Back to blog MSSP

How to Add vCISO Services to Your MSSP: Packaging, Pricing, and Delivery at Scale

Most vCISO content is written for buyers. If you run an MSSP and want to add fractional CISO services to your offering, you need a provider-side playbook for packaging, pricing, and delivering at scale.

Neil Cameron
· 13 min read
Most vCISO content is written for buyers. If you run an MSSP and want to add fractional CISO services to your offering, you need a provider-side playbook for packaging, pricing, and delivering at scale.

Key Takeaways

  • Most vCISO content online is written for buyers. This guide covers the provider side: how to package, price, and deliver vCISO services at scale across multiple clients.
  • The ISC2 2024 Cybersecurity Workforce Study reported a global shortfall of 4.8 million cybersecurity professionals (ISC2), which means more companies are actively looking for outsourced security leadership.
  • Three-tier packaging (Foundations, Growth, Enterprise) lets you match deliverables to client maturity without over-delivering on every engagement.
  • Reusable policy libraries, templated board reports, and questionnaire automation are what separate a scalable vCISO practice from a senior consultant burning out.
  • Start with your existing managed security clients. They already trust you, and adding strategic services increases account value without a new sales motion.

Most of what gets published about vCISO services is aimed at buyers: how to evaluate a fractional CISO, what to look for, how much to budget. This guide is different. It is written for the other side of the table: MSSP owners, independent security consultants, and managed service providers who want to build or expand a vCISO offering.

Your existing managed security clients already trust your team with their infrastructure. If you are earlier in that journey and still weighing what changes when an MSP starts selling security, start there: vCISO works best as a layer on top of an established managed security practice. When you add vCISO services, you also own their security strategy, risk posture, and compliance narrative. For MSSPs and independent security consultants, this is one of the highest-margin expansions available. You turn reactive monitoring revenue into recurring advisory revenue, and you keep clients from hiring a full-time CISO who might then question whether they still need your managed services.

The challenge is not demand. The ISC2 2024 Cybersecurity Workforce Study found a global shortfall of 4.8 million cybersecurity professionals, and most mid-market companies cannot justify a full-time CISO salary. The challenge is delivery: how do you provide board-level security leadership to ten or twenty clients simultaneously without burning through your most senior people?

This guide covers what clients actually expect from a fractional CISO engagement, how to package and price it, and how to deliver it across a growing client portfolio.

vCISO vs Fractional CISO: The Terms Clients Use

“vCISO” and “fractional CISO” describe the same service, but the terminology varies by buyer. Smaller companies and MSP-adjacent buyers tend to search for “vCISO.” Larger organisations and PE-backed portfolio companies often use “fractional CISO” because it mirrors fractional CFO and fractional CRO language they already understand.

For your marketing, lead with whichever term your target market uses. If you serve SMBs through an existing MSP or MSSP channel, “vCISO” is the term they will recognise. If you are targeting PE portfolio companies or mid-market firms with 200+ employees, “fractional CISO” may resonate more.

The service itself is the same: an experienced security leader, working part-time across multiple clients, who owns the security programme at the strategic level without being a full-time employee.

The terminology varies by buyer, but the service is identical. Lead with whichever term your target market already uses.

What this is not

A vCISO engagement is not a penetration test, a SOC service, or a compliance audit. Those are tactical, scoped deliverables. A vCISO engagement is ongoing, strategic, and cross-functional. Clients expect the vCISO to sit between their engineering team, their leadership, and their customers, translating risk into business decisions.

What Clients Actually Expect

Before you build packages, you need to know what shows up on a vCISO’s desk after the contract is signed. Here are the six deliverables that come up in almost every engagement.

Clients expect the vCISO to sit between their engineering team, their leadership, and their customers, translating risk into business decisions.

Board and leadership reporting

Clients expect a regular cadence (monthly or quarterly) of security reporting to their board or leadership team. This typically includes a risk summary, progress against a security roadmap, incident metrics, and compliance status. The format matters: boards want a one-page summary with a traffic-light status, not a 40-slide deck.

Risk register

A living risk register that identifies, scores, and tracks security risks. Clients expect you to maintain this, review it quarterly, and tie mitigations to their budget cycle. NIST SP 800-30 or ISO 27005 provide the methodology, and our guide to choosing a risk management framework covers how the main options compare. The value you add is contextualising risks for their specific business.

Policy set

Every client needs a foundational policy set: information security policy, acceptable use, access control, incident response, data classification, and vendor management at minimum. Our free policy generator and our worked policy examples are a practical base to customise from rather than drafting each one cold. For clients pursuing SOC 2 or ISO 27001, the policy requirements are prescriptive, and which certification to pursue first is a question you will field early in most engagements. For others, you are establishing baseline governance.

Incident readiness

Clients expect an incident response plan, a communication template, and ideally a tabletop exercise at least annually. They want to know that if something goes wrong, there is a playbook and someone (you) to coordinate the response.

Vendor due diligence

As your clients grow, they accumulate vendors. They need someone to assess third-party risk, review vendor security postures, and maintain a vendor inventory. This is a growing part of vCISO work, particularly for clients subject to SOC 2 Trust Services Criteria or who have contractual obligations to manage supply chain risk. For UK clients, the Cyber Security and Resilience Bill will sharpen those obligations further as it moves through Parliament.

Customer security reviews

This is the deliverable that surprises many new vCISO providers. Your client’s customers will send security questionnaires, request evidence packages, and schedule security review calls. Someone needs to own those responses, which in practice means maintaining a knowledge base per client rather than rebuilding context each time. For a 20-person SaaS company, responding to buyer security questionnaires can consume dozens of hours per quarter. This is where tools like ResponseHub become valuable: an AI-powered knowledge base that auto-completes questionnaires from existing policies and past responses, reducing what used to take days to minutes. If you are serving multiple clients, centralised questionnaire automation is one of the highest-return investments you can make.

The vCISO Delivery Stack: A Three-Tier Packaging Model

Packaging your vCISO services into clear tiers lets clients self-select based on their maturity and budget. It also protects your team from scope creep, because the deliverables in each tier are explicit.

Clear tier definitions protect your team from scope creep and let clients self-select based on their maturity and budget.

Table: The vCISO Delivery Stack: A Three-Tier Packaging Model
DeliverableFoundationsGrowthEnterprise
Security policy set (create/review)IncludedIncludedIncluded
Risk register (setup and quarterly review)IncludedIncludedIncluded
Board/leadership reportingAnnual summaryQuarterlyMonthly
Incident response planTemplate-basedCustomised + 1 tabletop/yrCustomised + 2 tabletops/yr
Vendor due diligenceGuidance onlyUp to 10 vendors/yrUp to 25 vendors/yr
Customer security review supportGuidance onlyUp to 5 questionnaires/qtrUnlimited
Compliance programme support (SOC 2, ISO 27001)Gap assessment onlyReadiness + auditor liaisonFull programme management
Strategic roadmap12-month plan12-month plan + quarterly refreshOngoing with monthly check-ins
Dedicated vCISO hours/month8-1015-2030-40

Foundations works for pre-revenue or seed-stage companies that need baseline governance, often because a prospect or investor asked for it. Growth fits Series A/B companies actively selling to enterprise buyers who face regular security questionnaires and need compliance readiness. Enterprise is for companies with complex environments, multiple compliance frameworks, or regulated industries.

Pricing Approaches for vCISO Services

There are three common pricing models, and most providers eventually settle on a hybrid.

Monthly retainer

A flat monthly fee tied to a service tier. This is the simplest model for both sides. Clients get predictable costs, and you get predictable revenue. The trade-off is that some months you deliver more value than others, and clients may question the fee during quiet periods.

Hours bank

The client purchases a block of hours per month or quarter. You track time and deliver a utilisation report. This works for clients who want flexibility, but it creates administrative overhead and incentivises clients to hoard hours or question every line item.

Per-client tiered pricing

A fixed price for a defined tier of service (as shown in the table above). This is the model that scales best because it decouples revenue from hours worked. As you build reusable templates, playbooks, and automation, your delivery cost per client drops while the price stays fixed.

Tiered pricing scales best because it decouples revenue from hours worked. As your delivery systems mature, cost per client drops while the price stays fixed.

Most mature vCISO practices use tiered pricing with an add-on mechanism for out-of-scope work (additional vendor assessments, ad hoc security review calls, M&A due diligence). Make the base package clear and the add-ons explicit so there is no ambiguity.

Delivering Across Many Clients Without Burning Out

The economics of a vCISO practice only work if your senior security people can serve multiple clients simultaneously. That means building repeatable systems.

Reusable policy libraries

Maintain a master set of security policies that you customise per client, rather than writing from scratch each time. Version-control them, and include client-specific variables (company name, data types, hosting providers) as fillable fields. One well-maintained library can serve dozens of clients with minimal per-client effort.

Templated board reports

Build a standard board report template with sections for risk posture, compliance status, incident summary, and roadmap progress. Populate it from each client’s risk register and tooling dashboards. A consistent format also trains your clients’ boards to know what to expect.

Centralised platforms

Use a GRC platform (Vanta, Drata, or similar) for each client’s compliance evidence and control monitoring. Some vCISO platforms like Cynomi offer multi-tenant dashboards designed specifically for MSPs managing many clients. The key is reducing context-switching: when you sit down to do Client A’s quarterly review, everything you need should be in one place.

Automation for questionnaires and evidence requests

Questionnaire volume is one of the biggest time sinks in vCISO delivery. If you are serving ten clients, you may handle dozens of overlapping security questionnaires each quarter, many asking the same questions in different formats. There are several ways to automate this, and it is worth reading them alongside the wider case for AI in MSSP delivery before you pick tooling. By automating responses across your client base with a tool like ResponseHub, you avoid manually re-answering identical questions for each client. That is what makes the difference between a practice that tops out at five clients and one that can grow to twenty.

Every policy, risk register, and questionnaire response you create adds to a library that makes the next client faster and cheaper to serve.

Who Should Deliver It: Staffing and Skills

A vCISO needs to operate at the intersection of technical security knowledge, business communication, and compliance expertise. That is a narrow talent pool.

The ideal profile

Former CISOs, senior security managers, or compliance leaders with experience presenting to boards and working cross-functionally. They need to be comfortable talking to a developer about API security and talking to a CFO about risk appetite in the same afternoon.

Building a team

If you are an MSSP adding vCISO services, your existing security operations team handles the technical delivery (monitoring, incident response). The vCISO layer sits above that, focused on governance, risk, and communication. You might start with one senior hire who serves three to five clients, then add capacity as your book grows.

Supporting roles

A GRC analyst or junior compliance specialist can handle much of the operational work: maintaining risk registers, updating policies, tracking evidence, preparing questionnaire responses. This frees your senior vCISO to focus on the strategic and client-facing work that actually requires their experience.

Launch Checklist

If you are ready to add vCISO services to your MSSP or consulting practice, here is a practical launch sequence:

  1. Audit your existing client base. Identify clients who already ask you security strategy questions, need compliance support, or are selling to enterprise buyers. These are your first vCISO candidates.
  2. Build your policy library. Create a reusable set of 8-12 foundational policies. Customise the variable fields. This is your biggest upfront time investment.
  3. Define your tiers. Use the three-tier model above as a starting point and adjust based on your market.
  4. Set your pricing. Start with tiered monthly retainers. You can add hours-bank options later for clients who want flexibility.
  5. Select your tooling. Choose a GRC platform, a questionnaire automation tool, and a board reporting template. Integrate them into a consistent delivery workflow.
  6. Hire or allocate your first vCISO. This person needs client-facing polish and security depth. If you do not have someone internally, hire for communication skills first and security credentials second, because the rest of your team can backstop the technical gaps.
  7. Pilot with two to three existing clients. Offer a discounted first quarter in exchange for feedback on your packaging and delivery process. Iterate before you go to market broadly.
  8. Build your external positioning. Create a dedicated vCISO services page, publish case studies (with client permission), and present the offering to your existing customer base before investing in outbound.

The Compounding Advantage

Every policy you write, every risk register you build, and every questionnaire you answer adds to a library that makes the next client faster and cheaper to serve. vCISO practices have a compounding delivery advantage: client number twenty costs meaningfully less to onboard than client number one, but you charge the same rate.

MSSPs already have the trust relationships and the technical infrastructure. When you add a vCISO layer, you turn those relationships into advisory engagements with higher margins, longer retention, and stronger differentiation against competitors who only offer monitoring and alerting.

Providers who build this capability now, while demand for fractional CISO services continues to outpace supply, will have a structural lead: a mature policy library, a trained delivery team, and a client base generating referrals.

Frequently Asked Questions

How many clients can one vCISO serve at the same time?

It depends on the tier of service and the maturity of your delivery systems. Based on typical engagements across the industry, a senior vCISO with strong templates, a GRC platform, and analyst support can typically serve 8-12 clients on a Foundations tier or 4-6 on a Growth tier. Without reusable systems, that number drops to three or four before quality suffers. The constraint is usually client-facing time (meetings, board presentations, incident response) rather than document production.

Do I need specific certifications to offer vCISO services?

No certification is legally required, but clients expect credibility. CISSP is the most widely recognised credential for this role. CISM (from ISACA) signals governance and management expertise specifically. If your vCISO team members hold either, it removes a common objection. Beyond individual certifications, your firm’s own compliance posture matters: holding SOC 2 or ISO 27001 yourself makes the conversation significantly easier.

Should I offer vCISO as a standalone service or bundle it with managed security?

Both work, but bundling tends to perform better for retention. Clients who buy vCISO alongside managed detection and response see you as their complete security function, which makes it harder for a competitor to displace you. Standalone vCISO engagements are viable but more vulnerable to churn if the client hires a full-time CISO or switches providers. Start with your existing managed clients and expand to standalone only once your delivery process is proven.

What is the biggest risk when launching vCISO services?

Scope creep. vCISO engagements touch every part of a client’s business, and without clear tier definitions, clients will treat you as an on-call security advisor for anything that comes up. Define your deliverables explicitly in your engagement letter, specify what is in-scope and what triggers an add-on fee, and review scope quarterly. The second risk is staffing: assigning someone who is technically strong but cannot communicate with a board will damage the engagement quickly.

How do vCISO services differ from compliance-as-a-service?

Compliance-as-a-service typically focuses on a specific framework (SOC 2, ISO 27001, HIPAA) and delivers audit readiness: evidence collection, control implementation, auditor coordination. A vCISO engagement is broader. It includes compliance as one workstream alongside risk management, security strategy, vendor oversight, incident readiness, and board reporting. Many vCISO engagements include compliance programme management, but the scope extends well beyond any single audit.

Get back to closing deals and shipping product

Upload your policies, let AI draft cited answers, and get your team reviewing instead of writing. No sales call — self-serve in under 5 minutes.

  • 7-day free trial
  • Cancel anytime
  • Full product