How to use this scope
A vCISO statement of work should tell both parties what will change, what will be delivered and who must make each decision. A list of security activities is not enough. “Provide strategic guidance” can mean a monthly call to one client and an operating security programme to another.
The sections below are a drafting framework for MSPs and security consultancies. Replace the bracketed prompts with client-specific language. Align the final document with your master services agreement and have suitable legal or commercial advisers review contractual terms. This page is a delivery template, not legal advice.
Before pricing the engagement, confirm the client’s size, operating model, regulated activities, technology boundaries and expected access to senior leadership. If those facts are unknown, use a paid discovery phase rather than guessing.
1. Engagement context
Sample wording
[Provider] will provide virtual Chief Information Security Officer services to [Client] for the business units, legal entities and technology environments listed in this scope. The engagement will establish and maintain a risk-led cybersecurity programme that supports the client’s business objectives and applicable obligations.
Add a short description of why the client is buying the service. Examples include responding to customer assurance requests, preparing for a certification, improving board oversight, meeting an insurer’s conditions or bringing several technical projects into one risk-based plan.
Record the service start date, initial term, renewal model and primary contacts. If the work follows an assessment or sales discovery, identify the documents on which the scope relies.
2. Objectives and outcomes
Use outcomes that can be reviewed, not promises that no responsible provider can guarantee. Avoid “ensure complete compliance” or “prevent all cyber incidents”.
Example objectives
- Establish a documented current and target cybersecurity profile using [agreed framework].
- Maintain a prioritised cyber risk register with named client owners and recorded treatment decisions.
- Give leadership a regular view of material cyber risks, delivery progress and decisions required.
- Coordinate an agreed security roadmap across internal teams and third-party providers.
- Improve the client’s ability to respond to customer, regulatory and assurance requests using reusable evidence.
NIST Cybersecurity Framework 2.0 can organise these outcomes without dictating a single implementation. Its Govern function is particularly useful when defining decision rights, policy, oversight, supply-chain risk and the relationship between cybersecurity and enterprise risk.
3. In-scope organisation and systems
State boundaries explicitly. Include:
- legal entities and business units;
- countries or operating locations;
- employees, contractors and approximate user count;
- cloud tenants, data centres, corporate networks and endpoints;
- business-critical applications and products;
- sensitive data types;
- material outsourced providers;
- applicable frameworks, regulations and customer commitments.
If the client cannot provide a reliable asset inventory at contract stage, say that the initial inventory will be based on the best available information and that new systems may require a scope change.
4. Service workstreams
Select only the workstreams the provider will genuinely staff and deliver.
Governance and programme management
- Maintain the security strategy, policy schedule and roadmap.
- Facilitate the agreed governance meetings.
- Track actions, dependencies, risks and decisions.
- Prepare leadership or board reporting at the agreed frequency.
Risk and compliance
- Establish a current profile against [framework or control set].
- Maintain cyber risk and treatment records.
- Map evidence to agreed customer, regulatory or certification requirements.
- Coordinate external audit or assessment activity where listed.
Security architecture and operations oversight
- Review material projects and proposed control changes.
- Advise on identity, vulnerability, endpoint, cloud, logging, backup and supplier controls.
- Review service reports from the client’s technology and security providers.
- Escalate material gaps to the named client owner.
Incident readiness
- Maintain an incident response plan and contact structure.
- Facilitate [number] tabletop exercises per year.
- Provide executive coordination during an incident only if this responsibility and its availability terms are expressly included.
Separate oversight from hands-on technical operation. If the MSP also runs security tools, distinguish the vCISO’s governance role from the managed service’s operational responsibilities.
5. Deliverables and acceptance criteria
Every deliverable needs a format, frequency, owner and acceptance rule.
| Deliverable | Frequency | Provider responsibility | Client acceptance |
|---|---|---|---|
| Current and target profile | Initial, then annual | Assess outcomes and record evidence | Sponsor reviews boundaries and factual accuracy within 10 working days |
| Cyber risk register | Monthly update | Draft and facilitate review | Named owners confirm decisions and dates |
| Security roadmap | Quarterly update | Prioritise agreed treatments and dependencies | Steering group approves changes |
| Executive risk report | Monthly or quarterly | Summarise material risks, progress and decisions | Sponsor confirms it is ready for the intended audience |
| Policy set | Per agreed schedule | Draft or update listed policies | Authorised client officer approves each policy |
| Tabletop exercise report | [frequency] | Design, facilitate and report | Sponsor accepts observations and action owners |
Sample acceptance wording
A deliverable will be considered accepted when the named client approver confirms acceptance in writing or does not provide specific material corrections within [10] working days. Acceptance does not transfer ownership of the client’s risks or management decisions to the provider.
Adjust this language to your contract and local law.
6. Roles and decision rights
Name roles rather than writing “the business” or “IT”. A simple responsibility model might be:
- Executive sponsor: approves strategy, priorities, budget and risk acceptance.
- vCISO: advises, facilitates, challenges and prepares agreed deliverables.
- IT lead: supplies technical evidence and owns agreed operational changes.
- Control owners: maintain controls and confirm remediation evidence.
- Privacy or legal lead: advises on notification, data protection and contractual matters.
- MSP service manager: coordinates managed service activity and dependencies.
State that the client retains accountability for business and risk decisions. The provider should not be described as accepting risk on the client’s behalf unless a properly authorised role and legal arrangement explicitly allows it.
7. Client dependencies
The delivery schedule should depend on timely client participation. Include obligations to:
- provide accurate information and reasonable access to evidence;
- nominate authorised decision-makers and control owners;
- attend scheduled workshops and governance meetings;
- review deliverables within agreed timescales;
- notify the provider of material business, technology or regulatory changes;
- implement or commission remediation unless separately included;
- protect provider accounts and follow the agreed evidence-transfer process.
Explain what happens when a dependency is missed. Usually the right response is to move a date, record reduced assurance or raise a change request, not silently absorb unlimited extra work.
8. Explicit exclusions
Common exclusions include:
- legal opinions or certification guarantees;
- formal audit or independent assurance, unless separately commissioned;
- penetration testing and vulnerability scanning;
- 24-hour monitoring or incident response;
- implementation of technical controls;
- procurement authority or approval of client expenditure;
- ownership of client risks;
- activities for unlisted entities, products or jurisdictions.
If another service covers an item, cross-reference it. An exclusion should not create ambiguity about who is responsible.
9. Meeting and reporting cadence
Define a workable rhythm:
- operational action review: fortnightly or monthly;
- sponsor or steering meeting: monthly;
- executive or board report: quarterly, or as agreed;
- annual strategy and target-profile review;
- urgent escalation outside the normal cadence for agreed severity conditions.
Set expectations for preparation, minutes and decisions. Meetings are not deliverables by themselves; they should move actions or decisions forward.
10. Change control
Sample wording
Either party may request a change where the organisation, technology boundary, obligations, delivery volume or required availability differs materially from this scope. The provider will document the requested change, its effect on deliverables, fees, dependencies and dates. No material change will take effect until authorised representatives agree it in writing.
Examples include an acquisition, a new regulated product, an accelerated certification deadline, a major incident or the addition of several business units.
11. Data handling and access
Identify what client information the provider will hold, where it will be processed, how access is controlled and when it will be deleted. Use least privilege for client systems. Avoid copying evidence into personal drives or uncontrolled project tools. Cross-reference the data-processing and security terms in the governing agreement.
Record whether the provider may use subcontractors, automation or AI-assisted tools, and the safeguards that apply. Client evidence should not be placed into a public model or reused for another client.
12. Commercial assumptions
Connect fees to the operating assumptions used to price the service. Record limits such as included meeting hours, number of entities, number of policies, assessment frequency, board attendance and travel. State the rate or process for work outside those assumptions.
Do not make the scope so rigid that ordinary advisory work triggers a change request every week. The purpose is to control material variation and protect service quality.
Final scope review
Before signature, check that:
- a new delivery lead can understand the client boundary without reading the sales emails;
- every recurring deliverable has a frequency and acceptance owner;
- advisory, operational and assurance responsibilities are separated;
- client dependencies and missed-dependency consequences are clear;
- incident support hours and responsibilities are unambiguous;
- exclusions match the proposal and master agreement;
- scope changes have an approval route;
- the client retains ownership of risk decisions;
- the fee assumptions match the delivery effort.
A strong scope is not the longest one. It is the document the provider and client can use six months later to resolve a question about priorities, ownership or what happens next.