Fractional CISO Services vs vCISO: What Clients Are Actually Buying

Need independent testing behind your fractional CISO or vCISO engagements?
Get a Pentest Quote
Fractional CISO vs vCISO title card with a star icon in the MSP Pentesting brand style.

Fractional CISO services and vCISO services are, in practice, the same offer sold by two different kinds of company to two different kinds of buyer. That's the honest answer and it's not what either camp's homepage says. MSP Pentesting only sells through partners, so we've quoted the testing line for both kinds of practice, and not one buyer has ever asked which word was on the invoice.

Because your client isn't buying a title.

They're buying a person who will answer for the answer.

Where the two words came from

Fractional is finance vocabulary. It arrived from the fractional CFO and fractional COO world, and it carries that world's assumptions: a real executive, a fraction of their week, a seat on the leadership team, a name on the org chart. Buyers who say fractional CISO are usually picturing one senior human they can call.

vCISO came out of the channel. MSPs, MSSPs and GRC boutiques needed a name for a productized security leadership service, and virtual stuck. Search behavior follows the same split: people looking for vciso companies and virtual ciso companies want a firm with a bench, a methodology and a contract, not one consultant's calendar.

Neither term is protected. Nobody certifies it. There's no registry, no exam and no minimum bar. Which means the words tell you almost nothing about what's behind them, and your client knows that, which is why the first meeting is really an audition.

Fractional CISO or vCISO comparison chart. The left column lists fractional CISO traits: one named executive, embedded in the org chart, board and investor facing, priced like a part-time hire, scales with that one person. The right column lists vCISO service traits: a team behind a method, sits outside the org chart, auditor and client facing, priced like a service, scales with your bench.

Those columns are tendencies, not laws. Plenty of MSPs deliver deeply embedded fractional-style leadership. Plenty of solo operators run a sharper methodology than a firm with forty logos. Use the columns to work out which shape the prospect already has in their head, then either match it or correct it early.

Term the buyer usesWho usually sells itWhat they pictureWhere it breaks
Fractional CISOIndependent operator, boutiqueA named executive, part timeOne calendar, one vacation, no bench
vCISOMSP, MSSP, GRC firmA service with a process behind itGeneric output if the human is thin
CISO as a servicePlatform-backed providersA dashboard plus a personTool output mistaken for judgment
Security advisorAnyone hedging on the titleAdvice without accountabilityNobody owns the decision

What clients are actually buying

Strip the naming argument away and every one of these deals comes down to the same five things. Sell those and the acronym stops mattering.

  1. A name on the answer. Somebody has to sign the security questionnaire, the insurance application and the board slide. Right now that's an owner or an IT manager who is guessing, and they hate it.
  2. A risk picture they can defend. Not a scan report. An assessment that says what could hurt this business, how likely it is, and what it costs to reduce. Our risk assessment service is what a lot of partners use as the opening artifact.
  3. A roadmap with dates and dollars. Twelve to eighteen months, sequenced, each item costed. The roadmap is what converts a scared client into a budgeted one.
  4. Someone in the room. The board meeting. The enterprise client's vendor review. The insurer's call. The auditor's kickoff. Those are the moments your client can't fake internally, and they're what they're really paying to stop dreading.
  5. Evidence it got done. Not intent, not a policy PDF nobody read. Tickets closed, controls in place, testing performed by somebody who didn't build them.
Five-step diagram of what a client is actually buying from a fractional CISO or vCISO: a name on the answer, a defensible risk picture, a roadmap with dates, someone in the room, and proof it got done.

Notice what isn't on that list. Tooling. Your clients don't buy a vCISO because they want another console. They buy one because there's a decision they can't make and a question they can't answer, and both have a deadline attached.

Three delivery models, three ways it goes wrong

The solo practitioner

Deep, personal, and your client loves them. They also have one calendar. When two clients hit an incident in the same week, one of them waits. When they take three weeks off, the program stops. If you're building this inside an MSP, the failure mode isn't quality, it's the bus factor.

The MSP-embedded vCISO

Best context in the business. You already know their patch posture, their identity mess and which director keeps approving exceptions. The conflict is structural: you're advising on a stack you also sell, and sooner or later the right recommendation costs you managed services revenue.

Handle it in the open. Name the conflict in the engagement letter, and route the assessment work that touches your own delivery to a third party. Clients respect that far more than they respect a pretense.

The platform-backed practice

Consistent, fast to stand up, and it makes junior staff productive. It also produces output that reads identically for every client, and buyers spot that in about two meetings. The platform should carry the paperwork. It can't carry the judgment.

The conflict nobody puts on the slide

Here's the part that decides whether the practice survives its second year.

Whichever word you put on the invoice, the same conflict shows up the second somebody outside the relationship asks for proof. You wrote the policy. You picked the tool. Now you're the one certifying it works, and the person reading the report can see that.

Buyers rarely argue with you about it. They just route the verification work somewhere else, and whoever gets it starts having quarterly conversations with your client.

So keep the testing line, and keep it independent. Our partners hand it to us as white-labeled penetration testing and it goes back out under their own logo.

If you're weighing whether to build the practice at all, the mechanics of staffing, packaging and the first three clients are covered in our guide to launching a virtual CISO practice.

Which clients are ready for this

Not every SMB needs one, and pitching it to a client with no forcing function wastes both your time. Four kinds of client buy this quickly, and you've already got at least two of them in your book.

  • The company failing vendor reviews. An enterprise customer sent a 300-question security assessment and the answers are embarrassing. There's revenue at risk and a date on it.
  • The compliance deadline. SOC 2, ISO 27001, CMMC, HIPAA. Somebody has to own the program, and the IT manager already has a job.
  • The PE-backed portfolio company. The sponsor wants consistent security reporting across ten companies and won't fund ten CISOs. This is the highest-leverage motion in the entire category.
  • The client who just got hit. Post-incident, the board asks who's in charge of this. If nobody can answer, they'll buy an answer inside the quarter.

The client with none of those is a maybe, and maybes eat your bench. Qualify on the forcing function, not the headcount.

What the first ninety days should produce

If you can't name the artifacts, you're selling hours. Three deliverables and one meeting cadence is enough to make the first quarter feel like progress.

A current-state assessment against a named framework, so there's a baseline nobody argues with later. A prioritized roadmap with owners, dates and rough cost, because a finding without a date is just an opinion. And a short risk register your client's leadership actually reviews, in their language, not ours.

Then a standing session, monthly or quarterly, in front of the people who fund it. Fractional buyers want that meeting on the calendar before they sign. vCISO buyers want the deliverable list first. Same engagement, two different opening questions, and answering the wrong one loses the deal on the first call.

Questions MSPs ask about fractional CISO work

Is a fractional CISO the same as a vCISO?

Functionally, almost always yes. The difference is packaging and expectation. Fractional implies one named executive embedded part time. vCISO implies a service delivered by a firm. Ask a prospect which picture is in their head before you answer, because correcting it later feels like a bait and switch even when it isn't.

What certifications does the person need?

None are legally required. That said, buyers, insurers and auditors do ask, and a CISSP or CISM shortens the conversation. What actually wins the room is a client reference in the same industry and a roadmap the prospect recognizes as their own situation. Certifications get you shortlisted. Specificity gets you signed.

How many hours a month should the engagement include?

Enough to run a fixed set of deliverables plus one recurring meeting, and not one hour more before you've measured what clients actually consume. Sell deliverables, not availability. Open-ended availability is how these retainers quietly stop making money, usually around month five, and by then the expectation is set.

Does the client care which word we use?

Only in the first meeting, and only because it sets their expectation. Say fractional and they picture a person. Say vCISO and they picture a firm. Match the word to the picture already in their head, then spend the rest of the meeting on the roadmap, which is the thing they actually renew.

What happens when the client wants to hire a real CISO?

Celebrate, then convert. The best outcome is a client who outgrows the retainer and keeps you for testing, assessment and program support. Write the transition into the contract at the start. It removes the client's fear of dependency, and it's the thing that makes a two year engagement possible.

Sell the meeting, not the title

Pick whichever word your market searches for and stop arguing about it. Fractional CISO services and vCISO services describe the same job: judgment, accountability and a plan, delivered by someone who doesn't need a full-time salary to be useful.

Just don't sell judgment and independent verification as one line item. That's two jobs, and the second one has to come from outside.

You don't have to build the testing half yourself. Our partners hand it to us and keep the client. Talk to us about a pentest partnership when you want to see how that split works on a live account.

Author

Connor Cady

Founder

Connor founded MSP Pentesting after working in the pentest industry and seeing a massive gap in the market. MSPs were being forced to choose between overpriced corporate firms and shady, automated scanners that auditors hate. He built this company to solve that "sticker shock" and give the channel a partner that prioritizes their margins and client relationships.

Join our MSP Partner Program

Want reseller pricing, sample reports, and partner resources?
Book a call with our team to get access.