Direct answer: A fractional or virtual CISO in Canada typically runs from around $3,000 a month for a light advisory engagement up into five figures for heavy involvement during an audit or a funding round. Ours starts at $3,000 a month and the figure is published on the pricing page.
What changes the number
Hours, mostly, but the shape matters more than the total. A vCISO who attends a monthly steering call and answers questionnaires is a different engagement from one running an active SOC 2 programme, sitting in customer security calls and reporting to your board.
Regulatory context moves it too. A fintech answering to bank and payment-partner diligence needs more senior time than a SaaS with one enterprise buyer asking for SOC 2.
Compared with hiring
A full-time security leader in Toronto costs well into six figures once you include benefits and equity, plus the months to hire and the risk of getting it wrong. The fractional version buys the judgement without the fixed cost, which is the whole point at your stage.
The honest counter is that a fractional CISO is not there every day. If security is genuinely core to your product rather than a requirement of selling it, you will eventually want somebody in-house, and a good vCISO will tell you when that point arrives and help you hire.
When you need something smaller
If the actual problem is one questionnaire, buy help with the questionnaire. If it is one audit, buy readiness. A retainer is for ongoing accountability: somebody who owns the programme, answers for it to buyers and your board, and is still there next quarter.
Our free vCISO ROI calculator compares the two against your own numbers, and the full-time CISO comparison lays out where each option stops making sense.
What you are paying for at each level
The monthly figure means very little without the shape of the engagement attached, and the shapes cluster into three.
Advisory. A monthly call, questionnaire support, review of significant decisions, and someone reachable when something unusual arrives. This is the right fit for a company with an internal owner who mostly needs a second opinion and a name to put on a form.
Programme ownership. The security roadmap, risk register, policy set, vendor programme and board reporting all owned externally, with regular working sessions and real involvement in decisions. This is what most companies mean when they say they need a CISO.
Embedded. Heavy weekly involvement, typically during an audit, a funding round, a large enterprise deal, or after an incident. Usually time-boxed, because sustaining it indefinitely costs more than a hire.
Comparing against a full-time hire
A security leader in Canada is a six-figure salary before benefits, equity and recruiting cost, and their first quarter is spent learning your environment rather than improving it. That is the right spend once the work is genuinely continuous.
The honest test is not cost per hour, because fractional always wins that comparison. It is whether the role has a full-time job to do. Signals that it does: more than two frameworks live, constant enterprise security review traffic, a security function with people in it to manage, and a roadmap that runs all year rather than in bursts.
Signals that it does not: one framework, periodic audit cycles, and a security workload that spikes around deals and then goes quiet. Hiring into that produces an underemployed senior person who drifts into adjacent engineering work, which is fine until the audit arrives.
What a vCISO does not solve
This is the distinction that saves money. A fractional CISO buys judgement and accountability: decisions made, risks accepted deliberately, representation to buyers and the board. It does not buy the programme being operated. Nobody senior at any price is going to spend their monthly allocation chasing evidence and running quarterly access reviews, and if they do, you are paying executive rates for coordination work.
If your actual problem is that the cadence keeps not happening, the cheaper and better-fitting purchase is an operational retainer, sometimes alongside a lighter advisory engagement. We wrote the comparison out in full in fractional CISO or compliance retainer.
Questions to ask before signing
Who specifically, by name, and what have they actually run? Fractional engagements are sold by firms and delivered by people, and the gap between the two is where disappointment lives.
What is the monthly commitment in hours or in outcomes, and what happens when a deal or an incident blows through it? How does the engagement end, and what do you keep? A vCISO relationship that ends leaving the risk register, policies and roadmap inside somebody else's systems has transferred very little.
And what do they refuse to do? An engagement that will not push back on scope, or will not tell you a control is theatre, is an expensive way to feel covered.
Our fractional CISO engagement is published at $3,000 a month as a starting point, and the scoping call will tell you honestly if a retainer or nothing at all is the better fit this quarter.
What the market charges, and why the spread is so wide
Published Canadian pricing for fractional security leadership runs from roughly $2,500 a month at the light end to well into five figures for embedded engagements. That spread is not mostly about quality. It is about three variables that rarely appear in the headline number.
Seniority. A former CISO of a regulated institution and a consultant who has run two SOC 2 programmes are both sold as fractional CISOs. Both can be the right choice. They are not interchangeable when your board asks a hard question.
Included capacity. Some engagements are hours-based with a hard stop. Some are outcome-based with soft boundaries. The second reads better and only works if both sides are honest about scope.
What is bundled. Policy work, questionnaire responses, audit support and tooling may be included or billed. Two identical monthly figures can differ by a factor of two in delivered work.
The industries that pay more
Regulatory context drives senior time. A fintech under PCI DSS and bank vendor diligence, or a health technology company handling personal health information under PHIPA, both require someone who knows that specific landscape, and the engagements are correspondingly heavier.
The same is true when your buyers are banks or governments. The security review at that end is not a questionnaire, it is a process with meetings, and somebody credible has to attend them.
Getting value out of the engagement
The companies that get the most from fractional leadership do three things consistently.
They bring decisions rather than tasks. The monthly session is worth far more spent on whether to accept a risk, how to scope a report, or what to tell a buyer than on status reporting that could have been a document.
They give access to the room where decisions happen. A vCISO who hears about an architecture choice after it shipped can only audit it. One who is in the design conversation can shape it, which is where the cost avoidance actually lives.
They keep the artefacts. Risk register, policies, roadmap and board materials should live in your systems, not the consultant's. An engagement that ends leaving you with nothing to hand to the next person has transferred very little.
Exit and succession
Every fractional engagement should have an ending in mind, and the two normal ones are that you outgrow it and hire, or that the programme stabilises and the engagement lightens. Both are good outcomes and both need planning.
The handover matters. Whoever takes over inherits scope rationale, auditor relationships, open risks and the reasoning behind decisions that will otherwise look arbitrary. Asking for that documentation to be maintained throughout, rather than produced at the end, is the difference between a clean succession and starting over.
How to compare quotes
Ask every firm for the same three things and the comparison becomes simple. The named person and what they have run. The monthly commitment expressed in something measurable. And an explicit list of what is not included.
Then ask each one what they would tell you not to do this quarter. The answer separates advisors from vendors faster than any pricing question, because a vendor has no incentive to shrink your scope and an advisor has no incentive to inflate it.
What a month actually looks like at the entry figure
Monthly numbers stay abstract until somebody itemises them. At the light end of the market, roughly $3,000 a month, you are buying something in the range of twelve to sixteen hours of senior time. That is not a lot, and how it gets spent is the whole question.
A realistic month at that level: one ninety-minute working session with the founder or engineering lead, two or three hours reviewing and responding to whatever buyer security material arrived, an hour on the risk register and roadmap, an hour or two of reading the things you changed since last month (a new subprocessor, a new production access grant, an architecture decision), one buyer call attended, and the remainder held back for the unplanned item that always turns up. Ask a prospective advisor to write that breakdown down before you sign. If they cannot, either they have not thought about it or the answer is uncomfortable.
Watch for the engagement where most of the allocation goes on writing status. A monthly deck that summarises what you already know is the cheapest thing to produce and the least valuable thing to buy. The hours should be going into decisions, buyer-facing work, and reading your environment.
The cost is not flat across an audit year
Companies budget fractional leadership as twelve equal months and then get surprised twice. The work is not evenly distributed and neither is the invoice, unless the contract deliberately smooths it.
In a typical first SOC 2 year the shape runs like this. The first two months are heavy, because scoping, the gap analysis and the initial policy decisions all land at once. Months three to six are moderate and mostly consist of chasing implementation that other people own. The observation window is comparatively quiet if the operating cadence is holding, which is exactly when companies wonder whether they still need the engagement. Then fieldwork arrives and the auditor's questions start, and that month is the heaviest of the year by a wide margin.
Two ways to price that. A flat monthly rate that averages across the year, which is easier to budget and means you overpay in quiet months and underpay in the audit crunch. Or a variable arrangement with a lower base and an agreed uplift during defined heavy periods. The flat rate is usually the better purchase, because the alternative creates a financial incentive to avoid calling your advisor in exactly the month you most need them.
The commercial terms that quietly change the real price
Two proposals at the same monthly figure can differ by thousands in practice, and the difference lives in clauses buyers skim.
Do unused hours roll over? Most engagements are use it or lose it, which is defensible because the advisor is holding capacity. What is not defensible is a hard reset combined with an overage rate that kicks in the moment you go a single hour past. Ask for either modest rollover, typically a month or a quarter, or a soft boundary with a stated tolerance.
What is the overage rate and who authorises it? A good arrangement names the hourly figure and says nobody bills past the allocation without written approval from someone on your side. Silence on this point is how a $3,000 month becomes a $6,400 invoice with a plausible explanation attached.
Minimum term and notice. Six-month minimums are common and reasonable, because the first two months are loaded with unpaid understanding of your environment. Twelve-month lock-ins with ninety days notice are not, at your stage. Thirty days notice after an initial term is the fair shape.
Rate escalation. Multi-year arrangements often carry an annual uplift. Ask what it is at signature rather than discovering it on the thirteenth invoice.
Where the work product lives. Covered elsewhere in this article as a principle. As a commercial term it belongs in writing: the risk register, policy set, roadmap and evidence live in your systems, you own them outright, and they stay yours on termination without an exit fee. Our own Workspace is free and yours to keep for exactly this reason.
Liability, insurance, and what a name on a document means
A fractional CISO puts their name on things: policy approvals, buyer attestations, sometimes a board paper. Occasionally a customer contract or an insurance application asks who your security officer is, and the honest answer is the fractional person.
That has consequences worth understanding before you sign. Check that the firm carries professional liability cover and ask for the limit, because it is normal to ask and telling silence when you do. Check the liability cap in the agreement, which is commonly capped at fees paid, often three to twelve months of them. That is standard in advisory work and it means the engagement is not an insurance policy. If a breach happens, your cyber cover and your own balance sheet carry it, not the consultancy's cap.
Also be clear about what an external person cannot sign. A fractional CISO can attest to how the programme runs and what has been implemented. They cannot certify you, they cannot be your named privacy officer under some statutes without a specific agreement, and they should refuse to sign a customer commitment about a control they have not verified. Someone who signs whatever is put in front of them is a risk to you, not a convenience.
What the price does when an incident lands
Almost no monthly allocation survives a real incident. A suspected data exposure consumes forty to eighty hours of senior time inside two weeks, between triage, evidence preservation, legal and privacy coordination, customer notification drafting, and the post-incident review that regulators and buyers will ask for afterwards.
So ask the question up front, in the quiet month, when you have leverage. Is incident support in scope or billed separately? What is the response commitment, and is it a target or a contractual obligation? Is there a rate difference for out-of-hours work? Some firms include a defined incident allowance in the monthly figure, some run incident response on a separate retainer, and some bill it as a project at a premium rate. All three are legitimate. Discovering which one you bought on day two of an incident is not.
When $3,000 a month is the wrong purchase
There are companies for whom the honest answer is do not buy this yet.
If you are pre-revenue with no enterprise buyer asking, a fractional CISO is a solution to a problem you do not have. Turn on MFA everywhere, get single sign-on, restrict production access to the people who need it, enable backups and confirm you can restore, and write down what data you hold. That is a fortnight of your own engineering time and it covers most of what an advisor would recommend in the first quarter anyway.
If the work in front of you has a defined end, buy it as a project instead. Readiness for one audit, a policy set built from nothing, a single buyer review: each of those has a deliverable and a finish line, and each is priced accordingly. A monthly retainer is a purchase of standing accountability between the projects, so buying one to close out a task means paying for eleven months of availability you never made a plan for.
If your budget is genuinely tight and the choice is between an advisory retainer and the audit itself, buy the audit path. A gap analysis and a readiness track produce a report a buyer can act on. Monthly advice with no report at the end of it does not unblock procurement. Our fixed-scope offerings are listed with their starting figures on the pricing page precisely so that comparison is possible without a call.
And if you already employ a competent security engineer or a technical founder who is genuinely engaged with this, the marginal value of monthly advisory drops sharply. What that company usually needs is a few hours of senior review at defined decision points, not a standing relationship.
The internal cost sitting next to the invoice
The last thing to budget is your own people's time, because fractional engagements fail on this more often than on money. An external advisor cannot grant access, cannot approve a policy on behalf of your company, cannot produce evidence out of systems they do not administer, and cannot make your engineers prioritise a fix.
Plan for one internal owner spending roughly four to eight hours a month, more during audit fieldwork, and for engineering to absorb remediation work that competes with the roadmap. Companies that do not allocate that time end up paying a monthly fee for advice that nobody has capacity to act on, which is the most expensive possible version of this purchase and the one most likely to be blamed on the advisor.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.
Fractional CISOOr talk about a retainerWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.