Skip to content

Fractional CISO: A 2026 Hiring Guide for European Companies

6 min read

What a fractional CISO does, why European regulation is driving demand, what it costs, and when part-time security leadership is the right call.


For most European companies, the need for security leadership announces itself twice. First an enterprise prospect sends a 200-line security questionnaire that nobody internally can answer. Then a regulator, an auditor, or an investor asks who owns information security, and the honest answer is a shared responsibility between an overworked CTO and a managed service provider. Neither moment calls for a full-time Chief Information Security Officer on a 200,000 euro package. Both call for someone senior who can own the problem.

A fractional CISO fills exactly that gap. This guide covers what the role does, why NIS2 and DORA have made it one of the fastest-moving fractional hires in Europe, what it costs across European markets, and how to structure the engagement so it delivers real security rather than a folder of policies nobody reads.

What is a fractional CISO?

A fractional CISO is an experienced security executive who leads your information security function part-time and on an ongoing basis, typically one to two days per week. They carry the same accountability as a full-time CISO, setting security strategy, owning risk, and answering to the board, but at a fraction of the cost and commitment.

The role is often confused with three other things it is not. It is not a security consultant delivering a one-off audit and leaving. It is not a managed security service provider running your firewalls and monitoring alerts. And it is not an interim CISO parachuting in for six months to cover a vacancy. A fractional CISO is a permanent part of your leadership, just not a full-time one. The label vCISO (virtual CISO) is often used interchangeably, though vCISO sometimes implies a more remote, advisory arrangement.

What does a fractional CISO actually do?

The common misconception is that a CISO is a senior engineer who configures security tools. In reality the role sits higher up. Tools and monitoring are usually delegated to the team or an external provider. The fractional CISO owns the parts that require judgement and accountability:

  • Run a risk assessment and set a prioritised security roadmap the business can actually afford
  • Own certifications customers ask for, most often ISO 27001 and SOC 2, from gap analysis to audit
  • Write and maintain the security policies, access controls, and incident response plan
  • Manage third-party and vendor risk, a growing burden under both NIS2 and DORA
  • Answer the security questionnaires and due-diligence requests that gate enterprise deals
  • Report security posture to the board and, increasingly, to regulators
  • Build a light security-awareness culture so the weakest link (people) improves

The goal is not maximum security. It is the right level of security for your size, sector, and risk, achieved without stalling the business.

Why are European companies hiring fractional CISOs now?

Two regulations have turned security from a nice-to-have into a board-level obligation, and both bite hardest in 2026.

NIS2. The EU directive widened the scope of cybersecurity rules to far more sectors and companies. Its transposition deadline was 17 October 2024, but most member states missed it, and the European Commission opened infringement procedures against 23 of them shortly after (ComplianceHub). By 2026 the national laws are landing: as of mid-2026, most member states have transposed NIS2 and the remainder are finalising it (NIS2 transposition tracker). Crucially, NIS2 makes management bodies personally accountable for cybersecurity risk management, with penalties for essential entities reaching up to 10 million euro or 2 percent of global annual turnover. Security is now a director-level liability, not an IT line item.

DORA. The Digital Operational Resilience Act has applied to financial entities since 17 January 2025, and 2026 marks its first real supervisory enforcement cycle, with regulators signalling they will act on incident-reporting and third-party-risk failures (ComplianceHub). For fintechs and any company serving financial institutions, DORA readiness is now a condition of doing business.

On top of regulation, enterprise buyers have tightened their own vendor due diligence. A single security questionnaire can now decide whether a deal closes. For a company between roughly 20 and 500 people, that combination of pressures often arrives years before a full-time CISO is affordable or even hireable, given how scarce senior security talent is.

When does a fractional CISO fit, and when do you need full-time?

Fractional works when the need is real but not yet full-time. Consider it when:

  • You are pursuing ISO 27001 or SOC 2, or answering enterprise security reviews
  • NIS2 or DORA now applies to you and nobody senior owns the response
  • Security currently sits with a CTO or founder who is stretched too thin
  • You want executive-grade judgement without a 200,000 euro-plus commitment

Move to full-time when security becomes a core, full-day concern:

  • You handle highly sensitive data at scale, or operate in a heavily regulated core (banking, health, critical infrastructure)
  • A dedicated security team of several people needs day-to-day leadership
  • Regulatory or customer obligations demand a named, full-time accountable officer

Many companies run a fractional CISO for 18 to 36 months, using the engagement to build the function, achieve the certifications, and hire the internal team, then either graduate to a full-time hire or keep the fractional lead as ongoing oversight. If you are weighing the model against alternatives, our guide on fractional versus interim versus consultant breaks down which fits which situation.

What does a fractional CISO cost in Europe?

Fractional CISO day rates in Europe run from roughly 1,050 to 1,950 euro for a senior operator, with the top of the market near 2,000 euro. Rates vary by country, as they do for every fractional role:

CountryFractional CISO day rate
GermanyEUR 1,100 to 1,900
NetherlandsEUR 1,150 to 1,950
BelgiumEUR 1,100 to 1,850
FranceEUR 1,050 to 1,800
United KingdomGBP 1,200 to 2,000

Figures from our fractional executive rates benchmark, which sources day rates across European markets.

At a typical engagement of one to two days per week, that translates to a monthly retainer of roughly 4,500 to 16,000 euro, depending on intensity and market. Compare that to a full-time CISO, whose base salary in Europe ranges from about 130,000 to 260,000 euro in 2026, with the upper end in regulated sectors and large enterprises (Optima Europe). And base is only part of it: at executive level, salary is typically 55 to 65 percent of total compensation once bonus, equity, and benefits are added. A fractional CISO delivers senior security leadership for a fraction of that, with no recruitment lead time and the flexibility to scale up or step back as your risk changes.

How do you structure a fractional CISO engagement?

The engagements that work share a few traits. Agree a clear scope and the specific outcomes you are buying, whether that is ISO 27001 certification, DORA readiness, or clean enterprise security reviews. Set the cadence in writing, usually a fixed number of days per month on a monthly retainer, which creates the mutual commitment that an hourly arrangement lacks. Give the fractional CISO a real mandate and board access, because security decisions that lack authority do not stick.

A sensible first 90 days looks like this: a risk assessment and gap analysis in month one, a prioritised roadmap and the highest-impact policies in month two, and by month three the certification track underway and a repeatable process for security questionnaires. From there the work shifts to steady execution and board reporting.

Frequently asked questions

What is the difference between a fractional CISO and a vCISO?

In practice the terms overlap and are often used interchangeably. Both describe part-time, ongoing security leadership. vCISO (virtual CISO) sometimes implies a more remote or advisory arrangement delivered through a provider, while fractional CISO tends to imply a named individual embedded in your leadership. What matters is the level of ownership and accountability, not the label.

Can a fractional CISO help with ISO 27001 or SOC 2?

Yes, this is one of the most common reasons companies hire one. A fractional CISO runs the gap analysis, builds the required policies and controls, prepares the evidence, and steers the audit. Because they have usually done it several times, they avoid the false starts that make certification slow and expensive the first time.

Does NIS2 or DORA require us to have a CISO?

Neither directive mandates a specific job title, but both require a named, accountable owner of cybersecurity risk management, and NIS2 makes management personally liable. In effect, you need someone senior who owns security and can demonstrate it to regulators. A fractional CISO is a proportionate way for a mid-sized company to meet that expectation without a full-time hire.

How many days per week does a fractional CISO work?

Most engagements run one to two days per week. Early on, during a certification push or a regulatory deadline, it may sit at the higher end. Once the function is built and running, it often settles to one day per week or less of ongoing oversight.

How is a fractional CISO different from a security consultant?

A consultant delivers a defined project, an audit or an assessment, and then leaves. A fractional CISO stays, carries ongoing accountability for your security posture, and is answerable for outcomes rather than deliverables. If you need a point-in-time review, hire a consultant. If you need someone to own security over time, hire fractionally.

How quickly can a fractional CISO start?

Usually within days to a couple of weeks, which is one of the model’s main advantages. Recruiting a full-time CISO in Europe commonly takes months given the shortage of senior security talent. A fractional hire lets you put accountable leadership in place before your next audit, deal, or deadline.


If regulation, a stalled enterprise deal, or a looming certification has put security on your board’s agenda, a fractional CISO is often the fastest proportionate answer. You can find a fractional CISO through Fractionista, or explore the wider model in our guide to what a fractional role is.

Gregor Zehetner

Thank you
for your interest!

Want to speed things up? Book a 20-minute briefing call so we can nail your personal on-boarding.