Practical guidance from our advisory team on cyber risk, compliance frameworks and security leadership for growing organizations — no vendor pitch, just what we'd tell a client.
A practical decision framework based on your buyers, not a feature comparison chart.
Beyond the title — the concrete deliverables and decisions a fractional CISO owns month to month.
The program is being reviewed — here's why that's not a reason to pause preparation.
The most common — and most expensive — sequencing mistake we see organizations make.
What directors are now expected to document — and why "we trust IT" no longer holds up.
Every requirement in the latest version is now enforced — here's what changed in practice.
Buyers Decide, Not Features
We get this question constantly, and the honest answer is: look at who's asking. If your growth is concentrated among U.S. enterprise and mid-market SaaS buyers, SOC 2 is usually the faster path to unblocking deals — it's the report most U.S. security teams already know how to read, and Type I can be achieved in weeks rather than months. If you're expanding internationally, selling into Europe, or competing for government and large enterprise RFPs that explicitly list certifications, ISO 27001 tends to carry more weight — it's a certification, not just an audited report, and it's recognized well beyond the U.S.
The good news: you rarely have to choose permanently. The risk assessment, control set and evidence base for one framework reuse heavily for the other. Most of our clients start with whichever framework their next three deals actually require, then layer the second on top once the first is stable — rather than trying to build both from scratch at once.
Rarely A Permanent Choice
Accountable Decisions, Not A Title
"Fractional CISO" gets used loosely, so it's worth being specific about what the role delivers month to month: ownership of the security roadmap and its prioritization, a recurring reporting cadence to leadership and the board, direction for whoever implements controls day to day (internal staff, an MSP, or specialist vendors), incident readiness and response leadership if something goes wrong, and a steady hand in vendor and third-party risk conversations that would otherwise fall to whoever's available.
What it isn't: a part-time systems administrator, a compliance-only checkbox exercise, or a name on a slide deck for sales. The value of the role is accountable decision-making — someone whose job it is to know what your top risks actually are and to say, clearly, what to do about them in an order that matches your budget and your business.
Roadmap, Not Just Advice
Keep Building, Don't Wait
CMMC is in an active review — the Department of War paused the rollout of later certification phases in mid-2026 to reassess the program's approach, with recommendations expected later this year. It's tempting to read that as a reason to wait. We'd push back on that. Self-assessment expectations that began rolling out in late 2025 are still in effect, prime contractors are already flowing CMMC-aligned requirements down to subcontractors ahead of any formal mandate, and the underlying control set — NIST SP 800-171 — isn't going anywhere regardless of how the certification mechanics evolve.
The contractors who come out ahead through this transition are the ones who keep building toward the NIST SP 800-171 control set now, so that whatever the finalized program looks like, they're closing a small gap instead of starting from zero.
NIST 800-171 Isn't Going Away
Risk Before Framework
The most expensive mistake we see is an organization committing to a compliance framework — ISO 27001, SOC 2, NIST CSF — before it has a clear picture of its own risk. Frameworks are structures for organizing and proving controls; they don't tell you which controls actually matter most for your business. Without a risk assessment first, teams frequently over-invest in controls the framework technically allows you to skip, while under-investing in the handful of gaps that would do real damage if exploited.
A structured risk assessment — typically two to four weeks — produces a risk register and gap analysis that then feeds directly into whichever framework you pursue. Nothing from that work is wasted; it just gets reused as the foundation, rather than redone from scratch once you've already picked a framework based on guesswork.
Two To Four Weeks
Documented, Not Assumed
The SEC's 2023 cybersecurity disclosure rules formalized something that was already becoming an expectation: boards need to be able to describe, in writing, how they oversee cyber risk — not just assert that "the team handles it." For public companies that means documented board processes for reviewing material incidents and risk posture. For private companies, the same expectation is filtering down through investors, insurers and enterprise customers running their own diligence.
In practice, this means a named executive or advisor who reports to the board on a set cadence, a documented risk register the board actually reviews, and an incident response plan the board has seen before it's ever needed — not assembled for the first time during an actual incident.
A Plan The Board Has Seen
Fully Enforced Since 2025
PCI DSS 4.0.1 is now the fully enforced standard — every requirement that was previously a "future-dated" best practice became mandatory as of March 2025. In practice, the changes organizations feel most are stricter multi-factor authentication coverage (extended well beyond just remote access), more rigorous and continuous vulnerability management, and tighter expectations around how service providers and their customers share compliance responsibility in writing.
If your last PCI assessment predates these requirements, it's worth treating this as a real gap assessment rather than a formality — the version number changed less than the enforcement did.
Worth A Real Gap Review
Our advisors are happy to talk through your specific situation directly.