HireACISO

vCISO services: what is in and out of scope

The phrase covers everything from four hours a month of advice to a security executive embedded three days a week. This page sets out what is normally inside the fee, what is not, and how to read a proposal.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

vCISO services normally include a gap assessment, a risk register, a policy set, a security roadmap, ownership of a compliance program such as SOC 2 or ISO 27001, customer questionnaire and vendor review support, third-party risk management, incident response leadership, and periodic reporting to your executives or board. They normally exclude monitoring and alert triage, tooling implementation, penetration testing, and the external audit itself, all of which are billed separately.

Providers use the same three words for very different amounts of work, so compare proposals on the scope table and the hours, not on the service list. Everyone's service list looks the same.

What is normally in scope

Services usually included in a vCISO retainer
ServiceWhat you should expect to receive
Gap assessment A written assessment against a named standard, with findings ranked by business impact rather than by control number
Risk register and roadmap A maintained register with named owners and a roadmap carrying dates and cost estimates
Policies and standards A policy set matched to what you actually do, approved and version controlled
Compliance program ownership Framework selection, scoping, auditor selection, evidence schedule, and the audit run to a date
Customer security reviews Questionnaire responses, a maintained answer library, and attendance on prospect security calls
Third-party risk Vendor review process, a tiered vendor inventory, and review of security terms in contracts
Incident response A tested plan, tabletop exercises, and leadership of the response when something happens
Reporting A monthly metrics pack and a quarterly executive or board report
Named security contact Your named officer for customers, insurers and regulators, within agreed availability

What is normally out of scope

Anything below that appears in a retainer at no extra cost deserves a question about how it is being resourced.

  • Monitoring and alert triage. Round the clock detection is a managed service with staffed shifts. A single part-time executive cannot provide it and should not claim to.
  • Tool implementation and administration. Deploying endpoint detection, configuring identity, building log pipelines. The vCISO specifies and verifies. Someone else builds.
  • Penetration testing. Scoped and managed by the vCISO, performed by an independent firm at $8,000 to $40,000 CAD depending on scope.
  • The external audit. The party that builds the program cannot attest to it. Budget $15,000 to $60,000 CAD for the audit or certification separately.
  • Compliance platform subscriptions. Typically $8,000 to $30,000 CAD a year, billed to you directly and annually in advance.
  • Remediation engineering. Your team, or a separately quoted implementation resource.
  • Legal advice. A vCISO makes a breach assessment with counsel, not instead of counsel.

Read the proposal for hours, not services

Two proposals listing identical services can differ by a factor of four in the attention behind them. The numbers that tell you what you are buying are hours per month, who specifically is doing the work and their seniority, meeting cadence, response time for an urgent customer request, and what happens to unused hours. If a proposal omits all five, ask before comparing prices.

Engagement models compared

vCISO engagement models compared, Canadian pricing in CAD
Model Effort Typical price Best for Weakness
Hourly advisory No commitment $200 to $400 per hour Companies with internal leadership wanting a second opinion Nobody owns the outcome
Advisory retainer 8 to 16 hours per month $3,000 to $6,000 per month Steady state after a certification is achieved Too thin to drive a first audit
Program leadership 20 to 40 hours per month $6,000 to $12,000 per month A first SOC 2 or ISO 27001 with a deadline Needs internal capacity to direct
Embedded 2 to 3 days per week $12,000 to $25,000 per month Post-incident recovery, standing up a team Approaches the cost of hiring
Fixed-scope project 6 to 16 weeks $15,000 to $60,000 total One defined outcome, such as readiness or diligence Ends whether or not the work is embedded

The full cost breakdown, including what pushes a quote to the top of its band and the loaded cost of the alternative, is on fractional CISO cost. For the week by week detail of what the hours are spent on, see what a vCISO does.

How to choose between them

Start from the outcome that has a date on it. If a customer contract requires a SOC 2 report by a fixed month, you need program leadership, because advisory hours will not move an evidence schedule. If you already hold a certificate and the work is maintenance and surveillance audits, advisory is the correct spend and paying for more is waste.

If the driver is a single event with a definite end, such as a diligence process or an insurer's application, buy the project. A retainer attached to a one-time need tends to persist long after the need does.

Embedded is the model to scrutinize. At $12,000 to $25,000 CAD a month you are within reach of a full-time salary, and if the need is genuinely permanent you should be running a search in parallel. Embedded earns its place as a bridge: someone senior holding the role while you recruit, or a first quarter of intensive rebuilding before stepping down. The comparison with hiring covers where the line sits.

What to check in the contract

  • Who does the work. Some firms sell a senior name and deliver a junior consultant. Name the individual in the agreement.
  • Continuity. What happens if that person leaves, and whether you approve the replacement.
  • Ownership of output. Policies, registers and assessments should be yours outright, in a portable format, and not hosted only inside the provider's platform.
  • Availability and response time. Specifically for incidents and customer calls. A named officer who is unreachable for a week is not a named officer.
  • Independence. Whether the provider also sells you the audit, the tooling or the managed service, and what that does to their advice.
  • Notice period. Month to month after an initial three to six month term is normal. A twelve month lock-in on a retainer is not.
  • Insurance. Professional liability cover appropriate to a role that signs statements to your customers.

Compare vCISO providers in Canada

Tell us the outcome you need and the date attached to it, and we will match the scope to Canadian providers who deliver it.

Get matched

Common questions

Do vCISO services include 24 hour monitoring?

No. Monitoring and alert triage require staffed shifts and are sold as a managed detection and response service, typically alongside the retainer rather than inside it. If a vCISO proposal claims round the clock coverage at retainer prices, ask who is on shift at three in the morning and what their response time commitment is.

Can one provider do both the vCISO work and our audit?

No, and you should decline if it is offered. The independence of the audit is the entire reason a customer accepts the report. A firm that built your control set cannot credibly attest to it, and an auditor who agrees to both is telling you something about the value of their opinion.

Do we keep the policies and documentation if we leave?

You should, and it belongs in the contract. Ask for output in a portable format you control, such as documents in your own storage rather than records inside the provider's platform. The risk to check for is a program that only functions while you keep paying for the tool it lives in.

Can a vCISO cover multiple entities or a group of companies?

Yes, and it is common after an acquisition, but price it per entity. Each company brings its own systems, its own contracts and often its own regulatory position, and treating a group as a single scope is how a retainer that looked adequate turns out not to be. Ask for the acquired entity to be assessed separately in the first quarter.

What if we already have an internal security manager?

Then buy advisory rather than program leadership. The useful pattern is a vCISO who provides the executive layer, board reporting and framework decisions while your manager runs delivery. Eight to sixteen hours a month is usually right, and the arrangement often becomes the path to promoting that manager into the role properly.