CISOvCISOSMEs

Fractional CISO: cost and company size

In-house or fractional CISO? At what company size? For what annual budget? A detailed breakdown with figures for the market's 4 pricing models.

Hakim Djelili6 min read

Hiring a full-time CISO costs between €120,000 and €180,000 a year including employer costs. For most SMEs and mid-sized companies, the role is neither affordable nor necessary. A fractional CISO (or vCISO, virtual Chief Information Security Officer) solves this equation by providing the same level of expertise at the level of involvement you actually need.

Three figures to remember

The market at a glance

€150k

Annual cost of a senior in-house CISO

€90–120k salary + employer costs + training + tools

€1,200 to €1,800

Senior fractional CISO day rate

Depending on experience, industry and region

20 to 50 days/year

Typical volume for an SME with 50–300 employees

Equivalent to €24–90k excl. VAT per year

The right time

From what company size does it make sense?

Size is not the only factor: what matters is the combination of size, industry and regulatory exposure.

1Do you have fewer than 30 employees and no identified regulatory requirements such as NIS2, ISO, HDS or DORA?

Yes

A one-off audit and awareness training are enough. A fractional CISO is not yet a priority.

No

A fractional CISO becomes relevant.

2Do you have between 30 and 500 employees OR face a regulatory requirement?

Yes

The fractional CISO sweet spot: flexibility, expertise and compliance.

No

Special case: a tailored audit is recommended.

3Do you have more than 500 employees and a structured IT team?

Yes

Hiring an in-house CISO becomes more cost-effective.

No

A blend of in-house and external support often works well, with a vCISO backing up a junior CISO.

The 4 models

How is a fractional CISO priced?

Most flexible

Day rate

  • Rate: €1,000 to €2,000 excl. VAT per senior day
  • Volume: 1 to 5 days per month, depending on need
  • Best for: getting started, one-off engagements, audits
  • Risk: scope can easily drift without clear boundaries

Most predictable

Monthly retainer

  • Rate: €1,500 to €6,000 excl. VAT per month
  • Volume: fixed allowance of 2 to 8 days
  • Best for: continuous oversight, compliance, committee meetings
  • Risk: possible underuse in some months

Strongest commitment

Annual retainer

  • Rate: €18,000 to €60,000 excl. VAT per year
  • Volume: defined programme with quarterly milestones
  • Best for: a NIS2 or ISO 27001 roadmap
  • Risk: requires a trusted partner

Broadest scope

Full engagement + tooling

  • Rate: €40,000 to €150,000 excl. VAT per year
  • Volume: CISO + EDR/MDR + awareness training included
  • Best for: fully outsourcing the security programme
  • Risk: technology lock-in

The decisive calculation

In-house vs fractional: the figures compared

Cost itemIn-house CISO (1 FTE)Fractional CISO (50 days/year)
Salary / fees€90k to €120k€60k to €90k
Employer costs€40k to €50k(included)
Continuing education€5k to €10k(included)
Tools, subscriptions€8k to €15kpartly included
Initial recruitment€15k to €30k (agency)·
Turnover risk (12–18 months)High for this roleLow
Annual total€140k to €200k€60k to €90k
Availability100% of the time5% to 20% of the time
Cross-industry expertiseLimited to their backgroundInherently diverse

What you are really buying

What a fractional CISO engagement includes

  • Strategic oversight: roadmap, prioritisation and quarterly security committee
  • Compliance: NIS2, ISO 27001, GDPR or DORA preparation, depending on your industry
  • Risk management: analysis, mapping and treatment plan
  • Information security policy: drafting, updates and operational implementation
  • Awareness: annual programme, simulations and metrics
  • Incident response: crisis leadership and forensic and legal coordination
  • Audits and controls: preparation, client security questionnaires and supplier audits
  • Regulatory and technology monitoring tailored to your industry

How to decide

3 steps to define your requirements

  1. Step 1

    30-minute self-assessment

    Rate your current maturity in governance, technology and compliance on a scale from 0 to 3.

  2. Step 2

    Target capacity

    Estimate the number of days needed each year: from 12 days for light compliance support to 60 days for a NIS2 + ISO roadmap.

  3. Step 3

    Choose the model

    Start with a 6-month monthly retainer, then move to an annual retainer that structures the programme once the roadmap is set.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call