Fractional CISO vs compliance consultant
Both roles turn up in the same month, for the same reason, and are frequently quoted against each other. They are not substitutes. One produces a defined outcome and stops; the other takes on responsibility that has no end date.
The difference is not seniority, and it is not how many hours a week somebody works. It is what they are on the hook for. A compliance consultant is accountable for a deliverable: a certification achieved, a gap closed, a questionnaire answered, a policy set written and approved, all of it measured against a standard somebody else wrote and a date somebody else set. A fractional CISO is accountable for decisions, including the decisions no framework asks about, for as long as the engagement runs.
That single distinction explains everything downstream. It explains why one is priced as a project and the other as a retainer, why one ends on a fixed date and the other ends when you replace it, and why the two most common hiring mistakes are so predictable that you can spot them in the first paragraph of a proposal.
What each role is actually accountable for
A compliance consultant is measured against a document. SOC 2 has trust services criteria. ISO 27001 has Annex A. PIPEDA has ten Fair Information Principles. Quebec's Law 25 has a schedule of obligations with dates attached. The consultant's job is to read your company against one of those, find where it falls short, close the distance, and assemble the evidence that proves it. When the report is signed or the certificate issued, the work is objectively finished. There is a definition of done and both parties can see it.
A fractional CISO has no equivalent document. The job is to decide what risk the company accepts and to be named as the person who decided. That covers the framework work, but it also covers the long list of things no framework asks about: whether to fire a vendor that just disclosed a breach, whether the new product line changes what data you are holding and under whose law, whether the engineering team's plan to ship on a Friday before a long weekend is acceptable this time, whether an insurer's question can be answered honestly as written. What a vCISO actually does sets out the week-by-week version of that, and what is a virtual CISO covers why virtual, fractional and vCISO all name the same job.
The test that settles most arguments
Ask what happens if the answer is not in the framework. A compliance consultant will tell you, correctly, that it is out of scope. A fractional CISO has to answer it anyway, because the question arrived and somebody has to own the call.
How the engagements are shaped differently
Consulting work is scoped. There is a statement of work, a list of deliverables, an acceptance criterion and an end date. Change the scope and you sign a change order. That is not a limitation, it is the product. A fixed scope is what makes the price knowable in advance and what protects you from paying for drift.
Fractional CISO work is a standing responsibility with a bounded time commitment. The retainer buys hours, but what you are actually buying is decision rights: somebody with the authority to say yes or no on security, whose name goes on the risk acceptance, who answers the customer's security team when they call. The hours are how the cost is controlled, not what the engagement is about. Engagement models covers how the retainer, project and hybrid shapes are structured in practice.
| Compliance consultant | Fractional CISO | |
|---|---|---|
| Accountable for | A named deliverable against a standard | Security decisions, including unframed ones |
| Contract shape | Statement of work, fixed scope, end date | Monthly retainer, hours band, notice period |
| Definition of done | Report issued or certificate granted | None. It ends when you replace the role |
| Authority | Recommends. Your people decide | Decides within an agreed risk mandate |
| Named externally | Rarely | Often, in contracts, insurance forms and diligence |
| Typical trigger | A deadline you have been given | A question nobody inside can answer |
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
How they are priced and staffed
Consulting is priced against effort for a known outcome, usually as a fixed fee or a phased fee, because the scope is defined before the money moves. The honest version of this splits into an assessment first and remediation second, since nobody can price the second before the first has told them what the gaps are. A firm that quotes a full readiness program to the dollar before it has looked at your environment is guessing, and the guess is protected by a change order you have not read yet.
Retained leadership is priced against availability. You are paying to have somebody's judgment on call within a response time, not to receive a fixed artifact. That is why the number tends to be monthly, why it survives a quiet month, and why the useful question at renewal is what decisions got made rather than what documents got produced. Fractional CISO cost in Canada has the benchmark bands by hours per month.
Staffing differs just as sharply. A compliance engagement is often delivered by a team: a lead who scopes it, an analyst who does the evidence collection, a technical writer for the policy set. Substitution is normal and mostly harmless, because the deliverable is defined. A fractional CISO engagement is one named person, and substitution is the whole risk. If the proposal says "our team" and never names a human, you are being sold consulting capacity with a leadership label on it. The contract checklist has the key person clause and the notice terms to insist on.
What happens at the end
A consulting engagement ends cleanly and should leave you self-sufficient against that one framework. You own the policies, the evidence register, the control mapping and the surveillance calendar. The failure mode is that nobody internal can maintain it, so the artifacts age quietly until the next audit cycle finds them stale. Ask before you sign who operates the controls after handover and what the twelve-month maintenance load looks like in hours.
A fractional engagement does not end, it transitions. Either the company grows into a full-time hire and the fractional CISO runs the search and hands over, or the scope shrinks back to periodic advisory. Both are planned outcomes and both belong in the contract from the start. An engagement that simply stops on thirty days notice leaves nobody holding the risk register, and the register is the part that matters.
Who should hire which, by trigger
Company size is a poor guide. A forty-person company selling only to other small businesses may need neither. A twelve-person company that just signed a bank may need both. Hire by what happened.
Hire a compliance consultant when the problem has a name and a date. A customer has made SOC 2 a contract condition for renewal. A European buyer has asked for ISO 27001. Law 25 obligations apply to you and nobody has mapped them. You failed a vendor security review on specific findings and have been given a remediation window. In each of these the outcome is defined by somebody outside your company, which is exactly the condition under which fixed scope works.
Hire a fractional CISO when the problem is that nobody can decide. Security questions arrive weekly and land on whoever is least busy. Your engineering lead has become the de facto security owner and it is costing you a senior engineer. A contract requires you to name a security officer. An incident happened and the post-mortem showed there was no one to call. Your board or your investors have started asking for security reporting and nobody can write it. When do you need a fractional CISO works through those triggers in detail, and the readiness check turns them into a short questionnaire.
The overlap, which is real
Most fractional CISO engagements in Canada have a certification underneath them, because the certification is what unlocked the budget. So the fractional CISO does compliance work: scoping the framework, running the readiness program, managing the evidence schedule, dealing with the auditor. From the outside those weeks look identical to a consulting engagement.
The difference is what else is inside the same retainer. The consultant's scope ends at the framework boundary. The fractional CISO's does not, and the questions that arrive from outside the framework are the ones that tend to cost money. One person genuinely does both jobs when the practitioner is senior enough to lead and hands-on enough to build, which is common in the Canadian market at the small end. That is a legitimate arrangement. What is not legitimate is a proposal that charges retainer pricing for consulting scope, or one that promises standing accountability while the statement of work lists only deliverables.
Where the two are bought together, split the contract into a defined readiness project with acceptance criteria and a separate standing advisory retainer with its own scope. Both can run at once and both can be assessed on their own terms at renewal. The scope definer produces that split as a document you can put in front of a provider.
What goes wrong when you hire the wrong one
The two failures are mirror images and both are common.
- A consultant asked to own incident response. The statement of work says readiness. Then something happens on a Saturday and the company calls the only security person it has heard of. A consultant may well help, but they have no mandate to disconnect a system, no authority to engage counsel, no standing to make the notification call, and no contractual obligation to answer at all. PIPEDA notification is a legal assessment with a real risk of significant harm test attached, and the breach record has to be kept for twenty-four months regardless of the outcome. Nobody makes that call on a favour.
- A fractional CISO asked to write forty policies in six weeks. This is buying a senior decision maker to do production work. It burns the retainer on drafting, produces a policy pack describing a company that does not exist, and leaves the actual decisions unmade. Auditors detect invented policies immediately by asking for the evidence each one implies. If the deliverable is volume of documents to a deadline, scope it as a project and price it as one.
- Either one asked to be the auditor. The firm that builds the program cannot attest to it. Audits are signed by an independent licensed CPA firm, and ISO certification comes from an accredited certification body. A proposal that blurs this line should end the conversation.
How to tell from a proposal which one you are buying
Ignore the title on the cover page. Read for these five things.
- Is there an end date? A hard completion date with acceptance criteria is consulting. A notice period and a monthly fee is leadership.
- Are the outputs documents or decisions? A deliverables list with no mention of risk acceptance, no reporting line and no named authority is a consulting engagement whatever it is called.
- Is a human named? One named practitioner, with their background, and a clause about what happens if they leave. Otherwise the firm is reserving the right to staff it with whoever is free.
- Is remediation priced before the assessment? It cannot honestly be. A quote that prices the fix before anybody has seen the gaps is either padded or about to grow.
- What is excluded? Look for incident response, customer questionnaires, vendor reviews and board reporting. If those are absent, they are not included, and they are the things that arrive whether or not you bought them.
Two more worth asking directly: which entity signs the contract and under which province's law, and where your engagement data lives. Both matter more in a Canadian context than most buyers expect, and both are easier to settle before signature than after.
The third option people conflate with both
A managed security service is neither of these, and it gets quoted against both because the invoice is also monthly. A managed service operates: monitoring, alert triage, endpoint coverage, patching, sometimes identity administration. It is a genuine need and for many companies it is the more urgent purchase. What it does not do is decide. An operator cannot independently judge the risk of the systems it runs, and asking it to do so puts it in the position of grading its own work. That is structural, not a criticism of any provider.
The practical failure is a company that buys managed monitoring, assumes security leadership is included, and discovers during a customer security review that nobody can answer questions about risk acceptance, policy ownership or third-party assessment. The service was doing its job. It was never asked to do this one. How the line gets drawn between leadership and managed operations works through the distinction. Most companies past a certain point need operations and decision-making both, bought separately and from different parties.
Not sure which one you need
Describe the trigger rather than the title. We will match you with Canadian providers who do that kind of work.
Get matchedThe tools on this site cover the adjacent questions: scoping an engagement, estimating hours, and checking a contract before you sign it. This site is run by TrazTech Inc., which also does readiness and fractional CISO work in Canada.
Common questions
Can one person be both a fractional CISO and a compliance consultant?
Often, and at the small end of the Canadian market it is normal. The practitioner who can lead is frequently the same one who can build. What should not blur is the contract. Write the readiness work as a project with acceptance criteria and the standing accountability as a retainer with its own scope, so you can judge each at renewal instead of guessing which half the fee paid for.
We just need SOC 2 by March. Which one is that?
A consultant. The outcome is defined, the date is set by someone outside your company, and fixed scope works well under those conditions. The reason to consider a fractional CISO instead is if the certification is the first of several external demands and nobody internal will own what comes after it. Certification is a point in time; the questions keep arriving.
Is a fractional CISO more expensive than a compliance consultant?
They are not comparable on price because they are not selling the same thing. A consulting fee buys a finished deliverable and stops. A retainer buys availability and judgment on an ongoing basis. Compare a consulting quote against another consulting quote for the same scope, and a retainer against the loaded cost of the alternative, which is usually a full-time hire or a senior engineer spending a third of their time on security.