Fractional CISO or a vCISO?

The short answer: in most cases these are the same job under two names, and the market does not agree on a definition for either. Here is what genuinely varies between providers, what to ask instead of trusting the label, and where the two words really do mean different things.

Are they the same thing?

These are the same job under two names, in the great majority of cases. The results for this question disagree with each other more sharply than any other comparison on this site: one says a vCISO and a fractional CISO are identical, one says a fractional CISO is an individual and a vCISO is a firm, one says a vCISO is more hands-on, another says less. All of them are vendors describing their own model. There is no standard, so the word on the invoice tells you nothing useful and the questions below do.

Names in use for roughly this arrangement: Fractional CISO, vCISO or virtual CISO, Outsourced CISO, Part-time CISO, CISO as a Service and Interim CISO, which genuinely does mean something different: full-time and temporary.

What actually varies, whatever it is called

Whether the security work or the paperwork is the productThe single most important distinction and the one the label never tells you. Getting a SOC 2 or an ISO 27001 certificate is an evidence exercise. Actually being harder to breach is a different exercise. A good engagement does both and says which one it is starting with; a weak one sells the certificate and lets you assume the other came with it.
Whether tooling is bundled, and who owns it afterwardsMany packages include a compliance platform, scanning, or evidence automation. That can be excellent value. It also means part of what you are paying is licence cost rather than senior hours, and it is worth knowing the split, and knowing what happens to your evidence if you leave.
Whether you get a person or a rotaAn individual knows your systems and your customers. A firm gives you cover, an escalation path, and someone who has seen your auditor before. Both work. What does not work is discovering after you have signed that the senior name in the pitch is not the person you get.
How hands-on they will beThis is where providers differ most in practice. Some set direction and hand you a plan. Some will configure the logging and write the policies themselves. Neither is wrong, but a plan handed to a team with no capacity to execute it is a document, not a security programme.

Ask these instead of trusting the label

What a vCISO actually is

A virtual chief information security officer: a senior security leader engaged part-time from outside. The term is used interchangeably with fractional CISO by most of the market, and to mean something narrower or broader by the rest.

What each one owns

A fractional CISOA vCISO
The security posture, and the decisions that change itIn most engagements, exactly the same list
The questionnaire, the audit and the enterprise deal it is blockingWhere a firm provides it, a bench and an escalation path behind the person
What gets fixed first, and what is accepted as a known riskWhere it is bundled, the tooling and the evidence collection alongside
Talking to your customers' security teams in their own languageWhere it is narrow, compliance paperwork rather than security itself

What neither of them does

Neither is a penetration test, a managed security provider or a SOC. Those find and watch. This decides. Buying a scanner when you needed a decision-maker is the commonest mistake in this category, and it is usually made under deadline.

How each one fails

The fractional CISO: Being hired a fortnight before a SOC 2 deadline and expected to produce twelve months of evidence that does not exist. The seat sets direction; it cannot retrofit a year of controls.

A vCISO: A bundled package where the tooling is the product and the senior hours are the wrapper, bought by a company that needed the reverse.

What they cost, on the same basis

A fractional CISO charges £900 to £1,500 a day, and most engagements run one to three days a week. Usually a monthly retainer, and frequently bundled with tooling, assessments or an audit-readiness programme, which makes a like-for-like price comparison harder than it looks. The monthly and annual arithmetic for the fractional side, against a full-time equivalent, is on the cost page for this seat.

Pick a vCISO when

We would rather say that plainly than win an engagement that was the wrong shape. Nobody pays us to list on the bench, so there is nothing in it for us either way.

When you want both

Rarely both, because in most cases they are one thing. What companies do commonly need alongside either is somebody doing the hands-on remediation, because the seat decides what to fix and does not spend three days a week fixing it.

Common questions

Is a fractional CISO cheaper than a vCISO?

On a like-for-like basis it usually is, because you buy the days you need rather than all of them. A fractional CISO runs £900 to £1,500 a day, most often one to three days a week. Usually a monthly retainer, and frequently bundled with tooling, assessments or an audit-readiness programme, which makes a like-for-like price comparison harder than it looks. But cheaper is the wrong question if the work genuinely needs the other one.

When should I pick a vCISO instead?

You want one contract covering the leadership, the tooling and the evidence You need cover with an escalation path rather than one named individual The work really is compliance paperwork and you know that going in

Can I have both?

Rarely both, because in most cases they are one thing. What companies do commonly need alongside either is somebody doing the hands-on remediation, because the seat decides what to fix and does not spend three days a week fixing it.

If fractional is the answer

Verified fractional CISOs, booked direct

See what the seat covers, or read how to interview for it.