Cybervize

Virtual CISO Costs 2026: Pricing Compared

Alexander Busse·March 6, 2026
Virtual CISO Costs 2026: Pricing Compared

As of August 2026. All prices are net of VAT. Every figure comes with a source; market prices are list prices from our own survey of public pricing pages.

Short answer: Published vCISO engagements in the DACH market run from €3,000 to €8,000 per month (market assessment by Ingenieurgesellschaft ISM, February 2026). At Cybervize, a virtual CISO costs €3,600 to about €8,500 per month for 2 to 6 consulting days, with the license for the Cybervize platform included in the retainer; ad hoc work is billed at €200 to €350 per hour. Below the vCISO segment there are external information security officers (ISO) from €275 per month, a narrower service with a different mandate.

The starting point: most companies do not have a CISO

Only 20 percent of mid-sized companies in Germany employ a CISO. In 47 percent, responsibility for cybersecurity sits with a specialist department, usually IT (Deloitte, Cybersecurity im Mittelstand 2025, a survey of 243 companies). That is rarely negligence. More often it is sober arithmetic: a full-time CISO costs €135,000 to €200,000 per year on an ongoing basis (the derivation follows below), and in many companies the actual need comes to a few days per month.

This is exactly the gap the virtual CISO fills, also called vCISO or external CISO: the CISO function at the scale a company actually needs. If you are searching for vCISO pricing, the complete answer is here: our own prices, the published prices in the market, how the cheaper ISO segment differs, the honestly calculated full-time hire, and the cases where a vCISO is not the right choice.

What a virtual CISO costs at Cybervize

Three pricing models are common in the market: the monthly retainer, the day rate, and the hourly rate. We work with monthly retainers and publish them, because the question of price should not be the opening move of a negotiation. As of August 2026:

  • Basic, from €3,600 per month: about 2 consulting days: analysis of your security posture, NIS-2 gap analysis, risk assessment with measures, monthly meeting with the executive team
  • Standard, €4,900 per month: about 3 consulting days, up to 24 hours, tighter cadence: weekly alignment, two executive meetings per month, building and maintaining the compliance catalog
  • Senior, about €8,500 per month: 5 to 6 consulting days, for companies with multiple sites, stricter regulatory oversight, or a security program of their own

For ad hoc work outside the retainer, an hourly rate of €200 to €350 applies. The minimum term is 6 months; after that, the retainer is cancelable monthly. Every tier includes the license for the Cybervize platform: risks, measures, incidents, and evidence live there, not in a service provider’s folders; a complete data export is part of the terms.

Per-day figures make the retainers comparable. At two consulting days, the Basic retainer works out to €1,800 per day; at 5 to 6 days, the Senior retainer comes to roughly €1,400 to €1,700 per day. For context: typical day rates for senior security consulting run €1,600 to €2,500 (kmusec, June 2026); the BDU-Honorarstudie 2025 measures an average of €1,300 per day across all consulting fields, and €1,600 at partner level.

On an annual basis: Basic €43,200, Standard €58,800, Senior about €102,000.

What an external CISO costs in the market: published prices

There is no robust pricing study for CISO as a service in the DACH region. What does exist are public price lists. We evaluated them (own survey, list prices, as of August 2026):

  • Cortina Consult: external ISO, flat fee, from €275 per month (source: cortina-consult.com)
  • frag.hugo: external CISO/ISO, three packages, €990 to €2,490 per month for 4 to 16 hours (source: fraghugo.de)
  • Ingenieurgesellschaft ISM: external ISO, three engagement sizes, €1,890 to €5,890 per month for 8 to 24 hours (source: ing-ism.de)
  • Wermescher (Austria): external CISO, retainer, from €3,520 per month (source: wermescher.com)
  • Cybervize: vCISO retainer, platform included, €3,600 to about €8,500 per month for 2 to 6 consulting days (source: cybervize.de/en/preise)

All provider prices are list prices from the respective pricing pages, retrieved in August 2026, net of VAT. The service scopes differ; a price comparison is no substitute for a scope comparison.

Ingenieurgesellschaft ISM also publishes a market assessment (February 2026): vCISO engagements at €3,000 to €8,000 per month, external ISO engagements at €1,400 to €3,500 per month. Our Basic and Standard tiers sit in the middle of that vCISO band. At about €8,500 per month, the Senior retainer is above every concrete published package price we found; calculated per consulting day, at €1,400 to €1,700 it sits at the lower end of the usual senior day rate band. Where €15,000 per month is quoted as a typical vCISO figure, that usually means an interim engagement with high presence, more on that below.

Two notes on how to read this overview. First: these are list prices; nobody publishes the prices actually negotiated. Second: the many providers without a pricing page are missing, among them TÜV, DEKRA, DataGuard, and secjur. Transparency is mixed among software competitors too: fuentis lists €379 and €979 per month for its ISMS software and quotes the CISO-as-a-service part only on request (fuentis.com, as of August 2026); VamiGRC publishes no prices.

vCISO or external ISO: two services under a similar label

The overview raises a fair question: why pay €3,600 per month when external security responsibility can be had from €275 per month? Because two different services are being sold under similar names here, and the difference is rarely explained.

An external information security officer (ISO) holds a designated role: keeping the security documentation current, answering inquiries, reporting at fixed intervals, and supporting audits. Typical scope: a few hours per month. For a company that needs a formal officer role with a manageable set of duties, this is the economically right choice, and €275 to €3,500 per month is a realistic range for it.

A vCISO, by contrast, takes over the CISO function: owning the security strategy toward the executive team, prioritizing risks and budget, steering measures and service providers, and in an emergency sitting next to management, not in the document archive. Typical scope: 2 to 6 days per month. That is leadership work bought by the day, not well-kept filing.

The price gap is therefore explained almost entirely by volume and role, hardly by the hourly price: the smallest frag.hugo package costs €990 for 4 hours, which is €247.50 per hour. Our Basic retainer, at two consulting days (16 hours, calculated with 8-hour days), works out to €225 per hour. So when you compare offers, ask first: how many hours or days are included, and which role is actually being filled?

vCISO or full-time hire: the calculation, line by line

The second benchmark is a full-time hire. This calculation is regularly set up wrong, in both directions. Here it is, every line item with a source:

Base salary. In the German Mittelstand, a CISO base salary typically runs €110,000 to €160,000 per year. Executive search mandates quote €110,000 to €150,000 (WK Personalberatung, 2025/26); placement and job ad data sit lower (Robert Half Gehaltsübersicht 2026: median €90,000; StepStone 2026: median €83,000). Large corporations and heavily regulated industries pay €200,000 and more including variable compensation.

Employer contributions. A flat 30 or even 42 percent is often added on top. That is wrong: because of Germany’s social insurance contribution ceilings (2026: €101,400 for pension and unemployment insurance, €69,750 for health and long-term care insurance), employer contributions are capped and add up to around €20,000 per year, regardless of whether the salary is €130,000 or €220,000. At €130,000 that is roughly 15 percent.

Ongoing total cost. Adding workplace, training, and tooling, you arrive at €135,000 to €200,000 per year.

First year. Executive search costs a one-time fee of 25 to 33 percent of the target annual salary (BDU-Marktstudie 2024: 27.5 percent on average). A sample calculation with disclosed assumptions: salary €130,000, employer contributions €20,000, workplace and training €8,000, recruiting at 27.5 percent of €130,000 = €35,750. First-year total: €193,750. Depending on salary level and fee rate, first-year costs land at roughly €170,000 to €250,000.

The line item that almost never gets counted: average tenure in the CISO role is around 39 months (Hitch Partners, 2025). Recruiting costs are therefore not a one-off effect; on average, they return every three years and a bit.

And now the part that rarely appears in provider articles: calculated per individual working day, the full-time hire is cheaper. €135,000 to €200,000 spread across roughly 220 working days comes to €610 to €910 per day; a vCISO day costs €1,400 to €1,800. The difference: with a full-time hire, you buy all 220 days, whether you need them or not. If your company genuinely has three days of CISO need per month, so 36 days per year, each day you actually use in the full-time model effectively costs around €3,750 to €5,600 (€135,000 or €200,000 divided by 36). The right question is therefore not “What does a CISO cost?” but “How many days of CISO work do we really have?”. The crossover point depends on both ranges: at €135,000 total cost and €1,800 per vCISO day it sits at around 6 days per month, at €200,000 and €1,400 per day at around 12 days. As a rule of thumb: from about eight days of sustained need, the full-time calculation is worth running for your individual case. If that describes your situation, we will tell you so in the first conversation.

What actually drives vCISO costs

Four factors decide where an engagement lands within the range. Not a surcharge table, but the amount of work:

  1. Scope and cadence. How many days per month are needed, and how often you report to the executive team or the supervisory board.
  2. Regulatory pressure. Anyone who falls under the NIS2UmsuCG, Germany’s NIS-2 implementation act (in force since December 6, 2025), as an important or particularly important entity carries registration, evidence, and reporting obligations that mean ongoing work. For context, because this is where selling on fear is popular: fines range up to €10 million or 2 percent of global annual revenue for particularly important entities, and up to €7 million or 1.4 percent for important entities. Those are statutory maximums, not expected values. There are no publicly known NIS-2 fines to date (as of August 2026). The GDPR shows how far apart maximum frames and practice sit: in 2025, 249 fines totaling €46.9 million became known in Germany, €45 million of that in a single case; without that outlier, the average was below €8,000 per case. The reason for a vCISO is not the maximum fine. It is the ongoing obligation that someone has to own competently.
  3. Structure. Multiple sites, plants, subsidiaries, or OT environments mean more coordination and assessment effort and additional reporting lines.
  4. Maturity and tooling. A company with a living ISMS needs steering; a greenfield company needs build-up first. And it makes a measurable difference whether the vCISO works on a platform where risks, measures, incidents, and evidence are already in place, or collects Excel spreadsheets every month. In the second case, you are paying senior day rates for document hunting.

What does not justify the price in any serious way: invented damage scenarios. The documented orders of magnitude look like this: GDV, the German insurers’ association, puts the average loss per insured cyber claim at €45,370 (an analysis across roughly 261,000 policies, mostly small and mid-sized companies); Hiscox measured median total costs of €16,050 per attack for Germany in 2023. At the upper end: ransomware victims in the 100 to 250 employee bracket paid an average of US$638,536 for recovery excluding ransom (Sophos State of Ransomware 2025; only actual victims were surveyed, so the figure is an upper bound). After a ransomware attack, companies were impaired for around three days on average (Bitkom 2023); where data was actually encrypted, 47 percent needed more than a week to recover (Sophos 2025). The frequently cited €3.87 million per data breach (IBM, 2025) comes from an enterprise-heavy sample and is no use as an expected value for mid-sized companies. And nobody can seriously quantify what share of such losses a vCISO would have “prevented”. A vCISO is not an insurance policy. It is a function.

Seven questions for every provider, including us

Put these questions to every provider, expressly including us:

  1. How many consulting days are included in the monthly retainer, and what does that make the cost per day?
  2. Who does the work: the person from the sales conversation or a rotating team? And who covers absences?
  3. What happens to hours that go unused in a given month?
  4. Which tooling does the work run on, and what stays with you after the engagement ends? Insist on a data export and on documents and evidence being yours.
  5. How long are the minimum term and the notice period? (With us: 6 months, then cancelable monthly.)
  6. How are travel and incidental costs billed?
  7. Who carries the responsibility in the end? The honest answer is uncomfortable: under Section 38 of the German BSI Act (§ 38 BSIG), management itself must implement the risk management measures and monitor their implementation. That duty stays with you, whomever you engage. A provider who promises to “take the liability off your hands” is promising something they cannot keep.

Plus one warning sign that needs no question at all: providers who argue with maximum fines and million-euro damages instead of days and deliverables.

When a vCISO is not the right choice

  • You need a designated officer role with a few hours per month. Then an external information security officer from a few hundred euros per month is the more economical solution. We do not serve this segment.
  • You need daily leadership presence. A security team of your own needs managing, committees meet weekly, the need sits permanently at eight or more days per month: then a full-time hire is the right decision despite the higher total cost.
  • You have an acute vacancy or are stabilizing after an incident. High presence for a few months is an interim engagement, not a vCISO retainer. Interim CISO engagements run €8,000 to €15,000 per month, project-based; at Cybervize without platform lock-in.
  • You have your own CISO and are only looking for the tooling. Then license the Cybervize platform directly (Core from €12,900 per year, Professional from €24,900 per year). Senior CISO support can be added when you need it and is not part of the license price.
  • There is nothing to steer yet. If your IT sits entirely with a service provider and neither customers nor regulators are asking for evidence, basic hygiene matters more than a CISO function. Buy the function when the obligations arrive.

The reason behind our price: the Cybervize platform

That leaves the question behind the price question: what do you get for 2 to 6 days per month? At Cybervize, the vCISO works on the Cybervize platform, and its license is included in the retainer. That is not a freebie. It is the reason the days flow into steering rather than administration: risks, measures, incidents, and evidence sit in the platform, and your compliance status can be shown at any moment, to the executive team, an auditor, or a customer. And when the engagement ends or an internal CISO takes over, data and evidence stay in your company rather than in a provider’s folder.

If you want to see what a vCISO engagement at Cybervize builds on: book a free demo of the Cybervize platform, 30 minutes. And if you want to work out the right scope for your situation, book a consultation. In both cases you get numbers first, then an offer.

Related articles

Related services