Senior security leadership, priced like you would expect.
A full-time CISO costs $250K to $400K a year. vCISO costs a fraction of that, month to month, with no long-term contract and the same senior experience.
- Kickoff call, gap analysis, policy inventory
- Light pentest on your app
- Prioritized remediation roadmap
- Exec readout deck and presentation
- Credited in full toward month one of retainer
- Monthly security reviews
- Policy review and recommendations
- Customer security questionnaire response
- Annual IR + DR tabletop exercise
- Slack and email access
- 48-hour response SLA
- Everything in Strategic vCISO, plus:
- Weekly syncs and embedded availability
- Hands-on policy authoring and remediation
- Audit preparation and fieldwork support
- Board and investor briefings
- Compliance platform admin (Vanta, Drata, Secureframe)
- Incident response leadership
- Same-day response SLA
- Threat-informed baseline (NIST CSF + MITRE ATT&CK)
- 12-month prioritized roadmap with owners
- Full pentest in days 31 to 60
- Closed first wave of high-priority gaps
- Board briefing and pentest summary at day 90
- First month of retainer credited if you continue
Annual billing means a single invoice for 12 months and a 15% discount on the Strategic vCISO retainer. Retainers remain cancellable with 30 days notice; unused balance prorated on termination. Sprint and Foundation pricing are flat-fee, not affected by billing cadence.
50% off retainer for 12 months.
Our first 5 retainer clients lock in Strategic vCISO at $2,500/mo or Embedded vCISO at $5,000/mo for 12 months. Plus the SOC 2 Sprint at $500. Trade: testimonial, case study rights, willingness to take a reference call. Year two reverts to list pricing.
Common questions
Most buyer questions, answered plainly.
How is vCISO different from hiring a full-time CISO?
A full-time CISO costs $250K to $400K fully loaded, takes 3-6 months to hire, and is often overqualified for Series A or early B companies. A virtual CISO gives you senior security leadership on demand, month-to-month. When you outgrow us, we help you hire the full-time CISO.
Is the Sprint cost really credited toward the retainer?
Yes. If you sign a retainer within 30 days of Sprint delivery, the $2,500 is credited in full against your first month. The Sprint becomes your month-one discount and we've already done the discovery work.
Can I cancel the retainer?
Yes. Every retainer is month-to-month with 30 days notice. No contracts, no minimums, no renewal traps. If vCISO isn't pulling its weight in a given month, you shouldn't pay for it.
Do you carry insurance?
Yes. vCISO Services, LLC carries professional liability / errors and omissions insurance sized for growth-stage engagements. Coverage certificates are available on request during procurement review.
Ready when you are
Your next move starts with a 30 minute call.
If vCISO is not a fit, we will say so on the call and point you toward someone who is. If we are, we will scope a Sprint, the 90-Day Foundation, or a retainer right then.