Last updated: 24 September 2026
Quick answer: Here is how to start a vCISO service: define who you will serve and which frameworks you will cover, package the service into clear tiers, build a repeatable onboarding assessment, standardise your policies and risk registers, agree governance reporting with each client, and run everything from one multi-client platform so delivery scales without adding headcount for every new client.
Many managed service providers already do half of a security leader’s job for their clients. They patch, monitor, back up and respond. What clients increasingly ask for is the other half: someone who owns the security programme, talks to the board and can show a regulator or auditor that risk is being managed. Learning how to start a vCISO service is how an MSP turns that demand into a recurring, higher-value line of business.
This guide walks through the practical steps, from defining scope and pricing models to building a delivery engine that works for ten clients as well as it does for one. It is written for MSPs, MSSPs and consultancies in the EU, UK and US.
How to start a vCISO service: what clients are buying
A vCISO (virtual chief information security officer) service gives a client senior security leadership on a fractional or outsourced basis. The provider sets strategy, owns the risk and compliance programme, and reports to management, without the client hiring a full-time CISO.
The role is about governance rather than tools. A vCISO decides which controls matter, why, who owns them and how progress is measured. Technical operations such as endpoint protection or monitoring may sit with the same MSP, but they are separate deliverables.
A typical vCISO engagement covers:
- security strategy and a prioritised roadmap;
- risk assessment and a maintained risk register;
- policies, standards and procedures;
- compliance with frameworks and regulations the client must meet;
- third-party and supply chain risk;
- incident response planning and exercises;
- reporting to the board or leadership team.
Why clients are asking for a vCISO now
Regulation has moved security accountability to the top of the organisation. That is why mid-sized companies now want named security leadership, even without a full-time executive.
- EU: Under Article 20 of the NIS2 Directive, management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Their members are also required to follow training.
- UK: The NCSC’s Board Toolkit supports the government’s Cyber Governance Code of Practice, which sets out what directors are expected to do on risk management, strategy, people, incident planning and assurance.
- US: The SEC rules adopted in July 2023 require public companies to disclose material cybersecurity incidents on Form 8-K, generally within four business days of determining materiality, and to describe board oversight and management’s role annually.
Frameworks point the same way. NIST released CSF 2.0 on 26 February 2024 and added a sixth function, Govern, covering how an organisation makes and monitors cybersecurity strategy decisions. That is vCISO work by definition.
For MSPs there is a second driver. NIS2 lists managed service providers and managed security service providers as covered entity types, and Commission Implementing Regulation (EU) 2024/2690 sets out technical and methodological requirements that apply to them. Clients know their providers are now in scope, and they expect those providers to speak the language of governance.
On 20 January 2026 the European Commission proposed targeted amendments to NIS2 to simplify compliance, and those proposals now go through the EU legislative process.
How to start a vCISO service in 7 steps
The steps below assume you already have a client base and some security expertise in-house.
Step 1: Choose your target clients and markets
Decide who you are building for. A 50-person software company chasing SOC 2 needs a different service from a regulated financial entity preparing for DORA oversight or a healthcare provider under HIPAA. Pick two or three segments where you already have clients and credibility.
Step 2: Define scope and the frameworks you will cover
Write down exactly what is in and out of scope. Common boundaries are:
- whether you perform technical testing or only commission and review it;
- whether you act as a named security officer to regulators or auditors;
- whether privacy and data protection work is included or offered separately.
Most MSPs start with a core set such as ISO 27001 requirements, the NIST Cybersecurity Framework, SOC 2 and NIS2, then add sector rules as demand appears.
Common mistake: promising to cover “any framework” from launch. Every framework you add needs templates, mapped controls and someone who can defend the work in front of an auditor. Start narrow and expand.
Step 3: Package the service into tiers
Clients buy outcomes, not hours. Package the service into two or three tiers that differ by depth and cadence rather than by vague effort.
| Element | Foundation | Standard | Regulated |
|---|---|---|---|
| Risk register review | Quarterly | Monthly | Monthly, with board reporting |
| Policy set | Core policies | Full policy framework | Full framework mapped to each regulation |
| Frameworks | One | Up to two or three | Multiple, including sector regulation |
| Vendor risk | Critical suppliers only | All key suppliers | Full register with contract clause checks |
| Incident readiness | Plan | Plan and annual exercise | Plan, exercises and regulatory reporting workflow |
| Leadership reporting | Quarterly summary | Quarterly meeting | Monthly metrics and quarterly board session |
This is an illustrative structure, not a benchmark.
Step 4: Choose a pricing model
Three models are common: a fixed monthly retainer per tier, a per-client fee with scoped add-ons such as audit support, or a project fee for the initial programme build followed by a retainer. Whatever you choose, price against your delivery cost per client, which depends heavily on how much of the work is templated and reusable.
In practice: separate the one-off onboarding effort from the recurring service in your proposal. The first months of an engagement usually take more work, and separating them stops the retainer being set too high for the steady state.
Step 5: Build a repeatable onboarding assessment
Your first deliverable to every client should be a baseline assessment against the frameworks in scope. Use the same questionnaire structure, scoring method and report format each time. A consistent baseline lets you show measurable progress later.
Cover governance, asset inventory, access control, vulnerability management, backup and recovery, incident response, supplier risk and awareness training. If a client is subject to NIS2, check the ten measures in Article 21(2), which run from risk analysis policies and incident handling to multi-factor authentication and secured communications.
Step 6: Standardise your delivery toolkit
The margin in a vCISO practice comes from reuse. Before you sign the fifth client, you should have:
- a master policy library you can tailor per client;
- a risk register template with agreed scoring criteria;
- a supplier assessment questionnaire;
- an incident response plan template and exercise scenarios;
- a board report template with a small set of stable metrics.
The biggest gain is mapping controls once and reusing the evidence across frameworks. An access review satisfies requirements in ISO 27001, SOC 2, NIS2 and several others. Tools that support AI-driven cross-framework control mapping save you from repeating the same work for each standard.
Step 7: Set governance and reporting rhythms
Agree with each client who the vCISO reports to, how often, and what decisions need their sign-off. Under NIS2, approval of risk-management measures sits with the management body, so your reporting must give directors enough to approve and oversee, not just a list of completed tasks.
Keep a decision log: when a client accepts a risk or delays a remediation, record who decided and why.
If you want to see how one platform can run assessments, policies, risks and vendors for every client at once, book a partner demo and we will walk you through a multi-client setup.
What skills and people do you need?
You need at least one person with genuine senior security experience who can lead client conversations with executives, plus analysts who can run assessments and maintain documentation.
Useful capabilities include risk management, audit experience with ISO 27001 or SOC 2, knowledge of the regulations in your chosen segments, and the ability to explain risk in business terms.
Common mistake: assigning the vCISO role to your most technical engineer. The core of the job is prioritisation, persuasion and documentation.
How do you avoid conflicts of interest?
Separate the people who design and oversee controls from the people who operate them where you can, and be transparent when the same MSP does both. A vCISO who reviews the MSP’s own service needs to be able to raise findings about it.
Privacy adds another layer. If you also offer a virtual DPO service, remember that the GDPR requires a data protection officer to act independently and not to receive instructions on how to carry out their tasks. Our guide to vCISO vs vDPO differences explains where the roles overlap and where they must stay separate. Keep the roles clearly defined in your contracts, even when one platform supports both.
Which tools does a vCISO practice need?
At minimum you need a place to run assessments, keep policies, maintain risk and vendor registers, track remediation tasks and store evidence, separated per client. Spreadsheets work for two or three clients and break down after that. Our article on running vCISO and vDPO services from one console looks at the multi-client model in more detail.
When comparing platforms, check for:
- true multi-tenancy, so each client’s data and users are isolated;
- white-label options so reports carry your brand;
- framework libraries and control mapping for the regulations your clients face;
- built-in compliance assessments and risk registers;
- a pricing model that does not penalise you for adding users or modules.
Enactia, the GRC platform for vCISO and vDPO services, is built for this model: it is multi-tenant and white-label, and Enactia for MSPs uses a flat fee per active client organisation with all modules and unlimited users included.
Launch checklist
- Target segments and their key regulations defined
- Scope statement with clear in and out of scope items
- Two or three service tiers with named deliverables
- Pricing model separating onboarding from the recurring fee
- Standard onboarding assessment and report template
- Master policy library, risk register and vendor questionnaire
- Board reporting template and decision log
- One pilot client to test the full cycle before wider launch
Key takeaways
- A vCISO service sells governance, risk and accountability, not extra technical operations.
- NIS2, the UK Cyber Governance Code of Practice and SEC disclosure rules all push security accountability towards leadership, which drives demand.
- Start with a narrow set of segments and frameworks, then expand.
- Margin comes from standardised assessments, templates and cross-framework control reuse.
- A multi-tenant, white-label platform lets delivery scale without linear headcount growth.
Frequently asked questions
What is the difference between a vCISO and an MSSP?
An MSSP operates security technology, such as monitoring, detection and response. A vCISO provides leadership: strategy, risk management, policies, compliance and reporting to management. Many providers offer both, but they are different services with different deliverables, and clients benefit when the governance role can independently review how operational controls are performing.
Do I need a certified CISO to launch a vCISO service?
No specific certification is legally required to offer a vCISO service. What you do need is someone with real senior security experience who can lead executive conversations and defend decisions to auditors. Certifications and audit experience in standards such as ISO 27001 or SOC 2 help build credibility with clients and are worth highlighting in proposals.
How many clients can one vCISO handle?
It depends on client size, regulatory complexity and how much of your delivery is templated. A practice built on standard assessments, a shared policy library and a multi-client platform can support far more clients per senior lead than one that builds everything from scratch. Track hours per client during your pilot to set your own ratio.
Should a vCISO service include privacy and GDPR work?
Security and privacy share much of the same groundwork, such as asset and data inventories, risk assessments, incident handling and vendor reviews. Offering both lets you reuse that work. If you act as a client’s data protection officer, keep the role independent as the GDPR requires, and define both roles clearly in your contracts.
How long does it take to onboard a new vCISO client?
Onboarding usually runs from an initial baseline assessment through a prioritised roadmap and the first round of policy and risk register work. The duration depends on the client’s maturity and the frameworks in scope. Setting a fixed onboarding phase in your proposal, separate from the retainer, keeps expectations clear on both sides.
Conclusion: build the engine before you scale
Starting a vCISO service is less about hiring a star security leader and more about building a delivery engine: clear scope, sensible tiers, repeatable assessments, reusable templates and governance reporting that directors can act on. Get those right with a pilot client, and each new client becomes faster and more profitable to serve.
If you are planning a vCISO or combined vCISO and vDPO offering, contact us or book a partner demo to see how Enactia supports MSPs and consultancies across every client from one console.
