Hael
Book a meeting
ISO 27001 · Services

ISO 27001 vCISO Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Under ISO 27001 the fractional role owns the ISMS: scope, risk, the Statement of Applicability, the annual cycle and the certification relationship.
  • Retainers commonly run £3,000 to £15,000 a month, with most mid-market arrangements between £4,000 and £9,000.
  • The certificate creates permanent obligations, which is the strongest argument for an ongoing arrangement.
  • Ask whether the internal audit is inside the retainer. If the same person built the ISMS, it should not be.
  • Ask about exclusions: certification fees, penetration testing and engineering work usually sit outside.

What the role covers

A virtual CISO, or fractional CISO, is senior security leadership engaged part time. Under ISO 27001 that role owns the information security management system: the scope, the risk assessment and treatment process, the Statement of Applicability, the control set, the annual internal audit and management review cycle, and the relationship with the certification body.

It is a leadership arrangement rather than a delivery one. Whether the person also implements depends on how the engagement is scoped, and that is the first question to settle.

AreaWhat the person owns
Scope and policyWhat the ISMS covers and the information security policy that governs it
RiskThe assessment method, the register, and the treatment plan that justifies control selection
Statement of ApplicabilityKeeping inclusions and exclusions justified as the organisation changes
Control operation oversightMaking sure access reviews, supplier assessments and change approvals actually happen and leave records
Annual cycleInternal audit scheduling, management review preparation, corrective actions
Certification relationshipSurveillance preparation, evidence coordination, findings
Incident leadershipResponse, records, lessons learned, and regulatory notification where relevant
Buyer questionnairesAnswering customer security reviews from the same evidence base
Board reportingExplaining the security position to leadership and customers

Why the certificate argues for an ongoing arrangement

ISO 27001 does not finish at Stage 2. Surveillance audits happen in years two and three, recertification at year three, and Clause 9.2 requires an internal audit every year.

Between those, the ISMS has to run. Access reviews performed and recorded. Suppliers assessed. Risks reviewed. Incidents documented. Corrective actions closed. Surveillance auditors sample the year, and a system that stopped operating in month three is found in month fourteen as a nonconformity.

A project engagement produces a certificate. Something has to hold the system afterwards.

What it costs

ModelTypical range
Monthly retainer, small organisation, narrow scope£3,000 to £5,000
Monthly retainer, mid-market£4,000 to £9,000
Monthly retainer, complex or multi-framework£9,000 to £15,000
Day rate£600 to £1,400
Fixed-fee project, implementation to certificate£15,000 to £50,000

A full-time CISO in the UK generally costs £120,000 to £220,000 fully loaded, and considerably more in the United States. A retainer at £6,000 a month is £72,000 a year. The comparison is not exact, since a full-time officer is present daily and manages a team, but for organisations below a few hundred people the fractional model usually matches the actual need.

The internal audit question

Ask specifically whether the internal audit is inside the retainer and who performs it.

Clause 9.2 requires objectivity and impartiality. A fractional CISO who built and runs your ISMS is not independent of it, so if they also perform the internal audit, that audit is worth little to a surveillance auditor.

Well-run firms handle this with a separate practitioner or by leaving it to a third party. Either is fine. What is not fine is one person building, running and auditing without anyone mentioning it. This is covered in ISO 27001 - Internal Audit Consultants.

What sits outside the retainer

Certification body fees, always: £5,000 to £20,000 for the initial cycle, then surveillance.

The initial implementation where no ISMS exists. A retainer holds a system; it does not build one from nothing.

Penetration testing, usually a separate specialist engagement, and expected by most enterprise buyers alongside a certificate.

Engineering work to build logging, monitoring or access controls into products.

Ask for exclusions in writing, along with hour caps and overage rates. A capped retainer becomes expensive in the month a surveillance audit or an incident lands.

Fractional, project, or a hire?

Best suited to
Fractional retainerA certificate held, buyer questionnaires arriving, multiple frameworks, no internal owner with capacity
Project consultantGetting to first certification, with someone internal taking the annual cycle afterwards
Full-time hireA large estate, a regulated firm, or a business where security is central to the product

Many organisations do best with a fixed-fee implementation followed by a smaller ongoing arrangement. That is how our implementation and continuous governance and assurance services fit together.

What to do next

Decide whether you are buying a certificate or a standing security function. Those need different contracts and different budgets.

Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how we work.

References

FAQ

What does a vCISO do for ISO 27001?

Owns the ISMS: scope, policy, risk, the Statement of Applicability, oversight of control operation, the annual audit and review cycle, and the certification relationship.

How much does a vCISO cost?

Commonly £3,000 to £15,000 a month, with most mid-market arrangements between £4,000 and £9,000.

Can the vCISO do our internal audit?

Not if they built and run the ISMS, because Clause 9.2 requires objectivity and impartiality. Ask who performs it and how independence is preserved.

Are certification fees included?

No. They are always separate, at £5,000 to £20,000 for the initial cycle plus surveillance.

Do we still need one after certification?

Only if nobody internal will run the annual cycle. Systems that stop after the certificate arrives are found at surveillance.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through ISO 27001 to certificate and maintain the position afterwards through our continuous assurance service, using a separate practitioner for internal audit where we built the system. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.