Fractional CISO vs. full-time: when each one actually makes sense

Fractional makes sense when a company needs security leadership and real structure but doesn't yet have enough constant work to justify a full-time executive salary and team. Full-time makes sense once security work fills a week on its own, or the company's risk profile (a regulated industry, sensitive data at real scale, board-level scrutiny) demands someone in the room every day.

By stage, budget, and risk

Company stage Budget Risk profile Recommendation
Pre-seed / seed, under ~20 people Little to no dedicated security budget Low-medium; no regulated data Fractional advisory, enough to unblock sales and vendor security questionnaires
Series A/B, ~20-100 people Growing budget, first compliance push Medium; early customer and vendor scrutiny Fractional: a SOC 2 or ISO 27001 readiness engagement plus an ongoing retainer
Series C+ / scaling, ~100-500 people Established budget, team forming Medium-high; multiple frameworks, possible M&A Fractional-to-full-time transition: build the program fractionally, hire full-time to run it
Regulated or 500+ people Significant budget High; constant regulatory, audit, or board scrutiny Full-time: the workload alone justifies a dedicated seat

When fractional makes sense

Fractional works best when the need is real but bounded: a certification project, a due-diligence push ahead of a raise or acquisition, or ongoing coverage for a company that isn't yet generating enough security work to fill a full week. It also works well as a bridge: building the program before the company is ready to hire and manage a full-time leader.

When full-time makes sense

Full-time makes sense once the work is constant: a growing security team to manage day to day, recurring audits and customer due diligence overlapping year-round, or a risk profile (handling regulated data, facing frequent incidents, sitting in front of a board regularly) that needs someone accountable in real time, not on a scheduled cadence.

What a fractional engagement actually looks like

Usually a base retainer covering standing responsibilities (risk register ownership, vendor review, policy maintenance) plus defined capacity for project-based spikes like an audit push or a due diligence response. The best engagements include an explicit, honest checkpoint for when the company should transition to full-time, not an incentive to keep the retainer running past the point it's still the right fit.

FAQ

Can a fractional CISO actually get a company through a SOC 2 or ISO 27001 audit?

Yes, this is one of the most common and well-suited uses of a fractional engagement. Certification projects are bounded in scope and time, which fits a part-time engagement well, as long as the fractional CISO has actually run one before, not just advised on one.

How many hours a week does a fractional engagement typically involve?

It varies widely by stage and need, commonly somewhere between a few hours a week for steady-state advisory and closer to half-time during an active audit push or incident. The right structure is usually a base retainer plus defined capacity for project-based spikes.

What happens when a company outgrows fractional coverage?

The clearest signal is when security work fills a full week on its own, independent of any single project. That's the point to hire full-time. A well-run fractional engagement should include an honest conversation about this transition, including helping scope and hire the full-time role.

Is fractional actually cheaper than hiring full-time?

Usually, at the stage where fractional makes sense, a company that isn't ready to fill a full-time security leadership role isn't saving money by hiring one anyway, since the role would be underutilized. The real comparison isn't cost, it's whether the workload justifies a full-time seat yet.

I've been a founder myself, so I know what fractional coverage actually needs to look like at each stage. I take on a small number of fractional CISO engagements at a time. Happy to talk through whether it's the right fit for where you are. Get in touch.