Most mid-market companies pay between $3,000 and $12,000 a month for a fractional CISO in 2026, and most engagements land in the $5,000 to $9,000 range. Compliance-heavy programs, meaning active SOC 2 or ISO 27001 work, PCI obligations, or standing board reporting, typically run $12,000 to $25,000 a month. A full-time CISO at the same companies costs $250,000 to $700,000 in total compensation — cash plus equity — before you count search fees, benefits, and ramp time.
Those ranges are wide, and the quotes you collect can vary by 5x or more for reasons providers rarely explain up front. This guide breaks down the full fractional CISO cost picture for 2026: published pricing by engagement model and company size, what actually drives the spread, and the breakeven math on fractional versus full-time — including the point where hiring fractional stops making sense.
One honesty note before the tables. There is no independent invoice survey for this market. Every public figure comes from providers themselves or from benchmarks that aggregate published provider rates. Treat the numbers here as market list-price ranges, not audited averages. Six independent sources converging on the same bands still tells you something, but any individual engagement can land outside them.
Published pricing by engagement model
The 2026 pricing guides from SideChannel, Ciphers Security, BD Emerson, Five Nines, vCSO.ai, and PlatOps describe the same basic menu, with variations at the edges. Consolidated:
| Engagement model | Typical 2026 range | What it usually covers |
|---|---|---|
| Advisory-only retainer | $3,000–$6,000/mo | Monthly executive guidance, program direction, board and customer-security-review support |
| Mid-market retainer (most common) | $3,000–$12,000/mo | Ongoing security leadership: roadmap, policy set, risk register, audit and customer support |
| Operational retainer (4–6 days/mo) | $8,000–$16,000/mo | Hands-on days with the team, running the security program directly |
| Embedded engagement | $15,000–$25,000/mo | Near-full-time presence, managing staff and vendor relationships |
| Compliance-heavy programs | $12,000–$25,000/mo | Active SOC 2/ISO/PCI pushes plus standing board reporting |
| Hourly advisory | $175–$600/hr | Short engagements, second opinions, due diligence |
| Fixed-scope project | $5,000–$75,000 | Assessments, SOC 2/ISO readiness, remediation plans |
The tiers track what several providers call day-rate bands. BD Emerson’s 2026 breakdown is the clearest published example: advisory work at $3,000–$6,000 a month, operational engagement of four to six days a month at $8,000–$16,000, and embedded work at $15,000–$25,000. SideChannel, drawing on 200-plus vCISO engagements, publishes $3,000–$12,000 for mid-market and $10,000–$20,000 for regulated environments. Ciphers Security puts the typical mid-market engagement at $5,000–$9,000, which matches where most buyers actually land. PlatOps adds hourly rates of $200–$400 and fixed-scope projects of $10,000–$50,000+, and vCSO.ai’s benchmark of published provider rates shows hourly advisory spanning $175–$600 and fixed-scope projects from $5,000 to $75,000.
One structural variant worth knowing about: Knex publishes component pricing instead of flat tiers — program governance at $3,000–$8,000 a month, a one-time SOC 2 or ISO readiness project at $5,000–$15,000, and quarterly board briefings at $1,500–$4,000. If a provider quotes you à la carte like this, total it up against a flat retainer. Both can be fair; the mistake is comparing one line item against someone else’s bundle.
What companies pay, by size
No source publishes audited pricing by headcount, but the ranges above map onto company size fairly predictably. These bands are synthesized from the published ranges above; treat them as indicative, not gospel.
| Company profile | Typical monthly retainer | Why it sits there |
|---|---|---|
| Under ~100 employees, first security program | $3,000–$6,000 | Advisory-weighted: framework selection, policy set, first SOC 2 push |
| 100–300 employees, enterprise sales motion | $5,000–$9,000 | The most common landing zone: audits, customer security reviews, board reporting |
| 300–500 employees, multiple frameworks | $8,000–$15,000 | Several frameworks in flight, real team to direct, more board work |
| Regulated fintech, crypto, or PCI-scoped | $10,000–$25,000 | Heavier obligations and evidence load; SideChannel’s regulated band, BD Emerson’s embedded tier |
The pattern underneath the table matters more than the bands themselves. Price follows scope, not headcount. A 90-person company that is PCI-scoped and selling into banks will pay more than a 400-person company with a light compliance calendar. When you get a quote that seems out of line with your size, it almost always means the provider is pricing the workload, and the real question is whether that workload estimate is right.
What actually drives the spread
Ciphers Security makes the point that should anchor every conversation you have with a provider: ask exactly how many hours the fee buys and what counts against them. That single number explains most of the price spread.
Beyond hours, four things move a quote:
Compliance load. A retainer that includes active SOC 2 Type II preparation, evidence management, and auditor coordination costs materially more than one where the auditor engagement is already done (see how we manage audit and evidence cycles). The difference is not sophistication, it is hours.
Board and investor reporting. Standing quarterly board briefings, insurance renewal support, and investor-facing risk summaries are real work, and providers price them in. Knex’s component pricing pegs board briefings at $1,500–$4,000 a quarter on their own.
Seniority and delegation. Some firms sell you the senior person’s judgment on the hours you see and delegate the rest to staff. Others put a 25-year practitioner in every seat. Neither model is wrong, but they price differently, and you should know which one you are buying.
Coverage terms. What happens during an incident? Is there a separate incident-response retainer, and does breach support count against your hours or bill separately? This is where the cheapest quote on the table often turns out to be the most expensive.
In my experience the policy documents are rarely what clients are really buying. What they are buying is someone who can stand in front of the board, the auditor, and their biggest customer’s security team and speak credibly to all three — and be reachable when one of those three gets difficult. Providers who structure the engagement around that reality quote more confidently and deliver more consistently.
Fractional vs full-time: the actual math
The full-time comparison people usually make is salary versus retainer, and it flatters the retainer for the wrong reasons. Do the full math.
A full-time mid-market CISO costs $250,000–$700,000 in total compensation in 2026, per KORE1’s salary guide, with cash base of $230,000–$400,000. The top of the market is higher: IANS Research and Artico Search’s 2025 benchmark, covering 566 CISOs surveyed between April and October 2025, put average total compensation at $844,000 in the tech sector and $744,000 in financial services.
Then the parts that don’t show up in the salary line. BD Emerson’s 2026 hiring breakdown counts a retained search fee at 25–30% of first-year compensation ($60,000–$100,000), four to six months of search with the seat empty, and a first-year loaded cost of $310,000–$500,000 once the recruiter fee and vacancy are priced in. One secondary aggregator (StealthAgents — treat as an estimate) puts first-year fully loaded cost for a mid-market hire at $800,000–$1.1M once equity, benefits, and ramp time are counted; KORE1’s stage table points the same direction, with mid-market total comp averaging near $415,000. Equity is the line item most budgeters miss: the same IANS benchmark found 70% of CISOs receive equity, and among top earners it can run to half of total pay.
Against that, even a compliance-heavy fractional engagement at $12,000–$25,000 a month is $144,000–$300,000 a year. This is why KORE1 — a retained search firm, meaning the “competition” for the fractional model — still says fractional beats full-time for companies under a few hundred people. When the search firm tells you not to hire, the answer is usually safe to trust.
Now the part most provider content skips: where it flips. BD Emerson’s breakeven analysis puts the crossover at $180,000–$220,000 of annual fractional spend, roughly 8–12 days a month. Below that, fractional is cheaper and usually better supported, because a fractional firm has depth behind the individual. Above it, you are paying full-time money for part-time presence, and a full-time hire wins. vCSO.ai describes the same wall from the hours side: once sustained need passes roughly 25 hours a month, retainers stop penciling. SideChannel frames the ceiling from the other end — whether the company needs 40 hours a week of security leadership or 10 to 15; most under 1,000 employees don’t.
Two things make that crossover earlier than raw math suggests. First, a full-time hire in a 100–300 person company often can’t fill 40 hours a week with CISO-grade work; Rob Black of Fractional CISO made this point plainly in IT Brew, noting that at roughly 250-person scale a full-time CISO needs a team, frequently treats the seat as an 18-month stepping stone, and there often isn’t 40 hours a week of work for one person. Second, tenure risk is real. IANS and Artico found 15% of CISOs changed employers in 2025, up from 11% in 2024 — the highest mobility in six years. Korn Ferry has long put average CISO tenure at 18–26 months, against roughly 4.9 years for the broader C-suite, and Cybersecurity Ventures reports 24% of Fortune 500 CISOs in the seat for about a year. Those tenure numbers are directional estimates rather than a single audited figure, but the pattern holds across sources. A fractional arrangement, where the firm holds the continuity rather than one individual, is often the more stable leadership structure even before cost enters the picture.
When a fractional CISO is the wrong choice
A credible pricing guide should say this out loud. Hire full-time instead when:
- Your sustained need exceeds roughly 8–12 days a month. If the honest demand forecast is above the BD Emerson crossover of $180,000–$220,000 a year in fractional spend, fractional pricing has stopped working in your favor. Paying fractional rates for what amounts to a full-time presence is the worst of both worlds.
- You are in active incident remediation. Breach response, regulatory notification, and post-incident hardening need someone on site daily. Fractional coverage during an incident is a stopgap, not a plan.
- A regulator or contract requires a named, accountable executive. Some regimes and enterprise contracts expect a designated senior leader with real authority inside the company. A time-shared arrangement can fall short of what the obligation actually contemplates, and “we have a vCISO” is not always an acceptable answer.
- You are building a security team of five or more. At that scale the job is managing people and budget every day. That is a full-time job by definition, and the fractional executive becomes a bottleneck.
Fractional is usually the right call when the driver is episodic or external: a SOC 2 or ISO push, enterprise customers with security questionnaires, a board that wants credible reporting, an insurance renewal, or investor diligence. If those describe your situation and you are under a few hundred people, you are the market this pricing exists for.
Buyer’s checklist: what to ask before signing
Prices differ 5x across providers, and the differences are legitimate only when you know what is underneath them. Before signing any fractional CISO retainer:
- How many hours does the fee buy, and what counts against them? Get it in writing. Per Ciphers Security, this single number explains most of the price spread.
- Who actually does the work? The named senior partner selling the engagement, a rotating bench, or delegated staff? Ask to meet the people who will sit in your board meeting.
- What happens in a breach? Is incident support included, priced separately, or excluded? Is there a response-time commitment?
- Which frameworks have they carried end to end? Not “supported” — carried through audit, evidence collection, and renewal, at companies like yours.
- What are the named deliverables? Board pack, risk register, policy set, audit support, insurance attestation. Vague engagement letters are where fractional relationships go wrong.
- What is the exit and transition terms? Your documentation, your systems, clean handover. Continuity risk should sit with the provider, not you.
- Who is the reference, and how similar is their company? A SaaS company at 200 employees is not a reference for a crypto exchange at 80.
- What does the provider decline to do? Firms that claim to cover everything from kernel forensics to board strategy in one retainer are usually reselling a network you’ll pay for later.
Frequently asked questions
How much does a fractional CISO cost per month? In 2026, most mid-market companies pay $3,000–$12,000 a month, with most engagements landing at $5,000–$9,000. Compliance-heavy programs with active SOC 2, ISO 27001, or PCI work commonly run $12,000–$25,000 a month. These are published market ranges from multiple 2026 provider benchmarks, not audited averages.
What do fractional CISOs charge per hour? Published 2026 hourly rates range from $175 to $600, with most quotes clustering between $250 and $500. Hourly pricing suits short engagements and second opinions; for ongoing leadership, retainers usually cost less per hour of actual work.
How much does a full-time CISO cost compared with a fractional one? A mid-market full-time CISO costs $250,000–$700,000 in total compensation in 2026, and first-year fully loaded cost including search fees, equity, benefits, and ramp time is estimated at $800,000–$1.1M. A typical fractional engagement runs $36,000–$108,000 a year. The crossover where full-time becomes the better spend sits at roughly 8–12 days a month of sustained need.
Is a fractional CISO worth it for a company under 200 people? Usually yes — a position argued even by retained search firms whose business is placing full-time CISOs. At that scale, security leadership needs are often well under full-time, while a full-time hire brings search costs, equity dilution, and tenure risk (CISO turnover reached a six-year high in 2025).
What makes one fractional CISO quote higher than another? Hours included and what counts against them, compliance load (an active audit costs more than a quiet year), board and investor reporting cadence, the seniority of who actually does the work, and incident-response terms. Two identical-looking $5,000 and $15,000 quotes usually differ on three of those five.
When should a company hire a full-time CISO instead? When sustained need exceeds roughly 8–12 days a month, when you are in active incident remediation, when a regulator or major contract requires a designated accountable executive inside the company, or when you are building a security team large enough to need daily management.
What to do next
The pricing above tells you the market. Your number depends on what you need covered: which frameworks, which customers, which board obligations, and how much of it you can do with the team you have.
If you want that translated into a number for your company rather than a range for the market, get a fractional CISO cost estimate for your company — a scoped 20–30 minute engagement-fit call covering pricing band, scope, and whether fractional or full-time fits your stage. Or schedule a consultation and talk through the inputs with us first.
Ron Moore runs NTD Consulting, which provides fractional CISO and cybersecurity advisory services to mid-market SaaS, fintech, and digital-asset companies.
Word count (article body only): 2,465 (verified by script)
Need a second set of eyes before your SOC 2 audit?
NTD Consulting offers a free 30-minute readiness assessment. No pitch, no pressure — just direct feedback on where your program is likely to get pushed back.
Schedule a 30-Minute Consultation