Fractional vs Full-Time CISO: The Breakeven Math
The breakeven between a fractional and a full-time CISO sits near $180,000 to $220,000 of annual fractional spend, which is roughly 8 to 12 days a month at prevailing rates. Below that line, fractional is cheaper and usually better supported, because a full-time CISO costs $250,000 to $400,000 and up once bonus, equity, benefits, recruiting fees, and vacancy time are counted. Above it, you are paying full-time money for part-time presence. The spreadsheet rarely decides the question on its own, though. Four things push companies past the line before the arithmetic does: headcount, regulatory load, incident frequency, and what the board expects to see in the room. Hybrid arrangements beat both pure options more often than either camp admits.
What a full-time CISO actually costs
Base salary is the number that gets quoted and the smallest part of the answer. Experienced CISOs command $200,000 to $300,000 in most US metropolitan markets and $300,000 to $400,000 in the coastal hubs and in heavily regulated industries. Add a bonus target of 15 to 25 percent, equity in venture-backed companies, and employer payroll taxes and benefits at 20 to 30 percent of base. A retained search costs 25 to 30 percent of first year compensation, which is $60,000 to $100,000, and the search itself takes four to six months during which nobody is doing the job. Median CISO tenure sits close to two years, so that search cost is recurring rather than one-time, worth $30,000 to $50,000 a year when amortized across the cycle.
Two costs get left off the comparison entirely. The first is the vacancy: audits still arrive, enterprise security questionnaires still stack up, and incidents do not wait for a search to conclude, so a five month gap has a price even when payroll shows a saving. The second is what the hire asks for on arrival. A new CISO who inherits no team almost always requests a security engineer at $150,000 to $200,000 loaded and a tooling budget in the same range. Hiring a CISO is rarely a single line item. It is the first line of a department.
What fractional costs, by days per month
Fractional CISO engagements price on a blended day rate, commonly $1,200 to $2,500 depending on the operator's depth and the firm behind them, sold as a recurring monthly commitment. Advisory engagements of one to two days a month run $3,000 to $6,000, or $36,000 to $72,000 a year. Operational engagements at four to six days a month run $8,000 to $16,000, or $96,000 to $192,000 a year. Embedded engagements approaching half time run $15,000 to $25,000 a month, which annualizes at $180,000 to $300,000. There is no recruiting fee, no equity dilution, and termination notice is typically 30 to 60 days rather than a severance negotiation. Our breakdown of vCISO pricing goes tier by tier on what each level should include.
The crossover, in numbers
Set the two side by side at like-for-like scope. An operational fractional engagement at four to six days a month costs $96,000 to $192,000 a year and delivers a senior operator with a bench behind them. A full-time CISO at the same seniority costs $250,000 to $400,000 loaded in a steady state year, and $310,000 to $500,000 in the hiring year once the recruiter fee and the vacancy are counted. On cash alone, fractional wins by a wide margin up to six days a month and still wins modestly at eight.
The crossover appears at 10 to 12 days a month. At $20,000 a month you are spending $240,000 a year for roughly half of a person's working month. That is full-time compensation for part-time presence, and at that point the question stops being financial. Either the work actually requires that much senior attention, in which case a full-time hire buys more of it for the same money, or the engagement has absorbed work that belongs to someone else and should be redistributed rather than repriced.
One caveat applies to both sides. The fractional number is predictable and the full-time number is not, because turnover is the variable. A company that hires three CISOs in six years pays three recruiter fees and lives through three onboarding curves and two vacancies. A company on a fractional retainer for six years usually keeps the same named operator throughout, and that continuity has value neither model prices explicitly.
What pushes an organization past the line
- Headcount and team size. The reliable trigger is not company headcount but security headcount. Once four to six people report into the function and need daily direction rather than weekly guidance, a part-time manager becomes the bottleneck. In practice that arrives somewhere between 500 and 1,000 employees.
- Regulatory load. One framework is a project. Three concurrent frameworks, say SOC 2 alongside ISO 27001 and HIPAA or CMMC, is a standing program with overlapping evidence cycles and audit calendars. Some regimes also expect a named, dedicated executive, and FedRAMP work and certain financial services contracts effectively require one.
- Incident frequency. One material incident a year is manageable inside a retainer with surge terms. Three or more, or any regulated breach carrying notification obligations, means incident command becomes a quarterly activity, and that pattern outgrows a part-time arrangement quickly.
- Board and customer expectations. When directors ask follow-up questions between meetings, or enterprise prospects want the CISO on calls weekly rather than quarterly, availability becomes the constraint rather than capability. This is the trigger cited most often and measured least often, so count the actual meeting hours before treating it as decisive.
What neither model gives you
Both models fail identically in one situation: when security has no authority. A CISO who reports three levels down, holds no budget, and learns about architecture decisions after they ship will be ineffective at any employment status. The same is true of a fractional engagement where the operator reports into IT rather than to the executive team. Before running any cost comparison, check whether the role you are pricing will be able to say no to a shipping deadline. If not, the money question is premature.
Neither model gives you a security team either. A fractional CISO can direct engineers, manage an MSSP, and own the program, but somebody still has to do the work. Companies that expect a two-day-a-month engagement to also perform vulnerability remediation and vendor reviews are buying a contradiction.
Hybrid patterns that work
The arrangement that fits most companies between 200 and 750 employees is a fractional CISO paired with an internal security lead. The fractional operator owns strategy, board reporting, audit and customer-facing security conversations, and the risk register. The internal hire, typically a security engineer or manager at $130,000 to $180,000 loaded, owns execution: tickets, tooling, remediation, and the day-to-day questions. Combined cost is $220,000 to $350,000 for two people with clearly divided work, against $250,000 to $400,000 for one executive who will ask for the engineer anyway.
Three more patterns come up repeatedly. A fractional CISO can run the search for a full-time successor, write the role description, screen candidates, and onboard the hire, then step down to a small advisory retainer. A fractional CISO can also sit alongside a new full-time hire for six to twelve months as a sounding board and as continuity if the hire does not stick. And fractional works well as a bounded surge: a FedRAMP push, M&A diligence, or a post-incident rebuild, where the need is 12 to 18 months of senior attention rather than a permanent seat.
How to run the comparison for your own company
Write the role description before pricing anything. List what has to be decided, owned, and defended over the next 12 months, then estimate the days each item takes. Most companies under 300 people who do this exercise land between four and eight days a month, which sits squarely inside fractional territory. Then price the full-time option loaded rather than at base, add the vacancy months and the amortized turnover cost, and be realistic about who you can recruit. A 60-person company budgeting $220,000 will not attract a CISO who has carried a program through a breach and a hostile audit. It will hire a director of security and pay CISO prices for someone still learning the executive part of the job. Fractional exists largely because that mismatch is so common.
Where BD Emerson fits
Our fractional CISO engagements are built around a named operator, a defined day commitment, and deliverables you can audit at 30, 60, and 90 days, which is what makes the comparison above meaningful rather than theoretical. For companies whose teams are distributed across regions and time zones, the virtual CISO model delivers the same leadership without an on-site assumption. If the exercise in the last section puts you at 10 days a month or more, we will tell you so, and we have run the search for the full-time hire that replaced us more than once.
