Canadian vCISO directory
What each listing means, how the tiers differ, and what to check before you sign with any of the firms below.
Filtering happens in your browser. Nothing is sent anywhere and the order never changes.
60 firms listed on HireACISO.
Nothing matches those filters. to see every firm again.
Our offerings
TrazTech Inc. VerifiedOperates this site
The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.
Everyone else
Listed from public information and not yet claimed by the firm, so the details here are ours rather than theirs. If this is your firm, claim it and it becomes yours to edit.
3Tenets Consulting Unclaimed
Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.
Agency Unclaimed
US based compliance engineers who run control implementation, evidence collection and audit coordination for client SOC 2 programs; the audit is performed by others.
Alloy Insights Inc. Unclaimed
Northern Ontario firm selling fractional CISO services described as embedded executive-level security leadership.
Apus Consulting Inc. Unclaimed
Firm selling a fractional CISO retainer providing CISO-level judgment for enterprise deals, investor diligence and board conversations.
BARR Advisory Unclaimed
Firm offering virtual CISO and security program management within its advisory and managed services line, oriented to compliance program delivery.
Brockton Point Solutions Unclaimed
Canadian firm offering virtual CISO support to strengthen security posture without the cost of a full-time executive.
Canadian Cyber Unclaimed
Governance, risk and compliance consultancy that guides clients through ISO 27001 scoping, gap analysis, policy development and implementation ahead of an external certification audit, and does not issue certificates.
Carmel Info-Risk Consulting Unclaimed
Vancouver consultancy offering an alternative to a full-time CISO, providing security leadership that works through the client existing IT team.
CISO Global Unclaimed
US firm offering vCISO services within its risk and compliance practice, oriented to compliance program delivery.
Cocoon CS Inc. Unclaimed
Firm selling a fractional CISO that brings security strategy, risk decisions and executive communication into focus, with compliance program work.
Cognisys Unclaimed
UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.
Compass IT Compliance Unclaimed
Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.
Concept GRC Unclaimed
Quebec firm selling a fractional cybersecurity director as an outsourced vCISO that runs the client security program, focused on compliance program delivery.
Core IT Unclaimed
Burnaby provider selling vCIO and vCISO services described as high-level IT and security leadership without the cost of a full-time executive.
CriticalMatrix Consulting Inc Unclaimed
Toronto cybersecurity and data governance consultancy offering fractional CISO, virtual CISO and CISO-as-a-service engagements.
Cyber Defense Group Unclaimed
US firm with dedicated virtual CISO service pages, selling strategic security leadership without the full-time cost.
Cyberium Group Unclaimed
Vancouver consultancy listing vCISO among its cybersecurity services, focused on compliance program delivery across SOC 2, ISO 27001 and ISO 42001.
Cybernow Unclaimed
Quebec firm selling a vCISO team alongside a 24/7 SOC and incident response for small and medium businesses.
CyberSecOp Unclaimed
US consultancy running a named virtual CISO program providing outsourced security leadership, with ISO 27001 and NIST program work.
DigiRisq Consulting Inc. Unclaimed
London Ontario consultancy selling fractional cybersecurity leadership through a dedicated fractional CISO service.
Digital Fort Unclaimed
Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.
Eficio Unclaimed
Montreal firm selling CISO360 as a Service, an outsourced security leadership offering with on-demand technology leadership support.
Fortium Partners Unclaimed
US firm selling virtual, fractional and interim CISO engagements as part of a technology leadership-as-a-service model.
Framework Security Unclaimed
Firm selling virtual CISO under managed security, delivered hands-on through weekly working sessions and engineers paired with client staff.
Fusion Computing Limited Unclaimed
Toronto provider selling combined vCIO and vCISO services as strategic IT planning and security leadership, including SOC 2 readiness support.
GreenHat Security Unclaimed
Firm selling fractional and virtual CISO services positioned as security leadership that fits the company stage, with SOC 2 readiness work.
Groupe AD Cyberdefense Unclaimed
Boutique consultancy offering ISMS governance, policy and committee work for ISO 27001 plus AI governance under ISO/IEC 42001, delivered as vCISO engagements, and does not issue certificates.
Groupe CyberSwat Unclaimed
Quebec City firm selling an on-demand security chief, marketed in French as chef securite a la demande or V-CISO.
GuardsArm Unclaimed
Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.
HALOCK Unclaimed
US consultancy offering CISO and vCISO advisory within its governance and risk management practice, oriented to compliance program delivery.
IRM Consulting & Advisory Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.
IS Partners Unclaimed
Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.
Kobalt.io Unclaimed
Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.
Kognitionsoft Ltd. Unclaimed
Firm selling fractional CISO services providing strategic leadership, security oversight, board-level reporting and mentorship for internal IT staff.
Lighthouse Data Consulting Inc. Unclaimed
Halifax firm selling virtual CISO and virtual DPO services as senior security and privacy leadership without a full-time hire.
Mirai Security Unclaimed
Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.
Neotrust Unclaimed
French firm with a Montreal office listing CISO as a service within its security transformation practice, alongside testing and compliance work.
Ntiva Unclaimed
US provider offering vCISO and compliance team services delivering executive-level security guidance.
OmniCyber Security Unclaimed
Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.
Oppos Unclaimed
Ontario firm whose service menu pairs vCISO services with compliance program management, positioned as security leadership.
POPP3R Cybersecurity Consulting Inc. Unclaimed
Winnipeg consultancy selling CISO-as-a-Service guidance and vCISO engagements, acting as an executive extension that leads security initiatives.
Propel Consulting Unclaimed
British Columbia consultancy listing a fractional Chief Information Security Officer service as security leadership.
QuantumSmart Unclaimed
Toronto firm selling fractional CIO and CISO leadership, giving a holistic view of the business and IT landscape without a full-time hire.
Rhymetec Unclaimed
Provider that sets up and runs a client internal information security and data privacy program, supplying executive-level security leadership.
RiskAware Inc. Unclaimed
Ontario consultancy offering virtual CISO services as cybersecurity leadership for organizations without an in-house security executive.
Sandstorm Cyber Unclaimed
Montreal firm selling vCISO services described as seasoned CISO leadership and security program oversight without the overhead of a hire.
Secrecy Evolution Unclaimed
Consultancy that performs ISO 27001 gap assessments mapped to Annex A and delivers remediation roadmaps and vCISO support, and does not issue certificates.
Secur01 Unclaimed
Quebec provider selling vCISO as CISO-as-a-service, with a virtual CISO guiding the client security strategy inside its managed services.
Sedara Security Unclaimed
US provider offering a virtual CISO service for security leadership and program resilience planning, alongside penetration testing.
SideChannel Unclaimed
US firm selling virtual CISO and fractional security services covering strategy, risk assessment and compliance program management, listing Canada as a service location.
Situate Business Solutions Unclaimed
Calgary firm listing vCISO as a standalone cybersecurity service, alongside PCI DSS compliance consulting.
Systemes Securitech Systems inc. Unclaimed
Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.
TEKAP Unclaimed
Quebec firm selling vCISO expertise, described as CISO experience in information security management at a fraction of the cost of a hire.
Tevora Unclaimed
Firm listing vCISO under resource augmentation, providing executive-level CISO assistance alongside compliance and testing work.
Trilogiam Unclaimed
Independent Quebec consultancy selling fractional security leadership, with CyberSecure Canada readiness work.
Truvo Cyber Unclaimed
Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.
TwelveDot Incorporated Unclaimed
Ottawa firm selling a Virtual CSO service giving companies of any size security leadership guidance on demand, alongside ISO 27001 program work.
Uzado Inc. Unclaimed
Ontario provider offering a fractional vCISO covering security strategy, board reporting and audit ownership, alongside compliance and testing work.
Workstreet Unclaimed
Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.
Browse a shorter list
The whole directory is above. These are the same firms cut down to one service or one province, which is usually the faster way in.
- AI security firms in Canada, 5 firms
- Cloud compliance firms in Canada, 7 firms
- Compliance advisory firms in Canada, 54 firms
- ISO 27001 firms in Canada, 18 firms
- ISO 42001 firms in Canada, 9 firms
- Penetration testing firms in Canada, 18 firms
- Security questionnaires firms in Canada, 6 firms
- SOC 2 readiness firms in Canada, 17 firms
- Trust center firms in Canada, 6 firms
- vCISO firms in Canada, 60 firms
- Fractional CISO firms in British Columbia, 7 firms
- Fractional CISO firms in Ontario, 15 firms
- Fractional CISO firms in Quebec, 9 firms
How do I know I can trust one of these firms?
Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.
Is a listing here a recommendation?
No. Firms are listed from public information or added by the firm itself, and a Verified badge is a tier rather than an endorsement. Nothing on this page says a firm is the right one for you. Compare at least three.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
This directory lists vCISO and fractional CISO providers serving Canadian companies. There are no listings in it yet. It is new, and a page of placeholder firms would waste your time. What this page can do today is tell you how listings work, what they cost, and what to ask a provider before you sign.
If you need providers now, the quote request goes to Canadian providers directly and is faster. If you run a firm, listing your firm is the page for you: a claimed listing is free and stays free, and the paid Verified tier is $300 CAD a month or $3,000 CAD a year. A listing is one channel and not the biggest. How to get vCISO clients covers where the work comes from, including what each channel costs a Canadian practice per signed client.
The three things sold as a vCISO
The directory is organised around this distinction. Three different services are sold under one title, priced differently, and a proposal that does not say which one it describes is the most common way a buyer ends up with something they did not want.
| What it is | What you get | What it does not include | Typical price, CAD |
|---|---|---|---|
| Security leadership | An accountable person who decides what risk the company takes, holds that position in front of a board, an insurer or a customer, and is named in your trust documentation | Delivery. They decide and direct, somebody else builds | $3,000 to $6,000 a month |
| Program delivery | Someone driving a SOC 2, ISO 27001 or remediation plan to a date: scope, control design, evidence, the auditor relationship | The audit itself, which has to be independent, and the engineering that closes the findings | $6,000 to $12,000 a month |
| Technical operations | Tuning a SIEM, managing endpoint tooling, triaging alerts, 24 hour coverage | Leadership. Nobody in this arrangement is accountable for the company's risk position | Priced as a managed service, per seat or per device |
The first two are vCISO work. The third is a managed security service wearing a better title, and buying it is fine as long as you know that is what you are buying. If a proposal spends most of its pages on tooling, it is the third thing. Listings here record which of the three a provider sells, because it is the first thing a buyer needs and the last thing most provider websites make clear. The longer version is on what a vCISO does.
What the directory will list
Providers who deliver fractional security leadership to companies operating in Canada: individual practitioners and firms offering a named security executive on a retainer or a fixed-scope engagement. Gap assessments, risk registers, policy sets, compliance program ownership, customer security reviews and board reporting.
Deliberately excluded: managed detection providers who do not offer leadership, staffing agencies placing permanent CISOs, audit firms, and anything with no Canadian client base. A provider who has never dealt with PIPEDA, PHIPA or Law 25 will learn on your budget.
Two axes are deliberately absent. There is no rating: we have not run these engagements, and a score we cannot defend is worse than none. There is no sort by price: a retainer is hours, and a number without the hours beside it misleads. What actually moves a rate covers why.
How listings work, and what each tier costs
Three states. The difference between the first two is who supplied the information. The difference between the second and the third is that somebody checked it and somebody paid for the checking.
| What you get | Unclaimed | Claimed | Verified |
|---|---|---|---|
| Appears in the directory | Yes | Yes | Yes |
| Who wrote the details | Us, from public sources | The firm | The firm |
| Firm can edit it permanently | No, until claimed | Yes | Yes |
| Description shown | One line | One line, 300 characters | Full profile |
| Business registration, insurance and credentials checked | No | No | Yes |
| Placement | Below claimed | Below Verified | Above the free tiers |
| Order within the tier is for sale | No | No | No |
| Cost | $0 | $0, permanently | $300 CAD a month, or $3,000 CAD a year |
Verified says specific facts were checked: that the business is registered in Canada, that the professional liability insurance the provider states is in place, and that the named practitioners exist and hold the credentials claimed. It says nothing about whether the work is good, and no amount of paying changes the order results appear in within a tier. The full terms, including what happens to enquiries on each tier, are on the page for firms.
Why the price is on the page before the listings exist
Directories that add a paid tier after building an audience usually change what free listings get at the same time. Publishing the price and the rules first means the terms a firm listed on day one agreed to are the terms on the page. Verified is a factual check, ordering is never sold, and if that changes it will be written here.
What a listing shows
The three rows below are examples, not real firms. The names are invented to show the format and the difference between the tiers.
Example Security Partners Verified
Illustration of a Verified listing, not a real firm. A Verified row carries the full profile and means we confirmed the registration, the insurance and the named practitioners. It does not mean we have judged the work.
Example Advisory (sole practitioner)
Illustration of a claimed listing, not a real firm. Claimed means somebody at the business confirmed they control it and corrected the details. It is free and stays free, and it carries a one line description rather than a profile.
Sample Fractional CISO Co Unclaimed
Illustration of an unclaimed listing, not a real firm. Unclaimed rows are built from public information and carry fewer fields until someone at the business confirms them, so treat the detail as only as good as the public record it came from.
Nothing above is a firm. Real listings will appear in these same three states, and the badges will mean what this page says.
How to evaluate a provider
After which of the three you are buying, the distinction that matters is an individual practitioner against a firm with a bench. Neither is right in general.
| Consideration | Individual | Firm with a bench |
|---|---|---|
| Who you get | The person you interviewed, every time | Often a different consultant than the one who sold the work |
| Continuity | Illness, holiday or a lost interest ends coverage | Cover exists, though the replacement may be junior |
| Range | Deep in what they have done, thin outside it | Specialists available for privacy law, cloud, incident work |
| Price | Usually the lower half of the band | Usually the upper half, carrying overhead |
| Incident capacity | One person cannot run a multi-day response alone | Can surge, if the contract says so |
An individual is often the better buy for a company under 100 people with a single framework and no regulated data. A firm earns its premium when you have several environments, an acquired entity, or a real chance of needing more than one pair of hands in a bad week.
What to ask before signing
- Which of the three are you selling me? Ask it directly and listen for whether the answer is about decisions or about tools.
- Who specifically does the work, and what else are they on? Get the individual named in the agreement and ask how many other clients that person carries. Someone holding eight retainers is not giving any of them much attention.
- What happens if that person becomes unavailable? Get the continuity arrangement in writing, including whether you approve the replacement and what happens to the fee while cover is junior.
- Two references from companies like yours. Same size, same framework, same province ideally. Ask the reference what the provider got wrong, not whether they were happy.
- Show me an anonymized deliverable. A risk register or a board report from a real engagement with names removed. Ten minutes with an actual artefact beats an hour of discussion.
- What do you sell besides advice? If they also provide the audit, the tooling or the managed service, understand how that shapes what they recommend. It does not disqualify anyone. It is context.
- Which Canadian privacy regime applies to us and why? A provider who answers PIPEDA for a Quebec company, or who has not heard of Law 25, is telling you their experience is American.
- What is not included? Compare against the scope list. Monitoring, tool implementation, penetration testing and the audit itself sit outside a retainer, and a proposal quietly including them is either underpriced or vague.
- Do you carry professional liability insurance? Ask for the coverage amount if the provider will be your named security officer.
Send every provider the same scope rather than your situation, or the proposals will not be comparable. The job description is the document to send, and the hours calculator gives you the monthly figure to put on it. Price the shortlist against the bands on fractional CISO cost. A quote well below the range means fewer hours than you assumed, not a bargain, and one well above needs to be explained by scope. Provinces are covered on the Canadian market overview, and if a SOC 2 report is the reason you are looking, what a vCISO owns on a SOC 2 program sets out what to hold them responsible for.
Skip the directory and get quotes
Describe your situation and the hours you think you need. We will put it in front of Canadian providers so you can compare like for like.
Get matchedCommon questions
How did firms get into this directory?
Most were researched from public information: registration records, the firm's own site, and the credentials it publishes. Those listings are ours rather than the firm's until someone there claims it. Nothing here is scraped from search results or invented to pad the list. A claimed listing is free and becomes the firm's to edit.
How much does it cost to be listed?
Nothing for an unclaimed or a claimed listing, permanently. Verified is the paid tier at $300 CAD a month or $3,000 CAD a year, and it covers the cost of checking business registration, insurance and practitioner credentials. Paying for Verified moves you above the free tiers and does not affect the order inside a tier, and it never buys a recommendation.
What does the Verified badge actually prove?
That specific facts were checked: the business is registered in Canada, the stated professional liability insurance is in place, and the named practitioners exist and hold the credentials claimed. It says nothing about quality of work. References and a sample deliverable remain the only way to judge that.
Should we choose an individual or a firm?
An individual practitioner is usually the better value for a company under about 100 people with one framework and no regulated data, because you get the senior person directly at the lower end of the price band. A firm is worth the premium when you have several environments, an acquired entity, or a genuine chance of needing more than one person during an incident.
How do I get my firm added?
Through the page for firms, which claims an existing listing or adds a new one with the same form. Use an address at your firm's own domain, because the confirmation link has to land in a mailbox at the company the listing points at. Claiming is free and you can correct or remove the listing at any time.
Is the operator of this site also a provider?
Yes. TrazTech Inc. operates this site and also does security and compliance work, so it appears in the directory like any other firm and sees enquiries from the quote form first. That is worth knowing before you read anything here as neutral, and it is stated on the quote form itself.