**Practice for 2026 scams before the scammer practices on you.**",
        "Three scenarios run at the kitchen table: the delivery text (smishing), **the voice that wasn’t (AI voice cloning — your “child” calls crying, needs money wired now)**, and the gamer’s account.",
        "Quick reference on the page: FBI tip line, NCMEC CyberTipline, FTC, 988."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 1000,
      "listPriceFrom": 1199,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1000,
          "listPrice": 1199,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "digital-estate-planning-workbook",
      "title": "Digital Estate Planning Workbook",
      "description": "7-page printable for your executor — accounts, passwords (via manager succession), crypto wallet guidance, platform legacy settings (Apple Legacy Contact, Google Inactive Account Manager, Facebook Memorialization), and RUFADAA authorization language. Passwords never go in a will; this is what goes instead.",
      "url": "https://ciso.diy/templates/digital-estate-planning-workbook",
      "image": "https://ciso.diy/images/og/digital-estate-planning-workbook.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "digital estate",
        "estate planning",
        "RUFADAA",
        "crypto inheritance",
        "executor",
        "digital legacy",
        "password succession",
        "PDF"
      ],
      "keyFacts": [
        "**Wills become public record at probate. Passwords and crypto seed phrases never belong in them** — this is what goes instead.",
        "Carries **RUFADAA legal authorisation language** and password-manager succession, so your executor has authority as well as access.",
        "Platform legacy settings covered directly: Apple Legacy Contact, Google Inactive Account Manager, Facebook Memorialization.",
        "Seven printable pages, including custodial and non-custodial cryptocurrency guidance."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 7,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 1200,
      "listPriceFrom": 1499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1200,
          "listPrice": 1499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "identity-theft-recovery-binder",
      "title": "Identity Theft Recovery Binder",
      "description": "Fillable 8-page binder built around FCRA §605B — the 4-business-day bureau block most identity theft kits skip. Includes a §605B dispute letter, §609(e) creditor records demand, phone scripts for banks/bureaus/debt collectors, Master Dispute Tracker, and 2026-verified bureau addresses. 21 fillable fields.",
      "url": "https://ciso.diy/templates/identity-theft-recovery-binder",
      "image": "https://ciso.diy/images/og/identity-theft-recovery-binder.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "identity theft",
        "FCRA",
        "605B",
        "credit bureau",
        "dispute letter",
        "fraud recovery",
        "debt collector",
        "FDCPA",
        "fillable PDF",
        "PDF"
      ],
      "keyFacts": [
        "**Built around FCRA Section 605B — the 4-business-day legal lever most identity theft kits do not even mention.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 1600,
      "listPriceFrom": 1999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1600,
          "listPrice": 1999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "small-business-cyber-starter-kit",
      "title": "Small Business Cyber Starter Kit",
      "description": "13-page fillable kit for solo founders and 2-25 person businesses — 2026 cyber insurance pre-fill worksheet (19 carrier questions), 7 starter policies (AUP, Password, Data Handling, Privacy Notice, IR Plan, Onboarding/Offboarding, Vendor Risk), and a 90-day implementation roadmap. 67 text fields + 66 checkboxes.",
      "url": "https://ciso.diy/templates/small-business-cyber-starter-kit",
      "image": "https://ciso.diy/images/og/small-business-cyber-starter-kit.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "small business",
        "cyber insurance",
        "acceptable use policy",
        "incident response",
        "MFA",
        "SMB",
        "starter kit",
        "fillable PDF",
        "PDF"
      ],
      "keyFacts": [
        "**82% of denied cyber claims in 2024 involved organisations without MFA.**",
        "Carrier applications now run **12–20 pages with line-by-line control questions** on MFA, EDR, backups and training.",
        "For solo founders, freelancers, agencies, e-commerce shops, consultants and 2–25 person businesses.",
        "**Not SOC 2, ISO 27001, HIPAA or PCI** — this gives your compliance consultant a head start, not a certification."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 13,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 2000,
      "listPriceFrom": 2499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 2000,
          "listPrice": 2499,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "senior-cyber-safety-workbook",
      "title": "Senior Cyber Safety Workbook",
      "description": "The dignified, 2026-current guide to elder cyber fraud — romance scam 4-phase playbook, AI voice cloning defense, government impersonation field guide, and fillable Family Safe Word card. For adult children buying for aging parents.",
      "url": "https://ciso.diy/templates/senior-cyber-safety-workbook",
      "image": "https://ciso.diy/images/og/senior-cyber-safety-workbook.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "senior",
        "elder fraud",
        "romance scam",
        "AI voice cloning",
        "grandparent scam",
        "Medicare fraud",
        "aging parents",
        "family safe word",
        "PDF"
      ],
      "keyFacts": [
        "**The FTC reported $2.4 billion in fraud losses to adults 60 and over in 2024 — quadruple what it was in 2020.**",
        "**AI voice cloning scams alone cost older adults $352 million last year.**",
        "The 8 most dangerous scams ranked by total losses: investment, romance, government impersonation, tech support, grandparent/AI voice, business impersonator, sweepstakes, charity.",
        "**Romance is the biggest dollar-loss category — the typical victim aged 80+ loses $9,500.**"
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 800,
      "listPriceFrom": 999,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 800,
          "listPrice": 999,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "wfh-remote-worker-security-kit",
      "title": "WFH / Remote Worker Security Kit",
      "description": "Four-page fillable PDF for remote employees and freelancers — home office audit, 2026 VPN comparison, AI tool risk policy, signed BYOD mini-policy, and monthly self-audit grid. Updated for post-quantum VPNs and co-working space security.",
      "url": "https://ciso.diy/templates/wfh-remote-worker-security-kit",
      "image": "https://ciso.diy/images/og/wfh-remote-worker-security-kit.png",
      "category": "awareness",
      "categoryLabel": "Security Awareness",
      "type": "product",
      "tags": [
        "remote work",
        "WFH",
        "freelancer",
        "VPN",
        "BYOD",
        "AI tool policy",
        "home office",
        "digital nomad",
        "PDF"
      ],
      "keyFacts": [
        "**Your company gave you a laptop and 30 minutes of IT onboarding.** This is the rest of it.",
        "Updated for 2026: AI tool risks, post-quantum VPNs and co-working space security.",
        "**17 specific checks** across physical workspace, home network and router — about an hour the first time.",
        "Five audited no-logs VPN providers compared — NordVPN, Proton, Mullvad, Surfshark, ExpressVPN — with 2026 differentiators including post-quantum encryption status."
      ],
      "formats": [
        "pdf"
      ],
      "deliverables": 4,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 600,
      "listPriceFrom": 799,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 600,
          "listPrice": 799,
          "formats": [
            "pdf"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "family-cyber-safety-pack",
      "title": "Family Cyber Safety Pack",
      "description": "Everything your family needs to be cyber-safe in 2026 — Home Network Audit, Family Online Safety Contract (AI/deepfake-aware), 3-scenario Cyber Drill with fillable Safe Word card, and IR Runbook for account compromise. 26% off individual.",
      "url": "https://ciso.diy/templates/family-cyber-safety-pack",
      "image": "https://ciso.diy/images/og/family-cyber-safety-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "family",
        "home network",
        "online safety",
        "kids",
        "cyber drill",
        "safe word",
        "incident response",
        "consumer bundle",
        "PDF"
      ],
      "keyFacts": [
        "Five PDFs, 18 pages: the router audit, the two-way family agreement, three dinner-table drill scenarios, and the fillable runbook for when an account actually gets hacked.",
        "**The drill pack is the one families skip and the one that changes behaviour** — practice for 2026 scams before the scammer practices on you."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 18,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 1800,
      "listPriceFrom": 2299,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 1800,
          "listPrice": 2299,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "home-network-security-audit-checklist",
          "title": "Home Network Security Audit Checklist",
          "url": "https://ciso.diy/templates/home-network-security-audit-checklist"
        },
        {
          "slug": "family-online-safety-contract",
          "title": "Family Online Safety Contract",
          "url": "https://ciso.diy/templates/family-online-safety-contract"
        },
        {
          "slug": "family-cyber-drill-tabletop-pack",
          "title": "Family Cyber Drill — Tabletop Pack",
          "url": "https://ciso.diy/templates/family-cyber-drill-tabletop-pack"
        },
        {
          "slug": "family-ir-runbook-account-compromise",
          "title": "Family Incident Response Runbook",
          "url": "https://ciso.diy/templates/family-ir-runbook-account-compromise"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "business-financial-cyber-pack",
      "title": "Business & Financial Cyber Pack",
      "description": "Lock down your accounts, protect your money, recover from identity theft, and pass your cyber insurance application — Password Manager Workbook, Cyber Insurance Checklist, Identity Theft Recovery Binder (FCRA §605B), and SMB Starter Kit. 24% off individual.",
      "url": "https://ciso.diy/templates/business-financial-cyber-pack",
      "image": "https://ciso.diy/images/og/business-financial-cyber-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "identity theft",
        "FCRA",
        "cyber insurance",
        "password manager",
        "small business",
        "consumer bundle",
        "PDF"
      ],
      "keyFacts": [
        "Built around **FCRA §605B — the 4-business-day legal lever most identity theft kits skip** — with fillable dispute letters and a master dispute tracker that becomes your evidence trail.",
        "Includes the 2026 cyber insurance pre-fill worksheet, because the broker application is where most small businesses first discover what they are missing."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 27,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 3400,
      "listPriceFrom": 4299,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 3400,
          "listPrice": 4299,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "password-manager-migration-workbook",
          "title": "Password Manager Migration Workbook",
          "url": "https://ciso.diy/templates/password-manager-migration-workbook"
        },
        {
          "slug": "personal-cyber-insurance-checklist",
          "title": "Personal Cyber Insurance Checklist",
          "url": "https://ciso.diy/templates/personal-cyber-insurance-checklist"
        },
        {
          "slug": "identity-theft-recovery-binder",
          "title": "Identity Theft Recovery Binder",
          "url": "https://ciso.diy/templates/identity-theft-recovery-binder"
        },
        {
          "slug": "small-business-cyber-starter-kit",
          "title": "Small Business Cyber Starter Kit",
          "url": "https://ciso.diy/templates/small-business-cyber-starter-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "elder-fraud-recovery-pack",
      "title": "Elder Fraud Recovery Pack",
      "description": "Built for the worst week — Senior Cyber Safety Workbook, Identity Theft Recovery Binder (FCRA §605B), and Family IR Runbook, plus a 2-page triage guide that tells you which workbook to open first based on what you discovered. 36% off individual.",
      "url": "https://ciso.diy/templates/elder-fraud-recovery-pack",
      "image": "https://ciso.diy/images/og/elder-fraud-recovery-pack.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "elder fraud",
        "senior scam",
        "identity theft",
        "FCRA",
        "caregiver",
        "romance scam",
        "consumer bundle",
        "PDF"
      ],
      "keyFacts": [
        "**The deepest savings in the consumer catalogue**, assembled for the moment after it happens rather than before.",
        "Fillable dispute letters, phone scripts for banks and bureaus, a 14-row master dispute tracker, and 2026-verified bureau addresses.",
        "The first-60-minutes / next-24-hours / cleanup-week playbook, with a pre-fill page for family contacts and fraud hotlines."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 21,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 2000,
      "listPriceFrom": 2499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 2000,
          "listPrice": 2499,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "senior-cyber-safety-workbook",
          "title": "Senior Cyber Safety Workbook",
          "url": "https://ciso.diy/templates/senior-cyber-safety-workbook"
        },
        {
          "slug": "identity-theft-recovery-binder",
          "title": "Identity Theft Recovery Binder",
          "url": "https://ciso.diy/templates/identity-theft-recovery-binder"
        },
        {
          "slug": "family-ir-runbook-account-compromise",
          "title": "Family Incident Response Runbook",
          "url": "https://ciso.diy/templates/family-ir-runbook-account-compromise"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "complete-cyber-library",
      "title": "Complete Cyber Library",
      "description": "The entire consumer catalog — 10 products covering family safety, financial protection, career planning, and small business documentation. 54 pages, scenario-based bundle index showing what to open first for any situation. 33% off individual.",
      "url": "https://ciso.diy/templates/complete-cyber-library",
      "image": "https://ciso.diy/images/og/complete-cyber-library.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "complete library",
        "family",
        "identity theft",
        "cyber insurance",
        "estate planning",
        "career",
        "small business",
        "consumer bundle",
        "PDF"
      ],
      "keyFacts": [
        "Eleven PDFs, 54 pages — **equivalent to three family products entirely free** against buying them individually.",
        "Family safety, financial protection, career planning and small business documentation, organised for how you actually use them rather than by product."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 54,
      "version": "1.0",
      "updated": "2026-05-22",
      "priceCurrency": "USD",
      "priceFrom": 6000,
      "listPriceFrom": 7499,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 6000,
          "listPrice": 7499,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "home-network-security-audit-checklist",
          "title": "Home Network Security Audit Checklist",
          "url": "https://ciso.diy/templates/home-network-security-audit-checklist"
        },
        {
          "slug": "family-online-safety-contract",
          "title": "Family Online Safety Contract",
          "url": "https://ciso.diy/templates/family-online-safety-contract"
        },
        {
          "slug": "family-cyber-drill-tabletop-pack",
          "title": "Family Cyber Drill — Tabletop Pack",
          "url": "https://ciso.diy/templates/family-cyber-drill-tabletop-pack"
        },
        {
          "slug": "family-ir-runbook-account-compromise",
          "title": "Family Incident Response Runbook",
          "url": "https://ciso.diy/templates/family-ir-runbook-account-compromise"
        },
        {
          "slug": "password-manager-migration-workbook",
          "title": "Password Manager Migration Workbook",
          "url": "https://ciso.diy/templates/password-manager-migration-workbook"
        },
        {
          "slug": "personal-cyber-insurance-checklist",
          "title": "Personal Cyber Insurance Checklist",
          "url": "https://ciso.diy/templates/personal-cyber-insurance-checklist"
        },
        {
          "slug": "identity-theft-recovery-binder",
          "title": "Identity Theft Recovery Binder",
          "url": "https://ciso.diy/templates/identity-theft-recovery-binder"
        },
        {
          "slug": "digital-estate-planning-workbook",
          "title": "Digital Estate Planning Workbook",
          "url": "https://ciso.diy/templates/digital-estate-planning-workbook"
        },
        {
          "slug": "cybersecurity-career-planner",
          "title": "Cybersecurity Career Planner 2026",
          "url": "https://ciso.diy/templates/cybersecurity-career-planner"
        },
        {
          "slug": "small-business-cyber-starter-kit",
          "title": "Small Business Cyber Starter Kit",
          "url": "https://ciso.diy/templates/small-business-cyber-starter-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "compliance-trifecta-bundle",
      "title": "Compliance Trifecta Bundle",
      "description": "SOC 2 + HIPAA + ISO 27001:2022 readiness in one bundle — the three certifications every enterprise buyer asks for. 17% off list.",
      "url": "https://ciso.diy/templates/compliance-trifecta-bundle",
      "image": "https://ciso.diy/images/og/compliance-trifecta-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "SOC 2",
        "HIPAA",
        "ISO 27001",
        "compliance bundle",
        "trifecta"
      ],
      "keyFacts": [
        "**The SOC 2 crosswalk in the ISO 27001 workbook maps ~75 of 93 Annex A controls directly to SOC 2 Trust Service Criteria** — dual-certification prep without duplicated work."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 89400,
      "listPriceFrom": 111800,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 89400,
          "listPrice": 111800,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 225500,
          "listPrice": 281900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 497800,
          "listPrice": 622200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "hipaa-readiness-accelerator",
          "title": "HIPAA Readiness Accelerator",
          "url": "https://ciso.diy/templates/hipaa-readiness-accelerator"
        },
        {
          "slug": "iso27001-readiness",
          "title": "ISO 27001:2022 Readiness Accelerator",
          "url": "https://ciso.diy/templates/iso27001-readiness"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "compliance-big5",
      "title": "Compliance Big 5 Bundle",
      "description": "SOC 2 + HIPAA + ISO 27001 + PCI DSS + CMMC 2.0 — every major compliance framework an auditor or regulator will ask about. 22% off list.",
      "url": "https://ciso.diy/templates/compliance-big5",
      "image": "https://ciso.diy/images/og/compliance-big5.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "SOC 2",
        "HIPAA",
        "ISO 27001",
        "PCI DSS",
        "CMMC",
        "compliance bundle"
      ],
      "keyFacts": [
        "**Eliminates the framework overlap analysis that consultants charge $50K+ to perform**, for organisations answering several compliance RFPs at once."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 137000,
      "listPriceFrom": 171200,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 137000,
          "listPrice": 171200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 342900,
          "listPrice": 428600,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 792200,
          "listPrice": 990200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "hipaa-readiness-accelerator",
          "title": "HIPAA Readiness Accelerator",
          "url": "https://ciso.diy/templates/hipaa-readiness-accelerator"
        },
        {
          "slug": "iso27001-readiness",
          "title": "ISO 27001:2022 Readiness Accelerator",
          "url": "https://ciso.diy/templates/iso27001-readiness"
        },
        {
          "slug": "pci-dss-readiness",
          "title": "PCI DSS v4.0.1 Readiness Accelerator",
          "url": "https://ciso.diy/templates/pci-dss-readiness"
        },
        {
          "slug": "cmmc-readiness",
          "title": "CMMC 2.0 Readiness Accelerator",
          "url": "https://ciso.diy/templates/cmmc-readiness"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "comply-federal",
      "title": "Federal Contractor Pack",
      "description": "CMMC 2.0 + NIST CSF 2.0 + PCI DSS for defense and federal contractors — built for DoD, GSA, and agency RFP responses. 18% off list.",
      "url": "https://ciso.diy/templates/comply-federal",
      "image": "https://ciso.diy/images/og/comply-federal.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "CMMC",
        "NIST CSF",
        "PCI DSS",
        "federal",
        "DoD",
        "government contractor"
      ],
      "keyFacts": [
        "**The CMMC workbook maps each practice to SP 800-171r3 requirements**, so the federal stack is answered once rather than three times."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 65400,
      "listPriceFrom": 81800,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 65400,
          "listPrice": 81800,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 163800,
          "listPrice": 204800,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 406600,
          "listPrice": 508200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "cmmc-readiness",
          "title": "CMMC 2.0 Readiness Accelerator",
          "url": "https://ciso.diy/templates/cmmc-readiness"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        },
        {
          "slug": "pci-dss-readiness",
          "title": "PCI DSS v4.0.1 Readiness Accelerator",
          "url": "https://ciso.diy/templates/pci-dss-readiness"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "comply-healthcare",
      "title": "Healthcare Security Pack",
      "description": "HIPAA + SOC 2 + Ransomware Readiness for healthcare SaaS and digital health. Healthcare ransomware is 31% of all attacks. 17% off list.",
      "url": "https://ciso.diy/templates/comply-healthcare",
      "image": "https://ciso.diy/images/og/comply-healthcare.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "HIPAA",
        "SOC 2",
        "ransomware",
        "healthcare",
        "digital health",
        "health tech"
      ],
      "keyFacts": [
        "**Healthcare ransomware response has HIPAA breach-notification timing requirements the generic playbooks miss** — this bundle covers both sides."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 76200,
      "listPriceFrom": 95200,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 76200,
          "listPrice": 95200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 192400,
          "listPrice": 240500,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 418100,
          "listPrice": 522600,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "hipaa-readiness-accelerator",
          "title": "HIPAA Readiness Accelerator",
          "url": "https://ciso.diy/templates/hipaa-readiness-accelerator"
        },
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "ransomware-readiness",
          "title": "2026 Ransomware Readiness Workbook",
          "url": "https://ciso.diy/templates/ransomware-readiness"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "comply-global-saas",
      "title": "Global SaaS Compliance Pack",
      "description": "SOC 2 + ISO 27001 + GDPR/DPIA for B2B SaaS going international — US enterprise + EU data subjects in one bundle. 17% off list.",
      "url": "https://ciso.diy/templates/comply-global-saas",
      "image": "https://ciso.diy/images/og/comply-global-saas.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "SOC 2",
        "ISO 27001",
        "GDPR",
        "global SaaS",
        "international compliance"
      ],
      "keyFacts": [
        "**The SOC 2 crosswalk in ISO 27001 means the three frameworks can be addressed together, not sequentially.**"
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 86200,
      "listPriceFrom": 107700,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 86200,
          "listPrice": 107700,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 212300,
          "listPrice": 265400,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 524400,
          "listPrice": 655500,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "iso27001-readiness",
          "title": "ISO 27001:2022 Readiness Accelerator",
          "url": "https://ciso.diy/templates/iso27001-readiness"
        },
        {
          "slug": "gdpr-dpia-workbook",
          "title": "GDPR & DPIA Compliance Workbook",
          "url": "https://ciso.diy/templates/gdpr-dpia-workbook"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "privacy-dual",
      "title": "Privacy Dual Coverage Bundle",
      "description": "2026 US state privacy program + EU GDPR/DPIA — every SaaS selling to US and EU customers needs both. 15% off list.",
      "url": "https://ciso.diy/templates/privacy-dual",
      "image": "https://ciso.diy/images/og/privacy-dual.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "GDPR",
        "CCPA",
        "US privacy",
        "privacy program",
        "data protection"
      ],
      "keyFacts": [
        "GDPR and the 20-state US wave in one purchase — two visually distinguishable workbooks, so a transatlantic privacy programme does not run out of one file."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 50900,
      "listPriceFrom": 63600,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 50900,
          "listPrice": 63600,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 129000,
          "listPrice": 161300,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 319400,
          "listPrice": 399300,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "us-privacy-program",
          "title": "2026 US Privacy Program Workbook",
          "url": "https://ciso.diy/templates/us-privacy-program"
        },
        {
          "slug": "gdpr-dpia-workbook",
          "title": "GDPR & DPIA Compliance Workbook",
          "url": "https://ciso.diy/templates/gdpr-dpia-workbook"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ciso-starter",
      "title": "New CISO Starter Pack",
      "description": "CISO 90-Day Onboarding + NIST CSF 2.0 Assessment + CISO Budget Workbook + Board Reporting Pack — your Day-90 board meeting in a bundle. 20% off list.",
      "url": "https://ciso.diy/templates/ciso-starter",
      "image": "https://ciso.diy/images/og/ciso-starter.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "new CISO",
        "onboarding",
        "NIST CSF",
        "budget",
        "board reporting",
        "CISO starter"
      ],
      "keyFacts": [
        "The four workbooks a new security leader needs in their first quarter: onboarding, framework baseline, budget, and the board pack."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 67000,
      "listPriceFrom": 83700,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 67000,
          "listPrice": 83700,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 179000,
          "listPrice": 223700,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 447800,
          "listPrice": 559700,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ciso-90-day-onboarding",
          "title": "CISO 90-Day Onboarding Workbook",
          "url": "https://ciso.diy/templates/ciso-90-day-onboarding"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        },
        {
          "slug": "ciso-budget-workbook",
          "title": "2026 CISO Budget Workbook",
          "url": "https://ciso.diy/templates/ciso-budget-workbook"
        },
        {
          "slug": "board-reporting",
          "title": "CISO Board Reporting Pack",
          "url": "https://ciso.diy/templates/board-reporting"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ciso-board-bundle",
      "title": "Board Preparation Bundle",
      "description": "CISO Budget Workbook + CISO Board Reporting Pack + NIST CSF 2.0 — everything a CISO needs for the quarterly board cycle. 17% off list.",
      "url": "https://ciso.diy/templates/ciso-board-bundle",
      "image": "https://ciso.diy/images/og/ciso-board-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "board reporting",
        "budget",
        "NIST CSF",
        "board preparation",
        "CISO"
      ],
      "keyFacts": [
        "**The Budget Workbook’s CRQ math converts NIST gap-analysis scores into dollar-denominated risk exposure — the language boards actually respond to.**"
      ],
      "formats": [
        "xlsx",
        "docx",
        "pptx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 49600,
      "listPriceFrom": 62000,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 49600,
          "listPrice": 62000,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 132600,
          "listPrice": 165800,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 331800,
          "listPrice": 414800,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ciso-budget-workbook",
          "title": "2026 CISO Budget Workbook",
          "url": "https://ciso.diy/templates/ciso-budget-workbook"
        },
        {
          "slug": "board-reporting",
          "title": "CISO Board Reporting Pack",
          "url": "https://ciso.diy/templates/board-reporting"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ciso-executive-suite",
      "title": "CISO Executive Suite",
      "description": "CISO 90-Day Onboarding + Budget + Board Pack + NIST CSF 2.0 + Tabletop Exercise Pack — the most complete CISO toolkit in the catalog. 22% off list.",
      "url": "https://ciso.diy/templates/ciso-executive-suite",
      "image": "https://ciso.diy/images/og/ciso-executive-suite.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "CISO",
        "executive",
        "onboarding",
        "budget",
        "board",
        "NIST CSF",
        "tabletop"
      ],
      "keyFacts": [
        "Onboarding, framework baseline, budget, board pack and the tabletop that turns a plan into evidence — the full executive-facing set."
      ],
      "formats": [
        "xlsx",
        "docx",
        "pptx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 74600,
      "listPriceFrom": 93200,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 74600,
          "listPrice": 93200,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 199400,
          "listPrice": 249200,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 498900,
          "listPrice": 623600,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ciso-90-day-onboarding",
          "title": "CISO 90-Day Onboarding Workbook",
          "url": "https://ciso.diy/templates/ciso-90-day-onboarding"
        },
        {
          "slug": "ciso-budget-workbook",
          "title": "2026 CISO Budget Workbook",
          "url": "https://ciso.diy/templates/ciso-budget-workbook"
        },
        {
          "slug": "board-reporting",
          "title": "CISO Board Reporting Pack",
          "url": "https://ciso.diy/templates/board-reporting"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        },
        {
          "slug": "tabletop-exercise-pack",
          "title": "Tabletop Exercise Pack",
          "url": "https://ciso.diy/templates/tabletop-exercise-pack"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vciso-starter",
      "title": "vCISO Starter Pack",
      "description": "vCISO Client-in-a-Box + NIST CSF 2.0 Assessment + CISO Board Reporting Pack — drop-in kit for fractional CISOs running concurrent clients. 20% off list.",
      "url": "https://ciso.diy/templates/vciso-starter",
      "image": "https://ciso.diy/images/og/vciso-starter.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "vCISO",
        "fractional CISO",
        "NIST CSF",
        "board reporting",
        "client management"
      ],
      "keyFacts": [
        "**The vCISO Client-in-a-Box embeds NIST CSF 2.0 assessment tabs that link to the standalone workbook format — consistent methodology across every client.**"
      ],
      "formats": [
        "xlsx",
        "docx",
        "pptx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 60600,
      "listPriceFrom": 75800,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 60600,
          "listPrice": 75800,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Team License",
          "price": 159800,
          "listPrice": 199800,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 351800,
          "listPrice": 439800,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "vciso-client-in-a-box",
          "title": "vCISO Client-in-a-Box",
          "url": "https://ciso.diy/templates/vciso-client-in-a-box"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        },
        {
          "slug": "board-reporting",
          "title": "CISO Board Reporting Pack",
          "url": "https://ciso.diy/templates/board-reporting"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vciso-complete",
      "title": "vCISO Complete Practice",
      "description": "vCISO Client-in-a-Box + CISO 90-Day Onboarding + NIST CSF 2.0 + Budget + SOC 2 + Board Pack — complete vCISO practice toolkit. 25% off list.",
      "url": "https://ciso.diy/templates/vciso-complete",
      "image": "https://ciso.diy/images/og/vciso-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "vCISO",
        "fractional CISO",
        "complete practice",
        "SOC 2",
        "NIST CSF",
        "board"
      ],
      "keyFacts": [
        "Everything a vCISO practice runs on: client management, onboarding, framework baseline, SOC 2 readiness, budget and the board pack — at the deepest discount in the practitioner line."
      ],
      "formats": [
        "xlsx",
        "docx",
        "pptx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 116600,
      "listPriceFrom": 145700,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 116600,
          "listPrice": 145700,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Team License",
          "price": 305700,
          "listPrice": 382100,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 719700,
          "listPrice": 899600,
          "formats": [
            "xlsx",
            "docx",
            "pptx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "vciso-client-in-a-box",
          "title": "vCISO Client-in-a-Box",
          "url": "https://ciso.diy/templates/vciso-client-in-a-box"
        },
        {
          "slug": "ciso-90-day-onboarding",
          "title": "CISO 90-Day Onboarding Workbook",
          "url": "https://ciso.diy/templates/ciso-90-day-onboarding"
        },
        {
          "slug": "nist-csf-assessment",
          "title": "NIST CSF 2.0 Self-Assessment Workbook",
          "url": "https://ciso.diy/templates/nist-csf-assessment"
        },
        {
          "slug": "ciso-budget-workbook",
          "title": "2026 CISO Budget Workbook",
          "url": "https://ciso.diy/templates/ciso-budget-workbook"
        },
        {
          "slug": "soc2-readiness",
          "title": "SOC 2 Readiness Accelerator",
          "url": "https://ciso.diy/templates/soc2-readiness"
        },
        {
          "slug": "board-reporting",
          "title": "CISO Board Reporting Pack",
          "url": "https://ciso.diy/templates/board-reporting"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "risk-readiness",
      "title": "Risk & Readiness Pack",
      "description": "Ransomware Readiness + Tabletop Exercise Pack + Cyber Insurance Workbook + Shadow AI Inventory — show underwriters and your CEO your program maturity. 20% off list.",
      "url": "https://ciso.diy/templates/risk-readiness",
      "image": "https://ciso.diy/images/og/risk-readiness.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "ransomware",
        "tabletop",
        "cyber insurance",
        "shadow AI",
        "risk readiness"
      ],
      "keyFacts": [
        "Assess, rehearse, insure and inventory — **the four artefacts an underwriter, a board and an auditor each ask for, produced once**."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 49800,
      "listPriceFrom": 62200,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 49800,
          "listPrice": 62200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 120200,
          "listPrice": 150200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 216200,
          "listPrice": 270200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ransomware-readiness",
          "title": "2026 Ransomware Readiness Workbook",
          "url": "https://ciso.diy/templates/ransomware-readiness"
        },
        {
          "slug": "tabletop-exercise-pack",
          "title": "Tabletop Exercise Pack",
          "url": "https://ciso.diy/templates/tabletop-exercise-pack"
        },
        {
          "slug": "cyber-insurance-workbook",
          "title": "Cyber Insurance Application Workbook",
          "url": "https://ciso.diy/templates/cyber-insurance-workbook"
        },
        {
          "slug": "shadow-ai-inventory",
          "title": "Shadow AI Inventory & Risk Scoring Workbook",
          "url": "https://ciso.diy/templates/shadow-ai-inventory"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "deal-cycle",
      "title": "Deal-Cycle Pack",
      "description": "M&A Cyber Diligence + VC Startup Due Diligence + Enterprise Questionnaire Response Kit — for deal advisors, corp dev, and VCs running cyber DD. 17% off list.",
      "url": "https://ciso.diy/templates/deal-cycle",
      "image": "https://ciso.diy/images/og/deal-cycle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "M&A",
        "VC",
        "due diligence",
        "enterprise questionnaire",
        "deal cycle"
      ],
      "keyFacts": [
        "**The Enterprise Questionnaire Response Kit maps to the same control framework, so sell-side documentation aligns with buy-side expectations.**"
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 43000,
      "listPriceFrom": 53700,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 43000,
          "listPrice": 53700,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 119400,
          "listPrice": 149200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 298600,
          "listPrice": 373300,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ma-cyber-diligence",
          "title": "M&A Cyber Diligence Workbook",
          "url": "https://ciso.diy/templates/ma-cyber-diligence"
        },
        {
          "slug": "vc-diligence",
          "title": "VC Startup Due Diligence Workbook",
          "url": "https://ciso.diy/templates/vc-diligence"
        },
        {
          "slug": "enterprise-questionnaire-kit",
          "title": "Enterprise Questionnaire Response Kit",
          "url": "https://ciso.diy/templates/enterprise-questionnaire-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cyber-insurance-readiness-kit",
      "title": "Cyber Insurance Application Readiness Kit",
      "description": "Answer the cyber insurance questionnaire honestly and still get approved — a 37-control self-assessment that sorts your fixes the way underwriters actually score them, an evidence binder skeleton, broker email templates, and an answer bank with truthful wording for the partial controls that get claims denied.",
      "url": "https://ciso.diy/templates/cyber-insurance-readiness-kit",
      "image": "https://ciso.diy/images/og/cyber-insurance-readiness-kit.png",
      "category": "cyber-insurance",
      "categoryLabel": "Cyber Insurance",
      "type": "product",
      "tags": [
        "cyber insurance",
        "underwriting",
        "application",
        "SMB",
        "MFA",
        "evidence binder",
        "broker",
        "MSP"
      ],
      "keyFacts": [
        "**“Yes” to a half-enforced control is the fact a carrier denies the claim on.** The answer bank gives truthful wording for the *partial* state across 15 controls, so you disclose accurately and still present well.",
        "37 controls, each carrying **the carrier’s own tier** — pass/fail (missing it commonly means a decline), rated (weak means higher premium or sub-limit), or credit (documented may earn 5–10%).",
        "The fix-first sheet sorts by that tier, so the top of your list is **“restore-test your backups”, not “consider a SIEM”**.",
        "An evidence binder skeleton of 16 numbered folders you fill as you remediate — so the binder is built by the time you apply."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "organization",
          "name": "Organization License",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 19900,
          "listPrice": 24900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vendor-risk-operations-kit",
      "title": "Vendor Risk Operations Kit",
      "description": "The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.",
      "url": "https://ciso.diy/templates/vendor-risk-operations-kit",
      "image": "https://ciso.diy/images/og/vendor-risk-operations-kit.png",
      "category": "vendor-risk",
      "categoryLabel": "Vendor Risk",
      "type": "product",
      "tags": [
        "vendor risk",
        "TPRM",
        "DORA",
        "Register of Information",
        "third-party",
        "AI vendors",
        "exit plan",
        "vCISO"
      ],
      "keyFacts": [
        "In the ESA dry run, **93% of firms failed data-quality checks** — and the failures were mechanical, not conceptual: missing LEIs, critical functions with no exit reference, contracts not linked to functions, subcontractor chains that stop halfway.",
        "The Register of Information builder carries **ten automatic quality checks** aimed at exactly those failures. It tells you which rows would be rejected **before a supervisor does**.",
        "It is a **working model, not the xBRL-CSV submission template**, and it files nothing. The column map to the ESA technical package is a planned v1.1.",
        "The annual review produces a **computed indicated decision** that must then be recorded as an actual decision with conditions — a review that ends in a filed document rather than a decision is the most common failure in this discipline."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 9,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "tprm-program-kit",
      "title": "TPRM Program Kit",
      "description": "Tier your vendors in an afternoon, then run the programme — a seven-factor tiering model everything else computes from, a 150-question bank across 15 domains (with an AI-vendor domain) mapped to CSF 2.0 / ISO 27001 / SOC 2, 20 contract clauses with a fallback ladder, an ERR-01-compatible risk register, monitoring cadence, and fourth-party concentration scoring.",
      "url": "https://ciso.diy/templates/tprm-program-kit",
      "image": "https://ciso.diy/images/og/tprm-program-kit.png",
      "category": "vendor-risk",
      "categoryLabel": "Vendor Risk",
      "type": "product",
      "tags": [
        "TPRM",
        "third-party risk",
        "vendor risk",
        "supplier assurance",
        "vendor tiering",
        "DORA",
        "GV.SC",
        "vCISO"
      ],
      "keyFacts": [
        "A **150-question bank across 15 domains** — original content, not a re-typed SIG — with **Q20 and Q60 as tested subsets of the same bank** rather than separate documents that drift apart.",
        "Every question maps to NIST CSF 2.0, ISO 27001:2022 and SOC 2, so **a vendor’s answers double as evidence for your own audits**.",
        "Includes an **AI-vendor domain** most off-the-shelf sets still lack: training-data use, model change control, sub-processor disclosure.",
        "Seven-factor tiering with weights you can change and a **Tier 2 floor override**, so anyone holding domain admin cannot score their way down. Register rows, concentration counts and the board slide all compute from that sheet."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 11,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 35900,
          "listPrice": 44900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 71900,
          "listPrice": 89900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "breach-first-72-hours-kit",
      "title": "I've Been Breached — The First 72 Hours Command Kit",
      "description": "It's 6 a.m. and everything is encrypted. This is what you do, and what you don't — a printable Hour-Zero card with the call order (insurer before any vendor, because off-panel forensics can void coverage), a workbook computing 25 notification clocks from your discovery time, the eight-gate ransom decision, and eleven communications templates.",
      "url": "https://ciso.diy/templates/breach-first-72-hours-kit",
      "image": "https://ciso.diy/images/og/breach-first-72-hours-kit.png",
      "category": "incident-response",
      "categoryLabel": "Incident Response",
      "type": "product",
      "tags": [
        "incident response",
        "breach",
        "ransomware",
        "crisis management",
        "business owner",
        "notification",
        "breach coach",
        "MSP"
      ],
      "keyFacts": [
        "**Leave the machines on and disconnect them.** Powering off destroys memory and, often, the encryption keys.",
        "**The insurer hotline comes before any vendor**, because engaging off-panel forensics can void the coverage that pays for all of this.",
        "**Clocks run from discovery, not from confirmation.** The workbook computes 25 of them, including the ones people do not know they have — customer contracts, PCI, FTC Safeguards, the credit bureaus, the 24-hour payment clocks.",
        "Written for the person in charge of the responders rather than the responders: an owner, GM, GC or CFO running five parallel lanes from one decision log."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "organization",
          "name": "Organization License",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "executive-tabletop-kit",
      "title": "Executive Tabletop Exercise Kit",
      "description": "Eight board-ready scenarios, ninety minutes each — 64 injects that each name the decision they force and the question to ask the room, a decision log that pre-fills and scores itself on time-to-decide, and an after-action report carrying the regulatory evidence statement for NYDFS 500.16(d), DORA Art. 11 and NIS2 Art. 20. A billable engagement in a box.",
      "url": "https://ciso.diy/templates/executive-tabletop-kit",
      "image": "https://ciso.diy/images/og/executive-tabletop-kit.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "tabletop",
        "exercise",
        "board",
        "executive",
        "incident response",
        "NYDFS 500.16",
        "DORA",
        "vCISO"
      ],
      "keyFacts": [
        "Regulators stopped accepting a documented plan: NYDFS 500.16(d) wants it **tested, “including senior officers”**, and DORA Art. 11 and NIS2 Art. 20 say the same. An untested plan and no plan are now treated as roughly the same thing.",
        "Each of the **64 injects names the decision it forces** — who calls the bank, whether to disable the agent, pay or don’t — and the question to put to the room.",
        "**“Unknown at this time” is a legitimate state** the group has to handle rather than a gap in the script, because that is the actual condition of hour one.",
        "The after-action report carries a one-paragraph **regulatory evidence statement** citing NYDFS 500.16(d), DORA Art. 11, NIS2 Art. 20, ISO 27001 and SOC 2 CC7.3 — the artefact a general counsel files after the session."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "security-metrics-library",
      "title": "Security Metrics & KPI Library",
      "description": "Stop reporting patch counts. 86 defined metrics with formulas, source systems, starting targets and an anti-gaming note each, mapped to CSF 2.0 / ISO 27001 / CIS v8 / SOC 2 and to the regimes that pull them — plus the twelve to start with at any maturity, a protection-level sheet that turns targets into priced decisions the board owns, and a dashboard that rolls one data-entry sheet into board, exec and ops views.",
      "url": "https://ciso.diy/templates/security-metrics-library",
      "image": "https://ciso.diy/images/og/security-metrics-library.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "security metrics",
        "KPI",
        "KRI",
        "board reporting",
        "ODM",
        "dashboard",
        "protection levels",
        "vCISO"
      ],
      "keyFacts": [
        "**86 metrics, not 100** — deliberately. Padding to the spec would have meant vanity metrics, which the guide spends a section arguing against.",
        "Every metric carries a formula, the source system, a starting target, a lead/lag flag, framework mappings, regulatory pull, industry flags and **an anti-gaming note saying how that specific number gets fudged**.",
        "**The twelve** are the same list three ways: the insurable baseline, the NYDFS certification core, and what examiners ask for first — so a new leader, an underwriter and an examiner look at one list rather than three.",
        "Protection levels turn targets into decisions: the sheet records **cost-to-hold and the business owner who agreed**, so “MTTR four hours versus one hour” becomes a priced option the board owns rather than a target the CISO wishes for.",
        "**Denominators come from the inventory, never from the tool.** 98% EDR coverage measured across the machines EDR already knows about is a tautology, not coverage."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 7900,
      "listPriceFrom": 9900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 7900,
          "listPrice": 9900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 19900,
          "listPrice": 24900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ciso-first-100-days-kit",
      "title": "The First 100 Days Kit",
      "description": "New seat, empty seat, or fractional seat — the hundred days that decide your tenure. Four entry modes auto-filter a 34-task plan, a 14-domain baseline including AI governance and personal liability, a budget builder in percent of revenue and IT, and the role charter and fractional engagement letter with a no-certification-without-verification clause.",
      "url": "https://ciso.diy/templates/ciso-first-100-days-kit",
      "image": "https://ciso.diy/images/og/ciso-first-100-days-kit.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "new CISO",
        "first 100 days",
        "vCISO",
        "fractional CISO",
        "interim",
        "engagement letter",
        "personal liability",
        "AI governance"
      ],
      "keyFacts": [
        "Average CISO tenure is under four years and roughly a third of seats change hands in any year, which makes **“the last one left” the modal way a security leader arrives**, not an edge case.",
        "**Four entry modes, one plan.** The 34-task plan auto-filters by the mode you set — an interim sees continuity tasks first, a fractional sees the engagement-letter and retainer tasks, a first-ever leader gets governance basics front-loaded.",
        "Both the charter and the engagement letter carry a **no-certification-without-verification clause**: where a regulator makes a named person certify, that signature is personal, and a fractional CISO can be asked to sign for controls they were never given access to verify.",
        "**AI governance and personal liability are baseline domains in their own right** — 14 domains scored 0–4, with an AI-inventory task in week two."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 6,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "nydfs-part-500-kit",
      "title": "NYDFS Part 500 Compliance Kit",
      "description": "Certification is April 15 — this decides whether you can sign it. A 19-section crosswalk whose summary produces the Certification-vs-Acknowledgment recommendation, all sixteen 500.3 policy areas with board-approval tracking, both filing forms pre-drafted with a two-signatory review record, the 72-hour and 24-hour notice templates, and the board report mapped to the six 500.4(c) topics.",
      "url": "https://ciso.diy/templates/nydfs-part-500-kit",
      "image": "https://ciso.diy/images/og/nydfs-part-500-kit.png",
      "category": "compliance",
      "categoryLabel": "Compliance",
      "type": "product",
      "tags": [
        "NYDFS",
        "23 NYCRR 500",
        "Part 500",
        "certification",
        "financial services",
        "insurance",
        "NAIC",
        "vCISO"
      ],
      "keyFacts": [
        "The centre of this is **the April 15 decision**: can you sign a Certification of Material Compliance, or do you owe an Acknowledgment of Noncompliance? The crosswalk turns section ratings into that recommendation.",
        "**A false certification is itself a violation**, and it is signed personally by the CISO and the highest-ranking executive. Both forms are pre-drafted, because the honest answer is sometimes the Acknowledgment.",
        "**Sixteen** policy areas at 500.3(a)–(p), not the fourteen most summaries repeat.",
        "Enforcement reaches small licensees — the Healthplex action was against an **insurance agent**, for no MFA, no retention policy and a late notice."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 15900,
      "listPriceFrom": 19900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 15900,
          "listPrice": 19900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 39900,
          "listPrice": 49900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "sec-8k-materiality-workbook",
      "title": "SEC 8-K Item 1.05 Materiality Workbook",
      "description": "Four business days — have the materiality process before you need it. 12-factor scoring with Known/Unknown flags, a timestamped clock log that evidences \"without unreasonable delay\", computed 8-K and 8-K/A deadlines, and the language-to-avoid table for the wording that enforcement has actually punished.",
      "url": "https://ciso.diy/templates/sec-8k-materiality-workbook",
      "image": "https://ciso.diy/images/og/sec-8k-materiality-workbook.png",
      "category": "governance",
      "categoryLabel": "Governance",
      "type": "product",
      "tags": [
        "SEC",
        "8-K",
        "Item 1.05",
        "Item 1C",
        "materiality",
        "disclosure",
        "public company",
        "board oversight"
      ],
      "keyFacts": [
        "Three years into Item 1.05, the SEC has **never penalised a registrant for filing late**. The October 2024 settlements — roughly $8M across four issuers — were about wording: impact described as hypothetical or limited when the company knew otherwise.",
        "Two clocks, kept apart. Discovery to determination has no fixed length and must be **evidenced step by step**; determination to filing is four business days to 5:30 pm ET. Conflating them is how programmes panic early or drift late.",
        "The 8-K template ships with a **language-to-avoid table**. \"No evidence of exfiltration\" is only true if your logging would have shown exfiltration.",
        "Every Item 1C paragraph carries a **\"basis\" line** naming the evidence that makes the sentence true — so anything the programme does not actually do this year comes out."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 8,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 11900,
      "listPriceFrom": 14900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 11900,
          "listPrice": 14900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 31900,
          "listPrice": 39900,
          "formats": [
            "zip"
          ],
          "recommended": true
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ma-exit-readiness-kit",
      "title": "Sell-Side Cyber Exit Readiness Kit",
      "description": "Look clean before they look. Run the buyer's cyber diligence on yourself 6–18 months out: a pre-mortem that scores the company today and at launch and sets escrow avoided against programme cost, the 41-artifact data room a buyer will ask for, a funded remediation programme, and a disclosure builder that turns every finding into fix, disclose or price.",
      "url": "https://ciso.diy/templates/ma-exit-readiness-kit",
      "image": "https://ciso.diy/images/og/ma-exit-readiness-kit.png",
      "category": "due-diligence",
      "categoryLabel": "Due Diligence",
      "type": "product",
      "tags": [
        "M&A",
        "private equity",
        "exit readiness",
        "sell-side",
        "data room",
        "disclosure schedule",
        "sponsor",
        "vCISO"
      ],
      "keyFacts": [
        "In the worked example a **$475,000 programme moves the target from PRICE & PROTECT with a $712,000 escrow ask to PROCEED**. Escrow avoided against programme cost is the ratio an operating partner needs before approving anything.",
        "The real decision per finding is **fix, disclose, or price** — and the schedule language is written in the structure of the buy-side kit’s eight buyer representations, so the two kits answer each other.",
        "The 41 artifacts a buyer’s diligence request list asks for, reorganised as the **seller’s** folder structure, so the cyber conversation closes in week one instead of running the whole confirmatory period.",
        "The Q&A bank exists for one failure mode: **the IT lead answering “what happens if he left tomorrow?” honestly and unrehearsed** is how an otherwise clean process acquires a finding."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 7,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 143900,
          "listPrice": 179900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ma-cyber-due-diligence-kit",
      "title": "M&A Cyber Due Diligence Kit",
      "description": "Find the breach before you buy it — a 3–4 week diligence method for mid-market add-ons and roll-ups. 46 phased requests, four interview tracks, and a red-flag model with anchored scoring that outputs cost-to-cure in basis points of EV and a proposed escrow multiple, with each SPA lever mapped back to the finding that justifies it.",
      "url": "https://ciso.diy/templates/ma-cyber-due-diligence-kit",
      "image": "https://ciso.diy/images/og/ma-cyber-due-diligence-kit.png",
      "category": "due-diligence",
      "categoryLabel": "Due Diligence",
      "type": "product",
      "tags": [
        "M&A",
        "private equity",
        "due diligence",
        "roll-up",
        "acquisition debt",
        "escrow",
        "corp dev",
        "vCISO"
      ],
      "keyFacts": [
        "Eight domains scored 0–4 against **anchored descriptors**, so two reviewers land on the same number, with **two hard triggers** that force WALK or RESTRUCTURE regardless of the total.",
        "The model converts cost-to-cure into **basis points of enterprise value** and a proposed **escrow multiple** — so the output arrives in the vocabulary the investment committee already uses, and the conversation starts at price rather than at patching.",
        "Each reps-and-warranties lever **maps back to the finding that justifies it**, so counsel is not asked to argue for language with no evidence behind it.",
        "A 3–4 week method: 46 phased requests, four interview tracks, a passive external attack-surface check, and a funded 100-day plan."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": 10,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 63900,
          "listPrice": 79900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 143900,
          "listPrice": 179900,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "both-sides-of-the-deal",
      "title": "Both Sides of the Deal",
      "description": "The M&A Cyber Due Diligence Kit + the Sell-Side Cyber Exit Readiness Kit — the same eight-domain method run as a buyer and as a seller. The disclosure schedules are structured around the buyer reps, so the two kits answer each other. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/both-sides-of-the-deal",
      "image": "https://ciso.diy/images/og/both-sides-of-the-deal.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "M&A",
        "private equity",
        "due diligence",
        "exit readiness",
        "sponsor",
        "bundle"
      ],
      "keyFacts": [
        "**A sponsor is usually on both sides within the same year** — buying add-ons for one platform while preparing another for exit — and an operating partner who knows exactly what a buyer will price is a better buyer too.",
        "For a fractional CISO, the pair is two distinct engagements off one method: a four-week diligence and a twelve-month readiness programme.",
        "The sell-side disclosure schedules are written in the structure of the buy-side reps, **so the two kits literally answer each other**."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 35800,
      "listPriceFrom": 44800,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 35800,
          "listPrice": 44800,
          "formats": [
            "zip"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 95800,
          "listPrice": 119800,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 215800,
          "listPrice": 269800,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ma-cyber-due-diligence-kit",
          "title": "M&A Cyber Due Diligence Kit",
          "url": "https://ciso.diy/templates/ma-cyber-due-diligence-kit"
        },
        {
          "slug": "ma-exit-readiness-kit",
          "title": "Sell-Side Cyber Exit Readiness Kit",
          "url": "https://ciso.diy/templates/ma-exit-readiness-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ma-diligence-complete",
      "title": "M&A Diligence Complete",
      "description": "The M&A Cyber Due Diligence Kit + the M&A Cyber Diligence Workbook — the engagement method and the deal model together. Run the diligence with one, price the findings with the other. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/ma-diligence-complete",
      "image": "https://ciso.diy/images/og/ma-diligence-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "M&A",
        "private equity",
        "due diligence",
        "deal team",
        "corp dev",
        "bundle"
      ],
      "keyFacts": [
        "**The kit is the process — what to request, who to interview, how to score it, what to hand counsel. The workbook is the arithmetic — what the findings cost and which deal mechanism carries them.**",
        "On a fast add-on you may run the workbook alone; on a platform deal or a roll-up you want the full engagement, and the workbook becomes the model inside it."
      ],
      "formats": [
        "zip",
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 29800,
      "listPriceFrom": 37300,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 29800,
          "listPrice": 37300,
          "formats": [
            "zip",
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 83800,
          "listPrice": 104800,
          "formats": [
            "zip",
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 197800,
          "listPrice": 247300,
          "formats": [
            "zip",
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ma-cyber-due-diligence-kit",
          "title": "M&A Cyber Due Diligence Kit",
          "url": "https://ciso.diy/templates/ma-cyber-due-diligence-kit"
        },
        {
          "slug": "ma-cyber-diligence",
          "title": "M&A Cyber Diligence Workbook",
          "url": "https://ciso.diy/templates/ma-cyber-diligence"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vendor-risk-complete",
      "title": "Vendor Risk Complete",
      "description": "The TPRM Program Kit + the Vendor Risk Operations Kit — design the programme, then actually run it. Tiering, questionnaires and clauses on one side; dossiers, scorecards, exit tests and the Register of Information on the other.",
      "url": "https://ciso.diy/templates/vendor-risk-complete",
      "image": "https://ciso.diy/images/og/vendor-risk-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "vendor risk",
        "TPRM",
        "third-party",
        "DORA",
        "supplier assurance",
        "bundle"
      ],
      "keyFacts": [
        "**The operations kit assumes tiers exist, questionnaires have gone out and contracts carry the clauses — all of which the programme kit produces.** Bought alone it is an operating layer with nothing underneath.",
        "Bought the other way round you have a designed programme that nobody runs after the first quarter — **the more common failure, and the harder one to notice**.",
        "Together they answer the two questions a supervisor asks in order: how do you manage vendor risk here, and what is the state of this vendor right now."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 23900,
      "listPriceFrom": 29900,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 23900,
          "listPrice": 29900,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 77800,
          "listPrice": 97300,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "tprm-program-kit",
          "title": "TPRM Program Kit",
          "url": "https://ciso.diy/templates/tprm-program-kit"
        },
        {
          "slug": "vendor-risk-operations-kit",
          "title": "Vendor Risk Operations Kit",
          "url": "https://ciso.diy/templates/vendor-risk-operations-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "new-ciso-starter",
      "title": "New CISO Starter",
      "description": "The First 100 Days Kit + the Cyber Insurance Application Readiness Kit + the First 72 Hours Command Kit — the plan, the fastest honest baseline, and the crisis card. The same first month. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/new-ciso-starter",
      "image": "https://ciso.diy/images/og/new-ciso-starter.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "new CISO",
        "vCISO",
        "fractional CISO",
        "onboarding",
        "cyber insurance",
        "incident response",
        "bundle"
      ],
      "keyFacts": [
        "**The plan, the fastest honest baseline, and the crisis card — the same first month.**",
        "37 controls scored the way a carrier scores them beats a maturity assessment for speed, and **insurance renewal is usually the first hard deadline waiting in the seat**.",
        "The command kit is the gap that turns a bad week into a bad year if the incident arrives before the programme does."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 20800,
      "listPriceFrom": 26000,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 20800,
          "listPrice": 26000,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 56800,
          "listPrice": 71000,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ciso-first-100-days-kit",
          "title": "The First 100 Days Kit",
          "url": "https://ciso.diy/templates/ciso-first-100-days-kit"
        },
        {
          "slug": "cyber-insurance-readiness-kit",
          "title": "Cyber Insurance Application Readiness Kit",
          "url": "https://ciso.diy/templates/cyber-insurance-readiness-kit"
        },
        {
          "slug": "breach-first-72-hours-kit",
          "title": "I've Been Breached — The First 72 Hours Command Kit",
          "url": "https://ciso.diy/templates/breach-first-72-hours-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "regime-clocks",
      "title": "The Regime Clocks",
      "description": "Four regulators, four clocks, one incident — the First 72 Hours Command Kit plus the CIRCIA, SEC 8-K and NYDFS Part 500 kits. The problem is sequencing: the confidential federal report precedes the public 8-K, and only the SEC clock waits for a materiality determination. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/regime-clocks",
      "image": "https://ciso.diy/images/og/regime-clocks.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "incident reporting",
        "CIRCIA",
        "SEC",
        "8-K",
        "NYDFS",
        "Part 500",
        "breach notification",
        "bundle"
      ],
      "keyFacts": [
        "**The problem is sequencing, not any single filing.** The confidential CIRCIA report usually precedes the public 8-K, the NYDFS notice runs on its own trigger, and **only the SEC clock waits for a materiality determination** — every other clock starts at discovery.",
        "Every kit’s clock sheet computes from the same input, the discovery timestamp, **so the four sequence against each other rather than being reconciled by hand at 3 a.m.**",
        "Few single companies are subject to all four. **The clearer buyer is a practice carrying clients across several regimes** — if you are subject to one, buy that kit on its own."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 35800,
      "listPriceFrom": 44700,
      "onSale": true,
      "licences": [
        {
          "id": "organization",
          "name": "Organization License",
          "price": 35800,
          "listPrice": 44700,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 95800,
          "listPrice": 119700,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "breach-first-72-hours-kit",
          "title": "I've Been Breached — The First 72 Hours Command Kit",
          "url": "https://ciso.diy/templates/breach-first-72-hours-kit"
        },
        {
          "slug": "circia-reporting-readiness",
          "title": "CIRCIA 72/24 Reporting Readiness Pack",
          "url": "https://ciso.diy/templates/circia-reporting-readiness"
        },
        {
          "slug": "sec-8k-materiality-workbook",
          "title": "SEC 8-K Item 1.05 Materiality Workbook",
          "url": "https://ciso.diy/templates/sec-8k-materiality-workbook"
        },
        {
          "slug": "nydfs-part-500-kit",
          "title": "NYDFS Part 500 Compliance Kit",
          "url": "https://ciso.diy/templates/nydfs-part-500-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cyber-before-and-after",
      "title": "Before & After",
      "description": "The Cyber Insurance Application Readiness Kit + the First 72 Hours Command Kit — qualify for the cover, then know not to void it at 6 a.m. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/cyber-before-and-after",
      "image": "https://ciso.diy/images/og/cyber-before-and-after.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "cyber insurance",
        "incident response",
        "breach",
        "SMB",
        "MSP",
        "bundle"
      ],
      "keyFacts": [
        "**The single most expensive mistake in the first hour is calling forensics before the insurer** — off-panel vendors can void the coverage you spent months qualifying for.",
        "Your application attested to controls. **If the incident reveals those answers were wrong, that is a misrepresentation problem on top of a breach** — which is what the answer bank exists to prevent."
      ],
      "formats": [
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 11800,
      "listPriceFrom": 14800,
      "onSale": true,
      "licences": [
        {
          "id": "organization",
          "name": "Organization License",
          "price": 11800,
          "listPrice": 14800,
          "formats": [
            "zip"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 32900,
          "listPrice": 41100,
          "formats": [
            "zip"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "cyber-insurance-readiness-kit",
          "title": "Cyber Insurance Application Readiness Kit",
          "url": "https://ciso.diy/templates/cyber-insurance-readiness-kit"
        },
        {
          "slug": "breach-first-72-hours-kit",
          "title": "I've Been Breached — The First 72 Hours Command Kit",
          "url": "https://ciso.diy/templates/breach-first-72-hours-kit"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cyber-insurance-complete",
      "title": "Cyber Insurance Complete",
      "description": "The Application Readiness Kit + the Cyber Insurance Workbook — get bound, then stay insurable. The kit runs the application and builds the evidence binder; the workbook is the standing programme between renewals. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/cyber-insurance-complete",
      "image": "https://ciso.diy/images/og/cyber-insurance-complete.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "cyber insurance",
        "underwriting",
        "application",
        "renewal",
        "broker",
        "bundle"
      ],
      "keyFacts": [
        "**The kit gets you bound; the workbook keeps you insurable.**",
        "The controls you attested to are the ones you must still have twelve months later — **and that is where most businesses quietly drift out of compliance with their own policy**."
      ],
      "formats": [
        "zip",
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 10600,
      "listPriceFrom": 13300,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 10600,
          "listPrice": 13300,
          "formats": [
            "zip",
            "xlsx",
            "docx"
          ],
          "recommended": true
        }
      ],
      "includes": [
        {
          "slug": "cyber-insurance-readiness-kit",
          "title": "Cyber Insurance Application Readiness Kit",
          "url": "https://ciso.diy/templates/cyber-insurance-readiness-kit"
        },
        {
          "slug": "cyber-insurance-workbook",
          "title": "Cyber Insurance Workbook",
          "url": "https://ciso.diy/templates/cyber-insurance-workbook"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "cra-complete-bundle",
      "title": "CRA Complete Bundle",
      "description": "EU Cyber Resilience Act Workbook + CRA 24-Hour Reporting Clock — the governance half and the operational half of the CRA in one purchase. 25% off buying them separately.",
      "url": "https://ciso.diy/templates/cra-complete-bundle",
      "image": "https://ciso.diy/images/og/cra-complete-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "CRA",
        "Cyber Resilience Act",
        "EU",
        "Article 14",
        "product security",
        "bundle"
      ],
      "keyFacts": [
        "**The workbook tells you whether the obligation attaches and what you must build. The clock tells you what to do in the twenty-four hours after someone exploits your product.**",
        "Buying only the first leaves you compliant on paper and improvising on the day; buying only the second leaves you with a runbook and no idea whether you are in scope."
      ],
      "formats": [
        "pdf",
        "zip"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-09-03",
      "priceCurrency": "USD",
      "priceFrom": 14900,
      "listPriceFrom": 18600,
      "onSale": true,
      "licences": [
        {
          "id": "standard",
          "name": "Standard",
          "price": 14900,
          "listPrice": 18600,
          "formats": [
            "pdf",
            "zip"
          ],
          "recommended": true
        }
      ],
      "includes": [
        {
          "slug": "cra-workbook",
          "title": "EU Cyber Resilience Act Workbook",
          "url": "https://ciso.diy/templates/cra-workbook"
        },
        {
          "slug": "cra-reporting-clock",
          "title": "CRA 24-Hour Reporting Clock",
          "url": "https://ciso.diy/templates/cra-reporting-clock"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "ir-stack-bundle",
      "title": "IR Stack Bundle",
      "description": "Ransomware Readiness Workbook + Tabletop Exercise Pack — prepare, practice, and survive a ransomware incident. 25% off individual pricing.",
      "url": "https://ciso.diy/templates/ir-stack-bundle",
      "image": "https://ciso.diy/images/og/ir-stack-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "ransomware",
        "incident response",
        "tabletop",
        "IR bundle",
        "playbook"
      ],
      "keyFacts": [
        "**The Ransomware Readiness Workbook builds your operational readiness. The Tabletop Exercise Pack tests it.**",
        "The readiness workbook includes a Tabletop Integration tab mapping directly to scenario S1 — run the tabletop, identify gaps, remediate, re-run."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 25800,
      "listPriceFrom": 32300,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 25800,
          "listPrice": 32300,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Organization License",
          "price": 66300,
          "listPrice": 82900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 149500,
          "listPrice": 186900,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "ransomware-readiness",
          "title": "2026 Ransomware Readiness Workbook",
          "url": "https://ciso.diy/templates/ransomware-readiness"
        },
        {
          "slug": "tabletop-exercise-pack",
          "title": "Tabletop Exercise Pack",
          "url": "https://ciso.diy/templates/tabletop-exercise-pack"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    },
    {
      "slug": "vciso-ops-bundle",
      "title": "vCISO Ops Bundle",
      "description": "vCISO Client-in-a-Box + Shadow AI Inventory + CISO Budget Workbook — the three tools every vCISO needs to run a full program. 18% off individual pricing.",
      "url": "https://ciso.diy/templates/vciso-ops-bundle",
      "image": "https://ciso.diy/images/og/vciso-ops-bundle.png",
      "category": "bundle",
      "categoryLabel": "Bundles",
      "type": "bundle",
      "tags": [
        "vCISO",
        "MSSP",
        "shadow AI",
        "budget",
        "governance bundle"
      ],
      "keyFacts": [
        "The three workbooks a vCISO runs a client on day to day: the client management system, the shadow AI inventory, and the budget model that turns findings into a funded ask."
      ],
      "formats": [
        "xlsx",
        "docx"
      ],
      "deliverables": null,
      "version": "1.0",
      "updated": "2026-04-23",
      "priceCurrency": "USD",
      "priceFrom": 58600,
      "listPriceFrom": 73200,
      "onSale": true,
      "licences": [
        {
          "id": "individual",
          "name": "Individual Practitioner",
          "price": 58600,
          "listPrice": 73200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        },
        {
          "id": "organization",
          "name": "Team License",
          "price": 150600,
          "listPrice": 188200,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": true
        },
        {
          "id": "mssp",
          "name": "vCISO / MSSP License",
          "price": 344300,
          "listPrice": 430400,
          "formats": [
            "xlsx",
            "docx"
          ],
          "recommended": false
        }
      ],
      "includes": [
        {
          "slug": "vciso-client-in-a-box",
          "title": "vCISO Client-in-a-Box",
          "url": "https://ciso.diy/templates/vciso-client-in-a-box"
        },
        {
          "slug": "shadow-ai-inventory",
          "title": "Shadow AI Inventory & Risk Scoring Workbook",
          "url": "https://ciso.diy/templates/shadow-ai-inventory"
        },
        {
          "slug": "ciso-budget-workbook",
          "title": "2026 CISO Budget Workbook",
          "url": "https://ciso.diy/templates/ciso-budget-workbook"
        }
      ],
      "availability": "InStock",
      "delivery": "digital-download"
    }
  ]
}