Hiring a full-time CISO costs between €120,000 and €180,000 a year including employer costs. For most SMEs and mid-sized companies, the role is neither affordable nor necessary. A fractional CISO (or vCISO, virtual Chief Information Security Officer) solves this equation by providing the same level of expertise at the level of involvement you actually need.
Three figures to remember
The market at a glance
€150k
Annual cost of a senior in-house CISO
€90–120k salary + employer costs + training + tools
€1,200 to €1,800
Senior fractional CISO day rate
Depending on experience, industry and region
20 to 50 days/year
Typical volume for an SME with 50–300 employees
Equivalent to €24–90k excl. VAT per year
The right time
From what company size does it make sense?
Size is not the only factor: what matters is the combination of size, industry and regulatory exposure.
Yes
A one-off audit and awareness training are enough. A fractional CISO is not yet a priority.
No
A fractional CISO becomes relevant.
Yes
The fractional CISO sweet spot: flexibility, expertise and compliance.
No
Special case: a tailored audit is recommended.
Yes
Hiring an in-house CISO becomes more cost-effective.
No
A blend of in-house and external support often works well, with a vCISO backing up a junior CISO.
The 4 models
How is a fractional CISO priced?
Most flexible
Day rate
- Rate: €1,000 to €2,000 excl. VAT per senior day
- Volume: 1 to 5 days per month, depending on need
- Best for: getting started, one-off engagements, audits
- Risk: scope can easily drift without clear boundaries
Most predictable
Monthly retainer
- Rate: €1,500 to €6,000 excl. VAT per month
- Volume: fixed allowance of 2 to 8 days
- Best for: continuous oversight, compliance, committee meetings
- Risk: possible underuse in some months
Strongest commitment
Annual retainer
- Rate: €18,000 to €60,000 excl. VAT per year
- Volume: defined programme with quarterly milestones
- Best for: a NIS2 or ISO 27001 roadmap
- Risk: requires a trusted partner
Broadest scope
Full engagement + tooling
- Rate: €40,000 to €150,000 excl. VAT per year
- Volume: CISO + EDR/MDR + awareness training included
- Best for: fully outsourcing the security programme
- Risk: technology lock-in
The decisive calculation
In-house vs fractional: the figures compared
| Cost item | In-house CISO (1 FTE) | Fractional CISO (50 days/year) |
|---|---|---|
| Salary / fees | €90k to €120k | €60k to €90k |
| Employer costs | €40k to €50k | (included) |
| Continuing education | €5k to €10k | (included) |
| Tools, subscriptions | €8k to €15k | partly included |
| Initial recruitment | €15k to €30k (agency) | · |
| Turnover risk (12–18 months) | High for this role | Low |
| Annual total | €140k to €200k | €60k to €90k |
| Availability | 100% of the time | 5% to 20% of the time |
| Cross-industry expertise | Limited to their background | Inherently diverse |
What you are really buying
What a fractional CISO engagement includes
- Strategic oversight: roadmap, prioritisation and quarterly security committee
- Compliance: NIS2, ISO 27001, GDPR or DORA preparation, depending on your industry
- Risk management: analysis, mapping and treatment plan
- Information security policy: drafting, updates and operational implementation
- Awareness: annual programme, simulations and metrics
- Incident response: crisis leadership and forensic and legal coordination
- Audits and controls: preparation, client security questionnaires and supplier audits
- Regulatory and technology monitoring tailored to your industry
How to decide
3 steps to define your requirements
Step 1
30-minute self-assessment
Rate your current maturity in governance, technology and compliance on a scale from 0 to 3.
Step 2
Target capacity
Estimate the number of days needed each year: from 12 days for light compliance support to 60 days for a NIS2 + ISO roadmap.
Step 3
Choose the model
Start with a 6-month monthly retainer, then move to an annual retainer that structures the programme once the roadmap is set.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call