How much does a vCISO cost?
What a fractional or virtual CISO actually costs per month, why the range is so wide, and how to tell a real vCISO retainer from light ISMS maintenance.
By Kellwick Team · July 17, 2026 · 2 min read
A virtual or fractional CISO usually runs on a monthly retainer. Commonly cited market benchmarks for mid-market companies sit somewhere between $3,000 and $12,000 a month, and the spread is real: it depends entirely on how many frameworks you are running, how mature your programme is, and how much genuine leadership (versus admin) you actually need.
The honest framing is that "vCISO" covers two very different things, and mixing them up is how companies either overpay for a name or underpay and get a checklist. Here is how the levels break down.
The three levels
| Level | Typical monthly | What it really is |
|---|---|---|
| ISMS Maintenance | from $2,000 | Operational upkeep of one framework |
| Compliance Lead | from $4,500 | Up to two frameworks + regular leadership |
| Fractional Security & Governance Lead | from $7,500 | Multi-framework ownership, board reporting, incident governance |
See what sits in each on the pricing page.
Why "$2,000 vCISO" is usually mislabelled
A $2,000/month retainer is realistic for keeping a single-framework ISMS alive - evidence checks, risk register upkeep, access and supplier review cadence, management-review prep. That is valuable, but it is maintenance, not CISO-level leadership.
A real vCISO covering ISO 27001, DORA, NIS2, GDPR, ISO 42001, incident governance and board reporting is not a $2,000 line item. When you see that price attached to the "vCISO" label, read the scope carefully - you are almost always looking at maintenance with a bigger name.
What moves the number
- Number of frameworks. One ISMS is very different from ISO 27001 plus DORA plus GDPR.
- Maturity. A young programme needs building; a mature one needs steering.
- AI in scope. ISO 42001 and AI governance add real work.
- Board cadence. Regular board reporting and incident governance is senior time.
- Incident load. Regulated environments with real incident volume need more capacity.
How to choose
If you need upkeep on one framework, ISMS Maintenance is the honest fit. If you have real, multi-framework obligations and cannot yet justify a full-time hire, the Fractional Security & Governance Lead gives you senior, multi-framework leadership at a defined monthly capacity.
Not sure which level fits? The pricing calculator will point you at one. Figures are indicative and not a binding quote.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.