HireACISO

What a vCISO contract should include

Two proposals at $8,000 CAD a month can differ by tens of thousands over a year once hours treatment, overage, notice and IP ownership are read properly. Here is the clause list, and the four terms most often missing.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A vCISO agreement needs twelve things in it: the named individual, the hours and how they are counted, what happens to unused and excess hours, a specific deliverable list with dates, response times, board and executive access, who signs a risk acceptance, ownership of the documents produced, confidentiality and data handling, insurance, notice on both sides, and what you get on exit. The four most often missing are the named person, the exit package, IP ownership, and who signs a risk acceptance.

The clause checklist

0 of 0 confirmed ยท

If you are still deciding whether to hire at all, start with when you actually need a fractional CISO, which covers the triggers and the three different things sold under the title.

What good clauses look like

Named person. The contract names the person who will act as your vCISO and says what happens if they leave: your right to approve a replacement or to exit without penalty.

Hours and response. A monthly hour allowance with the rollover rule written down, and three response times: routine, urgent and incident.

Exit. Thirty to ninety days notice, a handover of every document and credential, and deletion of your data from the provider's systems with confirmation.

Canadian note. If the vCISO will see personal information, the contract needs data protection terms. Under PIPEDA you stay accountable for what a service provider does with it, and Law 25 requires a written agreement with specific protections for Quebec personal information.

Why the named person clause matters most

Firm-delivered engagements are sold on a senior name and frequently staffed by someone junior after the first quarter. That is acceptable only if you agreed to it. The clause to ask for: the named individual attends the monthly executive call and the board presentation, and any change of that individual requires your written agreement.

Ask who will attend, and for their last three comparable engagements in a sentence each. A provider that cannot answer that in the sales call will not answer it in month four. The rest of the evaluation is on how to choose a vCISO, and the difference between person-delivered and firm-delivered is on CISO as a service.

The three response times

Response commitments worth writing into a vCISO agreement
SituationReasonable commitmentWhat happens without it
Routine question One business day Answers arrive at the monthly call and decisions wait four weeks
Customer security call or questionnaire Available within five business days A named security officer who cannot make the customer's call, which is worse than having no name
Suspected security incident Reachable within two to four hours, in stated hours You discover during the incident that the retainer was never an on-call arrangement

A monthly retainer at $5,000 CAD does not buy 24 hour on-call. A provider who claims it does is either not going to honour it or is pricing it in somewhere. State business-hours availability and accept it, or buy an incident response retainer separately. What that looks like is on the incident response plan.

The exit clause nobody negotiates

Ask what you receive on the last day: the risk register in a spreadsheet, the policy set in an editable format, the evidence collected, the vendor assessments, and a written handover note. Providers that keep work in their own platform sometimes hand you a read-only export or nothing at all, which turns a change of provider into rebuilding a year of work. Name the format in the contract, not just the fact of a handover.

Terms that change the annual number

  1. Setup or onboarding fee, typically $2,500 to $10,000 CAD, and whether it is credited against later months.
  2. Overage rate, and whether it is the same as the effective retainer rate or a premium. A premium overage rate on a tight hours cap is a price rise you agreed to in advance.
  3. Annual uplift. A fixed percentage is normal. An uncapped one is not.
  4. Travel and expenses, and whether on-site days are billed as hours plus travel or as a day rate.
  5. Minimum term and whether the discount for a longer term is real. Twelve months at ten per cent off is rarely worth the loss of flexibility in a first engagement.
  6. What is excluded. Penetration testing, tooling, audit fees and implementation work usually are. A proposal silent on exclusions will produce a surprise.

Run two proposals through those six lines and they become comparable. The worked version, with two proposals that look identical and are not, is on vCISO pricing.

Compare contracts before you sign one

The terms in this checklist are easiest to negotiate when you have more than one offer in front of you. Tell us what you need and compare providers.

Get matched

If your vCISO will also run your trust centre, write it into the scope. Who should run the trust centre lists the tasks to name.

Common questions

Should a vCISO be an employee or a contractor?

A contractor, in almost every case, and the agreement should say so clearly with the usual independent contractor language. What matters more for you is that being a contractor does not remove the accountability: the contract should still name them as your security officer for customer and insurer purposes if that is what you are buying.

Who owns the policies the vCISO writes?

You should, for anything produced specifically for your company, and you should get it in an editable format. Providers legitimately retain their own templates and methods, and the fair split is that their template stays theirs and your customised version is yours. Get that written down, because the default in a silent contract is not in your favour.

What notice period is normal?

Thirty days after an initial three to six month term, symmetrical on both sides. Be wary of an agreement where you owe 90 days and the provider owes 30. If a provider wants a longer initial term, ask for the first month to be a paid gap assessment you can walk away from.

Do we need them named on our cyber insurance?

Not usually. What the insurer wants is evidence that someone is accountable and that controls exist, and naming your vCISO on the application is enough. What you do want is confirmation that the provider carries their own professional liability and cyber cover, with the limits stated in the contract.