what is an ITSP pricing why now what you get the seven phases the difference order process order
ITSP — IT Security Plan

Your IT Security Plan, delivered in weeks — not quarters

A complete IT risk assessment and a security plan that treats every risk it finds — each with an owner, a deadline and a residual risk figure. Built to ITSRM v1.2, written by security-cleared senior consultants, at a price fixed before we start.

2–4 weeks
typical delivery
€9,800
fixed, from
ITSRM v1.2
methodology
EU PSC
cleared delivery
cl2r — itsp builder — local
~/cl2r › itsp build --system AGENCY-PORTAL --itsrm 1.2 CL2R ITSP Builder · runs locally · no external API   network isolation test ..... PASS   P1 system characterisation .... ✓ confirmed P2 primary assets ............. ✓ confirmed P3 supporting assets .......... ✓ confirmed P4 system modelling ........... ✓ confirmed P5 risk identification ........ 41 risks P6 risk analysis .............. computed, not generated P7 risk treatment ............. 38 treated · 3 accepted   ITSP_AGENCY-PORTAL_v1.0.docx ready for signature ITSP_AGENCY-PORTAL_risk.xlsx full risk study   7 phase gates · 7 sign-offs · one senior consultant ~/cl2r ›
Plain English

What is an ITSP?

Two halves in one approved document: the assessment that tells you where you stand, and the plan that tells you what to do about it.

IT Security Plan (ITSP)

The ITSP is the security document approved for a single CIS (Communication and Information System). It records what the system is, what data and functions it holds, how valuable those are to the organisation, what could compromise them, and what will be done about it — in a form your system owner can sign and your auditor can follow.

It is written against ITSRM (the IT Security Risk Management methodology, version 1.2, published by DG DIGIT Unit S1), which is the method EU institutions, bodies and agencies are expected to apply.

Assessment + remediation, together

  • 1. IT risk assessment. Data and functions valued on confidentiality, integrity and availability; supporting assets mapped; threats and risk scenarios identified; every risk scored and compared against the risk acceptance criteria agreed with you.
  • 2. Security plan. For every risk above the acceptance threshold, a named mitigation or remediation measure — with an owner, a sophistication level, a deadline, and the residual risk that remains once the measure is in place. Risks you choose to accept are recorded explicitly, with the accepting authority.

The assessment tells you where you stand. The plan tells you what to do. The same document evidences both — to your management, to your auditor, and to the regulator.

Pricing

Fixed price per plan. No day-rate surprises.

Choose the band that matches your system. The price is locked at scoping and does not move if the work turns out larger within that band.

Single system

Essential ITSP

€9,800
fixed price

One system with a contained footprint. Full IT risk assessment plus the mitigation and remediation plan, delivered remotely.

  • One system, straightforward architecture
  • Complete IT risk assessment
  • Mitigation and remediation plan
  • Approval-ready Word document + supporting workbook
  • One remote scoping workshop
  • Delivered in 2 weeks
  • 30 days post-delivery support
Order Essential
Extended scope

Complex ITSP

from€25,000
fixed price

The same complete engagement, sized for a bigger system: full assessment, full remediation plan, and support all the way to management approval — across every module and dependency in scope.

  • One production system with several modules, or with many dependencies
  • Inherited and shared-infrastructure risks handled explicitly
  • Everything in Standard ITSP
  • On-site workshops across your teams
  • Approval and governance support
  • Delivered in 5–7 weeks
  • 30 days post-delivery support
Order Complex

All prices are in euro and exclude VAT. Remote delivery is all-in — no expenses charged. Payment terms: 50% on order, 50% on acceptance. The price agreed at scoping is fixed: if the work turns out larger within the stated band, the price does not move. Framework and subcontracting arrangements are welcome — tell us your vehicle and we will quote accordingly.

Why Now

Two clocks are running. Both are against you.

The regulatory clock has already struck: for EU entities an approved cybersecurity plan stopped being good practice and became a legal obligation, with deadlines that are now behind us. The threat clock never stops — adversaries re-tool in days, your architecture changes every sprint, and a risk assessment that takes two quarters to write is out of date before it is signed. Compliance and defence now demand the same thing: a current, approved IT security action plan, produced fast enough to still be true.

Regulation (EU, Euratom) 2023/2841

Requires every Union entity to run a cybersecurity risk-management framework and to adopt an approved cybersecurity plan. Its implementation milestones — April 2025, September 2025 and January 2026 — have all passed. If your system has no current IT Security Plan, that is compliance debt accruing today.

Decision (EU, Euratom) 2017/46

Article 3 §4 states that IT security shall be based on a risk management process aimed at determining the levels of IT security risk and defining security measures to reduce them to an appropriate level at a proportionate cost. Together with its implementing rules of 13 December 2017, this is what the ITSP evidences.

ITSRM v1.2 is the method

A plan that does not follow the prescribed methodology will not survive review. We write to ITSRM v1.2 as a matter of course, so your plan speaks the language your reviewers, auditors and management already expect.

The Deliverable

A plan you can sign, defend and act on

“Our IT Security Plan is overdue, the system owner needs a signed plan with real remediation actions, and nobody has twenty days to spend on it.”

You receive a complete, approval-ready IT Security Plan for your system — professionally written, methodologically sound, and finished in weeks. Not a slide deck, not a findings memo. The actual document your system owner signs and your reviewers accept.

What that means for you

  • Fast. Weeks, not quarters. A plan that has been overdue for a year stops being overdue this month, without your team being pulled off their day jobs to produce it.
  • Professionally written. Institutional register, the structure reviewers expect, and an executive summary your management can actually read. No template filled in with placeholders.
  • Actionable. Every risk that matters comes with a concrete mitigation or remediation measure, a named owner and a deadline — so the plan turns into work, not shelf-ware.
  • Approval-ready. Written to be signed. It arrives with an approval note and we stay with you through the review cycle until it is accepted.
  • Cleared hands only. Written by a senior consultant holding an EU Personnel Security Clearance. No junior rotation, no offshore team, no handover halfway through.
  • Defensible. Built to ITSRM v1.2, so when someone asks how a number was reached, there is a method behind it — not a judgement call nobody can reconstruct.
  • Priced up front. One fixed fee agreed before we start. Rework inside the agreed scope costs you nothing.

Methodology & references

ITSRM v1.2 Reg. 2023/2841 Decision 2017/46 ISO 27005 ISO 27001 NIS2
Order an ITSP
The Method

Seven phases, one gate at each

01

System characterisation

02

Primary assets

03

Supporting assets

04

System modelling

05

Risk identification

06

Risk analysis & evaluation

07

Risk treatment

Learn more
The Difference

Same methodology. A fraction of the calendar.

The usual way
  • 15–25 consultant-days of effort per plan
  • Several months of elapsed time, often across two budget periods
  • Junior-heavy teams, senior review at the end
  • Billed by the day — every rework cycle costs you again
  • Tables rebuilt by hand whenever the architecture changes
With CL2R Advisory
  • 4–5 consultant-days of senior time per plan
  • 2–4 weeks elapsed, including your workshops and review cycles
  • One senior, security-cleared consultant, start to finish
  • One fixed price, agreed before we start — rework included
  • Change one asset and every dependent table recomputes

To be clear about where the time goes: document production itself is a matter of hours. The weeks are your scoping workshop, your document intake, your review at each of the seven gates, and your approval cycle. We have compressed the consultant’s desk work, not your governance.

Order Process

From first call to signed plan, in five steps

No procurement theatre. You know the price before the work starts, and what we need from you at every step.

01

Scoping call

Thirty minutes, free, no obligation. We establish what the system is, how complex it really is, your deadline, and which package fits.

02

Fixed-price offer

Within two business days you receive a written offer: scope, package, price, timeline, deliverables and acceptance criteria. Sign it and the price is locked.

03

Kick-off and intake

NDA in place, then a scoping workshop. You provide architecture documentation, the data inventory, existing controls and the names of your security roles. We do the rest.

04

Seven phases, seven gates

We work through the methodology phase by phase. You review and confirm each phase output before the next begins — short, focused reviews rather than one 80-page surprise at the end.

05

Delivery and approval

The finished IT Security Plan, the supporting workbook, and an approval note ready for signature — plus thirty days of support through your approval cycle.

Order

Start your ITSP

Book the scoping call, send the form, or simply email us. We reply to every enquiry within 24 business hours.

Step 1 — book a scoping call

Thirty minutes, free. The fastest route to a fixed price for your system.

Open calendar

Email

info@cl2r-advisory.com

Put your system name and target deadline in the subject line and we will come back with a scope proposal.

Response time

All enquiries answered within 24 business hours. Fixed-price offers issued within 2 business days of the scoping call.

Security-cleared delivery

Your plan is written by a senior consultant holding an EU Personnel Security Clearance — not by a junior team, and not offshore. Sensitive material stays with cleared personnel from intake to approval.

Your data will only be used to respond to your enquiry. We do not share your information with third parties. Please do not include classified or sensitive system details in this form — we will agree a secure channel before intake. See our Privacy Policy.

Get started

Your IT Security Plan is already overdue. Ours takes weeks.

Book a free 30-minute scoping call and get a fixed-price offer within two business days.

Book a call Order ITSP