Fractional CISO services and vCISO services are, in practice, the same offer sold by two different kinds of company to two different kinds of buyer. That's the honest answer and it's not what either camp's homepage says. MSP Pentesting only sells through partners, so we've quoted the testing line for both kinds of practice, and not one buyer has ever asked which word was on the invoice.
Because your client isn't buying a title.
They're buying a person who will answer for the answer.
Where the two words came from
Fractional is finance vocabulary. It arrived from the fractional CFO and fractional COO world, and it carries that world's assumptions: a real executive, a fraction of their week, a seat on the leadership team, a name on the org chart. Buyers who say fractional CISO are usually picturing one senior human they can call.
vCISO came out of the channel. MSPs, MSSPs and GRC boutiques needed a name for a productized security leadership service, and virtual stuck. Search behavior follows the same split: people looking for vciso companies and virtual ciso companies want a firm with a bench, a methodology and a contract, not one consultant's calendar.
Neither term is protected. Nobody certifies it. There's no registry, no exam and no minimum bar. Which means the words tell you almost nothing about what's behind them, and your client knows that, which is why the first meeting is really an audition.

Those columns are tendencies, not laws. Plenty of MSPs deliver deeply embedded fractional-style leadership. Plenty of solo operators run a sharper methodology than a firm with forty logos. Use the columns to work out which shape the prospect already has in their head, then either match it or correct it early.
| Term the buyer uses | Who usually sells it | What they picture | Where it breaks |
|---|---|---|---|
| Fractional CISO | Independent operator, boutique | A named executive, part time | One calendar, one vacation, no bench |
| vCISO | MSP, MSSP, GRC firm | A service with a process behind it | Generic output if the human is thin |
| CISO as a service | Platform-backed providers | A dashboard plus a person | Tool output mistaken for judgment |
| Security advisor | Anyone hedging on the title | Advice without accountability | Nobody owns the decision |
What clients are actually buying
Strip the naming argument away and every one of these deals comes down to the same five things. Sell those and the acronym stops mattering.
- A name on the answer. Somebody has to sign the security questionnaire, the insurance application and the board slide. Right now that's an owner or an IT manager who is guessing, and they hate it.
- A risk picture they can defend. Not a scan report. An assessment that says what could hurt this business, how likely it is, and what it costs to reduce. Our risk assessment service is what a lot of partners use as the opening artifact.
- A roadmap with dates and dollars. Twelve to eighteen months, sequenced, each item costed. The roadmap is what converts a scared client into a budgeted one.
- Someone in the room. The board meeting. The enterprise client's vendor review. The insurer's call. The auditor's kickoff. Those are the moments your client can't fake internally, and they're what they're really paying to stop dreading.
- Evidence it got done. Not intent, not a policy PDF nobody read. Tickets closed, controls in place, testing performed by somebody who didn't build them.

Notice what isn't on that list. Tooling. Your clients don't buy a vCISO because they want another console. They buy one because there's a decision they can't make and a question they can't answer, and both have a deadline attached.
Three delivery models, three ways it goes wrong
The solo practitioner
Deep, personal, and your client loves them. They also have one calendar. When two clients hit an incident in the same week, one of them waits. When they take three weeks off, the program stops. If you're building this inside an MSP, the failure mode isn't quality, it's the bus factor.
The MSP-embedded vCISO
Best context in the business. You already know their patch posture, their identity mess and which director keeps approving exceptions. The conflict is structural: you're advising on a stack you also sell, and sooner or later the right recommendation costs you managed services revenue.
Handle it in the open. Name the conflict in the engagement letter, and route the assessment work that touches your own delivery to a third party. Clients respect that far more than they respect a pretense.
The platform-backed practice
Consistent, fast to stand up, and it makes junior staff productive. It also produces output that reads identically for every client, and buyers spot that in about two meetings. The platform should carry the paperwork. It can't carry the judgment.
The conflict nobody puts on the slide
Here's the part that decides whether the practice survives its second year.
Whichever word you put on the invoice, the same conflict shows up the second somebody outside the relationship asks for proof. You wrote the policy. You picked the tool. Now you're the one certifying it works, and the person reading the report can see that.
Buyers rarely argue with you about it. They just route the verification work somewhere else, and whoever gets it starts having quarterly conversations with your client.
So keep the testing line, and keep it independent. Our partners hand it to us as white-labeled penetration testing and it goes back out under their own logo.
If you're weighing whether to build the practice at all, the mechanics of staffing, packaging and the first three clients are covered in our guide to launching a virtual CISO practice.
Which clients are ready for this
Not every SMB needs one, and pitching it to a client with no forcing function wastes both your time. Four kinds of client buy this quickly, and you've already got at least two of them in your book.
- The company failing vendor reviews. An enterprise customer sent a 300-question security assessment and the answers are embarrassing. There's revenue at risk and a date on it.
- The compliance deadline. SOC 2, ISO 27001, CMMC, HIPAA. Somebody has to own the program, and the IT manager already has a job.
- The PE-backed portfolio company. The sponsor wants consistent security reporting across ten companies and won't fund ten CISOs. This is the highest-leverage motion in the entire category.
- The client who just got hit. Post-incident, the board asks who's in charge of this. If nobody can answer, they'll buy an answer inside the quarter.
The client with none of those is a maybe, and maybes eat your bench. Qualify on the forcing function, not the headcount.
What the first ninety days should produce
If you can't name the artifacts, you're selling hours. Three deliverables and one meeting cadence is enough to make the first quarter feel like progress.
A current-state assessment against a named framework, so there's a baseline nobody argues with later. A prioritized roadmap with owners, dates and rough cost, because a finding without a date is just an opinion. And a short risk register your client's leadership actually reviews, in their language, not ours.
Then a standing session, monthly or quarterly, in front of the people who fund it. Fractional buyers want that meeting on the calendar before they sign. vCISO buyers want the deliverable list first. Same engagement, two different opening questions, and answering the wrong one loses the deal on the first call.
Questions MSPs ask about fractional CISO work
Is a fractional CISO the same as a vCISO?
Functionally, almost always yes. The difference is packaging and expectation. Fractional implies one named executive embedded part time. vCISO implies a service delivered by a firm. Ask a prospect which picture is in their head before you answer, because correcting it later feels like a bait and switch even when it isn't.
What certifications does the person need?
None are legally required. That said, buyers, insurers and auditors do ask, and a CISSP or CISM shortens the conversation. What actually wins the room is a client reference in the same industry and a roadmap the prospect recognizes as their own situation. Certifications get you shortlisted. Specificity gets you signed.
How many hours a month should the engagement include?
Enough to run a fixed set of deliverables plus one recurring meeting, and not one hour more before you've measured what clients actually consume. Sell deliverables, not availability. Open-ended availability is how these retainers quietly stop making money, usually around month five, and by then the expectation is set.
Does the client care which word we use?
Only in the first meeting, and only because it sets their expectation. Say fractional and they picture a person. Say vCISO and they picture a firm. Match the word to the picture already in their head, then spend the rest of the meeting on the roadmap, which is the thing they actually renew.
What happens when the client wants to hire a real CISO?
Celebrate, then convert. The best outcome is a client who outgrows the retainer and keeps you for testing, assessment and program support. Write the transition into the contract at the start. It removes the client's fear of dependency, and it's the thing that makes a two year engagement possible.
Sell the meeting, not the title
Pick whichever word your market searches for and stop arguing about it. Fractional CISO services and vCISO services describe the same job: judgment, accountability and a plan, delivered by someone who doesn't need a full-time salary to be useful.
Just don't sell judgment and independent verification as one line item. That's two jobs, and the second one has to come from outside.
You don't have to build the testing half yourself. Our partners hand it to us and keep the client. Talk to us about a pentest partnership when you want to see how that split works on a live account.



.avif)
.png)
.png)
.png)

