Last updated: 1 October 2026
Quick answer: The main vCISO pricing models for MSPs are hourly or day rates, fixed-price projects, monthly retainers, tiered packages and per-user or per-device pricing, often combined. Most MSPs anchor on a tiered monthly retainer priced from estimated hours, regulatory scope and delivery tooling costs, with projects and incidents billed separately.
Clients increasingly ask their managed service provider for security leadership, not just security tools. Boards want someone to own the risk register, answer auditors and brief directors. For many small and mid-sized organisations a full-time CISO is out of reach, so a virtual CISO (vCISO) service is the practical answer.
The hard part for the MSP is pricing it. Price too low and the service eats senior consultant time; price too high and clients stay with ad hoc advice. This guide compares the common vCISO pricing models, explains the cost drivers, and walks through a worked method for building your own price list.
Why do vCISO pricing models matter more now?
Because clients are asking for vCISO services in greater numbers. Regulation and governance frameworks now expect named, senior ownership of cybersecurity. Clients need that ownership but often cannot justify a full-time hire.
- EU: NIS2 makes management bodies approve and oversee cybersecurity measures and follow training. For digital providers, Implementing Regulation (EU) 2024/2690 sets detailed requirements and explicitly covers managed service providers and managed security service providers themselves.
- UK: the Cyber Security and Resilience (Network and Information Systems) Bill would bring managed service providers into scope, according to the House of Commons Library briefing. After passing the Commons, it had its House of Lords second reading on 14 July 2026, with committee stage scheduled from 1 September 2026.
- US: the SEC’s 2023 cybersecurity disclosure rules require public companies to describe board oversight of cyber risk and management’s expertise in handling it, which pushes governance expectations down to their suppliers.
- Frameworks: NIST CSF 2.0, released on 26 February 2024, added a Govern function focused on how organisations make and carry out cybersecurity decisions.
Each of these creates recurring governance work: policies, risk reviews, board reporting and supplier oversight. That recurring nature is why subscription pricing suits vCISO services.
What are the main vCISO pricing models?
There are five common vCISO pricing models, and most MSPs end up combining two or three of them. The right mix depends on how predictable the client’s needs are.
| Model | How it works | Strengths | Watch out for | Best for |
|---|---|---|---|---|
| Hourly or day rate | Bill actual time at an agreed rate | Simple, low commitment | Unpredictable revenue; clients ration contact | Ad hoc advice, early relationships |
| Fixed-price project | One price for a defined deliverable | Clear scope and outcome | Scope creep; no ongoing income | Gap assessments, policy sets, audit readiness |
| Monthly retainer | Fixed monthly fee for a set of services and hours | Recurring revenue, continuity | Unused or overused hours | Ongoing governance and reporting |
| Tiered packages | Two to four retainer levels with defined inclusions | Easy to sell and upgrade | Tiers that do not match real effort | Portfolios of similar clients |
| Per user or per device | Fee scales with headcount or endpoints | Scales with client growth | Governance effort does not scale linearly with users | Bundling with managed security services |
Hourly and day rates
Time-based billing is the easiest way to start, and it makes sense while you learn what a client really needs. Its weakness is that clients hesitate to call when every conversation costs money, which is the opposite of what a security leader should encourage.
Fixed-price projects
Projects work well for bounded tasks such as a NIS2 or ISO 27001 gap assessment, a policy suite or preparing for a certification audit. They are also a natural entry point: a gap assessment produces the roadmap that justifies an ongoing retainer.
Monthly retainers and tiers
A retainer turns vCISO work into recurring revenue. Tiers make it easier to sell: for example an Essentials tier covering policies and a quarterly risk review, a Standard tier adding monthly reporting and supplier reviews, and an Enhanced tier adding board attendance and audit support. Define each tier by deliverables and service levels, not only by hours.
Per-user or per-device pricing
This model fits MSPs that already bill managed services per seat. It is simple for the client to understand, but governance effort is driven more by regulatory scope and complexity than by headcount. Use it with a minimum fee, or as a component of a tiered retainer rather than the whole price.
What drives the cost of a vCISO engagement?
The biggest cost driver is senior consultant time, and that time is driven by scope, not company size alone. Price against these factors:
- Regulatory scope: the number of frameworks and laws in play (for example NIS2, DORA, ISO 27001, SOC 2, GDPR) and whether the client is directly regulated.
- Maturity: a client with no policies or risk register needs a build phase before steady-state governance.
- Governance cadence: how often you report, attend board or committee meetings and review risks.
- Third-party exposure: the number of critical suppliers that need assessment and monitoring.
- Audit calendar: certification audits, customer questionnaires and regulator requests.
- Incident support: whether incident coordination hours are included, capped or billed separately.
- Delivery tooling: the GRC platform and other tools you use per client.
- Liability and insurance: professional indemnity cover appropriate to advisory security work.
Common mistake: pricing a regulated client like an unregulated one of the same size. A 60-person payment firm under DORA needs far more governance time than a 60-person design agency, even though per-user pricing would treat them the same.
How do you build a vCISO price list? A worked method
The most reliable method is bottom-up: estimate the hours each deliverable takes, apply your blended rate, add tooling and a margin, then round into tiers. The worked example below uses hours only, so you can apply your own rates and currency.
Step 1: list recurring deliverables and hours
| Deliverable | Frequency | Estimated hours per year |
|---|---|---|
| Policy review and updates | Annual, plus changes | 16 |
| Risk register review with owners | Quarterly (4 x 6 hours) | 24 |
| Management security report | Monthly (12 x 3 hours) | 36 |
| Board or committee briefing | Twice a year (2 x 6 hours) | 12 |
| Critical supplier reviews | 10 suppliers x 2 hours | 20 |
| Awareness and tabletop exercise | Annual | 12 |
| Advisory time and questionnaires | Ongoing (4 hours a month) | 48 |
| Total | 168 |
Step 2: turn hours into a monthly fee
- Divide the annual hours by 12: 168 / 12 = 14 hours a month.
- Multiply by your blended hourly cost (salary, overheads and non-billable time).
- Add the monthly cost of tooling for this client.
- Add a contingency of 10 to 20% for unplanned work.
- Apply your target margin and round to a clean tier price.
Step 3: define what sits outside the retainer
Price separately, or cap, anything that is lumpy: the initial build phase, certification audit preparation, incident response coordination and new regulatory projects. State the rate for extra hours in the contract so there is no argument later.
In practice: revisit your estimates after the first two quarters. Actual timesheets per deliverable are the best data you will have for pricing the next client.
How can MSPs protect vCISO margins?
Margin in vCISO services comes from reuse. The more of the work you can standardise across clients, the less senior time each deliverable needs.
- Standard templates: keep a master policy set and adapt it per client with policy management rather than rewriting from scratch.
- Cross-framework mapping: when one client needs NIS2, ISO 27001 and GDPR, mapping controls across frameworks lets one piece of evidence serve several requirements.
- Shared risk libraries: start each client’s risk register from a curated library, then tailor.
- Repeatable supplier reviews: use standard questionnaires and scoring in vendor risk management.
- Predictable tooling cost: choose delivery tools whose cost per client is known in advance, so the tooling line in Step 2 does not grow unexpectedly.
Overlapping regimes are where scope creep usually starts. Our article on managing the overlap between DORA, NIS2 and the EU AI Act shows how unified control mapping keeps that work contained.
If you are designing a vCISO or vDPO offer and want to see multi-tenant delivery in practice, book a partner demo.
Should you bundle vCISO and vDPO services?
Often, yes. Security and privacy share evidence: incident response, supplier due diligence and security measures all matter under both cybersecurity rules and data protection law. GDPR Article 37(6) allows the data protection officer to fulfil tasks “on the basis of a service contract”, as the text of the GDPR states, so an external DPO service is a legitimate offer in the EU.
Our article on vCISO vs vDPO explains how the two roles differ. Bundling can raise the value of each client relationship and reduce duplicated work. Keep the roles distinct, though: the DPO must be able to perform tasks independently, so avoid a structure where the same person decides security strategy and then monitors its privacy compliance without any separation.
Enactia, the GRC platform for vCISO and vDPO services, is built around this combined model through Enactia for MSPs, with a flat fee per active client organisation and all modules included.
A quick decision guide
- New client, unclear needs: start with a fixed-price gap assessment, then propose a tier.
- Stable needs, several similar clients: use tiered monthly retainers.
- Existing per-seat managed security contract: add a governance component with a minimum monthly fee.
- Heavily regulated client: tiered retainer plus separately priced audit and regulatory projects.
- Occasional advice only: day rate, with a clear path to a retainer.
Key takeaways
- Most MSPs combine a tiered monthly retainer with fixed-price projects and separately billed incident work.
- Price from regulatory scope and governance cadence, not headcount alone.
- Build tiers bottom-up from deliverable hours, tooling cost, contingency and margin.
- Protect margins through templates, shared risk libraries and cross-framework control mapping.
- Bundling vCISO with vDPO services increases value, provided roles stay distinct.
Frequently asked questions
What is the most common vCISO pricing model?
Monthly retainers, often packaged as tiers, are the most common structure for ongoing vCISO work because governance tasks recur every month and quarter. Many MSPs pair the retainer with fixed-price projects for gap assessments or audit preparation and bill incident response separately. The best mix depends on how predictable each client’s needs are.
Should a vCISO retainer include incident response?
Include a defined amount of incident coordination, such as a set number of hours a year, and bill anything beyond it at an agreed rate. Unlimited incident support in a fixed fee is risky, because one serious incident can consume months of margin. Make the boundary between coordination and technical response work explicit in the contract.
How do I price vCISO services for a regulated client?
Start from the same bottom-up method, but add the extra deliverables regulation creates: board reporting, regulator requests, supplier oversight, testing and audit support. Regulated clients usually need a higher tier and a separate budget for new regulatory projects. Confirm which laws apply before quoting, because scope drives most of the effort.
Is per-user pricing a good idea for vCISO services?
It works as a component, especially if you already bill managed services per seat, but it rarely reflects governance effort on its own. A small, heavily regulated firm can need more senior time than a larger unregulated one. If you use per-user pricing, set a minimum monthly fee and tie extra deliverables to tiers.
How often should vCISO pricing be reviewed?
Review each client’s pricing at least annually and whenever scope changes, such as a new framework, a certification target or a change in regulatory status. Compare actual hours per deliverable against your estimates. Timesheet data from the first few quarters of an engagement is the best basis for adjusting both that client’s tier and your standard price list.
Choosing a vCISO pricing model that lasts
The best vCISO pricing models give clients predictable costs and give you predictable margins. Start with a clear gap assessment, price recurring governance bottom-up, keep lumpy work outside the retainer and reuse as much as you can across clients. Revisit the numbers once you have real delivery data.
To talk through your vCISO and vDPO service design, contact us or book a partner demo.
