Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

vCISO ROI Calculator

Compare a full-time CISO against a fractional (virtual) CISO retainer. Every figure below is yours to edit; the defaults are editable estimates, not market claims. The math updates in real time.

Editable estimate. Enter the number that fits your market and stage.

Payroll taxes, benefits, equipment, etc. as a % on top of salary.

25 % load
0%50%

Editable estimate. Agency fees, search time, ramp. Set to 0 to ignore.

How much executive security time you truly need each month.

4 days / month
1 day20 days

Editable estimate. Replace with a real retainer quote when you have one.

Full-Time CISO
$0
first-year total cost
  • Base salary$0
  • Benefits + overhead$0
  • Recruiting / onboarding$0
  • CapacityFull-time (~20 days/mo)
Fractional CISO
$0
annual retainer cost
  • Day rate$0
  • Days / month0
  • Benefits / recruiting$0 (none)
  • CapacityScoped to cadence
$0
estimated first-year difference vs a full-time CISO
How this is calculated (fully transparent)

Every figure is an input or editable estimate. Swap in your own numbers or a real quote.

What this suggests

Not ready for a call yet?

Get the security leadership playbook

A few short notes from Jacob on running security leadership at startup scale, without a full-time hire. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want it done for you?

CISO-as-a-Service

Senior security leadership on a retainer, scoped to your cadence.

Explore CISO-as-a-Service →

Talk to a Fractional CISO

See what a retained security leader would actually cost for your cadence against our pricing. Book a free call and we will scope it to your real needs, led by a published security researcher.

Explore CISO-as-a-Service Book a call

Frequently asked questions

Where do the numbers in this calculator come from?

Every dollar figure comes from you. You enter the full-time CISO salary you would expect to pay, the benefits and overhead load, and how many days of security leadership you actually need each month. The defaults are editable estimates, not market claims, so you can replace them with your own figures.

What is a fractional or virtual CISO?

A fractional CISO (also called a virtual CISO or vCISO) is a senior security leader engaged on a part-time, retained basis rather than a full-time hire. You get executive security judgment scoped to the cadence you actually need, without carrying a full salary, benefits, and equity.

Is this calculator free?

Yes, it is free with no payment or signup required. It is a planning aid to help you frame the cost tradeoff between a full-time and fractional security leader.

When does a fractional CISO make more sense than a full-time hire?

When you need senior security leadership for compliance, audits, or enterprise deals, but the workload does not yet justify a full-time executive salary. Fractional leadership also suits bridging a gap while you hire, or guiding a small team through SOC 2 or a specific project.

Want the full picture?

This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

Start your free assessment See what is in the Workspace

No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.