Technical evaluation

vCISO Lite versus RealCISO

Both platforms publish pricing. RealCISO ships a free tier, Cleo AI Agent (chatbot), an A-LIGN auditor partnership, and a white-label MSP platform — Enterprise at $4,167/mo. vCISO Lite ships 250+ SCF-cross-mapped frameworks, Trustworthy Autonomy, Evidence Graph, APRI, and productized services on the same SKU — Enterprise at $8,500/mo flat MSRP.

Prepared
Method
Capability walk against RealCISO’s published product surface (realciso.io, realciso.io/grc-platform/, realciso.io/assessments/, realciso.io/reports/) and vCISO Lite’s live platform. Both vendors’ pricing pages and third-party sources (Tracxn, G2, SourceForge) consulted for corporate + analyst context.
Sources
realciso.io/grc-platform/, realciso.io/assessments/, realciso.io/reports/, realciso.io/why-is-realciso-the-best-cyber-risk-assessment-platform/, vcisolite.com/features/compliance, vcisolite.com/services, vcisolite.com/pricing. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where RealCISO leads

  • Free-forever tier. $0 with 1 environment + watermarked report + Cleo credits.[1] vCISO Lite’s floor is $299/mo. Best answer for a $0 SMB first-assessment on-ramp.
  • Half our Enterprise price. $4,167/mo (Continuous Compliance + TPRM bundled) vs vCISO Lite $8,500/mo. §6 walks what the $52K/yr delta buys.
  • A-LIGN partnership. Named auditor seat in-platform.[6] vCISO Lite works with any auditor, no branded partnership.
  • White-label vCISO Platform for MSPs. Consultant License + $42/client/mo.[5] vCISO Lite has no MSP program today.

Where vCISO Lite leads

  • 250+ SCF-cross-mapped frameworks, 1,468 universal controls — 10x RealCISO’s 25+.[3] Every SCF-mapped control unlocks every framework that shares it.
  • APRI does what Cleo does — plus more, with governance Cleo doesn’t document. Same chatbot category. APRI adds end-to-end vendor questionnaires with cited evidence, board-pack PDFs, Linear-ticket remediation plans, SOC 2 readiness PDFs, vendor risk re-scoring, M&A data rooms. Caller-entitlement scoped, complete tool-call audit trail, observe-first with confirmation gates. Live MCP endpoint at mcp.vcisolite.com for Claude + Cursor.[2] §4.1 unpacks.
  • Trustworthy Autonomy — a category RealCISO doesn’t compete in. Cleo drafts, humans execute. Trustworthy Autonomy takes governed autonomous action; every action recorded to the Evidence Graph. Public beta 2026-07-07; Level 1 governance proven prod 2026-08-17. §4.2 unpacks.
  • Evidence Graph — externally-anchored, not snapshot. Per-event Ed25519 signing + RFC-3161 external timestamp anchor + transparency log live prod 2026-08-20. Auditor re-derives the chain without trusting the platform. RealCISO’s SHA-256 manifests are snapshot integrity, verified inside RealCISO.[4]
  • Evidence Graph SDK is licensable. Embed the same integrity in a partner product, internal system, or insurance pipeline. Optionality RealCISO doesn’t offer.
  • QCD / M&A methodology. Five-pillar CCOD probability-weighted loss quantification. No RealCISO equivalent.
  • Productized services on the same SKU. vCISO Services, Third-Party Risk Questionnaires, Compliance Kickstart, Quarterly Review, retainer — on the subscription.[5] RealCISO doesn’t deliver managed advisory; their vCISO Platform is for MSPs/consultants to deliver on top.
  • Founder-direct. [email protected] reaches the founder, not an SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
SMB and mid-market operators (25–1,500 employees) evaluating a platform-augmented vCISO product where compliance + AI-agent-in-prod + evidence integrity + productized services are on the same subscription. Direct-to-customer buyers, not MSPs or independent consultants looking for a white-label vCISO Platform to resell (RealCISO wins that segment; vCISO Lite has no MSP program today).
Evaluation frame
Ten capability categories the SMB and mid-market platform-augmented-vCISO buyer typically weighs. Not: everything each product does.
Comparison basis
Published product documentation, live product surfaces, both vendors’ pricing pages, and third-party corporate/analyst sources (Tracxn, G2, SourceForge). Not: analyst reports behind Gartner’s paywall, vendor-sponsored bakeoffs, or internal-only NDA material.

Out of scope

MSP channel
RealCISO’s Consultant License + $42/client/mo vCISO Platform is purpose-built for MSPs / MSSPs / vCISO consultants; this page does not litigate that segment. If channel-first go-to-market is a hard requirement, RealCISO is the specialist. vCISO Lite operates direct-to-customer today.
$0-cost first-assessment on-ramp
RealCISO Free is a real product and a real answer for SMB buyers who want a $0 assessment path. vCISO Lite’s floor is $299/mo. This page does not litigate whether Free is a viable long-term basis for a real audit; it is not, but it is a viable exploration path.
Roadmap
Only shipped, generally-available or public-beta capability is compared. Private-preview capabilities are footnoted where public.

Capability coverage

Ten capabilities§3

Amber = RealCISO ships it. Teal = vCISO Lite ships it. Split = both ship it (weighted when one is materially stronger). Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Same slots on both cards so the reader can eye-compare row by row. Framework decomposition lives in §5; full pricing anatomy in §6.

REALCISO · CLEO AI AGENTReads evidence · drafts answersRecommends fixesEmbedded in RealCISO workflowTrace format not publicly documented.Entitlement / authority model: not disclosed.vCISO LITE · APRIReads evidence · drafts answers (cited)Recommends fixesCompletes vendor questionnaires end-to-endGenerates board reports (PDF + presenter)Opens remediation plans in LinearSOC 2 readiness · vendor re-scoring · M&A roommcp.vcisolite.com · live in Claude + CursorCaller-entitlement scoped · every tool call recordedObserve-first · confirmation gate on writesSeparate category: Trustworthy Autonomy (autonomous execution) — us-only, RealCISO has no equivalent. See §4.2 below.
Both ship a chatbot. APRI covers more surface than Cleo, with governance guarantees Cleo doesn’t document.§4.1 below unpacks the capability delta. Autonomous execution (Trustworthy Autonomy) is a separate category — RealCISO has no equivalent. §4.2 covers it.
§4.1

Conversational AI assistant (chatbot / advisory surface)

Both ship a chatbot. Same category. APRI covers everything Cleo does and more, plus three architectural guarantees Cleo does not document.

RealCISO Cleo AI Agent

Reads evidence, drafts assessment answers, recommends fixes. Embedded in the RealCISO workflow.

Inputs
Evidence uploads, framework metadata, prior assessment answers, control-mapping context.
Outputs
Draft answers · fix recommendations · executive summaries.
Evidence
Cleo actions logged inside RealCISO; trace format not publicly documented. Entitlement / authority model not disclosed.
Fails when
Buyer needs full end-to-end questionnaire completion, board-report generation, Linear-ticket remediation plans, M&A data-room assembly, or an MCP endpoint exposing the assistant to Claude / Cursor / custom agents.
vCISO Lite APRI

APRI (AI-Powered Risk Intelligence) — MCP tool graph + evidence-backed answer surface. Everything Cleo does, plus: full CAIQ/SIG/custom questionnaire completion end-to-end with cited evidence; board reports (scan trends + finding severity, PDF + presenter); remediation plans opened as Linear tickets with owners + ETAs; SOC 2 readiness summaries mapped to Trust Service Criteria; vendor risk re-scoring; M&A data-room assembly (cross-framework evidence pack + scoped watermarked viewing rooms).

Inputs
Natural-language queries, uploaded questionnaires, scanner + policy state, evidence chain, MCP tool calls from external agents.
Outputs
Cited answers · questionnaire responses · board-pack PDFs · remediation Linear tickets · SOC 2 readiness PDFs · vendor tier changes · scoped M&A data rooms.
Evidence
Three architectural guarantees: (1) caller-entitlement scoped (APRI uses your entitlements, not a service account — if the user cannot see a record, neither can the agent acting on their behalf); (2) every tool call, parameter, and result recorded to the audit trail — replayable, exportable, addressable; (3) observe-first by default (writes go through a confirmation gate). MCP endpoint (OAuth 2.1 + PKCE) exposes APRI to Claude / Cursor / custom agents; also an in-app side-panel copilot.
Fails when
Buyer specifically wants Cleo's tighter embedding inside RealCISO's own workflow UI (APRI is architecturally external-first via MCP; the in-app copilot is a companion surface, not the primary one).
§4.2

Autonomous execution layer (governed action, separate from the chatbot)

This is a different category from §4.1. The chatbot drafts; the execution layer takes governed action. RealCISO does not ship in this category — a human executes what Cleo drafts. vCISO Lite ships Trustworthy Autonomy here.

RealCISO

Not offered. RealCISO's model is Cleo drafts + human executes. There is no autonomous-execution layer.

Inputs
N/A
Outputs
N/A
Evidence
N/A — the human on {company}'s team or an outside vCISO consultant is the executor of record.
Fails when
Buyer needs the AI to take action against controls (not just draft), with an evidence chain any auditor can independently verify.
vCISO Lite Trustworthy Autonomy

Autonomous operations layer of vCISO Lite, running on the Evidence Graph. Public beta since 2026-07-07. Level 1 agent governance proven in production 2026-08-17.

Inputs
Agent action requests · policy state · framework-control mapping · evidence chain state.
Outputs
Signed authorization decision per action · agent execution · evidence-chain record before AND after the action.
Evidence
Every autonomous action recorded to the Evidence Graph; published evaluation harness grades the agent by task category with pass rates + failure cases visible pre-purchase. Trace format and Evidence Graph anchor mechanism published.
Fails when
Buyer needs GA (not public-beta) autonomous action at trust-ladder rung 2 (scoped autonomy) or rung 3 (goal-oriented) today — those reach GA H1 2027 and H2 2027+ respectively. RealCISO does not compete in this category regardless.
§4.3

Framework corpus depth

RealCISO publishes 25+ frameworks; vCISO Lite covers those 25+ plus the rest of the SCF universe.

RealCISO

289-question assessment library mapped to 25+ named frameworks: SOC 2, NIST CSF 2.0, ISO/IEC 27001:2022, HIPAA, CMMC 2.0 L1/L2, NIST SP 800-171 Rev 3 with SPRS scoring, NIST 800-53, CIS Controls v8, PCI DSS, FedRAMP, NIST RMF, NIST AI RMF, SEC cybersecurity rules, plus additional privacy regulations.

Inputs
Assessment answers · uploaded evidence · integration-collected signals (15 integrations, 386 automated tests refreshed every 12 hours).
Outputs
Maturity L1–L5 scoring per control · gap identification · audit-readiness readout.
Evidence
Cross-framework mapping inside RealCISO's control model.
Fails when
Buyer's program touches frameworks not on RealCISO's published 25+ list (HITRUST, CJIS, DORA, NYDFS Part 500, NIS2, EU AI Act, ISO 42001 as a standalone standard, LGPD, PIPEDA, StateRAMP, and much of the SCF universe).
vCISO Lite

250+ SCF-cross-mapped frameworks (1,468 universal controls), built on the Secure Controls Framework (SCF) crosswalk auditors already recognize. Every SCF-mapped control unlocks the frameworks that share it.

Inputs
Assessment answers · evidence artifacts · scanner findings · policy decisions · auditor observations.
Outputs
Per-framework readiness signal · cross-framework reuse badges · roadmap prioritization by control-impact breadth · SCF-domain × evidence-strength heatmap.
Evidence
SCF crosswalk propagation writes credit against every framework that maps to the same universal control.
Fails when
Buyer needs a framework not currently in the SCF corpus (rare; most jurisdictional frameworks are already mapped) — custom framework build available.
§4.4

Evidence integrity substrate

The question an auditor / insurer / regulator will ask about the evidence after the fact. The chain that answers it has to be re-derivable without trusting the platform that produced it.

RealCISO

SHA-256 manifests + versioned edit history + sealed revision numbers. Snapshot integrity, verified inside RealCISO's platform.

Inputs
Uploaded evidence artifacts, control mappings, assessment answers.
Outputs
Manifest hash · immutable edit trail · sealed revision numbers.
Evidence
Log entries in RealCISO's proprietary store; verification requires trusting RealCISO's own reporting.
Fails when
Adversarial auditor asks to verify the chain independently without relying on RealCISO's attestation.
vCISO Lite

Evidence Graph — hash-chained records anchored to an external RFC-3161 timestamp authority. Per-event Ed25519 signing shipped 2026-08-16; transparency log + receipts live in production since 2026-08-20.

Inputs
Every agent action, evidence artifact, policy decision, and framework mapping.
Outputs
Sealed evidence chain · external timestamp attestation · re-derivable proof.
Evidence
Auditor re-derives the chain against the RFC-3161 attestation record; verification does not depend on trusting vCISO Lite.
Fails when
Buyer's existing audit tooling has not been briefed on RFC-3161 verification; onboarding the audit firm to the chain takes one call.
REALCISOEvidence artifact + editSHA-256Manifest + edit historysealed revision numbers, immutable logexportAuditor reads manifestVerification requires trusting RealCISO.vCISO LITE · EVIDENCE GRAPHEvidence artifact + editEd25519 signHash-chained recordevery block links to the prior hashRFC-3161 anchorre-deriveAuditor verifies chainagainst external anchor recordVerification does not require trusting vCISO Lite.
Snapshot integrity vs external-anchored chain.RealCISO’s SHA-256 manifests + immutable edit history are real snapshot integrity, verified inside their platform. The Evidence Graph writes per-event Ed25519 signatures + hash-chained records anchored to an external RFC-3161 timestamp authority; an auditor who distrusts the platform can independently re-derive the chain. This is an integrity-model distinction — not a capability list.
§4.5

Services on the same SKU vs Consultant License + $42/client model

Both are platform-augmented vCISO products. The difference is who delivers the vCISO service.

RealCISO

RealCISO the company does not deliver managed vCISO advisory itself. The vCISO Platform is sold to MSPs / MSSPs / vCISO consultants at Consultant License + $42/client/mo — the MSP or consultant delivers the vCISO service on top.

Inputs
Consultant's assessments, evidence collections, framework work.
Outputs
Multi-tenant dashboard for the consultant; MSP-owned client billing.
Evidence
Consultant's delivered work product; consultant's own advisory contract with the end client.
Fails when
Buyer wants one vendor for platform AND service — they'd need to contract RealCISO GRC separately from an MSP or independent vCISO using RealCISO's vCISO Platform.
vCISO Lite

Productized vCISO services on the same subscription as the platform. One vendor, one contract, one SKU.

Inputs
Service engagements: vCISO Services (advisory), Third-Party Risk Questionnaires (CAIQ / SIG / custom completion, evidence assembly, buyer Q&A handling, answer library, SLA on first draft), Compliance Kickstart (gap analysis + framework mapping + full audit preparation), Quarterly vCISO Review, ongoing retainer.
Outputs
Advisor cadence · Compliance Kickstart deliverables · questionnaire responses at agreed SLA · Quarterly Review board pack.
Evidence
Every service engagement writes to the Evidence Graph; advisor decisions are audit-traced.
Fails when
Buyer specifically wants an MSP-branded delivery model (RealCISO wins there) or already has a preferred external vCISO firm they want to keep using.
§4.6

Auditor collaboration model

How the auditor is invited into the platform, what they see, and whether their observation trail is captured on the shared chain.

RealCISO

A-LIGN partnership — direct-in-platform auditor seat. Named partnership; A-LIGN is a Big-Compliance CPA/QSA firm.

Inputs
Auditor observations, findings, evidence requests.
Outputs
Auditor-visible evidence + control mapping in RealCISO's platform.
Evidence
A-LIGN sees RealCISO's manifest + edit history; branded partnership shortens the vendor onboarding on A-LIGN's side.
Fails when
Buyer's audit firm is not A-LIGN — the named partnership doesn't apply; auditor onboarding follows RealCISO's generic auditor-invite path.
vCISO Lite

Magic-link auditor invite + TOTP on first login, no account in the customer tenant. Auditor + Trace lenses over one sealed Evidence Graph. Works with any audit firm.

Inputs
Any auditor (Big-4, mid-size CPA, QSA, PCAOB-registered, boutique).
Outputs
Cross-framework reuse badges on every evidence record. Type I vs Type II observation window on the graph. Q&A threads scoped to control or evidence record.
Evidence
Every auditor observation writes to the Evidence Graph; audit-trail integrity independent of vendor relationship.
Fails when
Buyer requires a branded-partner-firm relationship for procurement reasons (A-LIGN specifically) — vCISO Lite has no equivalent named partnership.

Framework & control coverage

Framework depth§5

RealCISO publishes 25+ frameworkson its pricing / assessments page — SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC L1/L2, NIST 800-171 Rev 3 + SPRS, NIST 800-53, FedRAMP, NIST RMF, NIST AI RMF, SEC cyber rules, plus additional privacy. vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls). The gap-fill frameworks vCISO Lite covers natively are highlighted below.

RealCISO[3]

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & sales motion

How each is bought§6

Two facing pricing stacks — the way a CFO reads a comparison. Amber column is RealCISO; teal column is vCISO Lite. Both publish; the sharpest question on this page is what the $52,000/yr Enterprise-tier delta buys.

RealCISO

$0 / mo

Enterprise tier · published on realciso.io/grc-platform/

Sales channel
Direct (self-serve on the pricing page) + MSP channel via vCISO Platform
Free tier
Yes — $0 forever, 1 environment, watermarked report, Cleo credits
Published tiers
Free · Essentials $300/mo · Professional $1,250/mo · Enterprise $4,167/mo · Enterprise Plus custom
MSP model
Consultant License + $42/client/mo · multi-tenant · white-label
Enterprise inclusions
3 environments · unlimited framework sets/members · dedicated CS manager · 99.9% SLA · Continuous Compliance + TPRM included
Add-ons
Continuous Compliance $100/mo · TPRM $100/mo · extra environment $5,000/yr
Managed vCISO advisory hours
Not delivered by RealCISO · MSP or consultant delivers on top
Named auditor partnership
A-LIGN direct-in-platform seat
Sales cycle
Self-serve signup on published tiers · Enterprise Plus contact-sales
vCISO Lite

$0 / mo

Enterprise tier · bundles Trustworthy Autonomy + Evidence Graph + APRI + services in-SKU

Sales channel
Direct · founder-accessible
Free tier
No · floor is $299/mo Starter
Published tiers
Starter $299/mo · Growth $599/mo · Business $999/mo · Ultra $1,499/mo · Enterprise $8,500/mo flat MSRP
MSP model
Not offered today · MSP program in evaluation
Enterprise inclusions
Trustworthy Autonomy + Evidence Graph + APRI + productized vCISO Services (advisory, Third-Party Risk Questionnaires, Compliance Kickstart, Quarterly Review, retainer) + 250+ SCF-cross-mapped frameworks
Add-ons
Per-action pricing on Trustworthy Autonomy pending (~$1.50–$2 per resolved action; not enforced during public beta)
Managed vCISO advisory hours
Yes · productized on the same subscription
Named auditor partnership
No · works with any audit firm via magic-link + TOTP invite
Sales cycle
Enterprise: one call · flat MSRP on file

Integration surface

Native connectors§7

RealCISO publishes 15 integrations, 386 automated tests refreshed every 12 hours. vCISO Lite’s full catalog on /features/integrations. Tables below list named integrations from both vendors’ public product pages.

IntegrationRealCISOvCISO Lite
AWSNativeNative
AzureNativeNative
GCPNativeNative
GitHubNativeNative
GitLabNative
Google WorkspaceNativeNative
Microsoft 365NativeNative
OktaNativeNative
JiraNativeNative
SlackNativeNative
ServiceNowNative
MCP (Model Context Protocol)Native
OpenAINative
AnthropicNative
Automated tests published?386 refreshed every 12 hoursContinuous — refresh cadence per integration

Deployment, data, extensibility

Platform architecture§8
AttributeRealCISOvCISO Lite
Service modelSaaS multitenant · Enterprise Plus offers DoD on-prem optionSaaS multitenant · Enterprise-tier isolated deployment on request
Data residencyNot publicly disclosed for standard tiers · Enterprise Plus DoD on-premUS (primary)
Tenant isolationLogical multitenant · dedicated environments at higher tiersLogical (row-level org scoping)
Public APIPublicly disclosed on pricing page: 15 integrations + 386 automated tests · full API spec not publishedREST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0
SSO / SCIMAvailable at higher tiers · specifics not publicly disclosedSAML 2.0 · OIDC · SCIM 2.0
Audit-trail modelSHA-256 manifest + versioned edit history + sealed revision numbers · platform-internal · exportableEvidence Graph · hash-chained per-event · Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Conversational AI assistant (chatbot)Cleo AI Agent · reads evidence, drafts answers, recommends fixes · embedded in RealCISO workflow · shipped GAAPRI (AI-Powered Risk Intelligence) · everything Cleo does PLUS end-to-end questionnaire completion · board-pack PDFs · remediation issues opened in Linear with owners + ETAs · SOC 2 readiness summaries · vendor risk re-scoring · M&A data rooms · caller-entitlement scoped · every tool call recorded · observe-first · MCP endpoint (OAuth 2.1 + PKCE) for Claude / Cursor / custom agents
Autonomous execution layerNot offered · Cleo drafts, human executesTrustworthy Autonomy (public beta 2026-07-07) · governed autonomous action · Level 1 agent governance proven in prod 2026-08-17 · published evaluation harness · trace format published
Managed vCISO services delivered by vendorNo · vCISO Platform sold to MSPs / consultants (Consultant License + $42/client/mo) to deliver on topYes · vCISO Services + TPR Questionnaires + Compliance Kickstart + Quarterly Review + retainer, all on the same SKU
Own complianceNot publicly disclosed on pages fetchedSOC 2 Type II · ISO 27001 (in progress) · runs on itself

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite over RealCISO

A PDF business case, personalized to your company, that lays out the three options, the cost math, and the honest tradeoffs — the argument you need to attach to a budget request or take into a vendor-selection meeting. Written to be credible with a buyer who's already priced RealCISO Enterprise at $50K/yr and needs to see what the delta actually buys.

View pricing

Notes & sources

Provenance§10
  1. [1] RealCISO published pricing tiers ($0 Free / $300/mo Essentials / $1,250/mo Professional / $4,167/mo Enterprise / custom Enterprise Plus) and Consultant License + $42/client/mo for the MSP vCISO Platform from realciso.io/grc-platform/ (accessed 2026-09-14). Add-ons: Continuous Compliance $100/mo · TPRM $100/mo · extra environment $5,000/yr.
  2. [2] RealCISO Cleo AI Agent (reads evidence, drafts assessment answers, recommends fixes) surface from realciso.io/ and realciso.io/assessments/ (accessed 2026-09-14). Cleo trace format not publicly documented on pages fetched today.
  3. [3] RealCISO framework list (25+ named: SOC 2, NIST CSF 2.0, ISO/IEC 27001:2022, HIPAA, CMMC L1/L2, NIST SP 800-171 Rev 3 + SPRS, NIST 800-53, CIS Controls v8, PCI DSS, FedRAMP, NIST RMF, NIST AI RMF, SEC cybersecurity rules, plus additional privacy) from realciso.io/ and realciso.io/assessments/ (accessed 2026-09-14). vCISO Lite framework depth (250+ SCF-cross-mapped, 1,468 universal controls) verified against live vcisolite.com/features/compliance— “We cover 250+ frameworks out of the box” and “Every framework runs off the same set of 1,468 universal controls”.
  4. [4] RealCISO evidence integrity model (SHA-256 manifest with sealed revision numbers, immutable edit history) from realciso.io/assessments/ and realciso.io/reports/ (accessed 2026-09-14). vCISO Lite Evidence Graph: per-event Ed25519 signing shipped 2026-08-16; hash-chained records anchored to an external RFC-3161 timestamp authority; transparency log + receipts live in production since 2026-08-20.
  5. [5] RealCISO vCISO Platform (multi-tenant, white-label, Consultant License + $42/client/mo) is sold to MSPs / MSSPs / vCISO consultants to deliver vCISO services to their end clients. Per RealCISO’s own materials, RealCISO the company does not deliver managed vCISO advisory itself. vCISO Lite productized services (vCISO Services · Third-Party Risk Questionnaires with CAIQ/SIG/custom completion + evidence assembly + buyer Q&A handling + SLA on first draft · Compliance Kickstart with gap analysis + framework mapping + full audit preparation · Quarterly vCISO Review · ongoing retainer) from vcisolite.com/services/vciso.
  6. [6] RealCISO A-LIGN partnership (direct-in-platform auditor seat) named on realciso.io/ and realciso.io/assessments/ (accessed 2026-09-14).
  7. RealCISO peer-review awards (G2 Summer 2026 High Performer, SourceForge Summer 2026 Leader, self-claimed “#1 vCISO platform (Summer 2026)” on G2, 4.8/5 across 223 SourceForge reviews) claimed on the RealCISO homepage. Peer-review recognition, not tier-1 analyst (Gartner MQ / Forrester Wave / IDC MarketScape) — no such tier-1 placement surfaced on any RealCISO page fetched today.
  8. RealCISO corporate state (founded 2020, Boston, 9 employees per Tracxn as of 2026-08-31) — Tracxn treats RealCISO as an independent company; whether it is a wholly-owned subsidiary of SideChannel Inc. (SDCH, publicly traded) in 2026 is not statedon any RealCISO page or SEC filing fetched today, and is flagged as unverified. Brian Haugli is listed as CEO & Co-Founder on realciso.io/about and is also founder/CEO of SideChannel; Nick Hnatiw is CTO & Co-Founder. Tracxn lists four co-founders including Matt Farry (as CEO) and Akash Desai (as CRO) alongside Haugli and Hnatiw — this reconciliation gap is flagged as unverified.
  9. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. RealCISO’s product surface is evolving; capabilities may have shipped since. Corrections: /contact.
  10. This page does not compare against Vanta, Drata, Sprinto, Secureframe, Thoropass, Hyperproof, Cynomi, or CyberSaint on their own merits — each has its own head-to-head brief under /compare. For AI Governance vendor comparisons (Credo AI, OneTrust, Holistic AI), see /vs/credo-ai et al.