A fractional CISO is an experienced Chief Information Security Officer who works for your company part-time on a monthly retainer and owns your security program, compliance, and board reporting. IRM's fractional CISO is a named, certified executive sized to your ARR stage.
A fractional CISO is an experienced Chief Information Security Officer who works for your company part-time, on a monthly retainer, and takes ownership of the security program the way a full-time CISO would: strategy, risk, compliance, vendor security, incident response, board reporting, and the security conversations that decide enterprise deals. The difference from a full-time hire is the fraction of a week you buy, typically 15 to 60 hours a month, against a full-time CISO baseline of roughly $250,000 a year in salary before benefits and equity.
IRM's fractional CISO service is delivered by the firm's founder, a CISSP, CISA, CRISC, CDPSE and CMMC-RP with 25 years across financial services, healthcare, education, defense, and SaaS, and an AI-Native practice that covers AI governance and AI security as part of the same role. You get a named executive, not a rotating bench, and the engagement is sized to your stage so the hours track the work rather than the other way around.
The term "fractional CISO" and "Virtual CISO (vCISO)" describe the same role; fractional emphasizes the part-time executive seat, virtual emphasizes remote delivery. IRM's Virtual CISO services page covers the full service catalog and industry variants; this page is about the leadership role itself, who it fits, and what the first 90 days look like.
If you are pre-revenue with a handful of engineers and no customer data of consequence, a one-time baseline assessment and a written security policy will carry you further than a retainer. Run the free CIS gap assessment, fix the IG1 safeguards, and revisit the question at your first enterprise deal.
If you already have 40 or more hours a week of security leadership work, a fractional CISO becomes the bridge to a full-time hire rather than the destination. We will tell you when that point arrives and help you write the job description and interview the candidates.
Security leadership needs grow with revenue and customer expectations, not headcount. This is how we size fractional CISO engagements.
| Stage | Typical ARR | What You Need | IRM Engagement |
|---|---|---|---|
| Pre-seed and bootstrapped | Under $1M ARR | A security policy, a baseline of technical controls, and someone who can answer the first customer questionnaire credibly. | Crawling tier, 15 to 20 hours per month, on demand for questionnaires and investor diligence. |
| Seed | $1M to $5M ARR | A first compliance credential (usually SOC 2 Type I), a vendor risk process, and a named security owner for sales calls. | Crawling or Walking tier, 20 to 40 hours per month, SOC 2 readiness inside the retainer. |
| Series A and B | $5M to $25M ARR | SOC 2 Type II or ISO 27001 maintained, board-level security reporting, incident response tested, and AI governance if you ship AI. | Walking or Running tier, 40 to 60 hours per month, fractional CISO seat on the leadership team. |
| Growth and PE-backed | $25M+ ARR | Portfolio-grade security governance, value-creation reporting to the sponsor, and a plan for the first full-time CISO hire. | Running tier managed program with a transition plan to an in-house CISO when the hours justify it. |
This is the sequence every IRM fractional CISO engagement follows, whatever the tier. By day 90 you have a risk register, a roadmap, a board pack, and controls that are operating rather than documented.
Fractional CISO engagements are monthly subscriptions sized by hours, so the cost scales with the work and can step down as the program matures.
From $2,000 per month
15 to 20 hours per month, on-demand or monthly subscription. Compare that with a full-time CISO baseline of roughly $250,000 a year before benefits.
Seed-stage companies building their first compliance program sit on the Walking tier from $4,250 per month (20 to 40 hours). Series A and later companies with a full leadership seat and managed compliance sit on the Running tier from $6,950 per month (40 to 60 hours). Pre-packaged Cyber and AI bundles start at $4,950. Use the vCISO ROI calculator to compare against a full-time hire at your hours.
See all Pricing TiersAssess the CIS Controls v8.1 safeguards at IG1, IG2, or IG3 (56, 130, or 153 safeguards), score each gap on a 5x5 risk matrix, and download a prioritized roadmap. It is the same baseline a fractional CISO starts from in week one. Your answers stay in your browser.
Run the CIS Gap AssessmentBook a Free ConsultationRelated: SOC 2 compliance is the most common first project inside a fractional CISO retainer, and CMMC compliance is the equivalent for defense subcontractors.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


