If you are still charging an hourly rate for GRC advisory, you are operating under a broken business model.

Hourly billing penalizes efficiency. The faster you automate a client’s SOC 2 evidence collection or streamline their vendor risk reviews, the less money you make. Worse, it turns strategic security leadership into a line-item transaction where clients scrutinize every 15-minute increment on your invoice.

To build a scalable vCISO practice, you must detach your revenue from hours worked and price based on governance outcomes and risk reduction.

The 3-Tier Fixed-Fee Retainer Framework

When pitching prospective SaaS clients or enterprise startups, anchor your proposals around three distinct engagement tiers:

Tier 1: Audit Readiness (Fixed-Project: $15,000 – $25,000)

  • Target: Seed to Series A startups preparing for their first SOC 2 Type I/II or ISO 27001 audit.

  • Deliverable: Gap analysis, policy drafting, compliance automation tool onboarding, control implementation, and final audit management.

  • Duration: 8 to 12 weeks.

Tier 2: Continuous vCISO & Assurance ($5,000 – $7,500/month)

  • Target: Post-audit SaaS companies needing ongoing security leadership, vendor risk management, and customer questionnaire execution.

  • Deliverable: Monthly risk committee guidance, customer security assessment responses, quarterly access reviews, continuous compliance maintenance, and board reporting.

  • Commitment: 6 or 12-month recurring contract.

Tier 3: Strategic Enterprise Oversight ($10,000+/month)

  • Target: Regulated enterprises or multi-framework environments facing heavy customer enterprise procurement scrutiny.

  • Deliverable: Full security program ownership, third-party audit facilitation, dedicated incident response tabletop exercises, custom AI governance, and direct customer deal-support calls.

3 Guardrails to Prevent Scope Creep

Transitioning to fixed-fee retainers only works if you set hard operational boundaries in your Master Services Agreement (MSA):

  1. Separate "Advisory" from "Execution": Your retainer covers program design, policy approval, guidance, and audit management. It does not cover hands-on engineering execution (e.g., configuring AWS IAM roles or fixing code vulnerabilities).

  2. Cap Customer Security Questionnaires: Uncapped questionnaire support destroys margins fast. Include up to 4 completed enterprise security questionnaires per month in Tier 2. Charge a fixed fee ($500–$750) for each additional request.

  3. Define Synchronous SLA Limits: Limit live meeting availability to a set schedule (e.g., one 60-minute weekly operational sync + asynchronous Slack access). This keeps clients from pulling you into daily internal standups.

Action Step for the Week

Take your current client base or latest proposal pipeline and run it through a fixed-fee audit:

  • Where are you giving away free execution hours?

  • Which client interactions can be shifted from synchronous calls to asynchronous status dashboards?

By fixing your pricing structure first, you create the bandwidth required to deliver true strategic value.

Deliverability Check:

Reply directly to this email and let me know: What is your biggest hesitation when moving from hourly billing to fixed-fee retainers? Reading every reply keeps updates in your primary inbox and informs future breakdowns.

Talk soon,

Marcus Lynch

Founder, Logical GRC

newsletter.logicalgrc.com