vCISO Pricing: Packaging a Retainer That Holds Margin

Cost the testing line before you quote the retainer.
Get a Pentest Quote
vCISO Pricing That Holds title card with a card icon in the MSP Pentesting brand style.

vCISO pricing breaks in a predictable, arithmetic way. You sold sixteen hours a month. The client consumed twenty-six. Your effective hourly rate just dropped by about 38 percent and nobody invoiced the difference, because there wasn't anything in the agreement to invoice against. MSP Pentesting sells through partners only, and when one of them reprices a retainer we're usually the line item they forgot to move.

Nobody loses this money in month one.

They lose it in month five, quietly, and they find out at renewal when somebody finally adds it up.

Price the capacity, not the availability

The single most expensive mistake in this category is selling access to a person instead of a defined set of outputs and a bounded amount of time.

Availability has no ceiling. Deliverables do. "Unlimited" and "as needed" are the two costliest phrases in a security retainer, and they usually get added late in a negotiation by somebody trying to close.

So write the package as a list of things that get produced and a band of hours that produces them. A quarterly risk review. A maintained policy set. A roadmap that gets updated. One standing leadership meeting. A named contact with a response commitment. That's a product. "Our vCISO is available to you" isn't a product. It's a liability with a monthly fee attached.

Five ways to bill it, and where each one leaks

ModelHow it billsWhere the margin leaksBest fit
HourlyTime and materialsClient rations hours, you carry no recurring baseShort remediation projects
Retainer with capped hoursFixed fee, hour band, overage rateThe cap gets tracked and never enforcedMost ongoing SMB programs
Deliverable packageFixed fee per named outputCreep inside a deliverable nobody scoped tightlyCompliance-driven clients
Per seat or per endpointScales with client sizeEffort doesn't track headcount at allBolting onto an existing MSP agreement
Annual program feeFixed annual, quarterly milestonesEffort front-loads, cash arrives evenlyClients in an audit year

Per-seat deserves a warning, because it's tempting for MSPs who already bill that way. A forty-seat manufacturer with an on-prem ERP, an OT segment and a demanding insurer is more work than a three-hundred-seat professional services firm that lives entirely in one cloud suite. Seat count doesn't measure security effort. It measures how easy the invoice is to explain, which isn't the same thing.

Chart of what belongs in a vCISO retainer. In the retainer: quarterly risk review, policy set and updates, roadmap and budget input, one standing leadership call, a named point of contact. Priced separately: penetration testing, audit fieldwork support, incident response hours, questionnaire surges, onsite visits and travel.

Four things that belong outside the retainer

This is where most of the recoverable margin is hiding.

  1. Penetration testing and independent assessment. Two separate reasons. It's a real hard cost with a subcontract behind it, and it's got to be independent of the advisory work or an insurer and an auditor will both discount it. Bundling burns your margin and your credibility in one move.
  2. Audit fieldwork support. Evidence collection during an active audit is a spike, not a steady state. Price it as a project attached to the audit, with its own start and end.
  3. Incident response hours. After-hours work, forensics, breach counsel coordination, notification decisions. If those hours come out of the same bucket as the quarterly risk review, one bad week erases the year.
  4. Questionnaire surges. One enterprise customer sending a 300-question security assessment can consume a quarter of capacity for a small client. Include one or two a year in the package and meter the rest.

Onsite visits and travel belong on that list too. They're the easiest thing to give away in a sales meeting and the hardest to claw back later.

The arithmetic that decides whether this works

Four numbers run the entire practice, and most people only track two.

  • The fully loaded cost of a delivery hour, including the senior time you'll actually need, not the junior time you hope to use.
  • The hours the package promises.
  • The hours the client actually consumes.
  • The number of clients one practitioner can hold before quality drops.

Gross margin on the engagement is the fee minus consumed hours times loaded cost, divided by the fee. Simple enough. What people miss is the sensitivity, and it's unforgiving. If you priced a package on sixteen hours and the client runs twenty-four, you didn't lose a third of your margin, you lost half the gap between your fee and your cost, which on a typical retainer is most of the profit.

Track consumed hours per client per month from the first invoice. Don't average it across the book, because the average is comforting and it's a lie. One client at three times the promised hours can erase the margin on four healthy ones, and the blended number will still look fine right up until somebody asks why the practice isn't throwing off cash.

Then set a hard cap on clients per practitioner and refuse to sell past it. Capacity you've oversold shows up as missed meetings, recycled deliverables and a churned client, which costs far more than the deal you turned down.

Five-step diagram for building a vCISO retainer that holds margin: fix the deliverables, cap the hours, price the capacity, meter the overage, and review the margin.

Meter the overage or don't cap it at all

A cap you never enforce is worse than no cap. It sets an expectation you've now proven you won't defend, and resetting it later feels to the client like a price rise for nothing.

Here's the mechanic that works. Report consumption every month alongside the invoice, in the same email, whether or not there's anything to bill. Show the number when it's under the band too. Once the number is routine, the month it goes over isn't a confrontation, it's just the next line in a report they already read.

Add a soft threshold around 80 percent of the band that triggers a conversation rather than a surprise. And set the overage rate above your blended rate deliberately. Overage isn't a product you want to sell, it's a pressure valve, and pricing it like a bargain guarantees you'll be running it every month.

The tooling line nobody budgets for

vCISO software and vCISO platform tools have gotten genuinely good. They generate policy sets, track control status, run assessments against a framework and produce a client-facing dashboard that makes the program feel real between meetings.

Two things you've got to get right in the model. Most are licensed per client, so the cost lands whether or not that client is profitable, which means it belongs in cost of goods and not in overhead. And a platform makes junior staff productive without reducing the senior hours the client actually values. Model it as a quality and consistency gain, not as a labor saving, or you'll price on savings that never arrive.

Raising the price on a client you already have

Do it at renewal, with 60 to 90 days of notice, and never as a bare increase. Tie it to two things: documented consumption, which you've got because you've been reporting it monthly, and something added to the package. A new deliverable, a broader framework, an extra review cycle.

Clients accept increases attached to scope. They resist increases attached to nothing, and they're right to. The ones who resist loudest are usually the over-consumers, which tells you exactly who needed repricing.

Questions MSPs ask when they reprice a retainer

What should be included in a vCISO retainer?

A recurring risk review, a maintained policy and standards set, a roadmap that gets updated, one standing leadership meeting, and a named contact with a defined response time. Everything episodic, meaning testing, audit support, incident work and questionnaire surges, sits outside on its own line.

Is a flat monthly fee better than hourly?

For an ongoing program, yes. Hourly billing teaches the client to ration contact, which is the opposite of what a security program needs, and it gives you no predictable base to staff against. Keep hourly for defined projects and keep the program on a retainer.

How does vCISO cost change with client size?

Less than people expect, and not linearly. Regulatory scope, the number of frameworks in play, how many third parties they answer to, and whether leadership actually engages drive far more effort than headcount. Price against those factors and you'll be right more often than you will pricing per seat.

Should the penetration test be bundled into the retainer?

No. It's a hard cost that varies with scope, and independence matters to the people reading the report. Quote it separately, mark it up if your agreement allows, and keep the advisory and the testing in different hands. That's the model our partners run with white-labeled penetration testing behind the practice.

How many clients can one vCISO carry?

It depends on package depth and how much of the production work a platform or a junior analyst absorbs. Set the number from your own measured consumption after two quarters rather than copying somebody's benchmark, then treat it as a hard ceiling. Everyone who's ignored their own number has regretted it.

Reprice the capacity, then the client

vCISO pricing isn't really a pricing problem. It's a scope-definition problem that's wearing a pricing problem's clothes. Define the outputs, bound the hours, put the episodic work on separate lines, and report consumption every single month so the numbers stay boring.

Do that and the retainer holds margin for years. Skip it and you'll be doing CISO work at helpdesk economics without ever quite noticing when it started.

Standing the practice up rather than repricing one? Start with our guide to launching a virtual CISO practice. Then get a pentest partnership in place, so the testing line is costed before you quote it.

Author

Connor Cady

Founder

Connor founded MSP Pentesting after working in the pentest industry and seeing a massive gap in the market. MSPs were being forced to choose between overpriced corporate firms and shady, automated scanners that auditors hate. He built this company to solve that "sticker shock" and give the channel a partner that prioritizes their margins and client relationships.

Join our MSP Partner Program

Want reseller pricing, sample reports, and partner resources?
Book a call with our team to get access.