vCISO vs Fractional CISO vs Interim CISO: What's the Difference

vCISO vs Fractional CISO vs Interim CISO: What's the Difference

vCISO vs Fractional CISO vs Interim CISO: What's the Difference

vCISO vs Fractional CISO vs Interim CISO: What's the Difference (2026)

The short answer, before the detail: virtual CISO and fractional CISO are the same thing under two names. Interim CISO is a genuinely different service, and confusing it with the other two is how companies end up buying the wrong shape of help.

Vendors rarely say this plainly, because three names sound like three products. They are not. What actually varies between engagements is time, duration, and what triggers the need, and once you see those three variables the labels sort themselves out.

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

The three models at a glance


vCISO / Fractional CISO

Interim CISO

Time commitment

Part-time, typically 4 to 16 hours a week

Near full-time, typically 3 to 5 days a week

Duration

Ongoing, no end date

Fixed, typically 3 to 9 months

What triggers it

A regulator, a customer, an investor, or a certification

A vacancy: a departure, leave, or a crisis

What you are buying

Senior judgement plus a programme built around it

Cover for a seat that has to stay filled

Cost shape

Monthly retainer scaled to hours

Close to a full-time salary, without the hiring overhead

Ends when

You outgrow it, usually past 300 to 500 people

The permanent hire starts

Virtual CISO and fractional CISO: the same role

A virtual CISO is a senior security executive who leads your information security programme on a recurring, part-time basis. A fractional CISO is a senior security executive who leads your information security programme on a recurring, part-time basis. That is not a typographical error, the definitions are identical.

Where people try to draw a line, the line does not hold. Some argue that fractional implies a fixed share of time while virtual implies remote delivery. In practice both are delivered mostly remotely with onsite time when it matters, and both are scoped in hours per week or per month. Buyers use the terms interchangeably, providers use whichever their market prefers, and no regulator or auditor has ever cared which word appeared on the invoice.

Two more names belong in the same bucket. Outsourced CISO is the same arrangement described from the buyer's procurement view. CISO as a Service is the same arrangement dressed in subscription language. Part-time CISO is the same arrangement stated most literally. If a provider tells you their fractional CISO is fundamentally different from a virtual CISO, ask them to describe the difference in hours, accountability, and deliverables. The answer usually evaporates.

What genuinely varies inside this category is not the label but the delivery model, and that difference is enormous. One provider gives you a named senior individual who writes the policies, runs the risk assessment, and sits in your audit. Another gives you a compliance platform with a pool of analysts behind it and the same job title on the website. We set out how to tell them apart in how to choose a vCISO provider. That distinction matters far more than virtual against fractional.

Interim CISO: genuinely different

An interim CISO fills a seat that already exists and is currently empty. The company had a CISO, or was about to have one, and now needs someone in the chair while the permanent solution is arranged.

Three things separate it from the fractional model.

Time. An interim engagement is near full-time, typically three to five days a week. You are not buying a fraction of a senior person's attention; you are buying most of it. That is why interim is the right answer when the work genuinely fills a week and the wrong answer when it does not.

Duration. Interim has an end date by design, usually three to nine months, often defined as running until the permanent hire starts. A fractional engagement has no natural end; it continues until the company outgrows the model.

Trigger. This is the clearest tell. Fractional engagements start because something external arrived: a regulator, an enterprise customer's security review, an investor's diligence, a certification deadline. Interim engagements start because someone left. The CISO resigned, went on extended leave, was moved after an incident, or the seat opened through an acquisition. The need is continuity, not capability that never existed.

Cost follows from the time. Because you are buying near-full-time senior capacity, interim prices closer to a full-time salary than to a retainer. It usually still lands below the fully loaded cost of a permanent hire, because you avoid the recruitment fee, the gratuity accrual, the visa costs, and the risk of a bad hire with a notice period attached, and because you are not paying during the months the seat would otherwise sit empty. What you do not get is the discount that makes fractional attractive, since that discount comes entirely from buying fewer hours.

When interim is genuinely the right call

Four situations, and they have a family resemblance.

Your CISO resigned and the replacement search will take months. This is the classic case. The programme cannot pause for a six to nine month search, the board still needs reporting, and the regulator still expects a named accountable person. Interim keeps the seat warm and the programme moving.

Extended leave. Medical or parental leave with a defined return date, where the role reverts rather than being refilled.

Post-incident. A breach has happened, the security leadership changed as a result, and the organisation needs experienced hands full time while it stabilises, investigates, and rebuilds trust with regulators and customers.

Integration after a transaction. Two security functions have to become one, and the workload during the merge genuinely fills a week, even though it will not afterwards.

The common thread: the work is temporarily much larger than the steady state. Interim matches a spike. Fractional matches a steady load.

When you are searching for interim but need a retainer

This is the more common case, and it is worth being direct about it because the wrong choice here costs real money.

Plenty of companies search for an interim CISO when what they actually have is a growth trigger rather than a vacancy. Nobody left; the company simply arrived at the point where a customer questionnaire, a licence application, or a SOC 2 requirement needs a senior owner. There is no seat to fill, because the seat never existed. Buying near-full-time cover for a workload that is genuinely four to eight hours a week means paying for idle capacity from the first month.

The other version: a company loses its CISO, assumes it must replace like for like, and hires interim at near full-time cost, when the honest measure of CISO-level decisions in the business is a few hours a week. The departure exposed the truth rather than creating a gap. In that case the right move is a fractional arrangement plus, if needed, execution capacity underneath it, which usually costs a fraction of the interim and covers more of the actual work.

A simple test. Ask how many hours a week of genuine executive-level security decisions your business generates, ignoring the operational work that more junior people should be doing. If the answer is under sixteen, a fractional engagement fits and interim is overbuying. If the answer is closer to forty and will stay there, you are looking at a permanent hire, with interim as the bridge to it. We set out the maths for both directions in Virtual CISO vs Full-Time CISO and the retainer bands in how much a vCISO costs in the UAE.

Does the label matter to a UAE regulator?

No, and this surprises people, so it is worth stating clearly.

Several UAE regimes require an appointed security leader by name. VARA names the CISO in its Technology and Information Rulebook for licensed virtual asset firms. ADHICS Section 2.1.3 requires Abu Dhabi healthcare entities to appoint a CISO or equivalent. The UAE Information Assurance Standards make the appointment an always-applicable control, control M1.1.3, kept separate from IT operations, with a governance committee above it.

What none of them do is specify the employment arrangement. The regulator's tests are about the individual and the accountability: is there a named person, are they qualified, do they have the authority and the reporting line the standard describes, can they face an examiner and answer for the programme, and is the security function separated from the function it oversees. A retained arrangement satisfies all of those, and so does an interim one. A pool of anonymous analysts satisfies none of them, whatever it is called.

So the label is a commercial description, not a regulatory category. What decides whether an arrangement holds up is whether a real, qualified, named individual sits behind it. The regime-specific detail is in our guides to VARA, ADHICS, and the UAE IAR.

How to decide, in four questions

  1. Is there a seat that is currently empty? If yes, you are in interim territory. If no seat ever existed, you are in fractional territory regardless of what the job boards call it.

  2. How many hours a week of genuine CISO-level decisions does the business produce? Under sixteen points to fractional. Consistently near forty points to permanent, with interim as the bridge.

  3. Is the need permanent or a spike? A licensing push, a certification, or an integration is a spike, and spikes are better served by scaling a retainer up temporarily than by committing to months of near-full-time cover.

  4. Who does the execution? This question cuts across all three models and is the one most often skipped. A senior person of any label who has no capacity behind them will produce a good plan and limited progress. Establish whether the arrangement includes people to write the policies, build the controls, and prepare the evidence, or whether that lands back on your team.

How Dynova fits

Dynova runs our retained vCISO service on the fractional model: a named senior CISO of record, fixed in the contract, working in a pair with a briefed backup, with a delivery team and a GRC platform behind them on the larger tiers so the programme gets built rather than described. Coverage spans CBUAE, VARA, ADHICS, UAE IAR, and PDPL alongside ISO 27001, SOC 2, and PCI DSS, and the same engagement can carry the Data Protection Officer role.

That model suits the trigger-driven need, which is most of the market. Where a company genuinely needs interim cover for a vacant seat, the honest answer is that this is a different commitment, and we will tell you so on the call rather than reshaping a retainer to look like something it is not. For what the retained model delivers under a deadline, we took OGold from a standing start to ISO 27001 certification with BSI in six months.

If you are not sure which shape you need, book a 30-minute call and we will work through the four questions above with your actual numbers.

Frequently asked questions

Is a vCISO the same as a fractional CISO?

Yes. Virtual CISO, fractional CISO, outsourced CISO, part-time CISO, and CISO as a Service all describe a senior security leader engaged on a recurring, part-time basis. Providers pick the term their market prefers. What varies between offers is the delivery model, whether you get a named individual with execution capacity or a platform with pooled analysts, and that difference matters far more than the label.

What is the difference between a fractional CISO and an interim CISO?

Time, duration, and trigger. Fractional is part-time and ongoing, typically 4 to 16 hours a week, and starts because a regulator, customer, investor, or certification created a need. Interim is near full-time and time-boxed, typically 3 to 5 days a week for 3 to 9 months, and starts because a seat became vacant. Interim prices close to a full-time salary; fractional costs a fraction of one because you buy fewer hours.

How much does a fractional CISO cost?

In the UAE, named-CISO retainers typically run from around USD 2,500 a month for steady-state oversight at about four hours a week, up to USD 7,000 to 12,000 a month during a build, certification, or licensing phase. Offers far below that level usually mean a compliance platform with pooled analyst hours rather than a named executive. The band-by-band detail is in how much a vCISO costs in the UAE.

Do UAE regulators accept a fractional or interim CISO?

The regimes that require an appointed security lead, including VARA, ADHICS, and the UAE Information Assurance Standards, specify the individual and the accountability rather than the employment arrangement. They expect a named, qualified person with the right reporting line, separated from IT operations, who can answer to an examiner. Retained and interim arrangements can both satisfy that. An anonymous pool of consultants cannot.

Can an interim CISO become a permanent hire?

Often, and it is a reasonable path. It also runs the other way: a fractional CISO can build the function, define the role, and help recruit the permanent hire, which is usually cheaper than hiring first and working out the scope afterwards. Companies that use a retained arrangement to design the role tend to write a better job description and interview against a clearer standard.

Can you get an interim CISO in the UAE?

Yes, interim CISO arrangements exist in the UAE, usually placed either through executive search firms or through security providers who can field a senior person at near-full-time capacity. Before you start that search, check whether the seat is genuinely full: many UAE companies that go looking for an interim CISO in the UAE have a trigger-driven need rather than a vacancy, and a retained arrangement covers it at a fraction of the cost. The regulatory position is the same either way, since VARA, ADHICS, and the UAE Information Assurance Standards specify the named individual and the accountability rather than the employment arrangement.

Which one do most growing companies need?

Fractional, by a wide margin. Most companies below roughly 300 to 500 people generate a few hours a week of genuine CISO-level decisions, with spikes around audits, licensing, and incidents. Interim is the right answer for a specific and narrower situation: an empty seat that has to stay filled while a permanent replacement is found.

Related: What Is a Virtual CISO? · Virtual CISO vs Full-Time CISO: The Real Cost in the UAE · How to Choose a vCISO Provider in the UAE · How Much Does a vCISO Cost in the UAE?

Experience

Get started

Don’t scale security harder. Scale smarter.

Dynova provides Virtual CISO (vCISO) and Fractional CISO services in Dubai and across the UAE, from security strategy and CBUAE, VARA, ISO 27001, PCI DSS and SOC 2 compliance to hands-on execution, security testing, and code review.

Info: info@business-ciso.com 

Incident Report: soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01, Issued by Meydan Free Zone, Dubai, UAE

Get started

Don’t scale security harder. Scale smarter.

Dynova provides Virtual CISO (vCISO) and Fractional CISO services in Dubai and across the UAE, from security strategy and CBUAE, VARA, ISO 27001, PCI DSS and SOC 2 compliance to hands-on execution, security testing, and code review.

Info: info@business-ciso.com
Incident Report: soc@business-ciso.com


Dynova Services LLC-FZ,

License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Get started

Don’t scale security harder. Scale smarter.

Dynova provides Virtual CISO (vCISO) and Fractional CISO services in Dubai and across the UAE, from security strategy and CBUAE, VARA, ISO 27001, PCI DSS and SOC 2 compliance to hands-on execution, security testing, and code review.

Info: info@business-ciso.com

Incident Report: soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE