vCISO Services vs. Fractional CISO Services: What Actually Differs
- 2 days ago
- 11 min read

By Yonatan Hoorizadeh, CISSP, CISM, CRISC, AAISM
Published By: Purple Shield Security
Published: July 29, 2026
Last updated: July 29, 2026
vCISO services, fractional CISO services, and CISO as a service are marketing labels, not defined products. Providers apply them inconsistently. What actually differs is the delivery model underneath: whether a named practitioner owns your program, whether execution is in scope or only advice, and whether the provider earns money from the tools it recommends.
Why can't the industry agree on what a vCISO is?
Because no standards body defines the terms. Vendors define them, and they define them differently. Three of the most visible firms selling into this market publish three incompatible explanations of the same vocabulary. A buyer comparing them is not comparing three different services. They are comparing three marketing dictionaries that happen to share words.
Vistrada, a consultancy that publishes definition guides for both terms, treats a vCISO as distinct from a fractional CISO, describing it as an ongoing outsourced service delivered by a team rather than by a single person.
Atlant Security, in its 2026 provider comparison, draws the line somewhere else entirely. It describes fractional as implying a heavier time commitment, on the order of two to three days per week with deeper integration into the organization, while virtual implies lighter touch, more remote delivery.
vCSO.ai rejects both framings. Its 2026 pricing guide argues that fractional CISO describes a role rather than a fixed product, the same way consultant or lawyer describes a role, and that what you are actually buying varies dramatically between firms.
None of those three is being dishonest. That is the point. The vocabulary has no owner, so each provider defines it in whatever way flatters its own delivery model. A firm that assigns a team defines vCISO as a team. A firm that bills two days a week defines fractional as two days a week. A firm that sells range defines the term as meaningless without scope.
We noticed this playing out in our own sales conversations. Prospects arrive having read four provider websites, holding a firm opinion about which label they want and no working definition of what they will receive. In one recent evaluation, a mid-market firm told our team they had ruled out
because they wanted someone embedded rather than remote. The fractional CISO proposal they had shortlisted instead offered fewer hours per month than the vCISO firm they had eliminated. The label had done all the deciding and none of the informing.
So the useful question is not which of the three labels you need. It is what sits underneath whichever one you are being sold.
The three delivery models behind every label
Underneath the vocabulary, vCISO services and fractional CISO services are sold in three delivery models: named practitioner leadership, pooled bench advisory, and platform led programs. All three models get marketed under all three labels. The model determines what you actually receive, which makes it the only thing worth comparing across proposals.
Named practitioner leadership
One senior person owns your security program. They attend leadership meetings, hold the risk register, report to your board, and are the escalation point when something breaks at 2am. SideChannel, which has published vCISO pricing benchmarks since 2023, describes this model as buying "a named CISO-caliber practitioner who owns your security program," and distinguishes it from a consultant who delivers a report and leaves.
The tell is simple. You can name the human. So can they, in writing, before you sign.
Pooled bench advisory
You are buying the firm rather than a person. Work is assigned from a bench, and the individual on your monthly call can change between quarters. This model is not inherently worse. It scales specialist coverage that a single practitioner cannot match, which matters if you need penetration testing, GRC tooling, and architecture review under one contract.
What it cannot do is continuity. vCSO.ai warns buyers that in a bench arrangement you may simply get whoever is available that month, which is a genuine problem when the value of the role depends on somebody remembering why a decision was made three quarters ago.
Platform led programs
A compliance automation platform runs the workflow and a human reviews it periodically. This is the cheapest tier in the market and it is legitimate for a company whose actual need is SOC 2 evidence collection rather than security leadership. It becomes a problem when it is sold as leadership. vCSO.ai notes that offerings priced below roughly five thousand dollars per month are usually a productized platform with light human oversight, a junior consultant learning on your budget, or a bench arrangement.
Here is how the three models compare on the things that turn out to matter:
Delivery model | Who owns the program | What is included | Incident response | Labels it gets sold under |
|---|---|---|---|---|
Named practitioner leadership | One senior, named security executive who attends your leadership meetings | Program strategy, policy and risk register ownership, board and audit reporting, hands on coordination of remediation | Usually retained, and the same person leads the response | vCISO, fractional CISO, CISO as a service |
Pooled bench advisory | The firm. Assigned staff can rotate between accounts | Assessments, documentation, framework mapping. Execution is typically a separate scope of work | Often called in cold and billed as a new engagement | vCISO, virtual CISO, CISO as a service |
Platform led program | A software workflow, with periodic human review | Policy templates, control mapping, evidence collection. Execution stays with your team | Not included | vCISO, vCISO platform, compliance automation |
Read that table across, not down. The rightmost column is the whole argument. Every one of these models is sold under the same names, which is why comparing labels across proposals produces nothing useful.
Who does your vCISO actually work for?
Most vCISO services sit inside a company that also sells something else: a managed service provider, a software reseller, a managed detection vendor. When the same firm recommends the tool and earns margin on the tool, that recommendation is not independent advice. Ask where a provider's revenue comes from before you ask what it charges.
This is not a fringe concern. Fractional CISO, a Boston based firm, makes the point publicly on its own site, noting that most cybersecurity and IT consultants collect commissions or finder's fees when they recommend particular tools or partner businesses.
The structural issue is easy to miss because it never shows up as bad advice. It shows up as a bias toward action. A security leader's most valuable output is sometimes the sentence "you do not need to buy anything this year, fix the process instead." A provider whose margin depends on the purchase is structurally unlikely to say that, and no amount of professional integrity fully neutralizes an incentive that is baked into the business model.
We have reviewed enough inherited security stacks to see the pattern in the invoices. We noticed that when the security advisor and the tool reseller are the same company, the stack grows at every renewal and almost never shrinks. In one assessment our team ran for a mid-market client, three separate products were licensed against overlapping problems, all sourced through the same advisor, and none had been evaluated against the others since the day they were bought. Nobody had done anything wrong. Nobody had been asked to say no, either.
The test is a direct question, asked in writing, before the engagement letter:
Do you resell, or receive commission or margin on, any product you would recommend to us?
Do you have referral or revenue sharing agreements with MSPs, MSSPs, or insurers?
Will you state in writing that you hold no financial interest in the recommendations you make?
Purple Shield Security was built to answer all three the same way, which is why we hold no MSP contracts, resell no tools, and take no vendor commissions. Any provider can adopt that posture. Fewer can adopt it in writing.
Whose name goes on the paperwork?
There is a practical test that cuts straight through the labels. Several documents require a specific human name in the security leadership slot. A provider either fills that slot or does not. If nobody at the firm will appear on your HIPAA designation, your cyber insurance application, your SOC 2 management assertion, or your board minutes, you have bought advisory work, whatever the proposal called it.
The clearest example is healthcare. As Paubox summarizes, the HIPAA Security Rule at 45 CFR 164.308(a)(2) requires covered entities and business associates to identify a Security Official responsible for developing and implementing the required policies and procedures, and this is a regulatory requirement rather than a suggestion. Patient Protect notes that the most common finding in Office for Civil Rights enforcement actions is that no one was ever formally designated at all.
We have seen the failure mode that sits one step past that, and it is more common than the missing designation. In several healthcare engagements we noticed the named Security Official was an office manager who had never read the organization's risk analysis and did not know one existed. The designation was technically compliant. The function behind it was not. On paper the organization had a security leader. In practice it had a name in a policy binder.
The same test applies well outside healthcare. Cyber insurance applications ask who is accountable for the control environment, and a wrong answer on an application is a coverage problem later. SOC 2 management assertions need an owner. Enterprise customer security questionnaires increasingly ask for the security leader's name and credentials before a deal closes. Board minutes recording that security was reviewed need to record who presented.
If the answer to all of those is "our IT provider," you do not have a security leadership gap on paper. You have one in the room.
What do vCISO services actually cost?
Across the market, vCISO services and fractional CISO services generally run from around 2,500 dollars per month at the small business end to around 30,000 dollars per month for large enterprise engagements. Treat that as an average rather than a quote. The same company can land at either end of that band once scope is defined, and plenty land outside it in both directions.
What moves the number:
Headcount, and how many of those employees touch sensitive systems
Industry, and whether it carries a sector specific regulator
Whether you handle regulated data such as protected health information (PHI), cardholder data, or criminal justice information
Number of physical locations and whether any are clinical, retail, or production sites
How many compliance frameworks you are carrying at once, and whether they have ever been crosswalked against each other
Whether incident response is retained in advance rather than called in cold during an event
Program maturity on day one, since a company starting from nothing costs more in year one than one maintaining an existing program
Board reporting cadence and whether the provider presents directly
Number of third party vendors in scope for review
Whether customer security questionnaires and audit support are inside the retainer or billed separately
Published benchmarks cluster inside that band. SideChannel puts most mid-market engagements between 3,000 and 12,000 dollars per month. vCISO.com reports an industry wide range of 3,000 to 15,000 dollars monthly. Consilien, writing specifically about California, puts most mid-market firms in the state at 5,000 to 12,000 dollars per month.
The comparison that usually settles the decision is the full-time alternative. Compass IT Compliance, citing IANS Research compensation data, reports that most CISOs earn between 250,000 and 700,000 dollars annually with a national average near 583,000 dollars, rising to roughly 844,000 dollars in technology and 744,000 dollars in financial services. Those figures are salary and compensation, before recruiting fees, equity, benefits, and the four to six months a search typically takes.
The more useful warning is about what the retainer excludes. Zip Security's 2026 pricing analysis flags contract terms worth reading closely: "plus expenses" clauses, and tier upgrades triggered by scope that arguably belonged in the original retainer. Its practical recommendation is to require a scope document that names who owns remediation of any issues found. Zip also notes that audits and testing are usually billed separately, with SOC 2 audits commonly running 15,000 to 100,000 dollars and formal penetration tests 10,000 to 50,000 dollars.
We noticed that the retainers that go wrong are almost never the ones priced too low. They are the ones where remediation ownership was never written down. Findings accumulate, the provider reports them faithfully every month, nobody is contractually responsible for closing any of them, and eighteen months later the program looks close to identical to the assessment that started it. The invoice was never the problem. The undefined verb was.
How do you tell leadership from advisory before you sign?
Ask questions the marketing page cannot answer. Every provider in this market will tell you it delivers strategic security leadership. Only some will name the individual, put remediation ownership into the scope document, and disclose their revenue model in writing. The answers sort the delivery models faster than any comparison chart, including the one above.
Bring these to the second call:
Who specifically is the named practitioner on our account, and will that person attend our leadership meetings?
How many other accounts is that person assigned to right now?
Does the scope document name who owns remediation of the findings you produce, and what happens if items stay open?
Is incident response retained under this agreement, or is it a new engagement priced at the moment we need it?
Do you receive commission, margin, or referral fees on anything you recommend to us?
Will you be named on our HIPAA designation, insurance application, SOC 2 assertion, or board minutes?
If we end the engagement, do the policies, risk register, evidence, and vendor inventory come with us in an editable format?
The last question separates providers more sharply than any of the others. A firm that keeps your documentation inside its own platform has created a switching cost that has nothing to do with the quality of its work.
Frequently asked questions
Can a vCISO serve as our designated HIPAA Security Official?
HIPAA requires that a specific individual be identified as responsible for security policies and procedures under 45 CFR 164.308(a)(2). The rule does not require that person to be an employee. Some organizations designate the vCISO directly, while others keep an internal designee with the vCISO performing the function behind them. Either arrangement works if the named person actually has authority, available time, and the current risk analysis in hand. What does not survive an OCR review is a designation with no function attached to it.
Does hiring a vCISO mean replacing our MSP or IT provider?
No, and the two roles are usually complementary. Atlant Security's provider comparison describes the common arrangement plainly: the virtual CISO sets priorities and defines what success looks like, while the managed provider runs the day to day controls. Problems arise in the opposite configuration, where the provider running the controls is also the party grading them. Separating those two jobs is often the entire reason a company brings in fractional CISO services in the first place.
What is the smallest company that should consider fractional CISO services?
Headcount is the wrong variable. The useful signal is a trigger event, and there are four common ones: the first enterprise customer security questionnaire your team cannot answer, the first cyber insurance renewal that arrives with a control checklist attached, the first time you begin handling regulated data such as PHI or cardholder data, and the first acquisition or funding conversation with real diligence behind it. We noticed almost every inbound call our team takes follows a trigger rather than a headcount threshold. A 25 person healthcare billing company frequently needs this before a 300 person distributor does.
What happens to our security program when the engagement ends?
Ask that question before it starts, not during the offboarding call. Your policies, risk register, evidence artifacts, vendor inventory, and incident response runbook should live in your own tenant, in editable formats, and should be yours to keep on day one rather than on request. Get it into the agreement. A provider comfortable with that term is telling you something real about how it expects to keep the account.
Purple Shield Security provides independent vCISO and fractional CISO services to small, mid-market, and regulated businesses across Los Angeles and Southern California, with no MSP contracts, no tool resale, and no vendor commissions. If you are mid evaluation and the proposals in front of you are not comparing cleanly, that is a short conversation worth having. Reach out through purpleshieldsecurity.com and we will walk through what each one is actually offering, including the ones that are not ours.



