How much does a vCISO cost?
Why vCISO pricing varies so much, how to tell a real vCISO retainer from light ISMS maintenance wearing a bigger name, and what to compare instead of the monthly figure.
By Kellwick Team · July 17, 2026 · 2 min read
A virtual or fractional CISO runs on a monthly retainer, and the market spread is genuinely enormous. That is not vendors being cagey - it is because "vCISO" covers two very different jobs, and the label is applied to both.
Mixing them up is how companies either overpay for a title or underpay and receive a checklist. So the useful question is not "what does a vCISO cost" but "how much senior capacity am I actually buying, and against how many obligations?"
Compare capacity, not price
Every honest retainer states three things. If a proposal is missing them, the monthly figure tells you nothing:
- Advisory days per month. One day a month and five days a month are different products, whatever they are called.
- How many frameworks are covered. One ISMS is a different job from ISO 27001 plus DORA plus GDPR.
- How many legal entities are in scope. A group structure multiplies everything behind the scenes.
Ours are published in full on the pricing page - the capacity, the framework limit, the entity limit and the response time for each tier - so you can hold them against anyone else's.
The tier that is usually mislabelled
A retainer that buys roughly one advisory day a month on a single framework is realistic and useful: evidence checks, risk register upkeep, access and supplier review cadence, management-review preparation. That is maintenance, and it is a real product.
It is not CISO-level leadership. Someone owning ISO 27001, DORA, NIS2, GDPR, ISO 42001, incident governance and board reporting cannot do it in a day a month, so when you see that scope attached to a small monthly number, read the capacity line rather than the title. Almost always you are looking at maintenance with a bigger name on it.
What moves the number
- Number of frameworks. Each one adds its own evidence, cadence and reporting.
- Maturity. A young programme needs building; a mature one needs steering. Building costs more.
- AI in scope. ISO 42001 and AI governance add real work, not a paragraph.
- Board cadence. Regular board reporting and incident governance is senior time, and senior time is the expensive part.
- Incident load. Regulated environments with real incident volume need standing capacity, not best effort.
- Market and travel. Delivery cost differs between markets, and on-site presence adds travel. This is a large part of why a single published figure would be wrong for most readers.
How to choose
If you need upkeep on one framework, ISMS Maintenance is the honest fit. If you have real multi-framework obligations and cannot yet justify a full-time hire, the Fractional Security & Governance Lead gives you senior, multi-framework leadership at a defined monthly capacity.
The five-question guide will point you at the right level, and the capacity of each is published at /vciso. The number itself comes from a short call, once we know the frameworks, the entities and where you are.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.