IRM Consulting & Advisory
Governance, Risk & Compliance (GRC)

vCISO Cost Guide: What a Virtual CISO Really Costs

What a Fractional/Virtual CISO costs: typical retainers, hourly rates and project prices, what drives the price, IRM's published tiers, and when you do not need a vCISO.

What a Virtual CISO really costs, what moves the price, and how to budget the first 90 days

How much does a vCISO cost in 2026?

Company size is a rough proxy for price because it tracks the real drivers: the number of systems, the data you hold and the obligations your customers put on you. The table below combines published provider benchmarks from 2026. Most of them are US figures in US dollars.

Company size

Typical monthly retainer

Annualised

What that usually buys

1 to 50 staff

$2,000 to $5,000

$24,000 to $60,000

Policies, a risk register, questionnaire support, a monthly check-in

50 to 200 staff

$3,000 to $9,000

$36,000 to $108,000

A running programme, one certification track, vendor reviews

200 to 500 staff

$5,000 to $12,000

$60,000 to $144,000

Programme leadership, board reporting, several frameworks

500+ staff or regulated and under audit

$10,000 to $20,000+

$120,000 to $240,000+

Near full-time leadership. At this point, price a full-time hire too

Our opinion, which some providers will dispute: below roughly $2,000 a month you are not buying security leadership. You are buying templates and a monthly call. That can be the right purchase at pre-seed. Just do not expect it to survive enterprise due diligence.

The Three ways vCISOs charge, and the trap in each

The pricing model matters as much as the number. Each one fails in a predictable way.

Pricing model

Best for

The trap

Monthly retainer

An ongoing programme with a certification or customer deadline

Unused hours disappear. Ask whether hours roll over and what happens when you exceed the cap

Hourly or block of hours

Ad hoc advice, a board meeting, one questionnaire

Nobody owns the programme. You get answers, not progress

Fixed-price project

A readiness assessment, a policy set, a gap analysis

The engagement ends at the report. The expensive part, fixing things, is not in the price

For most SaaS companies with a real deadline, a retainer is the right structure. For a company that only needs to know where it stands, a fixed project first and a retainer later is usually cheaper.

What pushes the price up?

Across our engagements, the same seven factors decide where a quote lands. Company size explains less than people expect.

  • The number of frameworks. One SOC 2 track is a different job from SOC 2 plus ISO 27001 plus a customer's own control set. Each extra framework adds mapping, evidence and audit time.

  • A hard deadline. A certification needed in five months for a named deal costs more per month than the same work over twelve.

  • Regulated data. Health information, payment card data or controlled defence information brings HIPAA, PCI DSS or CMMC into scope, each with its own assessors and evidence requirements.

  • AI features in the product. If you ship AI, customers now ask about AI governance, and ISO 42001 is becoming the standard they reference.

  • Selling into both the US and Canada. A company with US enterprise customers and Canadian personal information has to satisfy US contractual expectations and Canadian privacy law, including PIPEDA and, with Quebec customers or staff, Law 25. One programme can cover both, but mapping it takes hours.

  • Incident response commitments. A contractual response time is priced very differently from "we will help if something happens".

  • Board and investor reporting. Quarterly board materials are real work, and worth it, but they add hours.

vCISO vs a full-time CISO: the real maths

The comparison most pricing pages make is flattering and incomplete, so here is the honest version.

The IANS and Artico Search compensation survey of small and mid-market companies, those with up to $1 billion in revenue, found that CISOs there earn an average of $415,000 in total compensation. Our own ROI model uses a more conservative $250,000 salary baseline before benefits and equity, and we price fractional work at $200 an hour across roughly 10 to 60 hours a month.

At 30 hours a month, that is $6,000 a month or $72,000 a year. Against a $250,000 salary that looks like a large saving, and it is. But it is not a like for like comparison. You are buying 30 hours, not 160. What you save is the cost of senior leadership for the weeks when you do not need it.

The fair question is not "which is cheaper". It is "how many hours of senior security judgement does this company need each month right now?" If the honest answer is more than about 100, hire.

What IRM Consulting & Advisory charges

Most providers hide their pricing. Ours is published on our pricing page, and the tiers below are the live figures at the time of writing.

Tier

Stage

From

Hours per month

Scope

Crawling

Pre-seed

$2,000/month

15 to 20

Ad hoc cyber or AI governance consulting, a small sprint

Walking

Seed

$4,250/month

20 to 40

An intermediate programme, a sprint under six months

Running

Series

$6,950/month

40 to 60

A fully managed cyber or AI governance programme

Bundled packages

Any

$4,950/month

Varies

Pre-packaged Starter, Accelerator and Resilience bundles

If these figures change, the pricing page is the source of truth, not this post.

Costs a vCISO quote does not include

This is where budgets go wrong. A vCISO designs and runs the programme. They do not pay for it. Plan separately for:

  • The auditor. A SOC 2 or ISO 27001 audit is performed and invoiced by an independent firm. Your vCISO should not be your auditor.

  • Tooling. A compliance automation platform, endpoint protection, a password manager, logging. Some are already in place. Some are not.

  • Penetration testing. Most frameworks and most enterprise customers expect at least an annual test by a third party.

  • Your team's time. Engineers implement controls. Budget their hours, because this is the cost founders underestimate most often.

Ask every provider whether they earn referral fees on the tools they recommend. There is a defensible answer to that question. "No conflict at all" is rarely it.

When you do not need a vCISO

We turn work away for these reasons, and you should keep your money in these situations:

  • You have under about 15 staff, no enterprise customers and no regulated data. A free baseline assessment and a competent managed IT provider will do more for you than a retainer.

  • You need monitoring, not leadership. If the real gap is nobody watching alerts at night, you need a managed detection and response service. A vCISO will tell you that, then bill you for telling you.

  • You need one document, once. If a strong CTO needs a single policy set or a gap analysis, buy a fixed project.

  • You are past the point a fraction covers. Large, heavily regulated organisations with daily security decisions and a board that expects a named executive should hire a full-time CISO.

Budgeting the first 90 days

Money spent in the wrong order is the most common waste we see. This is the sequence we use, with the hours we typically need for a 30 to 200 person SaaS company.

  1. Days 1 to 30 (about 20 to 30 hours). Discovery: what data you hold, where it lives, who has access, what customers have already been promised. A baseline assessment and a ranked list of the ten risks that matter.

  2. Days 31 to 60 (about 20 to 40 hours). A risk register the leadership team has actually read, policies that describe what you do rather than what a template says, a vendor inventory and a reusable answer bank for security questionnaires.

  3. Days 61 to 90 (about 20 to 40 hours). A 12 month roadmap with costs attached, a decision on which certification to pursue and when, and the first security report for your board or investors.

By day 90 you should know your annual security budget within a reasonable range. If a provider cannot tell you that, the engagement is drifting.

The cost of doing nothing

The IBM Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million, a record high. Organisations that made extensive use of AI and automation in security saved $1.93 million compared with those that used none. IBM also reports that close to seven in ten breached organisations had no policy for governing AI.

A fair caveat: the IBM study skews towards larger organisations, and a breach at a 40 person company usually costs less in direct terms. The costs smaller companies feel first are different: the enterprise deal that stalls for a quarter, the diligence finding that lowers a valuation, the customer who does not renew. A $72,000 year of fractional leadership is roughly 1.4% of IBM's global average breach. It is also, more practically, often less than one delayed enterprise contract.

How to compare two vCISO quotes

Put the quotes side by side and ask each provider the same questions:

  • Who is the named person in my weekly meeting, and what are their certifications?

  • How many hours are included, do unused hours roll over, and what is the overage rate?

  • What is the response time commitment during an incident, and is it in the contract?

  • Which frameworks are in scope, and which would cost extra?

  • What do we own if we leave after six months, and in what format?

  • Do you earn anything from the tools, auditors or penetration testers you recommend?

  • What is the notice period?

The cheaper quote with a named senior practitioner usually beats the more expensive one staffed by whoever is free that week.

Get a number for your company

If you want to see where you stand before talking to anyone, our free self-serve assessments return a prioritised remediation roadmap without a sales call, including a cybersecurity baseline assessment. The live tiers are on our pricing page, and you can read how our virtual CISO services and fractional CISO services differ.

If a certification is the trigger, start with SOC 2 compliance, ISO 27001 consulting or, if you ship AI features, ISO 42001 consulting. Defence suppliers should read our CMMC compliance page. For background on the role itself, see what a virtual CISO actually does and our comparison of a full-time CISO vs a virtual or fractional CISO.

If you would rather talk it through, including whether you need a vCISO at all, book a call.

Keep Reading

Related Articles

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.