The CFO has two proposals open in her inbox. One is from a former Fortune 500 CISO turned independent consultant, retainer labeled “Fractional CISO,” $5,000 per month for 12 hours. The other is from a regional security firm, label “Virtual CISO Services,” $6,000 per month for “ongoing program support.” A third email from her MSP just landed offering “CISO-as-a-Service” bundled with their managed-detection product at $4,500 per month. Three labels, three prices, no clear way to tell which one actually matches the work she needs done.
She does what the founder in the last article did. She opens a search tab and types vciso vs fractional ciso, then fractional vs virtual ciso, then ciso-as-a-service vs vciso. The articles come back saying some version of “these terms are used interchangeably.” That is true in marketing copy. It is not true in delivery.
The three terms describe genuinely different engagement models. They have different price floors, different accountability structures, different bench depth, and different exit terms. The point of this article is to disambiguate them so the buyer knows what they are actually buying — and to name the vendors who operate in each model, because the labels on their proposals will not tell you.
A fractional CISO is one person on a retainer (hourly, individual consultant). A vCISO is a firm or platform where the lead is backed by a bench (service-led, dedicated hours scale with the tier). A CISO-as-a-Service is usually a larger consultancy or an MSP-resold offering with pooled delivery and managed-services SLAs. Labels overlap; engagement models do not.
Fractional CISO — what it actually is
A fractional CISO is an individual consultant. You hire a specific person for a defined number of hours per month at hourly rates, and that person shows up to do the work themselves. The model has been around since the 2010s and predates the vCISO label by about a decade.
Hourly rates in 2025 cluster around three tiers. The Blue Radius Virtual CISO Market Report (October 2025) puts the senior tier at $200–$400 per hour, the enterprise tier at $400–$650 per hour, and the junior tier at $150–$250 per hour. Cynomi’s August 2025 vCISO Costs guide reports $200–$300 per hour as the most common range for what it calls “independent vCISO consultants.” Rhymetec’s September 2024 fractional CISO pricing reference puts senior fractional rates at $200–$500 per hour. The numbers agree on a $200–$400 per hour core for senior independents serving SMB and mid-market.
Engagements are typically 8–40 hours per month. At 12 hours per month and $350 per hour, the effective retainer is $4,200 per month — which puts the fractional model in the same dollar range as the vCISO firm tier, but for a fundamentally different product. You are paying for one person’s calendar.
The buyer in this model is hiring a person, not a service. The CV matters. The references matter. The chemistry on the intro call matters. A large share of fractional CISOs are former in-house CISOs consulting solo after burnout — Cybersecurity Ventures and the Proofpoint 2025 Voice of the CISO Report both put average CISO tenure at 18–26 months, and Proofpoint found 75% of CISOs interested in a job change. The upside is depth: a fractional CISO with 15 years in-house at a regulated company brings pattern recognition no junior analyst can replicate. The downside is concentration risk: when that person is on vacation, sick, deep in another client’s incident, or pursuing a new in-house role, your security program slows or stops.
The exit is the cleanest in the category. You end the retainer at the contracted notice period (typically 30 days), the consultant hands over the policies and the runbooks if the engagement said they would, and you move on. There is no platform to migrate off, no MSP contract to break, no software subscription tied to the engagement. Fractional ciso pricing is the most transparent of the three models because the unit (one person’s hour) is the most legible.
vCISO — what it actually is
A vCISO is a service-led model. You engage a firm or a platform, not an individual, and the firm assigns the right lead plus a delivery team. Bench depth is part of the value. When the lead is unavailable, the firm covers. When the engagement crosses into a domain the lead does not own (PCI for an e-commerce client, HIPAA for a healthtech client, threat hunting after a security event), a specialist from the bench is pulled in.
Pricing for traditional vCISO firms is the only tier in the category where a serious vendor publishes a rate card. Pivot Point Security (now CBIZ Pivot Point) publishes that 90% of its clients pay $4,500–$12,500 per month for its Virtual CISO / Virtual Security Team service, with the full range running $4,000–$30,000+ per month and annualized engagements landing at $25,000–$100,000+ per year. The Pivot Point pricing page was last updated April 2025 and remains the cleanest anchor in the category. HALOCK Security Labs operates in the same range with its CISO & Virtual CISO Advisory line, anchored in HALOCK’s DoCRA (Duty of Care Risk Analysis) and “Reasonable Security” methodology — HALOCK does not publish a hard number, but independent tracking puts it in the $4,000–$15,000 per month range. SideChannel’s 2026 vCISO pricing guidance puts mid-market typical at $3,000–$12,000 per month.
The platform-augmented version of the vCISO model is the newer entrant. vCISO Lite operates here at $299–$1,499 per month, with the software automating the work that consultancy bench hours used to bill against (evidence collection, policy versioning, vendor questionnaire response, framework crosswalks) and a vCISO whose dedicated hours scale with the tier. Cynomi sells a similar platform to MSPs and MSSPs rather than directly to end clients, with Cynomi’s April 2026 partner guidance recommending MSPs charge their clients $1,000–$5,000 per month plus $150–$300 per hour for project work. The platform-augmented tier as the buyer experiences it spans $299/mo (direct subscription) up to about $5,000/mo (MSP-resold).
The accountability structure is the load-bearing difference between vCISO and fractional. In a fractional engagement, the consultant is accountable to you, full stop. In a vCISO firm engagement, there is a delivery manager, a senior partner, a client-success lead, and a written escalation path. When a SOC 2 audit goes sideways, the fractional CISO either lands the plane or does not. The vCISO firm has more people who can be put on the problem and more institutional process for putting them on it.
The exit in this tier is where buyers get hurt. Read the contract before signing. Standard provisions to look for: 90-day termination notice, full ownership and return of policies and evidence on exit, no claw-back of deliverables already paid for, no exclusivity clause preventing you from hiring your next vCISO from a competitor. Some vCISO firms write contracts that lock the buyer into a 12-month auto-renewing engagement with a 60-day notice window — meaning if you miss the window, you are in another year. That is the lock-in to watch.
The three largest compliance-automation platforms — Vanta, Drata, and Secureframe — do not sell their own vCISO service. Vanta runs a Service Provider Program, Drata maintains a Service Partner Directory plus a Concierge matchmaking layer, and Secureframe operates a Service Partner Program. All three push customers to partner consultancies. So when a founder Googles “Vanta vCISO,” what they actually find is a referral list. The consultant on the other end of the referral is often a fractional CISO operating solo — meaning the vCISO label on the Vanta partner page is actually the fractional model in disguise.
CISO-as-a-Service — what it actually is
CISO-as-a-Service is the label most often used by two groups: larger consultancies with managed-services arms (Optiv, LevelBlue, formerly AT&T Cybersecurity, rebranded May 2024) and MSP/MSSPs who resell platforms like Cynomi to bundle a security advisory offering on top of their existing managed-services contract. The model leans heavier on managed-services delivery than the boutique vCISO firm tier.
The structural feature that distinguishes CaaS from vCISO is pooling. A CaaS engagement at a large consultancy typically does not give the buyer a dedicated lead consultant working 12 hours per month on their account. Instead, the buyer gets access to a pool of specialists, with a named account manager coordinating, and the actual delivery hours are shared across multiple clients. The buyer is paying for the bench, not for a specific calendar. Pricing reflects this: the floor for a major-consultancy CaaS engagement is typically $5,000+ per month, sometimes substantially more, because the consultancy is sizing for the operational cost of running a 24x7 SOC plus an advisory layer.
MSP-resold CaaS is a faster-growing subcategory. Cynomi’s 2025 State of the vCISO Report (n=200 MSPs and MSSPs surveyed) found that 67% of MSPs offered vCISO services in 2025 versus 21% in 2024 — a tripling in one year. The MSP version of CaaS is typically priced as an add-on to an existing managed-services contract: $1,000–$5,000 per month for the advisory layer (per Cynomi’s April 2026 partner guidance) plus $150–$300 per hour for project work. The advisory hours are delivered by the MSP’s in-house security lead, often supported by a platform (Cynomi, ConnectWise, or a smaller white-label tool) that generates the artifacts. The buyer rarely meets the platform vendor; the MSP is the customer-facing brand.
SLA expectations are where CaaS materially differs from vCISO and fractional. Because CaaS engagements are usually bundled with managed-services or SOC operations, the SLAs tend to be tighter on the operational side: 1-hour response to P1 incidents, 24x7 monitoring, integrated ticketing into the buyer’s existing IT stack. The advisory layer (board reporting, framework strategy, vendor program build-out) often runs on a quarterly cadence rather than a continuous one. That trade is fine for some buyers and wrong for others — a healthtech Series B running concurrent SOC 2 Type II and HIPAA programs may need weekly advisory cadence and find the CaaS quarterly model too thin.
Naming names: Optiv, LevelBlue, Kroll, Coalfire, Mandiant (Google Cloud), and the security-services arms of the Big Four operate in the CaaS tier when they offer ongoing advisory packages. None publish pricing. Independent tracking puts the floor at $5,000 per month and the ceiling at $25,000+ per month for heavy regulated-industry retainers with included IR and SOC integration. Ciso as a service pricing and ciso as a service cost queries return wide ranges because the model itself is the widest.
The three side-by-side
Putting the three models in a single table is the fastest way to surface the differences the labels hide.
The first row is the one most buyers miss. “Who shows up” is not the same question as “who is on the proposal,” and the answer changes the value of the engagement more than any other variable. Consultancies are notorious for selling with the senior partner on the intro call and delivering with the analyst at the contract’s effective date. The honest disclosure is in the staffing plan, not the rate card.
When the labels mislead you
Most vendor landing pages use all three terms as synonyms because the SEO of each is too valuable to leave on the table. A consultancy delivering a pure fractional model (one consultant, hourly billing, no bench) will still write “Virtual CISO and CISO-as-a-Service” on its homepage. A regional MSP delivering a pooled CaaS model will market itself as a “fractional CISO firm” because the term tests well with founder-led companies who associate “fractional” with lower cost.
The disambiguating questions are mechanical. Ask them on the intro call, before the proposal is sent, and the picture clarifies.
- Will I be working with one named person, or a team? The answer that names a single individual is the fractional model. The answer that names a lead plus three or four supporting roles is the vCISO firm model. The answer that names an “account manager” plus a “specialist pool” is CaaS.
- How many hours per month will that named person spend on my account? If the answer is “as many as you need,” the answer is actually “as few as we can bill.” A real answer is a number.
- What happens when my lead is unavailable — vacation, illness, another client’s incident? Fractional: “I’m generally responsive within X hours.” vCISO: “Here is our written backup-coverage policy.” CaaS: “The pool covers; the named manager re-routes.”
- Is software included or billed separately? Platform-augmented vCISO bundles. Traditional vCISO firms almost always bill the GRC software (Vanta, Drata, Secureframe) separately at $10,000–$30,000 per year on top of the retainer. Fractional CISOs leave the software entirely to you. CaaS bundles when the consultancy has its own platform and unbundles when it doesn’t.
- Is incident response included, hourly, or capped? Most retainers in all three tiers exclude incident response and bill it at $300–$500 per hour when invoked. Some include “up to N incidents” per quarter. CaaS bundles more often than the other two because of the SOC integration.
- What is the exit clause and the IP-ownership clause? 30-day notice and full return of all deliverables is the standard fractional answer. 90-day notice with deliverable ownership clearly assigned is the standard vCISO answer. CaaS contracts bundled with managed services often have multi-year terms; read carefully.
The label on the proposal will not tell you which of these answers you are getting. The intro call will, if you ask.
How to choose between them
The decision is not about which model is “best” in the abstract. It is about which model matches the forcing function that triggered your search.
- One-month diligence sprint or audit-readiness push. Fractional CISO at $200–$400 per hour for 15–25 hours. You need a calendar and a brain; you do not need a bench. Fractional ciso cost is the right query for this.
- Quarterly board advisory with no operational role. Fractional CISO at 4–8 hours per month. The board wants a named executive; the company does not need ongoing program operation. Cheapest stable answer.
- First SOC 2, no enterprise customer-mandated specifics. Platform-augmented vCISO at $299–$1,499 per month. The work is mostly evidence collection and policy generation, which the platform handles at a fraction of consultancy hourly billing. Under $20,000 in year one against a SOC 2 audit cost of $7,000–$15,000.
- SOC 2 plus a regulated framework (HIPAA, PCI DSS, ISO 27001) at Series B or later. Traditional vCISO firm at $4,500–$12,500 per month (the Pivot Point Security band). Bench depth across multiple frameworks, weekly CTO cadence, monthly audit-committee cadence. vciso vs fractional ciso resolves cleanly toward vCISO here.
- Healthtech, fintech, or critical-infrastructure with continuous SOC plus advisory. CaaS at a major consultancy ($5,000–$25,000+ per month) or MSP-resold CaaS ($1,000–$5,000 per month on an existing managed-services contract). The 24x7 SOC requirement tips this away from boutique vCISO. Ciso as a service cost is the right query.
- $100M+ ARR with multi-jurisdictional regulatory exposure. The decision is between in-house CISO and heavy CaaS retainer. The math gets closer to a tie; deciding factors are equity comp, team build-out plans, and IPO timing.
At $299–$1,499 per month, a platform-augmented vCISO subscription delivers what a $4,500/mo traditional vCISO firm and a $300/hr fractional CISO at 12 hours per month deliver for the same SOC 2-only outcome. The work the consultancy bills against (access reviews, vulnerability scan ingestion, policy versioning, vendor questionnaire response) is the work the platform automates. The price difference is real, the outcome difference for single-framework SOC 2 programs is approximately zero, and the math holds until the buyer crosses into multi-framework regulated territory.
Frequently asked questions
What’s the difference between vCISO and fractional CISO?
A fractional CISO is one individual consultant on a retainer at $200–$400 per hour, 8–40 hours per month (Blue Radius Virtual CISO Market Report, October 2025). A vCISO is a firm or platform engagement where the assigned lead is backed by a bench — compliance specialist, incident responder, threat-intel analyst — and the firm covers when the lead is unavailable. The vCISO firm tier typically starts at $3,000 per month; fractional effective monthly costs land at $1,500–$8,000. The premium buys bench depth, not just hours.
Is CISO-as-a-Service cheaper than vCISO?
Usually no. CaaS is the label used by larger consultancies (Optiv, LevelBlue, Kroll) and MSP/MSSPs reselling platforms like Cynomi. Major-consultancy floors typically start at $5,000+ per month because of the larger bench and pooled delivery model. MSP-resold CaaS is cheaper as an advisory-only line (Cynomi’s April 2026 partner guidance: $1,000–$5,000 per month plus $150–$300 per hour for project work) but only because dedicated hours are traded for pooled coverage. The CaaS label is best read as a packaging choice, not a pricing tier.
Can I switch from a fractional CISO to a vCISO firm without re-onboarding?
Partly. Policies, risk register, vendor list, and evidence transfer if the engagement gave you IP ownership (read the contract). Relationships — auditor, insurance broker, named vendors — transfer if the consultant introduces them. What does not transfer is institutional context: the firm’s incoming lead needs 30–60 days to absorb what the fractional consultant knew. Plan for one quarter of overlap during the handoff. The transition is cleaner when the original engagement produced documented runbooks rather than tacit knowledge in one person’s head.
Which model is best for a startup?
For most early-stage startups with a single forcing function (first SOC 2, first enterprise customer, fundraise diligence), a platform-augmented vCISO subscription at $299–$1,499 per month is the right answer. A fractional CISO at $200–$400 per hour fits a time-boxed sprint — one-month diligence, audit prep, incident response. CaaS at $5,000+ per month is rarely the right starting point under $25M ARR unless the forcing function is regulated-industry SOC operations or board-level audit-committee reporting.
Do the three models have different SLA expectations?
Yes. Fractional engagements are usually best-effort (written reply in 24–72 hours, incident response billed separately). vCISO firms typically commit to written SLAs (24 hours non-urgent, 4 hours time-sensitive, faster for incidents) because the bench absorbs the on-call rotation. CaaS sits closer to managed-services SLAs (often 1 hour for P1 incidents, 24x7 monitoring tied to the SOC). Always get the SLA in writing — verbal commitments rarely survive the first real incident.
Why do vendors use the three terms interchangeably?
Because the category is unregulated and the terms all test well in search. Every vendor wants to rank for vciso pricing, fractional ciso cost, and ciso as a service, so landing pages use all three as synonyms regardless of what the vendor delivers. Cynomi’s 2025 State of the vCISO Report found 67% of MSPs now offer some form of vCISO in 2025 versus 21% in 2024, and the label is essentially chosen by marketing. The disambiguating questions are mechanical: who shows up, how many hours, what bench, what exit clause.
Bottom line
The three labels are not synonyms even though every vendor pretends they are. A fractional CISO sells you one person’s calendar at $200–$400 per hour. A vCISO sells you a firm’s bench at $3,000–$12,500 per month traditional or $299–$1,499 per month platform-augmented. A CISO-as-a-Service sells you a consultancy’s SOC plus advisory layer at $5,000–$25,000+ per month, or an MSP’s bundled offering at $1,000–$5,000 per month on top of an existing managed-services contract.
Pick the model that matches the forcing function. Time-boxed sprint: fractional. Continuous SOC 2-only program: platform-augmented vCISO. Multi-framework regulated program with board reporting: traditional vCISO firm. 24x7 SOC requirement plus advisory layer: CaaS. The expensive mistake is buying the model that matches the label that scored highest in someone else’s search marketing.
See vCISO Lite’s published platform-augmented pricing at vcisolite.com/pricing.
Sources
- Blue Radius, Virtual CISO Market Report 2025 (hourly tiers: $150–$250/hr junior, $200–$400/hr senior, $400–$650/hr enterprise): Market report (October 2025)
- Cynomi, vCISO Costs guide ($200–$300/hr most common independent rate): Definitive Guide (August 2025)
- Cynomi, vCISO Pricing Models for MSPs (April 2026 partner recommendation: $1K–$5K/mo + $150–$300/hr project work): vCISO Pricing Models 2026
- Cynomi, 2025 State of the vCISO Report (n=200 MSPs/MSSPs; 67% offer vCISO in 2025 vs 21% in 2024): vCISO services adoption coverage (July 2025)
- Pivot Point Security (CBIZ Pivot Point), vCISO published pricing ($4,500–$12,500/mo covers 90% of clients): Virtual CISO Pricing and Cost Drivers (April 2025)
- HALOCK Security Labs, CISO & Virtual CISO Advisory (DoCRA / Reasonable Security methodology): CISO Advisory Services (updated March 2026)
- LevelBlue (formerly AT&T Cybersecurity; May 2024 rebrand): SecurityWeek announcement
- Rhymetec, Fractional CISO pricing reference (senior fractional rates $200–$500/hr): What Is a Fractional CISO (September 2024)
- IANS Research / Artico Search, 2025 CISO Compensation Benchmark (n=566 US and Canadian CISOs; $415K SMB total comp): SMB & Mid-Market CISO Comp Data (June 2025)
- Proofpoint, 2025 Voice of the CISO Report (63% experienced burnout; 75% interested in job change): Voice of the CISO 2025
- Cybersecurity Ventures, CISO Workforce Report (average CISO tenure 18–26 months across the industry)
- Vanta Service Provider Program (no first-party vCISO; partner-referral model): Service Providers landing page
- Drata Service Partner Directory + Concierge: Service Directory
- Secureframe Service Partner Program: Service Providers landing page
Where this matters next
vCISO Pricing in 2026: What Virtual CISO Services Actually Cost — The pricing tiers behind the three labels — what each one costs, what you actually get, and where the $50x range comes from.
When Does Your Startup Actually Need a vCISO? (And When You Don't) — The forcing-function triggers that turn “we’ll figure it out” into “we need someone now” — and which of the three models matches each trigger.
What is a vCISO? A Complete Guide to Virtual CISO Services, Costs, and How to Choose (2026) — The pillar of this series — everything else assumes this as the baseline.