Fractional CISO Services Hero Banner
Fractional CISO

Fractional CISO Services for Startups, SaaS Companies and SMBs

A fractional CISO is an experienced Chief Information Security Officer who works for your company part-time on a monthly retainer and owns your security program, compliance, and board reporting. IRM's fractional CISO is a named, certified executive sized to your ARR stage.

  • CISSP, CISA, CRISC, CDPSE, CMMC-RP
  • 15 to 60 hours per month
  • From $2,000 per month

What is a Fractional CISO?

A fractional CISO is an experienced Chief Information Security Officer who works for your company part-time, on a monthly retainer, and takes ownership of the security program the way a full-time CISO would: strategy, risk, compliance, vendor security, incident response, board reporting, and the security conversations that decide enterprise deals. The difference from a full-time hire is the fraction of a week you buy, typically 15 to 60 hours a month, against a full-time CISO baseline of roughly $250,000 a year in salary before benefits and equity.

IRM's fractional CISO service is delivered by the firm's founder, a CISSP, CISA, CRISC, CDPSE and CMMC-RP with 25 years across financial services, healthcare, education, defense, and SaaS, and an AI-Native practice that covers AI governance and AI security as part of the same role. You get a named executive, not a rotating bench, and the engagement is sized to your stage so the hours track the work rather than the other way around.

The term "fractional CISO" and "Virtual CISO (vCISO)" describe the same role; fractional emphasizes the part-time executive seat, virtual emphasizes remote delivery. IRM's Virtual CISO services page covers the full service catalog and industry variants; this page is about the leadership role itself, who it fits, and what the first 90 days look like.

What your Fractional CISO Owns

  • Security strategy, prioritized roadmap, and an annual security budget the board can approve
  • Risk assessment, risk register, and quarterly risk reporting to leadership and the board
  • Compliance program ownership: SOC 2, ISO 27001, ISO 42001, CMMC, PIPEDA, HIPAA as required
  • Enterprise security questionnaires and customer security reviews, answered and defended
  • Vendor and third-party risk management, including AI vendors
  • Incident response plan, tabletop exercises, and incident command when it happens
  • Security awareness program and secure development practices with engineering
  • Investor, acquirer, and cyber insurance due diligence responses

When you do not need a Fractional CISO

If you are pre-revenue with a handful of engineers and no customer data of consequence, a one-time baseline assessment and a written security policy will carry you further than a retainer. Run the free CIS gap assessment, fix the IG1 safeguards, and revisit the question at your first enterprise deal.

If you already have 40 or more hours a week of security leadership work, a fractional CISO becomes the bridge to a full-time hire rather than the destination. We will tell you when that point arrives and help you write the job description and interview the candidates.

Who a Fractional CISO is for, by ARR Stage

Security leadership needs grow with revenue and customer expectations, not headcount. This is how we size fractional CISO engagements.

Who a Fractional CISO is for, by ARR Stage
StageTypical ARRWhat You NeedIRM Engagement
Pre-seed and bootstrappedUnder $1M ARRA security policy, a baseline of technical controls, and someone who can answer the first customer questionnaire credibly.Crawling tier, 15 to 20 hours per month, on demand for questionnaires and investor diligence.
Seed$1M to $5M ARRA first compliance credential (usually SOC 2 Type I), a vendor risk process, and a named security owner for sales calls.Crawling or Walking tier, 20 to 40 hours per month, SOC 2 readiness inside the retainer.
Series A and B$5M to $25M ARRSOC 2 Type II or ISO 27001 maintained, board-level security reporting, incident response tested, and AI governance if you ship AI.Walking or Running tier, 40 to 60 hours per month, fractional CISO seat on the leadership team.
Growth and PE-backed$25M+ ARRPortfolio-grade security governance, value-creation reporting to the sponsor, and a plan for the first full-time CISO hire.Running tier managed program with a transition plan to an in-house CISO when the hours justify it.

The First 90 Days with a Fractional CISO

This is the sequence every IRM fractional CISO engagement follows, whatever the tier. By day 90 you have a risk register, a roadmap, a board pack, and controls that are operating rather than documented.

Days 1 to 30

Assess and Stabilize

  • Baseline assessment against CIS Controls IG1 and your target compliance framework
  • Risk assessment and risk register with the top 10 risks agreed with leadership
  • Fix the urgent gaps: MFA, admin access, backups, endpoint protection, logging
  • Take over open customer questionnaires, vendor reviews, and insurance renewals
Days 31 to 60

Design and Govern

  • Security strategy and 12-month roadmap approved with a budget
  • Policy set issued and security roles assigned across engineering, IT, and people operations
  • Vendor and AI vendor risk process running, incident response plan written
  • Compliance program scoped (SOC 2, ISO 27001, ISO 42001, or CMMC) and evidence collection started
Days 61 to 90

Operate and Report

  • Monthly control operation: access reviews, vulnerability management, change approvals
  • Incident response tabletop exercise run with leadership
  • First board or investor security report delivered with metrics and risk trend
  • Roadmap re-planned for the next quarter and hours re-sized to the work

Fractional CISO Pricing

Fractional CISO engagements are monthly subscriptions sized by hours, so the cost scales with the work and can step down as the program matures.

Crawling tier, Pre-seed and bootstrapped

From $2,000 per month

15 to 20 hours per month, on-demand or monthly subscription. Compare that with a full-time CISO baseline of roughly $250,000 a year before benefits.

Seed-stage companies building their first compliance program sit on the Walking tier from $4,250 per month (20 to 40 hours). Series A and later companies with a full leadership seat and managed compliance sit on the Running tier from $6,950 per month (40 to 60 hours). Pre-packaged Cyber and AI bundles start at $4,950. Use the vCISO ROI calculator to compare against a full-time hire at your hours.

See all Pricing Tiers

See where you stand first for Free

Free, no signup, runs in your browser

Free CIS Controls Gap Assessment

Assess the CIS Controls v8.1 safeguards at IG1, IG2, or IG3 (56, 130, or 153 safeguards), score each gap on a 5x5 risk matrix, and download a prioritized roadmap. It is the same baseline a fractional CISO starts from in week one. Your answers stay in your browser.

Run the CIS Gap AssessmentBook a Free Consultation

Related: SOC 2 compliance is the most common first project inside a fractional CISO retainer, and CMMC compliance is the equivalent for defense subcontractors.

floating circle
Frequently Asked Questions

Frequently Asked Questions about Fractional CISO Services

A fractional CISO is an experienced Chief Information Security Officer who works for your company part-time on a monthly retainer, typically 15 to 60 hours a month, and takes ownership of the security program the way a full-time CISO would: strategy, risk management, compliance, vendor security, incident response, board reporting, and customer security reviews. You buy a fraction of an executive's week instead of a full-time salary.

They describe the same role. Fractional emphasizes the part-time executive seat, virtual emphasizes remote delivery. IRM uses both terms; the Virtual CISO services page covers the full service catalog and industry variants, while this page covers the leadership role itself. Either way you get a named executive, not a help desk or a rotating bench.

IRM's fractional CISO engagements start at $2,000 per month on the Crawling tier (15 to 20 hours), $4,250 per month on the Walking tier (20 to 40 hours), and $6,950 per month on the Running tier (40 to 60 hours), with pre-packaged bundles from $4,950. A full-time CISO in Canada or the US costs roughly $250,000 a year in salary before benefits, equity, and recruiting, so a fractional engagement typically runs 30 to 40 percent of that cost.

The usual trigger is the first enterprise deal that stalls on a security questionnaire, a SOC 2 or ISO 27001 requirement from a customer, an investor's diligence request, or a cyber insurance renewal that asks for controls you do not have. Companies between roughly $1M and $25M ARR get the most value; below that a one-time baseline assessment is usually enough, and above it the hours often justify a full-time hire.

A typical month includes running the control calendar (access reviews, vulnerability management, change approvals), answering customer security questionnaires, reviewing vendors, advancing the compliance program, coaching engineering on secure development, and reporting risk to leadership. Quarterly, the fractional CISO re-plans the roadmap and delivers a board-level security report. IRM sizes the hours to that work and adjusts them as the program matures.

Yes. Compliance program ownership is part of the role. IRM's fractional CISO scopes and runs SOC 2, ISO 27001, ISO 42001, CMMC, PIPEDA, and HIPAA programs inside the retainer, coordinates with auditors and CPA firms, and keeps the controls operating after the report or certificate is issued so renewals are routine.

Yes, and that is the point of the fractional model as opposed to project consulting. IRM's fractional CISO attends leadership meetings, owns the security budget request, presents to the board or investors on risk and progress, and is the named security executive customers and acquirers talk to. Engagements are structured so the board sees the same person every quarter.

Days 1 to 30 are assessment and stabilization: a baseline against CIS Controls, a risk register agreed with leadership, urgent fixes such as MFA and backups, and taking over open questionnaires. Days 31 to 60 are strategy and governance: a 12-month roadmap with budget, a policy set, vendor and incident response processes, and the compliance program scoped. Days 61 to 90 are operation and reporting: monthly controls running, a tabletop exercise, and the first board report.

Yes. IRM's founder is an AI-Native vCISO and Certified AI Auditor and Ethicist, so AI vendor risk, AI acceptable use, ISO 42001 and NIST AI RMF alignment, and the AI questions in enterprise security questionnaires are handled inside the same engagement rather than by a separate specialist.

IRM is a boutique, founder-led firm. Engagements are delivered by Victoria Arkhurst, CISSP, CISA, CRISC, CDPSE, and CMMC-RP, with 25 years of security leadership across financial services, healthcare, education, defense, and SaaS. You get a named executive who knows your company, not a rotation of consultants.

An MSSP or MSP operates security tooling: monitoring, endpoint protection, patching, help desk. A fractional CISO provides the leadership those tools do not: deciding what the program should be, owning risk and compliance, reporting to the board, and representing security to customers and investors. The two are complementary, and a fractional CISO often manages the MSSP relationship on your behalf.

When the security leadership work consistently exceeds 40 hours a week, or when a customer, regulator, or acquirer requires a dedicated in-house executive. IRM tracks the hours every month and will tell you when that point is approaching, then helps write the job description, interview candidates, and hand over the program so nothing is lost in the transition.
Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.