Direct answer: A fractional CISO buys judgement and accountability: someone senior who owns the security programme, makes the calls, and represents you to buyers, regulators and the board. A compliance retainer buys operation: the cadence run, the evidence produced, the auditor handled. Most companies past their first report need more of the second than the first, and the ones raising money or selling into regulated buyers need the first.
The two problems
The first problem sounds like this: we do not know what we should be doing, nobody senior owns security, and when a customer or an investor asks who is accountable we do not have an answer. That is a leadership gap.
The second sounds like this: we know exactly what we should be doing, it is written down, and it keeps not happening because everyone is busy. That is an execution gap.
They get conflated because both are sold as ongoing engagements at similar prices, and because a good fractional CISO will do some execution while a good compliance retainer will make some decisions. But buying the wrong one produces predictable disappointment: a CISO who spends their retainer chasing access reviews, or an operational retainer that will not tell you whether to accept a risk.
What a fractional CISO is for
Owning the security programme and its roadmap. Deciding which risks you accept on purpose and documenting why. Being the named security executive on questionnaires, diligence requests and regulator correspondence. Reporting to the board in language a board can act on. Reviewing architecture and change decisions while they are being made. Building the case for security spend, and equally for not spending.
The value concentrates in decisions and in representation. If your next twelve months contain a fundraise, an enterprise expansion into a regulated sector, or a board that has started asking security questions, that is the shape you want.
What a compliance retainer is for
Operating the calendar. Producing and filing evidence against controls. Running access reviews, vendor reviews, policy reviews and the risk register on cadence. Answering the security questionnaires that arrive with deals. Handling the auditor at the next cycle. Keeping the system description true when the environment changes.
The value concentrates in things happening on time, every time, without anyone internal having to remember. If your programme is built and your risk is that it quietly stops, that is the shape you want.
Where they overlap
Honestly, a lot. Both involve knowing what auditors accept. Both involve vendor risk. Both put someone senior in front of your buyers when a deal needs it. In smaller companies the same person often does both, which is why the labels blur.
The practical difference is what happens when the two compete for the hours. A fractional CISO with a fixed monthly allocation will spend it on decisions and leave the operational cadence to you. An operational retainer will run the cadence and escalate the decisions to you. If you need both, the scope has to say so explicitly, or the gap surfaces in the first busy month.
Cost
Fractional CISO engagements are typically priced per month against an agreed involvement level, and ours starts at $3,000 a month. Compliance retainers are priced from the load rather than a tier, which is why we scope them per client rather than publishing a single number.
The comparison people usually want is against a hire. A full-time security lead in Canada is a six-figure salary plus benefits, and their first quarter is spent learning your environment. That is the right spend at a certain size and clearly the wrong one before it. The test is whether the work is genuinely continuous or genuinely periodic.
How to tell which you need
Ask what happened in your last three security conversations. If they were decisions nobody felt qualified to make, you have a leadership gap. If they were tasks nobody had time to do, you have an execution gap.
Then look at the next twelve months. A fundraise, a first enterprise customer in a regulated sector, or a board that has started asking about security points to leadership. An observation window, a surveillance audit, a second framework, or a report that already exists and has to stay true points to execution.
Most companies past a first report have an execution gap they are describing as a leadership gap, because "we need a CISO" is easier to say than "nobody did the access reviews."
We sell both. Fractional CISO is a published SKU with a monthly price. Retainers are scoped from one call, and the written plan of approach says which of the two we think you actually need, including when the answer is neither yet.
What the month actually looks like
Both engagements are sold as monthly commitments, so the useful comparison is what the hours get spent on when nothing unusual is happening.
A fractional CISO month at a company of forty people tends to run: a standing weekly hour with the engineering lead or the CTO, one architecture or change review where a decision is being made that would be expensive to reverse, a pass over the risk register with two or three items moved, whatever buyer-facing work the deals require, and a monthly written update that a board or an investor can read without translation. Quarter ends add board material and a review of the roadmap against what actually shipped.
A compliance retainer month looks different. It is the access review pulled, distributed, chased and filed. Vendor reviews for whatever came due. New starters and leavers reconciled against the identity provider and the offboarding tickets. Policy items reaching their annual review date. The evidence register worked through so that anything expiring in the next sixty days has an owner and a date. Questionnaires answered as they arrive. Once a year the auditor arrives and the whole month bends around them.
Neither of those is more valuable in the abstract. They fail in different ways, which is the point of choosing deliberately.
How the hours are structured, and where the argument starts
Ask any prospective provider three questions before signing. How many hours a month am I buying, and what happens to unused ones. What is the response commitment when something urgent arrives mid-month. Who does the work if the named person is unavailable for two weeks.
The answers separate serious providers from optimistic ones. Hours that roll over indefinitely usually mean the provider expects to under-deliver in quiet months and is buying itself slack. Hours that expire monthly with no carry-over are honest but need a stated escalation path for the month a deal blows up. A named individual with no bench is a single point of failure that you should price consciously rather than discover in August.
The second thing to write down is the boundary. A fractional CISO engagement that has not said in writing who runs the operational cadence will spend its third month on access reviews, because access reviews have deadlines and strategy does not. If you want both, buy both explicitly and let the scope say which hours belong to which. Our own fractional CISO engagements start at $3,000 a month and the plan of approach names the split in the first week, because the alternative is a quiet reallocation nobody agreed to.
The accountability question, and what it actually means
People buy a fractional CISO partly for a name to put on a form. It is worth being precise about what that name carries.
An external fractional CISO can sign as the security lead on questionnaires, sit in buyer security calls as your security executive, be named in the system description as the owner of the programme, and represent you in an auditor walkthrough. What they cannot do is absorb your legal exposure. Regulatory accountability under PIPEDA, Law 25 or the sectoral rules sits with the organisation and, in a Law 25 context, with the designated privacy officer, who is your most senior person unless a written delegation says otherwise. If a provider implies that engaging them transfers liability, ask which clause of which statute they think does that.
Two practical consequences. First, check whether directors and officers cover, and any cyber policy, contemplates an external officer acting in that capacity, because some policies do not. Second, decide whether the fractional CISO is named in customer contracts. Naming a person creates a change-of-personnel problem when the engagement ends. Naming the role and the firm is usually the better construction.
Where each one fails
The figurehead failure. The fractional CISO is present at the buyer call, produces good board slides, and nothing in the environment changes between quarters because nobody internal was assigned the work. This shows up at the next audit as a set of controls that read well and have no artefacts behind them. The tell is a risk register where the same items have been open at the same rating for three quarters.
The ticket-queue failure. The compliance retainer runs the cadence beautifully and nobody is making decisions. Evidence gets filed for controls that no longer describe how the system works, because the environment changed and no one had the standing to say the description needed rewriting. This surfaces as a system description that has drifted from reality, which is a much harder conversation with an auditor than a missing artefact.
The seniority mismatch. You bought judgement and you are getting a competent analyst executing a checklist, or you bought execution and you are paying senior rates for someone who finds the operational work beneath them. Ask who does the work, not who sells it, and ask to meet that person before signing.
The automation illusion. A platform is showing ninety-four per cent green and everyone relaxes. Platforms monitor what they can integrate with, which is typically cloud configuration, identity and endpoints. They do not know whether your vendor reviews were meaningful, whether the risk register reflects the business, or whether the person who left in March still has an active account in a system the platform does not connect to. Green dashboards are an input, not an assurance.
Cost drivers on the retainer side
Fractional CISO pricing scales with involvement level and is reasonably predictable. Compliance retainers are priced from load, and the load comes from countable things worth knowing before you ask for a number.
Framework count is the big one, though not linearly: a second framework on top of a mature SOC 2 programme adds far less than the first one cost, provided evidence was collected in a way that maps to more than one control. Headcount and turnover matter because joiners and leavers drive access review volume. The number of systems that hold customer data drives vendor review volume. Questionnaire traffic is the most variable item and the one most people forget, since a busy enterprise sales quarter can produce more work than the audit does. Whether you are inside an observation window changes the intensity for those months. Whether the engagement includes incident response availability changes it materially, because standing readiness has a cost even in months when nothing happens.
If a provider quotes without asking about turnover or questionnaire volume, the number is a guess that will be revisited.
Measuring whether the money worked
Both engagements are easy to renew on vibes. Set measures at the start instead.
For leadership work: risk register items closed or consciously accepted with written rationale, decisions made within an agreed turnaround rather than sitting, deals unblocked and the time from security review to sign-off, board material delivered on schedule, and the count of security questions in diligence that were answered from existing documentation rather than triggering a scramble.
For operational work: percentage of scheduled control activities completed inside their window, evidence artefacts expiring without a refresh, questionnaire turnaround time, and the count of audit findings and auditor follow-up requests at the next cycle. That last number is the honest one. A retainer that produced a clean audit with few information requests earned its fee whatever else it did.
Review both at six months, not at renewal. Six months is enough to see whether the shape was right and early enough to change it without a contractual argument.
Clauses worth arguing about before you sign
A few contract terms decide how the engagement behaves under stress, and they are cheap to fix on the way in.
Ownership of work product. Policies, registers, control descriptions and evidence templates should be yours outright, in an editable format, with no licence that lapses when the engagement does. Some providers keep the programme inside their own tooling and hand back exports that are awkward to use anywhere else, which converts a supplier decision into a migration project.
Handover on termination. Name the artefacts and give a period, typically thirty days, in which they are transferred with a walkthrough. Without it you get a shared drive link and goodwill.
Notice and ramp-down. Sixty or ninety days each way is normal. Anything longer on your side and shorter on theirs is worth challenging.
Conflicts. Ask whether the provider works with your direct competitors and how information is separated. A reasonable firm will answer plainly rather than treat the question as an insult.
The path to a full-time hire
A fractional engagement should have a stated view on its own ending. For most companies the trigger is one of: security work consistently exceeding the purchased hours for three months running, a regulated customer contractually requiring a full-time employee in the role, an internal team large enough that daily management is the job, or a funding round where the plan already carries the headcount.
The transition is smoother when the fractional CISO writes the role definition, sits on the interview panel, and stays for a defined overlap. Two to three months at reduced hours while the new hire learns the environment costs less than the alternative, which is a full-time leader spending their first quarter reconstructing decisions from documents. Ask a prospective provider directly whether they will help you replace them. The answer tells you a lot.
When neither is the right purchase yet
Plenty of companies calling us do not need a monthly commitment of either kind, and saying so has cost us revenue we would rather not have had.
If you have never been through a framework and the only thing in front of you is a single customer asking for a report, buy the fixed-scope readiness work and stop there. A gap analysis from $3,000 tells you what the actual distance is, and the answer is frequently smaller than the fear. Committing to a retainer before you know the shape of the programme means paying monthly for work nobody has scoped. Our published SKUs exist for exactly this reason.
If you have fewer than about fifteen people and no regulated data, a competent engineering lead with two days a month of external advice usually beats either engagement. The cadence at that size is genuinely small, and the tooling to run it is free or close to it. Our Workspace is free and will hold the register, the policies and the evidence without a services contract attached.
If your problem is one project with a defined end, buy the project. Implementing ISO 27001 across 93 Annex A controls plus clauses 4 to 10, or preparing for CPCSC Level 2 against its 98 requirements, is finite work with a deliverable. Wrapping finite work in an open-ended monthly fee suits the seller more than the buyer, and the honest structure is a fixed-scope engagement with an optional retainer afterwards if the maintenance load turns out to be real.
And if what you actually need is somebody to answer one hard question, ask it. The first conversation is where we work out whether this is a leadership gap, an execution gap, or a project, and the written plan that follows says which, including the version where the answer is that you should wait six months and spend the money on engineering instead.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.
Fractional CISOOr talk about a retainer