Canadian vCISO directory
The directory is empty. It is being built, listings are free, and this page sets out what will be in it, how a listing works, and how to judge a provider in the meantime.
This directory lists vCISO and fractional CISO providers serving Canadian companies. There are no listings in it yet. It is new, nobody has been added, and putting up a page of placeholder firms to look established would be dishonest and would waste your time. What this page can do right now is tell you exactly how listings will work, and give you the questions that separate a provider worth paying from one worth passing on.
If you need providers today rather than when the directory fills, the quote request goes directly to Canadian providers we work with, and it is the faster route.
What the directory will list
Providers who deliver fractional security leadership to companies operating in Canada. That means individual practitioners and firms offering a named security executive on a retainer or a fixed-scope engagement: gap assessments, risk registers, policy sets, compliance program ownership, customer security reviews and board reporting. It is the work described on what a vCISO does.
Deliberately excluded: managed detection providers who do not offer leadership, staffing agencies placing permanent CISOs, audit firms, and anything with no Canadian client base. A provider who has never dealt with PIPEDA, PHIPA or Law 25 will learn on your budget.
Each entry will carry the province or provinces served, the engagement models offered, the frameworks the provider works to, and whether they are an individual or a firm with more than one practitioner. That last field is the one buyers most often fail to ask about and it changes the risk of the engagement more than price does.
How listings work
Three states, and the difference between them is about who supplied the information rather than how good anyone is.
- Unclaimed. Compiled from public sources. Free, and nobody at the firm has confirmed it. Details may be out of date.
- Claimed. Someone at the firm has confirmed they control the business, corrected the details and can keep them current. Still free.
- Verified. A paid tier. We confirm the business is registered in Canada, that the professional liability insurance the provider states is in place, and that the named practitioners exist and hold the credentials claimed. It says the facts were checked, not that the work is good. No amount of paying changes the order results appear in.
An entry will look like the example below. This is an illustration of the format using an invented firm. It is not a real provider and it is not a recommendation.
Example Security Partners Verified
Illustration of a Verified listing. Not a real firm. Shows the fields a claimed entry carries: provinces served, whether the provider is an individual or a firm with a bench, and the frameworks they work to.
Example Advisory (sole practitioner) Unclaimed
Illustration of an unclaimed listing. Not a real firm. Unclaimed entries are built from public information and carry fewer fields until someone at the business confirms them.
Why the tiers are described before the listings exist
Directories that add a paid tier after building an audience usually change what free listings get at the same time. Publishing the rules first means the terms a firm listed on day one agreed to are the terms on the page. Verified is a factual check, ordering is never sold, and if that changes it will be written here.
Adding your firm
If you provide vCISO or fractional CISO services to Canadian companies, send the details through the form and note that you are a provider rather than a buyer. A listing costs nothing. What we need is the legal business name, the provinces you serve, the engagement models and price bands you offer, the frameworks you work to, the named practitioners and their credentials, and whether you carry professional liability insurance.
Firms that also sell audits, penetration testing or managed detection are listed with that noted, because a buyer should know when advice comes from a party who benefits from the recommendation.
How to evaluate a provider
The most consequential distinction is between an individual practitioner and a firm with a bench, and neither is the correct answer in general.
| Consideration | Individual | Firm with a bench |
|---|---|---|
| Who you get | The person you interviewed, every time | Often a different consultant than the one who sold the work |
| Continuity | Illness, holiday or a lost interest ends coverage | Cover exists, though the replacement may be junior |
| Range | Deep in what they have done, thin outside it | Specialists available for privacy law, cloud, incident work |
| Price | Usually the lower half of the band | Usually the upper half, carrying overhead |
| Incident capacity | One person cannot run a multi-day response alone | Can surge, if the contract says so |
An individual is often the better buy for a company under 100 people with a single framework and no regulated data. A firm earns its premium when you have several environments, an acquired entity, or a real chance of needing more than one pair of hands in a bad week.
What to ask before signing
- Who specifically does the work, and what else are they on? Get the individual named in the agreement. Ask how many other clients that person carries. Someone holding eight retainers is not giving any of them much attention.
- What happens if that person becomes unavailable? Ask for the continuity arrangement in writing, including whether you approve the replacement and what happens to the fee while cover is junior.
- Two references from companies like yours. Same size, same framework, same province ideally. Ask the reference what the provider got wrong, not whether they were happy. The useful answer is specific.
- Show me an anonymized deliverable. A risk register or a board report from a real engagement, with names removed. Ten minutes with an actual artefact tells you more than an hour of discussion.
- What do you sell besides advice? If they also provide the audit, the tooling or the managed service, understand how that shapes what they recommend. It does not disqualify anyone. It is context.
- Which Canadian privacy regime applies to us and why? A provider who answers PIPEDA for a Quebec company, or who has not heard of Law 25, is telling you their experience is American.
- What is not included? Compare against the scope list. Monitoring, tool implementation, penetration testing and the audit itself sit outside a retainer, and a proposal quietly including them is either underpriced or vague.
- Do you carry professional liability insurance? Ask for the coverage amount if the provider will be your named security officer.
Price the shortlist against the bands on fractional CISO cost. A quote well below the range usually means fewer hours than you assumed rather than a bargain, and one well above needs to be explained by scope. Providers working in specific provinces are covered on the Canadian market overview, and if a SOC 2 report is the reason you are looking, what a vCISO owns on a SOC 2 program sets out what you should expect them to take responsibility for.
Skip the directory and get quotes
Describe your situation and the hours you think you need, and we will put it in front of Canadian providers so you can compare like for like.
Get matchedCommon questions
Why does the directory have no listings?
Because it is new and nobody has been added yet. Filling it with firms scraped from search results, or with invented names to make it look populated, would waste the time of every buyer who clicked through. It will show real providers when there are real providers in it, and until then the quote form is the working route to a shortlist.
Does it cost anything to be listed?
No. Standard and claimed listings are free and always will be. Verified is a paid tier covering the cost of checking business registration, insurance and practitioner credentials. Paying for Verified does not affect the order listings appear in and does not buy a recommendation.
What does the Verified badge actually prove?
That specific facts were checked: the business is registered in Canada, the stated professional liability insurance is in place, and the named practitioners exist and hold the credentials claimed. It says nothing about quality of work. References and a sample deliverable remain the only way to judge that.
Should we choose an individual or a firm?
An individual practitioner is usually the better value for a company under about 100 people with one framework and no regulated data, because you get the senior person directly at the lower end of the price band. A firm is worth the premium when you have several environments, an acquired entity, or a genuine chance of needing more than one person during an incident.
How do I get my firm added?
Send your details through the quote form and say you are a provider. We need the legal business name, provinces served, engagement models and price bands, frameworks, named practitioners with their credentials, and whether you carry professional liability insurance. Listings are free and you can correct or remove yours at any time by writing to [email protected].