If you've started pricing out a virtual CISO, you've probably noticed the numbers you're finding are all over the map. A quick search turns up quotes from $1,500 a month to $25,000 a month for what sounds like the same service. That spread isn't a pricing error. It reflects three genuinely different delivery models being sold under the same label, plus a scoping problem most buyers don't catch until they're three months into a contract.
Here's what a virtual CISO (also called a fractional CISO) actually costs in Canada right now, what moves the price, and how to scope the engagement so you're not paying platform rates for solo-consultant depth, or the reverse.
What "virtual CISO" actually buys you
A virtual or fractional CISO takes ownership of your security program: risk register, policies, vendor and customer questionnaires, incident response planning, and reporting to your board or your biggest customer's procurement team. It's not the same as a one-time gap assessment or a penetration test. It's an ongoing seat, usually a fraction of a week per month, held by someone who's done the job before and can speak for your program under scrutiny.
That distinction matters for pricing because a lot of the cheap quotes you'll see are actually gap assessments or template-based questionnaire fillers wearing a vCISO label. They're not wrong to exist, they're just a different, cheaper thing.
2026 pricing ranges by delivery model
Three models dominate the Canadian market, and each has a defensible price band:
- Solo consultant / independent vCISO: roughly $2,500 to $6,000 CAD per month for a small to mid-size company (under 150 employees, one or two frameworks in scope). You're paying for one person's time and judgment. Availability is the main risk, since there's no bench behind them if they're sick, on vacation, or overbooked during your audit window.
- Platform / managed-service vCISO: often $4,000 to $10,000+ per month, frequently bundled with a GRC software licence you're required to use. Pricing here scales with headcount and the number of frameworks (SOC 2, ISO 27001, PIPEDA, HIPAA) rather than with actual hours of senior attention. A meaningful chunk of the fee can be software margin, not advisory time.
- Boutique firm: typically $3,500 to $9,000 per month, scaled to company size and audit scope. You get named-person continuity (the same person who did your risk assessment writes your board deck and answers your customer's questionnaire) backed by a small team for coverage. This is the model at traztech's fractional CISO service, where the person running your program is a published security researcher, not a rotating account manager.
One-time or short-burst SOC 2 readiness sprints are priced differently again, usually as a fixed project fee rather than a monthly retainer, since the scope and end date are known upfront.
What actually drives the number
Company size and framework count set the floor, but four other factors move the quote more than buyers expect:
- Number of active questionnaires. A company fielding two vendor security reviews a quarter needs far less time than one fielding two a month because every enterprise deal now requires one.
- Board or investor reporting cadence. Monthly board security updates cost more in prep time than quarterly ones.
- Existing documentation state. Walking into a company with zero written policies costs more in the first 90 days than one with an outdated but usable policy set.
- Audit readiness timeline. Compressing a SOC 2 or ISO 27001 timeline to hit a deal deadline adds hours, and usually adds cost, regardless of which model you pick.
Ask any vendor to walk you through how these four factors change their number before you sign. If they can't, the quote was a guess.
How to scope without overpaying
The most common overpay pattern isn't a bad hourly rate, it's buying more scope than the business needs in year one. A 40-person Series A company chasing its first SOC 2 report does not need the same monthly hours as a 300-person company maintaining ISO 27001 and SOC 2 simultaneously. A few ways to keep scope honest:
- Ask for a fixed monthly hour or day allotment, not a vague "as needed" retainer. It's the only way to compare quotes apples to apples.
- Separate the initial buildout (policies, risk register, first questionnaire responses) from steady-state maintenance. Buildout is naturally heavier and shouldn't set your ongoing run-rate expectation.
- Confirm whether audit liaison work (sitting with your auditor during fieldwork) is included or billed separately. This is a common line-item surprise.
- Check whether the retainer is month-to-month or locks you into a 12-month term. Programs change as companies grow, and flexibility is worth paying slightly more for.
If your immediate driver is a specific certification deadline rather than an ongoing program, it's worth scoping that separately. Compare against a broader compliance readiness engagement to see whether you need standing vCISO coverage yet or a fixed-scope sprint to close the gap first.
What a fair quote looks like
For a Canadian B2B company in the 30 to 150 employee range chasing a single framework (most commonly SOC 2, since it's the one US enterprise buyers ask for), a fair monthly range in 2026 is $3,500 to $7,000 with a boutique firm or solo consultant, assuming a defined hour allotment and a named person who stays on the account start to finish. Above that range, you should be getting either multiple frameworks in scope or meaningfully higher touch (weekly, not monthly, check-ins). Below it, ask hard questions about who's actually doing the work and how many other accounts they're running at the same time.
Pricing that varies wildly for the same stated scope is usually a sign the vendor hasn't scoped it yet, not that you're getting a deal.
Get a real number for your program
Generic ranges are a starting point, not a quote. The only way to get an accurate number is to have someone look at your actual framework requirements, questionnaire volume, and current documentation state. Talk to us and we'll give you a scoped estimate, not a guess.
Where the hours actually go in a normal month
Monthly retainers get compared on price because buyers rarely see what the time is spent on. Here is what a steady-state month looks like for a 60-person Canadian SaaS company holding one framework, which is the most common shape we run.
Roughly a third of the time goes to customer security reviews: questionnaires, follow-up calls with a prospect's security team, redlining the security schedule in an MSA, and answering the one architecture question that decides whether the deal moves. Another third goes to the compliance programme itself: access reviews chased and recorded, risk register updated, vendor reviews, policy exceptions decided rather than left open, and evidence collected while it is fresh instead of reconstructed the week before fieldwork. The remaining time splits between engineering conversations about specific decisions, incident and alert triage when something looks odd, and reporting to whoever needs it, which is usually a board deck or an investor update.
Notice what is not in there. Writing code, tuning your EDR, running your pen test, administering your identity provider. A fractional CISO who is doing those things is either being used as a cheap senior engineer or is padding the retainer, and both outcomes cost you the thing you were buying, which is judgment and accountability.
The first ninety days cost more than the run rate, and should
Buildout and steady state are different jobs. In the first month the work is discovery: what you actually run, who has access to what, which contractual commitments you have already made in signed MSAs, and where the real exposure is versus where the anxiety is. Month two is construction: the policy set, the risk register, the control owners, the first pass at whatever framework you are chasing. Month three is when the system starts operating on its own cadence and the load drops.
Quotes that flatten this into one number across a twelve-month term are usually pricing the average and hoping the light months balance the heavy ones. That is fine if you understand it. What is not fine is a vendor selling steady-state hours in month one, because you will feel starved exactly when you need the most attention, and then feel over-served in month eight when nothing is happening.
The cleaner structure is a defined buildout block at a fixed fee, then a monthly retainer sized to the real ongoing load. At traztech, fractional CISO coverage starts from $3,000 a month, and where a company's actual driver is a first audit rather than standing coverage, we will usually say so and point them at a fixed-scope readiness engagement instead. Our published price floors exist so that conversation starts from a number rather than a discovery call designed to find your budget.
What a vCISO cannot do, whatever you pay
Three limits are worth understanding before you sign, because they change what you should scope around.
A fractional CISO cannot be present at all times. If your regulatory or contractual position requires round-the-clock security monitoring, that is a managed detection service, not an advisory retainer, and buying the retainer instead leaves you with a person who reads the alert at nine the next morning. Decide deliberately whether after-hours incident response is in the agreement, what the response time commitment is, and what it costs when it is used. Vague "we're there if something happens" language is the most expensive sentence in this market.
A fractional CISO cannot manufacture internal ownership. Access reviews are performed by the people who own the systems. Engineering fixes are made by engineers. If nobody inside the company is accountable for doing what the programme requires, the retainer produces documents and nothing changes, and after two quarters the buyer concludes vCISOs do not work. What was missing was a counterpart with authority, not a better advisor.
A fractional CISO usually cannot serve as your named regulatory officer where a statute requires an identified individual inside the organization. Check the specific requirement before you assume the retainer covers it. Most Canadian companies asking this question are fine, but the ones who are not tend to discover it during a procurement review, which is a bad time.
The comparison people actually want: retainer versus a full-time hire
The instinct is to compare the monthly retainer against a monthly salary, and that comparison flatters the hire. The honest version adds employer costs, recruiting fees, equity, tooling the new hire will immediately want, and the fact that a security leader hired into a company with no programme spends their first two quarters building the same thing a retainer would have built, only slower because they are also learning the business from scratch.
The load-bearing difference is not cost, it is coverage shape. A full-time hire gives you presence, internal authority, and someone in every meeting. A retainer gives you seniority you could not otherwise afford, at a fraction of a week per month, with no ramp. Under roughly 100 people with one framework in play, the retainer usually wins on both cost and outcome. Somewhere between 100 and 250 people, or once you are running two frameworks plus a regulated customer base, the calculus flips, because the volume of internal work exceeds what a part-time seat can hold.
The transition is the part nobody plans. If you expect to hire in twelve to eighteen months, write the handover into the engagement now: the programme documentation stays yours, the risk register is in a system you control, and the outgoing advisor spends the first month of the new hire's tenure transferring context rather than disappearing on the last invoice. We treat that as a normal, good outcome. A retainer that ends because you outgrew it is the engagement working.
Costs the retainer does not include
Buyers get surprised by the same line items repeatedly, so budget for them separately from day one.
Audit fees. Your auditor or certification body bills you directly and is independent of your advisor. Any firm offering to both prepare and audit you should be disqualified on that basis alone.
Penetration testing. Frameworks require it, customers ask for the report, and it is specialist work priced per engagement. Ours starts from $1,000 for a tightly scoped test, and scope is what moves that number, not company size.
GRC tooling. Optional more often than vendors admit. A 40-person company with one framework can run a spreadsheet risk register and a shared evidence folder without harm. The tool earns its licence when you are maintaining two or more frameworks with overlapping evidence.
Remediation. The largest number in the whole exercise and the one that never appears in a compliance quote. Identity tooling, logging, backup restore testing, and the engineering hours to implement it all. Ask any prospective vendor to give you their honest estimate of remediation effort after the first assessment, and treat "minimal" as a red flag rather than good news.
How to tell in ninety days whether you are getting value
Set the test before you sign, because the failure mode is quiet. By day 30 you should have a written picture of your actual exposure, a prioritized list of what to fix, and a named owner for each item who works for you. By day 60 the policy set should exist and be approved by someone with authority, and the top two or three risks should be in progress rather than documented. By day 90 you should be able to answer a customer security questionnaire faster than you could before, and your advisor should be able to sit in a buyer's security call and speak to your programme without needing your CTO in the room.
If none of that has happened and the reporting consists of a status document nobody outside the security channel reads, you have bought a ghost retainer. Say so early. Good advisors would rather have that conversation in month three than lose the account in month nine.
When not to hire a vCISO at all
You need one artefact, not a programme. If a single customer needs a completed questionnaire and a recent test result to sign, buy those. A questionnaire response plus a scoped penetration test costs far less than three months of retainer and closes the same deal.
You are chasing one audit with a fixed end date. A readiness engagement with a defined scope and deliverables is the right shape here, and it is cheaper than open-ended coverage. Our SOC 2 track starts from a $3,000 gap analysis for exactly this reason: the buyer wants a certificate, not a standing seat, and pretending otherwise is how retainers get sold to people who do not need them.
You are under about fifteen people with no enterprise pipeline. Your risk is real but your governance need is not. Turn on multi-factor authentication everywhere, get backups tested, restrict production access to the smallest possible group, and revisit when a deal actually stalls on security.
You already have a competent technical leader with capacity. If your VP Engineering has run a SOC 2 before and can carve out real time, what they usually need is twenty hours of review from someone who has been on the other side of the audit, not a monthly retainer. Buy the review.
Your problem is a live incident. A retainer is the wrong instrument for a breach in progress. You need incident response now and a programme afterwards, and the order matters. We keep those as separate engagements under our retainer and response arrangements so nobody is waiting on a contract negotiation while an attacker is still in the environment.
Where a fractional seat does earn its keep is when security has become a recurring cost of doing business, meaning enterprise questionnaires arrive monthly, an audit is annual rather than one-off, and someone has to own the answer when a customer's security team asks who is accountable. That is the case our fractional CISO service is built for, and it is a narrower case than the market's marketing suggests.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.
Fractional CISOOr talk about a retainerWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.