Because “vCISO” names a title, not a quantity. One buyer wants a monthly sanity check on security decisions; another wants an entire security function carried — frameworks, audits, buyer reviews, incident readiness. Any market average flattens those into one meaningless figure, which is why credible providers ask about scope before they talk price, and why rate cards found online say more about the marketer than the market.
The four models buy different things. Hourly buys answers and bills every question. A retainer buys a fixed slice of a leader’s month — strategy and meetings, with implementation usually excluded. Project pricing buys a bounded deliverable, like a gap assessment. Bundled pricing buys the leader and the execution team together, so the roadmap and the work it creates sit under one price. The cheapest-looking model and the cheapest total are rarely the same one.
Agency only sells the bundled shape: vCISO leadership built into a managed compliance program, with engineers doing the recurring work under the same agreement. For startups there is no quoting step at all — published packages span $2,500 to $12,500 depending on stage, with the GRC platform, audit, pen test, and operated program inside that number. The full breakdown — each model’s hidden costs, plus the six drivers behind any quote — is on the vCISO pricing page.
Five inputs move the number: which frameworks and how many, your audit date if one is booked, how much buyer diligence lands per month, the rough shape of your environment — cloud accounts, headcount, vendor count — and whether you want execution included. With those, a real quote takes one call.
Check what happens after the advice. Low headline prices usually scope out the doing — remediation, evidence, questionnaires — which lands back on your engineers and re-enters the budget as lost roadmap. Compare total cost to outcome, not monthly fee to monthly fee.