Fractional CISO or a vCISO?
The short answer: in most cases these are the same job under two names, and the market does not agree on a definition for either. Here is what genuinely varies between providers, what to ask instead of trusting the label, and where the two words really do mean different things.
Are they the same thing?
These are the same job under two names, in the great majority of cases. The results for this question disagree with each other more sharply than any other comparison on this site: one says a vCISO and a fractional CISO are identical, one says a fractional CISO is an individual and a vCISO is a firm, one says a vCISO is more hands-on, another says less. All of them are vendors describing their own model. There is no standard, so the word on the invoice tells you nothing useful and the questions below do.
Names in use for roughly this arrangement: Fractional CISO, vCISO or virtual CISO, Outsourced CISO, Part-time CISO, CISO as a Service and Interim CISO, which genuinely does mean something different: full-time and temporary.
What actually varies, whatever it is called
Ask these instead of trusting the label
- Is the goal to pass an audit, to be materially harder to breach, or both, and which are we starting with?
- What is bundled: tooling, evidence collection, policy templates, and what does each cost separately?
- Who is the named person, how many other clients do they hold, and what happens when they are unavailable?
- How hands-on will you be, and what are you expecting our team to do?
- Which frameworks have you personally taken a company through, at what size, and how long did it take?
What a vCISO actually is
A virtual chief information security officer: a senior security leader engaged part-time from outside. The term is used interchangeably with fractional CISO by most of the market, and to mean something narrower or broader by the rest.
What each one owns
| A fractional CISO | A vCISO |
|---|---|
| The security posture, and the decisions that change it | In most engagements, exactly the same list |
| The questionnaire, the audit and the enterprise deal it is blocking | Where a firm provides it, a bench and an escalation path behind the person |
| What gets fixed first, and what is accepted as a known risk | Where it is bundled, the tooling and the evidence collection alongside |
| Talking to your customers' security teams in their own language | Where it is narrow, compliance paperwork rather than security itself |
What neither of them does
Neither is a penetration test, a managed security provider or a SOC. Those find and watch. This decides. Buying a scanner when you needed a decision-maker is the commonest mistake in this category, and it is usually made under deadline.
How each one fails
The fractional CISO: Being hired a fortnight before a SOC 2 deadline and expected to produce twelve months of evidence that does not exist. The seat sets direction; it cannot retrofit a year of controls.
A vCISO: A bundled package where the tooling is the product and the senior hours are the wrapper, bought by a company that needed the reverse.
What they cost, on the same basis
A fractional CISO charges £900 to £1,500 a day, and most engagements run one to three days a week. Usually a monthly retainer, and frequently bundled with tooling, assessments or an audit-readiness programme, which makes a like-for-like price comparison harder than it looks. The monthly and annual arithmetic for the fractional side, against a full-time equivalent, is on the cost page for this seat.
Pick a vCISO when
- You want one contract covering the leadership, the tooling and the evidence
- You need cover with an escalation path rather than one named individual
- The work really is compliance paperwork and you know that going in
We would rather say that plainly than win an engagement that was the wrong shape. Nobody pays us to list on the bench, so there is nothing in it for us either way.
When you want both
Rarely both, because in most cases they are one thing. What companies do commonly need alongside either is somebody doing the hands-on remediation, because the seat decides what to fix and does not spend three days a week fixing it.
Common questions
Is a fractional CISO cheaper than a vCISO?
On a like-for-like basis it usually is, because you buy the days you need rather than all of them. A fractional CISO runs £900 to £1,500 a day, most often one to three days a week. Usually a monthly retainer, and frequently bundled with tooling, assessments or an audit-readiness programme, which makes a like-for-like price comparison harder than it looks. But cheaper is the wrong question if the work genuinely needs the other one.
When should I pick a vCISO instead?
You want one contract covering the leadership, the tooling and the evidence You need cover with an escalation path rather than one named individual The work really is compliance paperwork and you know that going in
Can I have both?
Rarely both, because in most cases they are one thing. What companies do commonly need alongside either is somebody doing the hands-on remediation, because the seat decides what to fix and does not spend three days a week fixing it.