Which vCISO provider is right for your company?

Key takeaways

  • Providers of an outsourced CISO mandate fall into four models: an independent consultant or law firm holding the named officer role, a specialist consultancy on a vCISO retainer, a managed security provider offering vCISO as an add-on, and a European compliance platform with named certified experts.
  • The decision turns on one question: is the provider selling the named officer role or the steering function? The officer role holds the appointment and keeps documentation current. The CISO mandate owns security strategy, risk prioritisation and budget toward the board. The price gap between those two scopes is wider than the price gap between providers.
  • Published monthly retainers run from roughly 275 to 8,500 EUR in Germany and 2,000 to 5,000 EUR in France, with day rates of 800 to 1,500 EUR (figures collected August 2026). Only a small share of the market publishes prices at all.
  • Software alone cannot hold the mandate. Implementing Regulation (EU) 2024/2690, Annex point 1.2.3, requires at least one person directly answerable to the management bodies for network and information system security, and it applies directly across the EU.
  • Kertos sits in the fourth model. The AI agent KAIA works as the virtual CISO day to day, and a named certified expert from the Kertos team takes the mandate, the reporting and the audit work. Hosting and jurisdiction stay in Europe.

What a proposal costs per month is the last question in this selection, not the first. Two offers 3,000 EUR apart routinely describe two different products in this market. The sections below set out the models, the criteria the decision actually turns on, and when an internal hire beats any of them.

Which provider models exist for an outsourced CISO mandate?

Independent consultant or law firm holding the officer role. One person holds the named security officer role, keeps documentation current and reports at fixed intervals. Billing is a small retainer or hourly. The operational ISMS work stays largely with your team.

Specialist consultancy on a vCISO retainer. The focus is the steering function: security strategy, risk prioritisation, board reporting. You buy consultant days, not an outcome. Check how many days the retainer actually contains, because that is where the market's price spread comes from.

Managed security provider with vCISO as an add-on. The core product is technical operations, meaning monitoring, detection and response. The CISO service sits on top of a security product. This works when you want to outsource operations anyway, and works less well when your real need is governance, evidence and audit readiness.

European compliance platform with named certified experts. Software and mandate come from one provider. Evidence is produced continuously in the system that also holds risks, controls, policies and vendors, and a named expert takes the steering, the reporting and the audit support.

A terminology note, because it causes real confusion in cross-border buying. English-speaking markets say vCISO, virtual CISO, fractional CISO or CISO as a Service. The German market sells the same work as externer CISO and, for the narrower officer role, externer Informationssicherheitsbeauftragter (ISB). French providers say RSSI externalisé. The words differ, the two underlying scopes do not.

How do you tell which provider model fits you?

By eight criteria that rarely appear in a proposal comparison, although they determine the effort of your first year.

CriterionIndependent consultant or law firmConsultancy on a vCISO retainerManaged security providerEuropean platform with named experts
What is being soldthe named officer rolethe steering functiontechnical operations, CISO work as an add-onmandate and evidence production in one scope
Who is namedthe engaged persona consultant of the firm, changing in daily workdepends on the contract, often nobody by namea named certified expert of the provider
Documentation and evidenceproduced by you, reviewed by themtemplates and review, upkeep stays with youstrong on technical evidence, thin on organisationalproduced in the system, assessed by the expert
Audits and customer security questionnairesstrong on substance, evidence has to be assembledcovered in the retainer, evidence depends on your upkeepusually not in the standard scope, check the proposalevidence already in place, the named expert leads
Response time and coverone person, absence is a riskcover arranged in house, fix response time in the contractSLA for operations, written opinions billed separatelycover within the expert team, one fixed contact
Billingretainer with an hour allowance, or time and materialsretainer by consultant dayslicence plus a consulting componentmandate and platform in one scope, extras clearly bounded
Where the data sitswith the consultant, often email and cloud folderswith the provider, tooling differs per engagementin the security product, check the parent companyEuropean hosting, European entity and jurisdiction
Typical monthly priceroughly 275 to 2,500 EURroughly 2,000 to 8,500 EURmostly on requestplatform and mandate quoted together by scope

Four questions separate proposals faster than any price comparison. Is the provider selling the officer role or the steering function? Is documentation produced for you or only reviewed? Who is named, and how is cover arranged when that person is unavailable? What happens during an audit or an incident, and is that inside the retainer or billed by effort?

For the last question, German practice supplies a contract checklist that travels well. The BSI IT-Grundschutz baseline requirement ISMS.1.A5 (Edition 2023) demands three things from a contract with an external security officer: the officer's full task scope together with the associated rights and duties, a suitable confidentiality agreement, and a controlled termination including handover of the tasks to the client. Those three belong in any such contract, in any jurisdiction.

What does an outsourced CISO mandate cost?

Published retainers run from roughly 275 to 8,500 EUR per month depending on scope and country. The figures below come from providers' own public pages and from salary databases, collected in August 2026. Both markets are shown, because published rates differ and a single range would flatten that.

Cost blockGermanyFrance
Officer role, flat monthly retainerroughly 275 to 2,500 EUR, usually 4 to 16 hours per monthroughly 2,000 to 4,000 EUR published, 2,000 to 5,000 EUR quoted as indicative
vCISO retainer, steering functionroughly 3,600 to 8,500 EUR for 2 to 6 consultant daysroughly 4,000 EUR at 4 days per month, about 48,000 EUR per year
Provider day ratederived from retainers, roughly 1,200 to 1,700 EUR800 to 1,500 EUR published
Provider hourly rate159 to 350 EUR550 EUR day rate for emergency response
Freelance hourly rateroughly 106 EUR for information security (freelancermap, 3,114 profiles)not separately published in the sources checked
Independent day-rate anchor1,300 EUR average, 1,600 EUR at partner level (BDU, Honorare im Consulting 2025, published 15 December 2025)not available from a non-vendor source
Internal hire, gross annualmedian 61,100 EUR for a security officer, 83,000 EUR for a CISO (StepStone, 2026)median 76,758 EUR, range 52,500 to 101,000 EUR (Hays, 2026)

Two notes on reading this. The BDU survey does not break out information security, so it anchors a day rate without being a security benchmark. And only a small share of either market publishes prices at all, so anyone comparing only the published ones is looking at a self-selected sample rather than a market. Get at least one proposal from the half that quotes on request. The equivalent breakdown for the data protection role is in our overview of what an external DPO costs.

Do you have to fill the role at all, and does an outsourced mandate satisfy it?

No general legal duty to appoint a CISO exists in EU law or in German or French national law. The duty arrives through the framework that applies to you.

FrameworkWhat is requiredOutsourced mandate permitted
Implementing Regulation (EU) 2024/2690, Annex point 1.2.3at least one person must be directly responsible to the management bodies for network and information system securityyes, a named person is required, not an employee
ISO/IEC 27001:2022, clause 5.3 and Annex A 5.2information security roles and responsibilities must be assigned and communicatedyes, an audit tests the assignment and its effectiveness, not employment status
NIS2 as transposed in Germany: BSIG, section 30(2) and section 38(1) and (2)ten risk management measures, no role named; management itself must implement and monitor, with internal liability toward the entityyes, but ultimate responsibility stays with the management body
BSI IT-Grundschutz, ISMS.1.A4 and ISMS.1.A5 (Edition 2023)management must appoint a security officer; A5 requires appointing an external one where the role cannot be filled internallyyes, expressly provided for and mandatory where no internal appointment is possible
FranceNIS2 is not yet transposed, so no national obligation applies (checked 10 August 2026)the Implementing Regulation still applies directly

The first row is the one that matters for European SaaS and cloud companies. Implementing Regulation (EU) 2024/2690 is a regulation, so it applies directly without national transposition, and Article 1 lists DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms and trust service providers. For those entity types there effectively is a named security person requirement across the EU, including in member states that have not yet transposed NIS2. The German wording was checked on EUR-Lex on 28 August 2026.

One misconception belongs corrected here, because it appears in proposals. An outsourced mandate does not transfer legal responsibility. Under BSIG section 38(1) the management body must implement and monitor the measures itself, and it stays ultimately responsible even when it uses external help. What transfers is the performance of the tasks, plus the provider's contractual commitment to the outcome. A provider promising to assume your liability is describing the law incorrectly. How role, evidence and testing fit together under NIS2 is covered in our guide to preparing for NIS2.

Does "vCISO" mean a person or a piece of software?

Both, and that is the problem. The same three letters are sold as two different products, and proposals rarely say which one you are getting.

One is a human on a part-time mandate, called virtual only because the work is remote. The other is a software product, increasingly AI-driven, that maintains risks, tracks controls, produces evidence and flags gaps. Both are useful. They answer different questions.

The software does the continuous work at a speed manual effort cannot match, because integrations pull the actual state out of your systems and drift shows up immediately rather than during audit preparation. What it cannot do is carry the responsibility toward the management bodies that Annex point 1.2.3 of Implementing Regulation (EU) 2024/2690 describes, or sign the written opinion an auditor or an enterprise customer asks for.

So for any proposal with vCISO in the name, ask about both. Which system maintains the evidence, and who is the person named when it matters and signing when it counts? Proposals that deliver only one of the two are not bad, they are incomplete, and the missing half lands on your team. Which software runs under a mandate is compared in our overview of choosing the right ISMS software.

When is an internal hire the better choice?

In three situations. First, when security decisions arise daily inside the product or engineering process and scheduled availability is too slow. Second, when the business model is itself security critical, such as critical infrastructure or running your own data centres, because the role is then a full-time job. Third, when large customers or investors explicitly require an internally staffed function, which is a contractual requirement rather than a technical one.

CriterionOutsourced mandateInternal hire
Time to being operationaltwo to six weeks to mandate start45 percent of European organisations take three to six months to fill even an entry level security role (ISACA, State of Cybersecurity 2025, n = 740)
Annual costroughly 3,300 to 102,000 EUR depending on scope and hoursgross median 61,100 EUR for a security officer and 83,000 EUR for a CISO in Germany, 76,758 EUR for a RSSI in France, plus employer costs, training and certifications
Available experiencea cross-section of several mandates and industriesone career history; specialist knowledge is bought in
Presence in daily workscheduled; short questions need a defined channelavailable daily, close to product and engineering decisions
Cover during absencearranged within the team depending on the model, fix it in the contractabsence removes the function entirely

In practice the sequence is often mixed. An outsourced mandate builds the ISMS and carries the first certification, then an internal hire takes over operations while the provider stays for audits, incidents and the annual review. If that is your plan, put the orderly handover in the contract from the start.

Where does Kertos fit in this comparison?

In the fourth model, with two layers. The AI agent KAIA works as the virtual CISO day to day: it maintains risks, controls, policies and evidence across more than 100 integrations, answers technical questions in the context of your own data, and surfaces what is missing before an auditor asks. On the second layer, a named certified expert from the Kertos team takes the mandate: security strategy, risk prioritisation, board reporting, and support through audits and incidents. The certifications are spread across the team; not every person holds every one.

Covered frameworks are ISO 27001, ISO 27701, ISO 42001, GDPR, NIS2, the EU AI Act, SOC 2, TISAX and C5, in one system rather than as separate projects. The platform and the company are European, hosting sits on European infrastructure, and jurisdiction stays within the European legal area. That is the difference between data residency and data sovereignty: a server location in the EU says nothing about which law the parent company is subject to.

Results from the model: a 100 percent pass rate in supported audits, roughly 80 percent less manual effort, 98 percent customer satisfaction and up to 60 percent lower cost than traditional consulting. AskUI reached ISO 27001 certification in 8 to 10 weeks without bringing in external consultants.

Frequently asked questions

What does a virtual CISO actually do?

A vCISO runs information security on a mandate basis, with steering rather than technical operations as the core of the role. Six blocks of work are typical: security strategy and roadmap; risk management; building and running the ISMS under ISO/IEC 27001 or BSI IT-Grundschutz; translating regulatory requirements from NIS2, TISAX, SOC 2 or the C5 attestation into concrete controls; reporting to the board; and support through audits, customer security questionnaires and security incidents.

What is the difference between a vCISO, a fractional CISO and CISO as a Service?

In practice the three terms describe the same delivery model and are used interchangeably by providers. The distinction that does carry meaning is scope, not label: an engagement holding the named officer role and keeping documentation current is a different product from one owning strategy, risk and budget toward the board. That is what explains a monthly price range from a few hundred to several thousand euros. Ask which of the two a proposal covers.

How quickly can an outsourced CISO mandate start?

Two to six weeks to mandate start is usual, depending on contract review and onboarding. For comparison, ISACA's State of Cybersecurity 2025 found that 45 percent of European organisations need three to six months to fill an entry level information security role. That gap is the real reason companies go external ahead of a certification or a NIS2 deadline.

Does an outsourced CISO take on the liability?

No. Under BSIG section 38(1) the management body must implement and monitor the risk management measures itself, and it stays ultimately responsible even when it uses external help. A mandate transfers the performance of the tasks and the provider's contractual commitment to the outcome, not the legal responsibility.

Can the same person be the security officer and the data protection officer?

Technically yes, advisable rarely. The roles can conflict, because the data protection officer monitors the processing activities that the security officer helps secure. The Bavarian state office for information security advises against combining them; its guidance is written for public bodies, but the reasoning carries in a company too. The provider side of the data protection role is covered in our comparison of external DPO provider models.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check