Fractional CISO services and what each costs
Fractional CISO work is usually sold as a monthly fee, but underneath it is a set of named deliverables you can price individually. Knowing what each one is worth is how you tell a fair retainer from an expensive one.
Fractional CISO services break down into about a dozen named deliverables: a gap assessment, a risk register, a policy set, a security roadmap, ownership of a compliance program, customer questionnaire and vendor review support, third-party risk management, an incident response plan and the tabletop that tests it, cyber insurance application support, board and executive reporting, and a handover package at the end. Some of those are one-time artifacts worth buying on their own. The rest only work as an ongoing arrangement: their value is in being maintained, not produced.
Each is priced standalone below in Canadian dollars, so you can read a retainer proposal and see what you are being sold. What is inside versus outside a typical retainer fee is set out on vCISO services, and the retainer bands themselves are on vCISO pricing.
One-time deliverables you can buy on their own
Each has an end, an acceptance test, and a document you keep. If a provider will not sell them separately, find that out before you sign a retainer.
| Deliverable | Standalone price | What good looks like |
|---|---|---|
| Security gap assessment | $5,000 to $20,000 | Findings mapped to a named framework, each with an owner, an effort estimate and a date. Not a maturity score on its own |
| Risk register and risk assessment | $5,000 to $15,000 | Risks written in business terms with named owners and accepted risks explicitly signed off, not a spreadsheet of vulnerabilities |
| Policy set, authored | $8,000 to $25,000 | Twelve to twenty policies that describe what your company actually does. Templates with your logo on them fail audits |
| Security roadmap | Usually bundled with the assessment | Sequenced by dependency and budget cycle, with a version that fits on one page for the board |
| Incident response plan | $4,000 to $12,000 | Names, phone numbers, decision authority, and the breach assessment steps PIPEDA requires |
| Tabletop exercise | $4,000 to $10,000 per exercise | A written scenario, executives in the room, and a findings memo that changes the plan afterwards |
| Cyber insurance application support | $3,000 to $8,000 | The provider answers the application directly and evidences the control claims, rather than reviewing your draft |
| Security diligence response for a raise or sale | $8,000 to $25,000 | An account of known risks with dates against them that survives a buyer's technical reviewer |
| ISMS build for ISO 27001 | $25,000 to $60,000 | Scope, statement of applicability, risk methodology and the management review cycle actually running |
Buy the assessment first, always
Buy the gap assessment first and read it before committing to anything ongoing. A good one frequently concludes that your next purchase is implementation capacity rather than more leadership, and that conclusion is worth the fee. Insist on owning the output in an editable format with no restriction on showing it to another provider.
The services that only work ongoing
These have no end state. Their value comes from someone attending to them every month, which is why buying them as a one-off produces an artifact that is stale within a quarter.
- Compliance program ownership. Driving a SOC 2 or ISO 27001 to a date, keeping evidence collected inside the observation window, and managing the audit firm. The single most time-hungry thing on this list.
- Customer questionnaire and vendor review support. For a company with large buyers this can consume half a retainer by itself. Ask how many questionnaires a month are included before you agree a fee.
- Third-party risk management. Reviewing your own suppliers, which PIPEDA makes your responsibility when personal information is handled on your behalf.
- Access reviews. Quarterly, evidenced, and the artifact that answers more questionnaire items than any other.
- Board and executive reporting. A quarterly paper that a non-technical director can act on. See the board report template for what belongs in one.
- Risk register maintenance. A register nobody has touched in six months is evidence of a program that is not running, and auditors read the modification dates.
- Named security officer for customers and insurers. Being reachable, taking the customer's call, and standing behind the answer.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The deliverables that are specific to Canada
American providers do not produce these. Their absence from a proposal means the templates were written for a different country.
| Deliverable | Why it exists |
|---|---|
| Designated individual accountable for personal information | PIPEDA requires a named person. The role is often assigned to the fractional CISO in practice, which should be explicit in the contract |
| Breach record register, retained 24 months | PIPEDA requires a record of every privacy breach whether or not it was reportable. Almost no small company keeps one |
| Privacy impact assessments | Quebec's Law 25 requires them for projects involving personal information, and for transfers outside Quebec |
| PHIPA agent obligations | Holding health information for an Ontario custodian usually makes you an agent under that Act, with duties that follow the data |
| Federal contract security requirements | Reading what a solicitation actually obliges you to do, including screening, and closing the gap before award |
What gets sold under this name and is not
Three things appear in proposals headed fractional CISO services that are a different purchase at a different price.
Monitoring and alert triage. Running a detection stack and responding to alerts is a managed security service. It is priced per endpoint or per log volume, it is delivered by a shift rota, and it is not leadership. A proposal that spends most of its pages on tooling is selling you this.
Tooling implementation. Deploying endpoint detection, configuring identity, standing up logging. Real work, frequently necessary, and engineering rather than executive time. Paying $300 an hour for it is poor value.
The audit itself. Whoever built your program cannot attest to it. The audit or certification goes to an independent firm at $15,000 to $60,000 CAD, and a penetration test at $8,000 to $40,000 CAD is separate again.
That split is also the commercial question facing the consultancies that sell them, worked through with the revenue arithmetic in from project work to retainer.
Diligence support gets bought at a specific moment rather than as part of a program, and what a Canadian Series A actually checks is narrow enough that most of the preparation is document work you can do yourselves.
Price these against real Canadian providers
Tell us which deliverables you need and whether you want them one at a time or on a retainer. We will put the same scope in front of providers that do the work.
Get matchedCommon questions
Can I buy just a gap assessment without a retainer?
Yes, and for a company under fifty people it is usually the right first purchase. Expect $5,000 to $20,000 CAD depending on scope and framework. Some providers price it as a loss leader and credit it against a retainer, which is fine, but confirm you own the output outright either way so it remains useful if you go elsewhere.
What does a fractional CISO produce in the first 90 days?
Typically a gap assessment against a named framework, a risk register with owners, a prioritised roadmap, and either a first policy set or the plan to build one. If a provider cannot tell you what artifacts exist at day 90, that is the question to press on, because the first quarter is where a retainer earns its keep or does not.
Does a fractional CISO manage our security tools?
No. They decide what tooling the program needs and hold whoever operates it to account, but running a detection stack is a managed security service with different economics. If you need both, buy both and keep them contractually separate so the person advising on tooling is not the person selling it.
Which services should we keep in house instead?
Evidence collection, ticket chasing, access review execution and policy formatting. All of that is work a competent operations or IT person can do at a fraction of $300 an hour, and doing it internally is the largest saving available on a retainer. A provider worth hiring will point this out without being asked.
What should be in the handover if we end the engagement?
Every artifact in editable form: policies, risk register, roadmap, assessment, evidence index, vendor register and the breach record. Also the credentials and administrative access to any platform bought in your name. Agree this at the start rather than at the end, because a handover negotiated during a departure rarely goes well.