Back to Blog

What a vCISO Actually Does: A Week-by-Week Breakdown of the First 90 Days

Every vendor's 'what we do' page is a feature list. This article walks the first ninety days of a real-shaped vCISO engagement at a 32-person Series A SaaS company on a SOC 2 deadline — named artifacts, named calls, named blockers, week 1 through week 12.

Quick Answer

Every vendor's 'what we do' page is a feature list. This article walks the first ninety days of a real-shaped vCISO engagement at a 32-person Series A SaaS company on a SOC 2 deadline — named artifacts, named calls, named blockers, week 1 through week 12.

Every vendor’s “what we do” page answers the question the same way: a tidy feature list. Policy development. Vendor risk. Compliance support. Incident response. Strategic advisory. The list is technically correct and operationally useless — it tells the buyer nothing about what actually shows up week one, what artifact lands on the founder’s desk by Friday of week three, or what fieldwork looks like in week eleven.

This article walks the first ninety days of a real-shaped vCISO engagement at a 32-person Series A SaaS company — the most common buyer of the platform-augmented tier — with the most common forcing function attached: one enterprise customer that asked for a SOC 2 Type II report ninety days from now. Day 1 of the engagement is day 1 of the SOC 2 clock. Day 90 is audit-report delivery or the deal is at risk. Each week below names the work, the artifacts, the participants, and the typical blockers.

The 90-day arc, in one sentence

Weeks 1–4 are discovery, gap assessment, audit-firm selection, and the signed policy library. Weeks 5–7 are evidence pipelines, vendor inventory, and the incident response plan. Weeks 8–9 are the risk register and audit-firm contract. Weeks 10–11 are evidence preparation and fieldwork. Week 12 is the draft Type II report, the board update, and the next-90-day plan.

The 32-person scenario

The reference engagement is a Series A SaaS company in the workflow-automation category. 32 employees: 18 engineers, 4 product, 3 customer success, 3 go-to-market, 2 ops, 1 founder/CEO, 1 CTO. Cloud-native on GCP. Google Workspace + Okta for identity. GitHub for code, GitHub Actions for CI/CD. Datadog for observability. HubSpot CRM, Stripe payments. Customer data is application telemetry plus uploaded workflow definitions — no PHI, no PCI cardholder data, no SSNs. Roughly 35 active vendors.

The forcing function is a single enterprise customer at $480K ACV that issued a 130-question security questionnaire (half clearly lifted from the Shared Assessments SIG Lite). It requested a SOC 2 Type II report “at deal close or within 90 days of contract signature.” The founder negotiated 90 days. The vCISO is engaged on day 1 at a $799/month platform-augmented tier (~8 hours per month dedicated time plus platform-driven evidence collection between calls). No GRC platform in place beyond a Notion workspace the CTO uses for half-finished policy drafts. Everything below starts from that baseline.

Week 1: Discovery and scoping

Monday morning is a 90-minute kickoff: founder, CTO, vCISO. The vCISO is mapping (a) what already exists in writing, (b) what exists only in the CTO’s head, (c) what evidence the customer is actually demanding, and (d) the named systems of record. The output is a 1-page scope memo — named systems, named owners, named deadline, named in-scope frameworks (SOC 2 Trust Services Criteria CC1 through CC9 plus the supplemental category Confidentiality).

Tuesday through Thursday is the asset inventory. The vCISO walks the cloud account (every GCP project, region, service account), the identity provider (every Workspace and Okta user, role, group), the code repositories, the CI/CD pipelines, the data stores (Postgres, BigQuery, Cloud Storage), and the customer data flows. Done in-house this takes a competent founder 40–60 hours over two weeks; done by a vCISO with a platform pulling reads from the cloud account and identity provider, it takes about 8 hours over three days.

Friday is the existing-posture audit. What controls exist (MFA, SSO, scanner output, vuln management, encryption at rest and in transit)? What is documented vs only in the CTO’s head? Which customer-questionnaire questions does the company already have a credible answer for? Output: a 2-page gap-summary executive memo, sent to the founder Friday evening.

Week 1 artifacts

1-page scope memo, asset inventory across cloud + IdP + repos + CI/CD + data stores + data flows, gap-summary executive memo. Total in-scope frameworks named. Customer questionnaire mapped to the SOC 2 Common Criteria so the founder can answer questions in week 2 with the gap assessment’s vocabulary, not the customer’s.

Week 2: Gap assessment and audit firm selection

Two parallel workstreams. The vCISO runs a formal gap assessment against the SOC 2 Trust Services Criteria — every control in CC1 through CC9, plus A1 (availability) and C1 (confidentiality). Each control rated: in place / partially in place / not in place / not applicable. The doc lands at 25–30 pages and is the most-referenced artifact for the next ten weeks.

In parallel, the audit-firm shortlist. The vCISO selects three firms on size (mid-tier or boutique — Big 4 is the wrong choice at this stage and 2–3x the cost), industry fit, and price. Drata’s 2026 SOC 2 cost guide places small-company Type II at $12K–$20K and mid-market at $30K–$60K. The 32-person SaaS is squarely small-company — the vCISO targets $14K–$17K for the Type II plus a $5K–$8K readiness review bundled by the audit firm.

By Friday the three intro calls are done. Each firm has provided a written proposal. The vCISO has scored them against a standard rubric: scope coverage, observation-window flexibility (3-month vs 6-month vs 12-month), total cost, communication cadence, evidence-portal usability, references. The founder picks two finalists; the third is held in reserve.

Week 3: Policy library and frameworks

Week three is policy. The platform-augmented tier’s leverage shows up here most visibly: the vCISO generates a 12-policy library against the live stack, not from generic templates the founder has to translate. The 12 policies:

  • Information Security Policy (the umbrella document; sets the program’s scope, governance, and review cadence)
  • Access Control Policy (least-privilege, MFA, quarterly access reviews, privileged-access procedure)
  • Change Management Policy (PR review, deploy gating, production-change evidence, emergency-change procedure)
  • Incident Response Policy (the policy; the runbook itself comes in week 6)
  • Vendor Management Policy (tiering, DPA requirements, annual review cadence, breach notification clause)
  • Business Continuity Policy (RTO, RPO, annual tabletop, named alternates for critical roles)
  • Data Classification Policy (Public, Internal, Confidential, Restricted; handling rules for each)
  • Data Retention Policy (per data category; deletion procedure; legal-hold exception)
  • Acceptable Use Policy (the employee-facing one; signed at hire and at annual training)
  • Encryption Policy (at-rest and in-transit standards; key rotation; cryptographic algorithm requirements)
  • BYOD / Remote Work Policy (device standards, MDM enrollment, lost-device procedure)
  • Software Development Lifecycle Policy (secure-coding standards, dependency management, code-review requirements)

Each policy is versioned (v1.0, dated, named author, named approver, next-review date 12 months out). Each is reviewed by the CTO mid-week, edited where stack-specific language is wrong, and signed by the founder/CEO by Friday — signed PDF plus Notion source of truth.

The policy library is not a deliverable in itself

A 12-policy PDF stack signed and forgotten is what bad vCISO engagements produce. A 12-policy library with versioning, approver names, scheduled review dates, and references from the gap assessment back into specific controls is what an audit firm tests against. The difference is operational, not editorial — and it shows up in week 11 when the auditor asks who reviewed each policy and when.

Week 4: Identity, access, change-management evidence

The vCISO configures three highest-volume control categories to produce evidence automatically for the rest of the engagement.

Access reviews: a quarterly cadence in the identity provider with a named reviewer per system (CTO for engineering, ops lead for business systems, founder for finance and HR). The first review is run live during week 4 so the audit has an artifact dated inside the observation window. Typical first-pass findings at this scale: 6–12 stale users, 3–5 over-privileged service accounts, 1–2 shared logins that need to be replaced with named credentials.

Change-management evidence: GitHub branch protection verified, PR-review requirements documented, deploy gating captured automatically from GitHub Actions audit logs. By week 11 fieldwork the stream has six weeks of operating data — enough for the auditor’s sampling-based test of effectiveness.

Cloud-config drift detection: scanner integration (Trivy was in CI but not as a continuous control), GCP Security Command Center findings ingested into the evidence stream, drift alerts wired to a Slack channel the CTO actually checks. Three evidence pipelines live by Friday.

Week 5: Vendor risk inventory

At Series A SaaS scale the vendor count typically lands at 28–45 active vendors (industry composite). The reference company is at 35. Every vendor gets a row:

  • Name and category (payment processor, CRM, observability, hosting, productivity, security, support)
  • Tier — 1 critical (operations stop if the vendor is down), 2 important (degraded but functional), 3 utility (replaceable in 30 days)
  • Data classification (what data the vendor touches — Confidential customer data, Internal company data, Public)
  • Compliance posture (SOC 2 Type II report current? ISO 27001 certified? HIPAA BAA if PHI? Last reviewed when?)
  • Contract status (DPA signed? Term remaining? Auto-renew date? Breach notification clause?)
  • Annual review date (per the Vendor Management Policy)

By Friday the inventory is complete. Five to seven vendors are flagged for follow-up — usually a tier-2 SaaS vendor without a current SOC 2 report, a tier-3 vendor whose DPA expired in a prior contract renewal, and a tier-1 vendor whose audit report is older than 18 months. Flagged vendors get remediation work running through weeks 6–9.

Week 6: Incident response plan and tabletop

The policy was written in week 3; the plan is the operational document — roles, escalation tree, comms tree, evidence-preservation steps, customer-notification decision tree. Structure follows NIST CSF 2.0 Respond (RS) and Recover (RC) functions and aligns to RC.RP-1 (the recovery plan must be executed during or after a cybersecurity incident).

The plan names the incident commander (CTO), the deputy (vCISO), the comms lead (founder), the technical lead (rotating senior engineer), the customer-notification lead (head of customer success), and the legal lead (outside counsel on retainer). It includes the customer-notification decision tree mapped to signed customer security addendums — 24-hour, 72-hour, and “without undue delay” clauses.

Thursday is the tabletop. 60 minutes, founder + CTO + ops lead + vCISO. Scenario: a phishing email to a sales rep results in credential theft; the attacker uses the credential to access HubSpot and exports the contact database. Real-time decisions: is this reportable under any signed customer security addendum? Notify affected customers? When and in what form? Engage outside counsel? Notify cyber insurance? Preserve what evidence and how? The tabletop produces 8–14 action items — tighten Okta session timeout for sales-org users, add CRM-export alerts, draft the customer notification template now (not during an incident), document the legal counsel engagement procedure.

Week 7: Vulnerability program and scanner integration

Trivy was already in CI (the CTO added it last year) but findings were not tracked, prioritized, or remediated on a defined SLA. The vCISO wires Trivy output, GCP Security Command Center findings, and a new dependency scanner (Snyk or Dependabot) into the evidence stream. Risk-acceptance criteria documented. Remediation SLAs set:

P0 — Critical, exploitable

Remediated in 7 days. Examples: any CVE on CISA's Known Exploited Vulnerabilities (KEV) catalog that affects an internet-exposed service, any authentication bypass in a production-facing dependency, any container running with a known critical vulnerability for which a patch is available. The SLA clock starts when the scanner flags the finding, not when an engineer triages it.

P1 — High severity

Remediated in 30 days. Examples: high-severity CVEs in production dependencies without active exploitation, container-image vulnerabilities in non-internet-facing services, IAM misconfigurations that violate least-privilege but require a separate vulnerability to chain into a real exposure. Tracked weekly in the vCISO sync.

P2 — Medium severity

Remediated in 90 days. Examples: medium-severity findings in dev/staging environments, deprecated TLS ciphers on services with adequate compensating controls, file-permission drift on non-sensitive paths. Tracked monthly. Often batched with quarterly maintenance windows.

Friday is the first vuln-review meeting. The CTO, the vCISO, and one engineer triage open findings, assign owners, and remediate the P0s before the meeting ends. Output: vuln program documented, SLAs published, scanner evidence flowing for week-11 sampling.

Week 8: Risk register and board prep

At 32 people pre-Series-B, a full FAIR analysis is overkill. The vCISO uses a qualitative-to-semi-quantitative bridge — named risks, treatment plans, owner, dollar-range single-loss expectancy, dollar-range annualized loss. Top 5 risks for the reference company:

Risk
Treatment
Owner
Annualized loss estimate
Credential theft via phishing leading to customer-data exposure
MFA hardening, sales-team training, CRM-export alerting
CTO
$120K–$450K
Critical vendor outage (Stripe or GCP) cascading to revenue loss
Documented runbook, alternate-payment-rail evaluation, GCP multi-region for stateful services
CTO
$80K–$600K
Insider risk from a contractor with over-privileged access
Quarterly access reviews, contractor-offboarding checklist, just-in-time access for production
Ops Lead
$50K–$300K
Public CVE in an open-source dependency exploited in production
Dependency scanner with P0 SLA, SBOM tracking, image-signing for production deploys
CTO
$40K–$200K
Customer-data exposure via API misuse from a poorly-scoped access token
Scoped tokens, rate limiting, anomalous-access detection, token rotation procedure
CTO
$60K–$280K

The vCISO drafts the first board-ready security report Thursday and Friday. Three pages: program status (the 90-day SOC 2 progress), top-5 risks with treatment plans, next-quarter forward plan. Format mirrors what an audit committee wants to see, so the founder is not rebuilding the artifact later. Delivered Friday evening; presented at the next board call in week 10.

Week 9: Audit firm contract and readiness review

The founder signs with the boutique mid-tier firm the vCISO recommended in week 2. Total contract: $14,500 for the Type II audit with a 3-month observation window plus a $6,000 readiness review bundled at signature. The observation window starts retroactively from week 4 (when evidence pipelines went live) — industry-standard for first-time SOC 2 engagements.

The audit firm’s readiness checklist arrives Tuesday. The vCISO walks it against the evidence pipelines and the gap assessment from week 2. About 75% of items are already in evidence; 18% need minor formatting (signed PDFs not Notion exports); 7% are real remaining gaps for weeks 10–11. Each gap gets an owner and a due date.

The 7% remaining gaps, named

At the reference company the remaining gaps were: a missing formal vendor-offboarding checklist (CC9), a documented penetration test from the prior year that needed re-running because the auditor flagged the scope as too narrow (CC4), a security awareness training program with completion records (CC1), and a documented business continuity tabletop exercise (A1 Availability). All four were remediated in weeks 10–11. None of them required new platform spend.

Week 10: Evidence preparation and gap remediation

The platform has been collecting access reviews, change-management logs, vuln scan results, and cloud-config snapshots for six weeks. The vCISO assembles the auditor’s evidence packet — one PDF or zipped folder per control category, in the order the audit firm requested. At the reference engagement that is roughly 280 distinct evidence artifacts spanning the 50-ish in-scope SOC 2 controls.

In parallel, the four remaining gaps from week 9 get remediated. The vendor-offboarding checklist is written and signed. The pen test is re-scoped and run by an external firm at $9,500; the report goes into the evidence packet. Security awareness training is rolled out via KnowBe4 (bought week 9); all 32 employees complete it by Thursday. The BC tabletop runs Friday (90 minutes, scenario: a GCP regional outage cascading into the Stripe dependency).

Friday evening the evidence packet is ~80% pre-assembled. The vCISO sends it to the audit firm so they can begin desk review before fieldwork starts Monday.

Week 11: Audit fieldwork

Fieldwork runs Monday through Friday — auditor onsite, or increasingly on Zoom for SaaS audits at this scale. The audit firm’s lead and one senior reviewer run control walkthroughs, evidence sampling, and team interviews. The vCISO is the named point of contact, schedules every interview, attends every walkthrough, and handles all auditor follow-up — including the day-two request for additional evidence that always shows up.

Interview schedule: CTO (90 min, technical controls), founder/CEO (30 min, governance and risk management), ops lead (45 min, vendor management and access reviews), two engineers (30 min each, change-management walkthrough), customer success lead (30 min, incident notification procedure). Total team time across fieldwork ~18 hours; vCISO time ~32 hours.

By Friday the auditor has tested every in-scope control, sampled evidence, completed interviews, and identified findings. At a well-prepared 90-day engagement the typical first-Type-II finding count is 2–5 — usually documentation gaps or sample-size issues, rarely substantive control failures. Findings are discussed live; the audit firm and the vCISO agree on language before the draft report is written.

Week 12: Draft report, board update, next-90-day plan

Monday and Tuesday the audit firm drafts the Type II report. Wednesday the draft lands. The vCISO reviews every page — management assertion, scope, system description, control table, test results, findings, opinion. Where the audit firm’s language is overly conservative or imprecise, the vCISO pushes back — a SOC 2 report is partly an audit document and partly a sales document, and the language matters for the enterprise customer reading it next week.

Thursday the founder presents the second board-ready security report. It covers the SOC 2 outcome, the 4 remediated gaps, the top-5 risks with updated treatment status, and the next 90 days. The board approves continuing the vCISO retainer at $799/month.

Friday the report is signed. Either the final Type II is delivered (if the audit firm’s turnaround is fast enough) or a letter of expected delivery is issued to the enterprise customer — industry-standard when the report is in final review but a few days behind. The deal closes. The 90-day clock stops.

The week-12 deliverable that buyers forget to ask for

The next-90-day plan is the most under-valued artifact in the engagement. It covers continuous evidence collection (no week-by-week panic next year), quarterly access reviews scheduled and assigned, vendor reassessment cycles starting with the highest-tier vendors, the second board update, the year-2 Type II planning, and the framework-expansion question (is HIPAA or ISO 27001 next?). Without this document the company drifts back to ad-hoc security work and arrives at year-2 fieldwork unprepared.

What doesn’t happen in the first 90 days

The 90-day arc finishes a SOC 2 Type II report. It does not finish a security program. The honest list of what does NOT get delivered:

  • ISO 27001 certification. Typical timeline 6–9 months for a first-time engagement; Stage 1 + Stage 2 audits plus annual surveillance over a three-year cycle. 90 days delivers gap assessment and policy alignment, not certification.
  • HITRUST validated assessment. 9–18 months for a first-time CSF r2 assessment (~135 to ~400+ controls depending on type). Readiness work is in scope; certification is not.
  • FedRAMP or CMMC. FedRAMP Moderate authorization typically 12–24 months; CMMC Level 2 typically 6–12 months from readiness. The vCISO scopes the work; 90 days does not deliver authorization.
  • Security operations. 24/7 SOC, threat hunting, full IR retainer, MDR integration — separate vendors, contracts, and ramp time. The vCISO architects and selects; the vCISO is not the SOC.
  • A security headcount. The engagement bridges between “no one runs security” and “we’ve hired a security leader,” typically at $50M–$100M ARR. It does not replace that hire.
  • Recurring penetration testing. Most retainers exclude pen testing or include one scoped test per year at additional cost ($8K–$25K for an external SaaS pen test at this scale). The vCISO selects the vendor and manages scoping; the test is a third-party deliverable.
  • Cyber insurance procurement. The vCISO is the named CISO on the application and can answer underwriter questions, but the broker handles placement.

After the 90 days

The work does not end — it changes shape. The recurring cadence through year 2:

  • Continuous evidence collection. Week-4 pipelines run for the full Type II observation window — 6 or 12 months for year 2 (longer windows produce more credible reports for enterprise customers). The vCISO reviews the stream weekly and triages anomalies.
  • Quarterly access reviews. Per the Access Control Policy. Each review typically catches 3–8 stale accounts and 1–3 over-privileged service accounts.
  • Annual vendor reassessment. The 35-vendor inventory is re-walked annually. Tier-1 vendors get a deeper review (current SOC 2 report, DPA reviewed, breach clause re-confirmed); tier-3 gets a lighter touch.
  • Annual penetration test. Scoped and procured by the vCISO; executed externally at $8K–$25K. Findings feed the P0/P1 SLAs.
  • Year-2 Type II audit. The 3-month first-year window expands to 6 or 12 months. Audit firm contract renews with a small increase — $16K–$19K vs $14.5K year 1.
  • Next-framework planning. Most companies add a second framework in year 2 — HIPAA (healthcare), ISO 27001 (European customers), or PCI DSS (payments at volume). The vCISO runs the gap assessment in parallel with year-2 SOC 2 operations.
  • Quarterly board reporting. The week-8 artifact becomes a recurring three-page document. The audit committee, once formed, gets the report directly.
12-policy
library generated, versioned, and signed in week 3 — the artifact every SOC 2 audit references first
28–45
active vendors typical at a Series A SaaS company; inventoried and tiered in week 5 of the engagement
P0 7d / P1 30d / P2 90d
remediation SLAs documented in week 7 and tracked weekly thereafter by the vCISO

Frequently asked questions

What does a vCISO do in the first 30 days?

In the first 30 days a vCISO runs discovery (kickoff call, asset inventory, posture audit, customer-questionnaire intake), executes a formal gap assessment against the target framework, shortlists audit firms and runs introductory calls, and generates or imports the policy library aligned to the live stack — typically 12 signed policies covering information security, access control, change management, incident response, vendor management, business continuity, data classification, data retention, acceptable use, encryption, BYOD/remote work, and software development. The first 30 days produce a 1-page scope memo, a gap assessment, an audit-firm shortlist with proposals, and a signed 12-policy library.

How long does it take a vCISO to get a company SOC 2 ready?

For a 30–50 person SaaS company with a clean cloud-native stack and one enterprise customer driving the deadline, a vCISO can get the company to a signed SOC 2 Type II report (or a letter of expected delivery) in 90 days. The arc runs discovery and policies through weeks 1–4, evidence pipelines and vendor inventory through weeks 5–7, risk register and audit-firm contract through weeks 8–9, evidence preparation and fieldwork through weeks 10–11, and report draft and next-90-day plan in week 12. A first SOC 2 Type II observation window is typically 3 months per AICPA guidance, and a 3-month window is the path most 90-day engagements choose.

What is included in a vCISO engagement?

A standard vCISO engagement includes asset inventory and posture audit, framework gap assessment, policy library generation and versioning, identity and access reviews, change-management evidence pipelines, vendor risk inventory and tiering, an incident response plan plus tabletop exercise, vulnerability management program and scanner integration, a quantified risk register, audit firm selection and management, evidence preparation, fieldwork support as named auditor point of contact, and board-ready reporting. Most engagements explicitly exclude 24/7 security operations, full incident response retainer (often hourly when invoked), and headcount hiring.

Does a vCISO handle incident response?

A vCISO writes and tests the incident response plan, runs the tabletop exercise, and is the named escalation contact when an incident occurs, but most retainers do not include open-ended incident response delivery. Standard practice is either a separate hourly billing rate ($300–$500/hr) when an incident is invoked, or a capped allowance — often expressed as “up to N incidents per quarter.” For continuous 24/7 monitoring and response, a separate MDR (Managed Detection and Response) provider is the right counterpart to a vCISO, not a replacement.

Can a vCISO get me audit-ready in 90 days?

Yes, for SOC 2 Type II at a 30–50 person SaaS company with a clean cloud-native stack, an existing customer driving the deadline, and a willing internal team (typically the CTO plus one ops lead). 90 days is the most common forcing-function timeline and matches the cadence of a single first audit observation window plus fieldwork. It is NOT enough time for ISO 27001 certification (typically 6–9 months), HITRUST (9–18 months), or FedRAMP/CMMC at any level. For frameworks beyond SOC 2 the 90-day plan delivers gap assessment and readiness work, not a signed report.

What does a vCISO produce as deliverables?

Concrete artifacts from a 90-day engagement include: 1-page scope memo, asset inventory, framework gap assessment, audit-firm shortlist with proposals, 12-policy library signed by the CEO, access review schedule and first review report, change-management evidence pipeline configuration, cloud-config drift detection setup, vendor inventory with tiering (typically 28–45 vendors at Series A SaaS scale), incident response plan, tabletop exercise readout and action items, vulnerability program documentation, quantified risk register with top-5 risks, first board-ready security report, signed audit firm contract, readiness checklist with gap remediation plan, ~80% of audit evidence preassembled, audit fieldwork interview schedule, and the draft Type II report (or letter of expected delivery).

Bottom line

What a vCISO actually does is not a feature list. It is a 90-day sequence of named artifacts, scheduled calls, signed documents, and remediated gaps that converts “the founder hired a vCISO” into “the enterprise customer received a SOC 2 Type II report.” Four phases: discovery and policies (weeks 1–4), evidence and vendors and IR (weeks 5–7), risk register and audit-firm contract (weeks 8–9), fieldwork through report (weeks 10–12). The platform-augmented tier at $299–$1,499/month matches this scope for a 30–50 person company.

The most common buying mistake is assuming the most expensive tier delivers the most thorough 90-day arc. It does not. At this company size, the work the consultancy tier bills against — access reviews, change-management evidence, vendor questionnaires — is the work a platform automates. The second most common mistake is hiring a vCISO without a forcing function and expecting them to invent one. The vCISO runs the program against the deadline the customer (or board, insurance, investor) set. No deadline, no engagement — or a much lighter touch and a much smaller artifact list.

See vCISO Lite’s published platform-augmented pricing at vcisolite.com/pricing.

Sources

  • Drata, SOC 2 Cost Guide (Type II small/midsize $12K–$20K, mid-market $30K–$60K, readiness $5K–$25K, March 2026): Drata SOC 2 cost reference
  • AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017, with 2022 points of focus update): AICPA TSC document
  • NIST Cybersecurity Framework 2.0 (RC.RP-1 recovery plan execution; February 2024): NIST CSF 2.0
  • Shared Assessments, Standardized Information Gathering (SIG) Questionnaire 2025 release (SIG Lite 128 questions, SIG Core 627 questions, SIG Detail 1,936 questions): SIG product reference
  • IANS Research / Artico Search, 2025 CISO Compensation Benchmark (n=566 US and Canadian CISOs; baseline cost reference for the in-house alternative cited in spoke 1): SMB & Mid-Market CISO Comp Data
  • HIPAA Security Rule, 45 CFR §164.308(a)(1)(ii)(A) Risk Analysis requirement (for engagements that extend scope into PHI handling): 45 CFR Part 164 Subpart C
  • CISA, Known Exploited Vulnerabilities (KEV) Catalog (the canonical source for P0 prioritization in week 7 of the engagement): CISA KEV Catalog
  • HITRUST, CSF Validated Assessment timeline guidance (9–18 month typical first engagement): HITRUST CSF product page
  • ISO/IEC 27001:2022 (the international standard; certification typical 6–9 months for a first-time engagement): ISO 27001:2022
  • Pivot Point Security (CBIZ Pivot Point), vCISO published pricing (April 2025 rate card): Virtual CISO Pricing and Cost Drivers

Where this matters next

vCISO Pricing in 2026: What Virtual CISO Services Actually CostThe three pricing tiers, why the range is fifty times wide, and which tier matches the 90-day engagement shape this article describes.

When Does Your Startup Actually Need a vCISO? (And When You Don't)The forcing-function triggers that put a 90-day clock on the calendar in the first place — and the cheaper ways to handle each one short of a retainer.

What is a vCISO? A Complete Guide to Virtual CISO Services, Costs, and How to Choose (2026)The pillar of this series — the umbrella explainer this 90-day breakdown sits under.

Share this article:

Ready to build your security program?

See how easy it can be.