How do compliance and vCISO firms find clients?
Compliance and virtual CISO firms sell judgement to organizations that suddenly need a security program they can show someone else. This page covers the certification deadlines that start those searches, how to package fixed-scope offers, which partners send referrals, and how to plan content around dates buyers cannot move.
How do compliance and vCISO firms find clients?
Mostly through deadlines and referrals. A customer asks for SOC 2, a defence contract asks for certification, an insurer asks about controls, and the organization needs help fast. Firms that publish clear explainers on those requirements, offer a fixed-scope readiness project and keep close ties with auditors, MSPs and lawyers get the call.
A vCISO is also a trust purchase. The client is handing an outsider the security leadership seat, often reporting to the CEO or board. That makes the advisor's name, track record and writing matter more than for most security services. Founders of these firms usually are the marketing: their talks, posts and answers on calls carry the brand.
Which certification deadlines create demand right now?
For Canadian firms serving defence suppliers, the Canadian Program for Cyber Security Certification (CPCSC) is the big one. Level 1 is an annual self-assessment of 13 controls and is the only level in effect. Level 2 will be an external assessment by an accredited certification body against 98 controls, and Level 3 an assessment by National Defence against 130 or more; both are under development with no dates. The controls derive from the Cyber Centre's ITSP.10.171, closely adapted from NIST SP 800-171 and 800-172, and the Standards Council of Canada accredits certification bodies.
Clients bidding on US defence work face CMMC. The CMMC program rule (32 CFR part 170), effective December 16, 2024, sets Level 1 as a self-assessment of the 15 FAR 52.204-21 requirements for federal contract information, Level 2 as a self or third-party assessment of the 110 NIST SP 800-171 R2 requirements for controlled unclassified information, and Level 3 as a government assessment of 24 NIST SP 800-172 requirements. It phases in over three years. How contract clauses apply is covered in US expansion.
Smaller Canadian clients may ask about CyberSecure Canada, aimed at small and medium-sized businesses. ISED stopped being its program authority on March 31, 2023, and certification and recertification are now handled through the Standards Council of Canada. Check the current scheme with the SCC before describing what it certifies against.
How do CPCSC and CMMC levels compare?
Prospects with both Canadian and US defence work will ask whether one effort covers both. The shared roots in NIST SP 800-171 help, but the schemes are separate. A side-by-side table is useful content in its own right.
| Level | CPCSC (Canada) | CMMC (United States) |
|---|---|---|
| 1 | Annual self-assessment, 13 controls; in effect | Self-assessment of 15 FAR 52.204-21 requirements |
| 2 | External assessment by an accredited body, 98 controls; under development | Self or third-party assessment of 110 NIST SP 800-171 R2 requirements |
| 3 | Assessment by National Defence, 130+ controls; under development | Government assessment of 24 NIST SP 800-172 requirements |
| Control source | ITSP.10.171, adapted from NIST SP 800-171 and 800-172 | NIST SP 800-171 R2 and 800-172 |
Bid timing and Canadian procurement steps are in selling to government.
How should a compliance or vCISO firm package its offers?
Start with a fixed-scope project that answers the buyer's immediate question, then offer an ongoing role once the gap list exists. Fixed scope makes the first purchase easy for finance and gives you a natural review point.

Name each offer after the outcome the buyer is chasing, not your internal method. "CPCSC Level 1 readiness" is searched and understood; "security maturity uplift" is not.
| Offer | Scope | Length | Leads to |
|---|---|---|---|
| Gap assessment | Current state against one framework, prioritized gap list | 3 weeks | Readiness project |
| Readiness project | Policies, evidence, control fixes for one framework | 8 to 12 weeks | Assessment support |
| Assessment support | Prepare evidence, attend audit or assessment meetings | Per assessment | vCISO retainer |
| vCISO retainer | Monthly leadership hours, board reporting, vendor reviews | Ongoing | Renewal |
Training is often a control in the frameworks above, so many vCISO firms partner with or resell security awareness training.
Plan content around the dates buyers cannot move
Deadline content works because the reader has a reason to act this quarter. Keep a simple calendar: when a scheme changes, when a level comes into force, when your clients' customers run annual vendor reviews. Publish a plain explainer before each date, a checklist a week or two later, and a short recorded walkthrough from the advisor who would do the work. Update the same pages when facts change rather than writing new ones, and show the date you last checked them. Prospects forward those pages to their leadership, which makes them sales material as much as search content.
Package the first 90 days at a fixed price.
Buyers facing a deadline want to know what they get, by when, for how much. An open-ended advisory retainer is a harder first purchase than a scoped readiness project.
Which partners send compliance and vCISO referrals?
ShoutEx view: referrals beat paid channels for most firms in this category, because buyers want someone vouched for. The partners worth investing in are those who meet the buyer at the trigger moment.
- Audit and certification firms that meet organizations unprepared for an audit and need someone to send them to.
- MSPs and MDR providers whose clients ask for policies, risk assessments or board reporting.
- Law firms handling privacy, contracts and defence procurement.
- Insurance brokers whose clients face control questionnaires at renewal.
- Penetration testing firms whose findings reveal a missing program.
Give each partner a one-page description of what you do and do not do, a clear referral process and a regular update on how referred clients are doing. Your own trust signals matter too: a compliance firm without its own documented controls is a hard sell.
What should a compliance or vCISO firm measure?
Measure where clients come from and how often a first project turns into an ongoing role.
| Metric | Why it matters |
|---|---|
| Enquiries by trigger (contract, customer, audit, insurer) | Shows which deadlines drive demand |
| Enquiries by source (partner, search, talk, referral) | Shows where to invest time |
| Gap assessment to readiness conversion | Tests whether the first offer leads somewhere |
| Readiness to retainer conversion | The main driver of recurring revenue |
| Partner referrals per partner | Shows which relationships to deepen |
Frequently asked questions
What does a vCISO do?
A virtual or fractional CISO provides security leadership part time: setting priorities, reporting to leadership, handling customer security reviews and guiding audits, without a full-time hire.
Which CPCSC level is in effect?
Level 1, an annual self-assessment of 13 controls. Levels 2 and 3 are under development and no dates have been published.
Does CPCSC certification satisfy CMMC?
They are separate schemes. Both draw on NIST SP 800-171, which helps, but a supplier with US defence work needs to meet CMMC on its own terms.
What are the CMMC levels?
Level 1 is a self-assessment of 15 FAR requirements, Level 2 covers the 110 NIST SP 800-171 R2 requirements by self or third-party assessment, and Level 3 is a government assessment of 24 NIST SP 800-172 requirements.
Who runs CyberSecure Canada now?
Certification and recertification are handled through the Standards Council of Canada. ISED stopped being the program authority on March 31, 2023.
Can a compliance firm promise clients they will pass?
No. The assessor or auditor decides. Promise readiness work and support, and describe what the client must do.
Should vCISO pricing be public?
Publishing the structure, such as a fixed fee for a gap assessment and a monthly retainer for ongoing hours, helps buyers shortlist you even if exact numbers are quoted.
What content works best for compliance firms?
Plain explainers on specific requirements and deadlines, comparison tables between frameworks, checklists and short videos from the advisor who will do the work.
Sources & further reading
Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.