How many vCISO hours a month do you need?
The most asked question about fractional security leadership is how many hours to buy. Buying twenty and consuming eight is the usual way companies overpay, and buying eight when the work needs thirty is how a deadline gets missed.
Hours are the whole price. A vCISO retainer is one senior person's attention measured in a monthly number, and every provider's quote is that number multiplied by a rate that barely moves across Canada. Getting the number right before you take a proposal is the difference between comparing quotes and guessing at them.
Six questions. The answer appears on this page with the arithmetic shown, and nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
How the number is built
A baseline by headcount, plus the work the year actually contains, plus whatever the program is missing, minus whatever you already have and whoever you have to direct. The result is a range, because the honest answer to this question is a range: an incident-free quarter and a bad one differ by more than everything else on the list combined.
| Company size | Baseline hours per month |
|---|---|
| 1 to 20 | 4 |
| 21 to 50 | 6 |
| 51 to 200 | 10 |
| 201 to 500 | 16 |
| More than 500 | 22 |
Those baselines come from what the recurring work costs at each size: monthly access and vulnerability review, the risk register, supplier additions, quarterly board reporting and the questionnaires that arrive whether or not you planned for them. They are the floor for a program that already runs, not an estimate of a first year.
| Answer | Effect | Why |
|---|---|---|
| A first certification with a date | Plus 14 | Scope, control design, evidence chase and the auditor relationship, for the duration |
| Recovering from an incident | Plus 20 | Front-loaded into the first quarter, then steps down sharply |
| A regulator or statutory obligation | Plus 8 | Evidence in the regulator's form, not the framework's |
| Questionnaires arriving steadily | Plus 4 | Falls once an answer library exists |
| Maintaining a certification | Plus 4 | Surveillance, evidence continuity, annual reviews |
| Nothing written down | Plus 6 | The first pass at policy, register and inventory has to be written by someone |
| Cloud plus on premises, or a second entity | Plus 4 to 6 | Two scopes, not one |
| A security team of two or more | Minus 6 | The role becomes direction rather than delivery |
| Nobody internal at all | Plus 4 | Everything routes through the one person you are paying most for |
| Each control genuinely in place | Minus 1 | Up to five. Evidence that exists does not have to be created |
Rates are the easy half. Canadian retainers price at roughly $300 to $375 CAD an effective hour and the rate falls as the commitment rises, which is why the published bands on vCISO pricing line up the way they do. The total cost of a year, including the audit, the platform and the penetration test that sit outside every retainer, is on fractional CISO cost.
If the answer comes back small
It sometimes does, and that is a real answer rather than a failure of the tool. Under about 25 people with nothing external forcing the question, a founder and a competent managed IT provider cover the ground, and buying fractional leadership before there is a program to lead produces documents nobody reads. The need check is the longer version of that argument, and the case for waiting sets out what to do instead.
Common questions
How many hours a month does a vCISO actually need?
For a company of 50 to 200 people in steady state, 8 to 16 hours a month keeps a program honest. Driving a first SOC 2 or ISO 27001 to a contractual date takes 20 to 40 hours a month for as long as the date runs. Recovering from an incident takes two or three days a week for a quarter and should step down after it. Company size matters less than what the year contains.
What happens to hours we do not use?
That depends entirely on the contract and it is worth thousands a year. Some providers roll unused hours forward for a quarter, some let them expire monthly, and some cap the rollover. Ask before you sign, and ask what an overage hour costs as well, because a program that runs hot for two months around an audit adds up quickly when overage is billed at a premium.
Is it cheaper to buy more hours?
Per hour, yes. The effective rate falls from about $375 CAD an hour on a small advisory retainer to about $300 on a larger program retainer, which is why providers push the bigger number. It is only a saving if you consume them. Buying twenty hours and using eight costs more per hour of value received than buying ten and using ten.
Does the first month need more hours than the rest?
Almost always, and many providers price it separately as an assessment at $5,000 to $20,000 CAD before the retainer begins. That is reasonable, since the inventory, the gap assessment and the roadmap all land in the first four weeks. Ask whether the fee is credited against the retainer and make sure you own the output.
Should we buy hours or a fixed-scope project?
If what you need is one defined outcome with an end date, buy the project: readiness, an ISMS build or a diligence response run $15,000 to $60,000 CAD in total and nobody has to guess at hours. Buy a retainer when you need somebody accountable between the projects, which is the part a fixed scope cannot cover.
Take the number to providers
Tell us the hours you landed on and what has a date against it, and we will put the scope in front of Canadian providers who work at that size.
Get matched