The same three letters cover wildly different purchases. One company buys a few advisory hours a month to sanity-check decisions; another hands over its entire security function — frameworks, audits, questionnaires, incident response. Quoting those the same way would be malpractice, which is why serious providers scope first and price second.
It also means published “average vCISO rates” deserve suspicion. Nobody’s average is your quote, and pages that print one are guessing. The honest way to evaluate pricing is structural: understand what each model includes, where its hidden costs sit, and which one matches the amount of security function you actually need to buy. That’s what the comparison below does — qualitatively, on purpose.
Project-based work is the fourth model — covered separately below, because it isn’t a standing service.
| Hourly | Retainer | Bundled with execution | |
|---|---|---|---|
| What you’re buying | Answers on demand — reviews, opinions, and decisions billed by the clock | A standing slice of a security leader’s calendar every month | Leadership plus the team that executes the roadmap it produces |
| What’s included | Only what you ask for; everything the advice creates stays with your team | Strategy, meetings, and documents; implementation is usually out of scope | Strategy through remediation, evidence, audits, and questionnaires under one agreement |
| Cost predictability | Low — every question, incident, and audit season runs the meter | Moderate — the fee is fixed, but out-of-scope work accumulates beside it | High — one program price that already contains the work |
| Who it fits | A team needing a second opinion or a one-off decision, not a program | Companies with in-house security hands that only lack senior direction | Companies with no security staff that need outcomes, not recommendations |
| Hidden costs | Your engineers’ hours implementing the advice — the invoice nobody prints | The execution gap: findings pile up faster than anyone closes them | Few, if scoped honestly — verify which audits and frameworks the price covers |
The fourth model is the fixed-fee project: a gap assessment, a readiness push before a specific audit, an incident postmortem. Projects price well because the deliverable has edges — you know when it’s done. For a defined artifact with a deadline, this is a perfectly good way to buy.
What a project can’t deliver is standing accountability. Risk doesn’t end when the deliverable ships, audits recur annually, and buyers keep asking questions between assessments. Most companies that shop for “a project” are really at the start of a calendar — which is worth knowing before you pay for the same discovery phase twice.
Agency doesn’t sell vCISO time on a separate meter. The security leader comes built into a managed compliance program: they set the roadmap, and U.S.-based forward-deployed engineers, supercharged by proprietary AI do the work the roadmap creates — controls, evidence, audit management, buyer questionnaires. One scope, one price, no gap between the advice and the doing.
For startups the numbers are published rather than quoted: all-in packages run $2,500 to $12,500 depending on stage and stack — GRC platform, audit, pen test, and the operated program included — against the $25,000–$60,000+ that assembling those pieces separately typically costs. Partner credits (up to $50,000 across the tools in a typical startup stack) offset a real share of year one. Later-stage engagements are scoped to your environment; the drivers below are exactly what the scoping call walks through.
Six drivers explain most of the spread between any two engagements.
Scope, almost entirely: how many frameworks, how many audit windows a year, how much buyer diligence lands per month, and — the big one — whether the provider executes the roadmap or only writes it. The title on the proposal is the same; the amount of security function being purchased isn’t.
Cheapest per invoice, often priciest per outcome. The meter runs on every question, audit season multiplies the hours, and your engineers absorb the implementation the advice generates. Hourly is right for a bounded decision; as a standing program it’s the most expensive model wearing the smallest number.
Usually not — a classic retainer buys leadership: strategy, reviews, meetings, documents. The remediation, evidence collection, and questionnaire grind either lands on your staff or bills separately. Before signing any retainer, ask one question: when the roadmap creates work, whose calendar does it land on?
A near-term audit compresses everything: readiness gaps get fixed on a deadline, evidence has to exist for the whole window, and auditor management becomes a weekly workstream. The calendar is a genuine cost driver, which is also the argument for engaging before the audit is booked rather than after.
Materially. Agency’s startup engagements bundle up to $50,000 in partner credits across the typical stack alongside the published $2,500 to $12,500 packages — so the all-in program can land near what teams expected to spend on software alone. Details live on the startup program page.