Fractional CISO · vCISO · Compliance

vCISO vs compliance consultant: which does your startup actually need?

vCISO vs compliance consultant: which does your startup need?

They sound similar and overlap in tasks, but they solve different problems. One delivers a project; the other owns your security program. Here's how to tell which you need.

What is the difference between a vCISO and a compliance consultant?

Hire a compliance consultant when you have a defined, time-boxed goal — get SOC 2-ready, close a gap assessment, pass one audit. Hire a fractional CISO (vCISO) when you need someone to own security decisions on an ongoing basis: answer customer security questionnaires, set risk priorities, represent you to auditors and the board, and keep the program running between audits.

vCISO vs compliance consultant: a side-by-side comparison

DimensionCompliance consultantFractional CISO / vCISO
EngagementProject / fixed-feeOngoing monthly retainer
ScopeA specific framework or auditWhole security program + risk decisions
Owns decisions?AdvisesYes — accountable owner
Security questionnairesSometimesCore part of the role
Board / customer faceRarelyRepresents security externally
Best whenOne clear deliverableSecurity is ongoing but doesn't justify a full-time CISO

When should you hire a vCISO vs a compliance consultant?

What is a fractional CISO who can also implement the controls?

Most vCISOs come from pure governance backgrounds and can't implement the controls they recommend. A fractional CISO who is also a CISA + AWS Solutions Architect Professional writes the policy and builds the IAM, KMS, CloudTrail and Config controls behind it — so audits go faster and there's no gap between the paperwork and the actual cloud account.

Not sure which you need?

Tell me your stage and what's stuck — I'll give you a straight recommendation, consultant or fractional CISO.

Fractional CISO / vCISO →Book a free call
## What each one costs, honestly

Price is where the two roles diverge most sharply, and comparing headline rates without comparing scope produces bad decisions.

A compliance consultant is usually engaged for a defined deliverable — a gap assessment, a policy set, readiness for a specific audit — and priced as a project. That is genuinely efficient when the need is bounded. The trap is that the deliverable is documentation, and documentation does not implement itself. Teams routinely buy a readiness assessment, receive a competent forty-page report, and discover the actual work has not started.

A vCISO is a retained arrangement, typically monthly, and looks more expensive per month while covering something different: ongoing decisions, questionnaire response, vendor assessment, and accountability that persists after the report is delivered. The comparison that matters is not consultant-project versus vCISO-month, it is total cost to actually reach the outcome — including the engineering time that a report-only engagement pushes back onto your team.

The pattern I see most often is a company buying the assessment first, stalling on remediation for a quarter because nobody owns it, then engaging leadership anyway. Sequencing it the other way round is usually cheaper.

## How each one fails

Both models have characteristic failure modes, and knowing them is more useful than a feature comparison.

The consultant engagement fails when the deliverable is mistaken for the outcome. A policy set nobody has read, a control matrix that describes an idealised company, a risk register generated from a template — all of these pass a superficial review and none of them survive an auditor asking someone to walk through a real change. It also fails when the consultant has never operated the systems they are writing controls for, producing requirements that are technically incoherent on your actual stack.

The vCISO engagement fails when the commitment is too thin to be real. A few hours a month buys you a name on an org chart and not much else — the questionnaire still lands on an engineer, the risk decisions still get made by whoever is nearest, and the arrangement provides the appearance of leadership without its substance. It also fails when the vCISO is governance-only and cannot engage with the infrastructure, which turns every finding into a ticket for your team to interpret.

The common root cause in both cases is buying the artefact rather than the outcome.

## Questions worth asking before you hire either

A short list that reliably separates people who have done the work from people who have read about it.

## Structuring it so it actually works

Whichever model you choose, a few structural decisions determine whether you get value.

Name the outcome, not the artefact. "SOC 2 Type 2 report issued with no exceptions" is a goal. "Gap assessment delivered" is an activity that may or may not lead anywhere.

Put the questionnaire and audit response explicitly in scope. This is the single largest hidden cost of enterprise sales, it recurs, and if it is not assigned it lands on whichever engineer is least able to refuse it.

Agree what happens during an incident before there is one — availability, escalation, and whether it sits inside the retainer or outside it. Negotiating that mid-incident is expensive in both money and judgement.

And require that the risk register and roadmap say what is not being done and why. A roadmap containing only planned work is a wish list; one that records accepted risks with reasoning is a decision record you can defend to an auditor, a customer, or a board.

Common questions

Is a vCISO the same as a compliance consultant?

No. A compliance consultant delivers a project (e.g., SOC 2 readiness); a vCISO owns your ongoing security program, makes risk decisions, and represents security to auditors and customers on a retainer.

When should a startup hire a fractional CISO?

When customers/investors send security questionnaires, you're pursuing SOC 2 or ISO 27001, or security decisions are piling up without a senior owner — but you don't yet need a full-time CISO.

How much does a vCISO cost vs a full-time CISO?

A fractional CISO is a monthly retainer scaled to scope — typically a fraction of a full-time CISO salary, with the flexibility to scale up around audits and down afterward.

Can one person be both?

Yes, and that is the arrangement I run — but verify it rather than assume it. Plenty of people describe themselves as hands-on and have not touched a cloud console in years. Ask for the implementation detail on a specific control; the answer is immediately diagnostic.

Do we need either one if we already have a security engineer?

Possibly not. A capable security engineer plus a bounded compliance consultant for the audit covers a lot of ground. What an engineer typically cannot provide is the accountability layer — representing security to a board, owning risk acceptance, and making scope decisions that need organisational authority rather than technical judgement.

Which should come first if we can only afford one?

If a specific audit is committed with a date, a consultant scoped tightly to that audit is the efficient choice. If the driver is broader — enterprise buyers, a growing estate, a board asking questions — leadership first tends to cost less overall, because it prevents the common failure of buying a report and then discovering nobody owns the follow-through.