Pricing

Clear pricing baselines. Scoped to the actual work.

Choose a vCISO ownership level or request a separately scoped project.Choose the vCISO ownership level that fits your team. Focused assessments and technical projects are scoped separately with fixed or capped pricing when possible.

Engagement options

Choose the level of ownership you need.

Start with a clear baseline. The written intake confirms the scope, responsibilities, and final price before you commit.

Save 15% with annual billing

Your team executes. We guide.

Advisory vCISO
Senior direction for teams that can run the work internally but need an experienced security leader to set priorities and review decisions.
From$3,000
Per month · billed monthly
Start an Advisory request
  • Monthly security and risk review
  • 12-month security roadmap
  • Policy and control review
  • Compliance and audit guidance
  • Executive-ready recommendations
  • Email access with a 48-hour response SLA
Recommended

We manage the program.

Managed vCISO
Ongoing ownership of the security and compliance program for teams that need the work managed, not another list of recommendations.
From$5,000
Per month · billed monthly
Start a Managed request
  • Everything in Advisory, plus:
  • Biweekly working sessions
  • Policy authoring and evidence management
  • Compliance platform administration
  • Audit coordination and questionnaire response
  • Risk register, tabletop, and executive reporting

We embed and execute.

Embedded vCISO
Hands-on security leadership for complex programs, tight audit timelines, M&A, or teams that need a security leader inside the operating cadence.
Custom
Typically $10,000+/month
Scope an Embedded engagement
  • Everything in Managed, plus:
  • Weekly leadership and engineering cadence
  • Hands-on remediation and control implementation
  • Multi-framework and audit fieldwork leadership
  • Board, investor, and customer security briefings
  • Incident leadership with same-day response

Monthly retainers remain month to month. Annual billing is one prepaid invoice with a 15% discount; cancel with 30 days' notice and the unused prepaid balance is refunded on a prorated basis.

Prices shown are engagement baselines. Final pricing depends on your environment, compliance obligations, implementation needs, and response expectations. The written intake confirms the scope and final price before purchase.

What hands-on means

Senior direction backed by technical execution.

We prioritize the work against your risks, deadlines, and agreed roadmap. Direction, program management, and hands-on implementation are stated explicitly in the scope so you know what is owned and what remains with your team.

Architecture and data-flow review

Trust boundaries, sensitive data paths, integrations, and the design decisions that create or reduce material risk.

Identity and cloud hardening

IAM, logging, network exposure, secrets, and cloud configuration reviewed and remediated when implementation is in scope.

Control and evidence remediation

Policies, procedures, control operation, and audit evidence brought into alignment with how the environment actually works.

Penetration testing and validation

Scoped offensive testing and technical validation tied to the roadmap—not a disconnected annual checkbox.

Incident readiness

Actionable runbooks, escalation paths, tabletop exercises, and leadership support before a real incident forces the issue.

Questionnaires and audit support

Customer security reviews, evidence requests, auditor coordination, and the technical follow-through needed to close gaps.

Responsibility by engagement level

Focused project

We define the outcome, boundaries, deliverables, assumptions, and finish line before the work begins.

Ongoing ownership

We define the operating cadence, responsibilities, response expectations, and program backlog around the work you need owned.

Expanded execution

When hands-on implementation or enterprise coordination is needed, it is added explicitly to either scope rather than hidden inside a tier.

FAQ

Common questions

Most buyer questions, answered plainly.

How is vCISO different from hiring a full-time CISO?

A full-time CISO costs $250K to $400K fully loaded, takes 3-6 months to hire, and is often overqualified for Series A or early B companies. A virtual CISO gives you senior security leadership on demand, month-to-month. When you outgrow us, we help you hire the full-time CISO.

Which engagement shape is right for us?

Use a focused project for a bounded assessment, test, or remediation initiative. Use ongoing program ownership when you need recurring leadership, audit management, and cross-functional accountability. If the right starting point is not obvious, request a written recommendation and we will map it for you.

Are the listed prices final?

The listed prices are engagement baselines. Environment size, deadlines, frameworks, response expectations, and implementation responsibilities determine the final scope and price. The written intake confirms both before you commit.

Do you carry insurance?

Yes. Cyber Syndicate, LLC dba vCISO.com carries professional liability / errors and omissions insurance sized for growth-stage engagements. Coverage certificates are available on request during procurement review.

Not sure where to start? Request a written recommendation.

Ready when you are

Start with the essentials.

Share the essentials once. You'll receive a recommended starting scope, a working price range, and any focused questions needed to finalize it within 24 hours.