A senior security leader for a few days a month. They build your security program, get you through SOC 2 or ISO 27001, and answer the security questionnaires that slow down deals.
Tell us what you need and our team will introduce you to people who fit.
Or browse profiles yourself
A fractional CISO, also called a virtual CISO or vCISO, is an experienced security executive who leads a company's information security program part-time. They set security strategy, run compliance work such as SOC 2 and ISO 27001, handle customer security reviews, plan incident response and report risk to the board. Most engagements cost $4,500–$12,500 a month.
Security work tends to arrive before companies are ready for it. A large customer sends a 300-question security questionnaire, an investor asks about SOC 2, or an insurer wants to see an incident response plan. Suddenly someone has to own security, and the most technical person in the room gets the job by default.
A fractional CISO takes that on properly. They assess where you stand, build a program sized to your risk, choose the controls and tools, and own the relationship with auditors and customers' security teams. Most work alongside your engineers or IT provider, who do the hands-on implementation.
Only about one in 10,000 companies worldwide employs a full-time CISO, which is why the fractional model has become the default for startups and mid-size companies.
Most fractional CISO engagements cost $4,500–$12,500 a month, with company size and compliance scope explaining most of the difference. Startups typically pay $1,500–$5,000, while regulated or multi-framework programs run $10,000–$20,000. GoFractional's live data shows an average of $223 an hour, or $10,400–$13,000 a month for about 13 hours a week.
Typical monthly retainer
$4,500–$12,500/mo
Hourly rate in live job posts
$200–$250/hr
Monthly cost in live job posts
$10,400–$13,000/mo
| Pricing model | Typical range | Best for |
|---|---|---|
| Startup (1–50 employees) | $1,500–$5,000 per month | Foundational policies, first SOC 2, security questionnaires |
| Small business (50–200) | $4,000–$8,000 per month | Building the first full security program |
| Mid-market (200–500) | $8,000–$15,000 per month | Multiple frameworks, board reporting, vendor risk |
| Upper mid-market (500–1,000) | $10,000–$20,000 per month | Regulated industries and several stakeholders |
| Hourly | $200–$400 per hour | A risk assessment, an audit prep sprint, a single customer review |
| Full-time CISO | $250,000–$500,000 per year | Large companies with a dedicated security team |
A full-time CISO's total cost, including salary, benefits, equity and recruiting, typically lands between $250,000 and $500,000 a year, and a search takes four to six months. A $5,000-a-month fractional retainer works out to $60,000 a year and can usually start within two to four weeks.
On MentorCruise: 20 matching mentors list monthly plans from $100 to $480 (median $295). Plans cover regular calls and chat, so they suit advisory-level support. For more hours, ask for a custom engagement.
Each framework (SOC 2, ISO 27001, HIPAA, PCI DSS) adds work. Running two at once can push pricing up by a quarter or more.
More employees, systems and vendors mean more to secure and more to audit.
Some retainers include hands-on implementation; others only cover strategy and oversight.
Health, payment and financial data bring stricter requirements and higher rates.
Most fractional CISO engagements combine strategy, compliance and the security work that unblocks sales.
A review of your systems, access, vendors, policies and risks, with a prioritized roadmap.
Scoping, control design, tool selection, evidence collection and managing the auditor.
Answering questionnaires, joining security calls with prospects, and maintaining a trust center.
Security policies people actually follow, plus awareness training for staff.
A tested plan for breaches and outages, and senior leadership when something goes wrong.
Security risk explained in business terms, with progress against the roadmap.
Beyond compliance projects, the ongoing role covers these areas.
Decides what to fix first based on real risk, not vendor marketing.
Reviews the security of the tools and suppliers you rely on.
Translates security requirements into tasks your team or provider can implement.
Makes sure the right people have the right access, and that it's removed when they leave.
Supports cyber insurance applications and works with counsel on privacy obligations.
Runs the annual cycle of audits, reviews and policy updates.
Security spend can go to people, services or software. Here's what each covers.
| Option | What you get | Missing piece | Typical cost |
|---|---|---|---|
| Fractional CISO | Security leadership, strategy and accountability | Hands-on implementation may be extra | $4,500–$12,500/mo |
| Managed security provider (MSSP) | Monitoring and response tools | Strategy and compliance ownership | Priced per device or user |
| Compliance platform | Automated evidence and policy templates | Judgment on scope and risk | Annual subscription |
| Full-time CISO | Dedicated security executive | Nothing, but it's expensive and slow to hire | $250,000–$500,000/yr |
A common setup for startups: a compliance platform for automation, an engineer or IT provider for implementation, and a fractional CISO to own the program and talk to auditors and customers.
The trigger is usually a customer, an auditor or an incident.
When not to hire one: Very small companies with no sensitive data and no enterprise customers can usually start with good IT hygiene: multi-factor authentication, device management and backups.
Enterprise prospects ask for SOC 2 reports, pen tests and questionnaires your team can't answer confidently.
You've promised a customer or investor SOC 2, ISO 27001 or HIPAA compliance by a certain date.
Health, financial or personal data raises the stakes and the regulatory requirements.
A breach, phishing loss or near miss shows you need someone senior in charge of security.
Senior operators who have done this job. Many offer an intro call, so you can check fit before you commit.
Ask about specific outcomes, not credentials. A good candidate will tell you what didn't work as readily as what did.
Which frameworks have you taken companies through, and how long did it take?
Do you include hands-on implementation, or only strategy?
Which compliance platforms and auditors have you worked with?
How do you handle customer security calls and questionnaires?
What happens if we have an incident at 2am?
Still have questions? Email our team and we'll help you work out what you need.
Most fractional CISO engagements cost $4,500–$12,500 per month. Startups typically pay $1,500–$5,000, while regulated or multi-framework programs run $10,000–$20,000. Hourly work runs $200–$400.
Yes. Fractional CISO, virtual CISO and vCISO all describe a part-time security executive. The terms are used interchangeably.
Typical services include a security assessment, SOC 2 or ISO 27001 readiness, customer security reviews, policies and training, incident response planning and board reporting.
Yes. Leading SOC 2 projects is one of the most common reasons companies hire a fractional CISO. They scope the audit, design controls, choose tools and manage the auditor, while your team handles implementation.
Usually when enterprise customers start asking for SOC 2 reports and security reviews, or when you handle sensitive health, financial or personal data.
Use the form on this page to describe your compliance goals and deadlines, and we'll introduce you to security leaders who fit. You can also browse mentors with CISO and security leadership experience directly.
We've already delivered 1-on-1 mentorship to thousands of students, professionals, managers and executives. Even better, they've left an average rating of 4.9 out of 5 for our mentors.
Get matchedTell us what you're working on and we'll introduce you to people who have done this job before.