How Much Does a vCISO Cost?

A vCISO typically costs $3,000 to $25,000 per month in 2026, depending on how many days of leadership you are buying and what the engagement covers. Advisory retainers of a day or two per month run $3,000 to $6,000, operational engagements at four to six days run $8,000 to $16,000, and embedded arrangements approaching half time run $15,000 to $25,000 or more. Set that against a full time CISO, whose fully loaded cost lands between $250,000 and $400,000 and up once salary, bonus, equity, benefits, and recruiting are counted, and the fractional model is how most companies under about 1,000 employees buy security leadership. The pricing models, what each tier should include, and the warning signs follow.
The three pricing models
Nearly every vCISO offering is one of three shapes, and plenty of engagements combine them.
Retainer by days per month is the standard. You buy a recurring slice of a senior security executive, priced at a blended day rate that usually falls between $1,200 and $2,500 depending on the person's depth and the firm behind them. The retainer covers a defined cadence: leadership meetings, program oversight, reporting, and a set of owned responsibilities rather than a bucket of hours to burn.
Project-scoped work covers defined builds: standing up a security program, leading a SOC 2 or ISO 27001 readiness effort, running a post-incident rebuild. These price like consulting projects, commonly $25,000 to $75,000 depending on scope, and they end. A common pattern is a project to build the program followed by a smaller retainer to run it.
Incident surge is the model nobody reads until they need it. When something breaks, the vCISO steps into incident command at hourly rates typically between $250 and $500, or at premium day rates, above the retainer. What matters is that the terms and the availability commitment exist in the contract before the bad day, not after.
What drives the rate
Within any tier, four things move the day rate. Seniority and scars: an operator who has carried a program through audits, board fights, and a live incident prices above one who has written policies about them. Industry: regulated healthcare, financial services, and defense work carry a premium because the wrong answer costs more there. The bench: a solo practitioner can be excellent, but a firm brings specialists for cloud, compliance, and incident response behind the named lead, and that backup is part of what you are paying for. And deliverable load: an engagement that includes customer-facing security calls and questionnaire ownership consumes more hours than the calendar shows, and careful firms price that in rather than letting quality slide. Geography matters less than it once did; remote delivery has largely flattened the coastal premium for fractional work, though an on-site expectation for incidents prices it back in.
What each retainer tier should include
- Advisory, 1 to 2 days a month, $3,000 to $6,000. A quarterly risk review that produces a real document, ownership of the policy set, a quarterly report the board can read, and a named person your executives can call when a decision cannot wait. Right for companies under roughly 100 employees with a light compliance load.
- Operational, 4 to 6 days a month, $8,000 to $16,000. Everything above, plus running the risk register, vendor security reviews, customer questionnaire and audit ownership, an annual tabletop exercise, and monthly metrics that track something other than training completion. This is the tier most companies holding a SOC 2 or ISO 27001 certification actually need.
- Embedded, 8 to 12 days a month, $15,000 to $25,000 and up. Weekly presence in leadership meetings, management of internal security staff and the MSSP, budget ownership, incident command, and support for board sessions, customer executive calls, and M&A diligence. This tier is a bridge: either toward a full time hire or through a defined high-stakes period.
Whatever the tier, two things should be non-negotiable: a named individual whose calendar you can see, and deliverables tied to months, not sentiments. If the proposal cannot say what you will hold in your hands after 90 days, keep shopping.
The full time comparison
The $250,000 to $400,000 figure is not a scare number; it is arithmetic. Base salaries for experienced CISOs run $200,000 to $300,000 in most US metros and higher in the coastal hubs. Add bonus, equity, and benefits at 20 to 30 percent of base, a recruiter fee of 25 to 30 percent of first year compensation, and four to six months of search time during which you have nobody. Then note that median CISO tenure hovers around two years, so the recruiting cost is not a one-time event; it is a cycle. The vacancy itself has a price too: audits still arrive, customer security reviews still stack up, and incidents do not wait for the search to conclude.
The comparison cuts both ways. A full time CISO gives you daily presence, organizational authority, and someone whose entire attention belongs to your company, which no fractional arrangement matches. A fractional engagement gives you a senior operator at 10 to 40 percent of the loaded cost, often with a bench of specialists behind them for cloud, compliance, and incident response questions no single human covers equally well. Under about 500 employees, the fractional math usually wins. Past that, it depends on what your customers, regulators, and roadmap demand.
Warning signs of a hollow vCISO offering
The label is unregulated, so the market carries some products that are a policy template subscription wearing a title. The tells are consistent. No named individual until after signature, which means you are buying a queue. A refusal to say how many clients each named CISO carries; past eight to ten, your slice of their attention is thinner than the invoice implies. Deliverables that are template packs with your logo, visible because the SaaS policy library arrives before anyone has asked how you make money. No board-facing artifact cadence, no metrics commitment, and no incident availability language in the contract. And the quiet conflict: a vCISO who also resells the security tools they recommend is an account manager with a better title.
None of these are exotic, and they compress into five questions worth asking on the first call. Who exactly is my CISO, and how many clients do they carry. What artifacts will exist after 90 days. What happens when I call during an incident. Which metrics will you commit to reporting against. And do you earn margin on anything you might recommend I buy. A real offering answers all five without flinching; a hollow one reschedules the call.
When fractional stops making sense
The model has a ceiling, and pretending otherwise is its own warning sign. The signals that you have outgrown it: a security team of four to six people who need daily management rather than weekly direction, regulators or enterprise customers who expect a named full time executive, product decisions that need a security voice in the room every day rather than every week, and fractional spend that has crept toward $180,000 to $220,000 a year, at which point you are paying full time money for part time presence.
The graceful exit is planned: the fractional CISO helps write the role description, screens the candidates, onboards the hire, and steps back to a small advisory retainer or a clean handoff. An offering that resists that conversation is protecting its revenue, not your program.
The arrangement also works in reverse once you have hired. Plenty of companies keep a small fractional retainer alongside a new full time CISO for the first year, as a sounding board, an extra set of hands during audit season, and continuity if the hire does not stick. That is a feature of the model, not an admission that it failed.
Buying security leadership at the right size
Price the decision the way you would any executive function: what does the business need to decide and defend this year, and who is qualified to own it at the fraction of time it actually takes. If the answer is a defined slice of a senior operator with deliverables you can audit, that is exactly what our fractional CISO engagements are built to be, and the virtual CISO model extends the same leadership to teams that are fully remote or spread across regions. If you are still weighing whether you need the function at all, why every business needs a vCISO makes the case from the risk side rather than the budget side.
