Freelance cybersecurity work has stopped being a fringe career choice. Organisations that cannot hire a full-time penetration tester, cloud security architect, or compliance lead still need the work done, and increasingly they buy it by the day rather than by the headcount. If you have solid skills and a few years of delivery behind you, freelancing is a realistic route to more control over your work and, usually, more money.
It is also a business. In short, you start freelancing in cybersecurity by narrowing to one specialism you can deliver unsupervised, building three to six months of financial runway, setting a day rate from the revenue you need rather than the market average, registering and insuring properly, and lining up your first one or two engagements through people who already know your work. This guide covers each of those parts in turn, plus the unglamorous admin.
Are you ready to go freelance?
There is no certification that makes you a freelancer. What clients buy is the confidence that you can walk into an unfamiliar environment and deliver without supervision. In practice that means:
- Two to five years of hands-on delivery in a specialism you can name in one sentence. "Cybersecurity generalist" is a hard sell. "Web application penetration testing for fintech" is not.
- Evidence you can point at. Certifications (OSCP, CISSP, CCSP, ISO 27001 Lead Implementer), redacted report samples, CVEs, CTF placements, public write-ups, or references from people willing to take a call.
- The ability to scope your own work. Clients will describe a vague problem. You need to turn it into a statement of work with deliverables, dates, and a price.
- A financial runway. Three to six months of expenses covered. Your first invoice may not be paid for 60 days after your last salary lands.
If you are missing one of these, you are not blocked — you are early. Contract inside an existing consultancy first, or take on weekend work alongside a permanent role where your contract allows it.
Pick a specialism clients already budget for
The freelance market pays best where demand is spiky and in-house cover is thin. Consistently strong areas:
- Offensive security: penetration testing, red teaming, web and mobile application testing, and increasingly AI/LLM security testing.
- Cloud security: AWS, Azure, and GCP hardening, IAM reviews, Kubernetes security, infrastructure-as-code review.
- GRC and compliance: ISO 27001, SOC 2, NIS2, DORA, and GDPR programmes. Regulatory deadlines create work that has to happen on a date.
- Incident response and DFIR: retainer work and surge capacity.
- Fractional leadership: virtual CISO engagements for companies too small for a full-time security executive.
Pick one to lead with. You can broaden later; you cannot market yourself before anyone can remember what you do.
How to set your freelance rate
Most new freelancers underprice, then discover they have built a job with worse benefits. Start from what you need to earn, not from what feels polite to ask.
Step 1: work out your billable days. There are roughly 260 working days in a year. Subtract holiday, sick days, admin, sales, and training and you land at 180 to 200 billable days in a good year. In your first year, assume 120 to 150.
Step 2: work out your target revenue. Take the salary you want, add employer costs you now carry yourself — pension, insurance, equipment, software, accountancy, training, downtime — and add a buffer. A common rule of thumb: target 1.5x to 2x your equivalent permanent salary to end up materially better off.
Step 3: divide. Target revenue ÷ billable days = your day rate floor.
Example: you want the equivalent of a €80,000 salary. Target revenue of €140,000 across 160 billable days gives a floor of roughly €875 per day.
Step 4: sanity-check against the market. Day rates vary widely by region, specialism, and client type, and end clients pay more than agencies who take a margin. Ask peers directly — freelancers talk about rates far more openly than employees do, and inside communities like Cyberr you can compare notes with people doing your exact work in your market.
A few pricing rules worth adopting from the start:
- Quote in day rates, not hourly, for project work. Hourly invites micro-management.
- Price fixed-scope deliverables as fixed fees once you know how long they take you. A penetration test you can deliver in four days does not have to be sold as four days.
- Charge for retainers up front. Reserved capacity is worth paying for.
- Never discount silently. If a client needs a lower price, reduce the scope with it.
- Raise your rate on new clients first. It is easier than renegotiating with existing ones.
Finding your first clients
Freelance cybersecurity work is bought on trust, and trust travels through networks rather than job adverts. In rough order of return on effort:
- Your existing network. Former colleagues, managers, and vendors already know how you work. Tell them clearly what you are now available for and what a good referral looks like.
- Professional communities and networks. Being visible where security work gets discussed matters more than a polished website. On Cyberr you can publish a verified professional profile, connect your certifications, and stay visible to peers and hiring teams — including anonymously, if you are still employed.
- Consultancies and boutique firms who subcontract overflow work. Lower rates, but steady volume while you build.
- Public proof of work. Conference talks, write-ups, open-source tooling, and useful posts do more sales work than cold outreach ever will.
- Cybersecurity services marketplaces, used selectively alongside your own network rather than instead of it.
Two habits separate freelancers who stay busy from those who cycle between famine and burnout: always keep one conversation warm while you are delivering, and ask every satisfied client for a referral and a testimonial before the engagement closes.
Another route to finding cybersecurity clients
Freelancing still depends heavily on reputation, referrals and professional networks. Heelr adds another route: a cybersecurity services marketplace where independent professionals can make their expertise available to organisations looking for specialist support.
Heelr is connected to Cyberr and is built specifically for cybersecurity services rather than general freelance work, so briefs arrive from buyers who already know they need security expertise. The two platforms do different jobs:
- Cyberr is the professional network for cybersecurity. It is where you build your profile, connections and professional presence, and where your certifications and experience are visible.
- Heelr is the cybersecurity services marketplace. It provides a route for eligible professionals to offer cybersecurity services to organisations.
Eligibility is not automatic. To offer services through Heelr you need an active Cyberr Premium membership and Cyberr ID verification. Neither platform guarantees projects, clients or income, and neither vouches for a provider's suitability for a specific piece of work — the client still scopes and selects, exactly as they would through a referral.
Treat it as one channel among several. Cyberr explains how Cyberr and Heelr work together, and you can learn more about becoming a provider on Heelr.
The admin nobody warns you about
- Register properly as a sole trader, limited company, or the local equivalent, and take 30 minutes of an accountant's time to pick the right one.
- Get professional indemnity and cyber liability insurance. Many clients will not sign without it, and offensive work makes it non-negotiable.
- Use a written contract for every engagement, covering scope, rates, payment terms, liability caps, IP ownership, and — for testing work — explicit written authorisation to test the in-scope systems.
- Invoice on a schedule and chase late payment early. Net 30 with a stated late-payment charge is reasonable; do not let an invoice reach 60 days in silence.
- Set money aside for tax from every payment, not at year end.
- Book training and holiday into the calendar as unavailable days. Skills decay and burnout are the two most expensive risks in a one-person business.
A realistic first-year timeline
| Phase | Focus | | --- | --- | | Months −3 to 0 | Build runway, define your specialism, set your rate, line up one or two first engagements, sort registration and insurance. | | Months 1 to 3 | Deliver the first engagement well. Collect a testimonial. Publish something useful. Keep two conversations warm. | | Months 4 to 9 | Repeat business and referrals start arriving. Raise your rate for new clients. Turn down badly-scoped work. | | Months 10 to 12 | Convert your steadiest client to a retainer. Review your rate, utilisation, and specialism against what actually sold. |
Where Cyberr and Heelr fit
An independent cybersecurity career rests on four things: professional reputation, network and visibility, credible evidence of your skills and experience, and routes to prospective clients. Most of that is built by doing good work and being known for it — no platform substitutes for either.
Cyberr is the professional network for cybersecurity people rather than a generic job board. Independent professionals use it to publish a verified profile, connect and validate certifications from Credly, Hack The Box, and TryHackMe, stay visible to peers and hiring teams, and keep that presence current without broadcasting a job search to their current employer.
Heelr is the cybersecurity services marketplace connected to Cyberr. For eligible Premium, identity-verified members it adds one more route to prospective clients alongside your own referrals and network.
Create your free Cyberr profile, or if you are already consulting independently, explore independent consultant pricing on Heelr.
Related reading: The future of cybersecurity freelancing and Cybersecurity careers: a path to a rewarding and in-demand profession.
Frequently asked questions
Join the Cyberr Community
Create your free Cyberr account today.


