How to choose a vCISO: an evaluation guide
Choosing a vCISO comes down to four things: who actually shows up, whether they have done your specific trigger before, whether they are independent of what they will recommend you buy, and what you keep when the engagement ends. Price separates almost nobody.
Choose the provider who has run your specific trigger before, will put a named person on it who you have met, has no financial interest in the tools they will tell you to buy, and will hand you a package you own when it ends. Everything else, including the monthly rate, is second order. Two proposals at the same price routinely differ by more than $30,000 CAD a year once the terms are counted, which is covered on vCISO pricing.
The answer may be nobody. Under about 25 people with nothing external forcing the question, a retainer is premature and the money belongs on the basics instead. Run the qualification tool first, and treat a "not yet" as a real result rather than a prompt to shop harder.
Do three things before you talk to anyone
- Write the trigger in one sentence. "Our largest customer requires a named security officer by 31 March" is a scope. "We should probably take security seriously" is not, and a provider handed the second one will sell you the largest thing you will agree to.
- Size the hours yourself. Use the hours calculator or work it out by hand. A provider sizing your retainer has an interest in the answer, and the single largest saving available on this purchase is buying fewer hours than the first proposal suggests.
- Decide what stays internal. Evidence collection, ticket chasing and policy formatting do not need a security executive at $300 an hour. Write down which of those your own operations people will carry.
The questions that actually separate providers
Most evaluation questions get the same answer from everyone. These do not.
| Ask | A good answer sounds like | A bad answer sounds like |
|---|---|---|
| Who is the named individual, and is that contractual? | A name, their availability in days per month, and a clause that says you approve any substitution | "Our team", or a principal in the sales call who is never mentioned again |
| Describe the last three engagements like ours in a sentence each | Specific triggers, sizes and outcomes, including one that went badly | Sector generalities and a logo wall |
| What do you sell besides advice? | Nothing, or a clear statement of the products they resell and how recommendations are documented with alternatives | A vague answer, or a retainer priced below what the hours could possibly cost |
| What do we own when this ends? | Everything, in editable formats, with no restriction on showing it to another provider | Access to a portal that stops working when billing stops |
| How many hours did you bill against your last three retainers of our size? | A real number, usually below contracted, and advice to buy fewer hours | Contracted hours quoted back, or no idea |
| What would make you tell us not to hire you? | A described situation. Everyone competent has one | "We can help any company", which is a sales answer to a judgement question |
| Who answers a customer security questionnaire, you or us? | A clear split with an hours estimate attached | Silence, and then it consumes half the retainer in month three |
The independence question deserves a position
A vCISO attached to a managed security provider is being paid to lead your program by a company whose revenue depends on selling you more product. That is manageable if you know it and if recommendations arrive in writing with at least one alternative and a stated reason. It is not manageable when the retainer is priced below cost as a route into a tooling contract. A retainer quoted at $2,500 CAD a month is not cheap advice, it is a distribution channel. Read the whole master services agreement before you decide that is fine.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Which credentials mean something
Certifications are a weak signal for this role and a strong one for the roles underneath it. A person with no formal credential who has been examined by a regulator three times is a better hire than one with four acronyms and no scar tissue.
- CISSP
- Broad and common. Confirms the person knows the vocabulary. Says almost nothing about whether they can run a program or hold a room.
- CISM or CRISC
- Management and risk oriented, so more relevant here than CISSP. Still a floor rather than a differentiator.
- Prior audit and examination experience
- The most useful thing on the CV. Someone who has sat opposite an auditor or a regulator makes different decisions than someone who has read about it.
- Sector experience in your sector
- Matters most in financial services, health and anything with operational technology. Matters least in general B2B software, where the trigger is usually SOC 2 and the work is portable.
- Canadian privacy law fluency
- Non-negotiable if you hold personal information. A provider whose templates do not mention PIPEDA's 24 month breach record obligation, or Law 25 where you have Quebec customers, is selling you American work in Canadian dollars. See how a DPO differs from a CISO.
Reading credentials
What they tell you. CISSP, CISM and CISA show broad knowledge and experience requirements. ISO 27001 Lead Implementer or Lead Auditor shows framework depth. None of them shows the person has run a program at a company your size.
How to verify. ISC2 and ISACA both let you verify a member's certification online. Ask for the certification number.
What matters more. References from two or three companies of your size and stage, and a sample board report the person wrote.
Taking references properly
Two references, chosen by you rather than offered, are worth more than five they picked. Ask for a client at your size with your trigger, and for one engagement that has ended. The second request reveals the most: a provider with no completed engagements is either new or has never let a client leave cleanly.
Taking references that tell you something
Who to ask. A client that has worked with the person for at least a year, and one that stopped working with them.
What to ask. What changed in the first ninety days, how often the vCISO was actually available, and what they would do differently.
Red flag. References only from long-past engagements, or only from people who were not the day-to-day contact.
A scoring sheet you can put in front of a board
Weight the criteria before you see the proposals, not after, because afterwards you will weight them to match the provider you already liked.
| Criterion | Weight | How to score it |
|---|---|---|
| Relevant experience with your exact trigger | 25% | Count comparable engagements, not years in the field |
| The named individual, and your confidence in them | 25% | Score the person you met, not the firm |
| Independence from what they will recommend | 15% | What they sell, and whether alternatives get documented |
| Contract terms: term, rollover, overage, exit | 15% | Use the contract checklist |
| Price, normalised for hours and inclusions | 10% | Only after everything above is comparable |
| Cultural fit with your executive team | 10% | Can they say no to your CEO in a way your CEO accepts |
Price at 10 per cent is deliberate. The spread between credible Canadian providers on a mid-market retainer is a few thousand dollars a month. The spread between a provider who has run your trigger before and one who has not is a delayed audit, a lost large deal, or a program that has to be rebuilt. If price is doing more than 10 per cent of the work in your decision, the proposals were not normalised properly.
Red flags
- A proposal that arrives without asking what triggered the question.
- Twelve month minimum term on a first retainer. Three to six is reasonable, twelve transfers all the risk of a bad fit onto you.
- The compliance platform subscription buried inside the retainer with no line item, so you cannot tell what the advice costs.
- A promise of round the clock incident availability on a mid-market retainer. It is not being honoured or it is priced in somewhere you have not found.
- Refusal to sell any deliverable standalone. It usually means the deliverables are thin and the value is the recurring invoice.
- No answer to what they would decline to work on.
Judging it after you sign
The evaluation does not end at signature. By day 30 you should have an assessment you understand and a roadmap with dates and owners. By day 90 the first items should have closed and the board should have seen something. What that looks like properly is on the vCISO first 90 days, and if it is not happening, the diagnosis and the exit are on when a vCISO is not working.
The cheapest version of this decision is deciding not to make it yet. If the trigger was a single stalled deal, a deal blocked on a security review is usually a fixed-scope project rather than a provider search, and under 30 people the free list answers more of a questionnaire than any purchase does.
Putting TrazTech through the same questions
TrazTech operates this site and is listed first in the directory, so run the scoring sheet on it rather than around it. What it does is readiness and program leadership, with the implementation as well as the advice. It coordinates with the CPA firms that issue SOC 2 opinions and can introduce you to one, which is an introduction and not preferential pricing or a result. The compliance workspace it runs is free and stays at $0 on an engagement, so it is not sitting inside a retainer unlabelled.
What it will tell you not to buy: under about 25 people, not yet, which is this site's position and TrazTech's. Where a regulator drives the mandate, a specialist working in that regime weekly is the better hire. And a company with nobody available to do the work does not need advice yet, it needs capacity.
Get comparable vCISO proposals
Send one scope to several Canadian providers and get quotes you can put side by side without normalising them yourself.
Get matchedCommon questions
How do I choose between vCISO providers in Canada?
Score four things before price: whether they have run your exact trigger before, who the named individual is and whether that is contractual, whether they sell products they will also recommend, and what you own when the engagement ends. Send every provider the same written scope so the proposals are comparable, and weight price at around 10 per cent of the decision.
How many providers should we talk to?
Three is usually right. One gives you no calibration, and five costs you weeks of executive time on a purchase of $60,000 to $120,000 CAD a year. Make all three price the same document rather than their own reading of your situation, otherwise you are comparing three different products.
Should we choose an independent operator or a firm?
An independent gives you the person you interviewed, at a lower rate, with a single point of failure on holidays, illness and their next full-time offer. A firm gives you cover and specialists to pull in, at a higher rate, with a real risk that the day to day work is done by someone junior. If you are a small company with one trigger, the independent is usually right. If you have a committee expecting continuity, read CISO as a service.
What if the best provider is more expensive than we budgeted?
Buy fewer hours from them rather than more hours from someone weaker. Eight hours a month of a person who has run your trigger before beats twenty hours of someone learning it on your time, and you can move internal people onto the evidence and coordination work. Ramping, where you buy 30 hours for the first two months and 12 after, is normal and worth asking for.
Is it a problem if the vCISO works with our competitors?
Usually not, and often it is why they are worth hiring, because sector pattern recognition is most of the value. What matters is a confidentiality clause that survives the engagement and a clear position on what they will not carry between clients. Ask them directly how they handle it. A provider who has never thought about the question is the one to worry about.