Skip to main content

GRC & Compliance

Per-tenant monthly add-on. ISO 27001, NIS2, GDPR coverage via Cyberday ISMS. Available to COSAINT clients below the 50-user COSAINT Strategic minimum.

Available to COSAINT clients below the 50-user COSAINT Strategic minimum. At 50 users and above, GRC is included in COSAINT Strategic.

Discuss Your Compliance Requirements

Four levels of compliance support

Start with the ISMS platform, policy framework, and the logging ISO 27001 requires. Add a named compliance consultant, certification support, and vCISO advisory as your requirements grow.

GRC Foundation

ISMS platform and policy framework

EUR 945 /tenant/mo

Get your ISMS running on Cyberday with ISO 27001 control mapping, a maintained policy library, and the logging Annex A requires. Managed by Tarbh Tech, reviewed quarterly. Suits organisations driving their own compliance programme.

  • Cyberday ISMS platform, full framework library included
  • ISO 27001 Annex A control mapping and evidence artefacts
  • Policy library setup and maintenance
  • Blackpoint LogIC SIEM: log collection, retention, and monitoring (Annex A 8.15, 8.16)
  • Platform administration and user management
  • Quarterly ISMS review

GRC Managed

Foundation plus a named ISMS owner

EUR 2,095 /tenant/mo

A named compliance consultant owns your ISMS day to day, with fortnightly working sessions. For organisations building towards certification or maintaining an ISMS without internal resource.

  • Everything in GRC Foundation
  • Named ISMS owner, a qualified compliance consultant
  • Fortnightly 2-hour workshops with minutes and action tracking
  • Risk assessment, risk register, and risk treatment plan
  • Statement of Applicability
  • Supplier and vendor security assessments
  • Management review twice yearly

GRC Certified

Managed plus audit and certification

EUR 2,495 /tenant/mo

Everything needed to reach certification and hold it. Independent internal audit, and we attend the external audits with you. For organisations actively certifying or already certified.

  • Everything in GRC Managed
  • Annual independent internal audit by a qualified ISO 27001 lead auditor
  • Stage 1 and Stage 2 certification support
  • Surveillance and recertification audit attendance
  • Non-conformity and corrective action tracking to closure

GRC Advisory

Certified plus vCISO and multi-framework

EUR 2,895 /tenant/mo

Adds strategic security advisory and support for frameworks beyond ISO 27001. For regulated organisations, or those reporting compliance posture to a board.

  • Everything in GRC Certified
  • vCISO advisory, 4 hours per month
  • Multi-framework implementation: NIS2, DORA, GDPR, ISO 27701
  • Business continuity plan documentation
  • Tabletop exercise facilitation
  • Quarterly management review reports and board-level narrative

Prices are per tenant per month, exclusive of VAT, and do not vary with user count. External certification body fees are payable directly by the client.

Frameworks covered

ISO 27001

International standard for information security management systems. Annex A control mapping and evidence packs included.

NIS2

EU Network and Information Systems Directive. Readiness assessment and alignment for essential and important entities.

GDPR

General Data Protection Regulation. Data protection policies, breach notification procedures, and processor management.

GRC & Compliance FAQ

Which COSAINT tier do I need?
Any COSAINT tier qualifies. The GRC add-on is designed for organisations below the 50-user COSAINT Strategic minimum, so it sits on top of whichever tier you are already on. At 50 users and above, GRC is included in COSAINT Strategic and no separate add-on is needed.
What is Cyberday?
Cyberday is an ISMS (Information Security Management System) platform that manages your compliance framework digitally. It maps controls to ISO 27001 Annex A, tracks evidence, manages policies, and provides a continuous view of your compliance posture. We set it up, maintain it, and run workshops to keep it current.
Can I start with GRC Foundation and upgrade later?
Yes. GRC Foundation suits organisations driving their own compliance programme. GRC Managed adds a named ISMS owner with fortnightly working sessions. GRC Certified adds independent internal audit and certification support. GRC Advisory adds vCISO advisory and frameworks beyond ISO 27001. You can move up a level at any renewal point, or mid-term with a prorated adjustment.
What if we are on COSAINT Strategic?
At 50 users and above, GRC capability is already included in the COSAINT Strategic base tier – Cyberday ISMS, Microsoft Purview, Microsoft Sentinel, and vCISO advisory all form part of the tier. Strategic clients do not need a separate GRC add-on.

Discuss your compliance requirements

ISO 27001, NIS2, GDPR – we will help you build and maintain the compliance framework your organisation needs.

Get in Touch

Or email us at hello@tarbh.tech