Skip to content
    August 20, 2026| Top Floor Team| 11 min read

    What Should a vCISO Deliver in the First 90 Days?

    By day 90 a competent vCISO should have handed you four things: a complete inventory of assets, vendors, and access; a risk assessment with a prioritized roadmap that carries owners and rough costs; a first tranche of closed gaps rather than identified ones; and a report you could put in front of an investor, a board, or an insurance underwriter without rewriting it.

    Those four map onto public guidance you can check the work against. NIST's Cybersecurity Framework 2.0 states the dependency in as many words: "Once assets and risks are identified and prioritized, PROTECT supports the ability to secure those assets." Be precise about what that does and does not license. NIST is describing a logical dependency, not an implementation schedule, and it is explicit on timing in the other direction: "The Functions should be addressed concurrently." So the 90-day ordering below is Top Floor's recommended sequence for an organization starting from nothing, not a NIST requirement; what the framework supplies is the reason spending money before you have an inventory tends to buy the wrong things. CISA's Cybersecurity Performance Goals 2.0, a voluntary baseline organized under the same six functions from Govern through Recover, names the specific quick wins worth closing first.

    Here is the contrarian part: almost every published 90-day plan is written to coach the incoming security leader. This one is written for the person who hired them, so it is a checklist of what to demand and when to worry.

    Below: the three gates, what each one produces, what a bad 90 days looks like from the buyer's seat, and when 90 days of security leadership is not what you should be buying at all.

    Key takeaways

    • Four artifacts by day 90: inventory, risk assessment with a costed roadmap, closed quick wins, and a board-ready report.
    • The sequence follows public guidance, so you can check it: NIST CSF 2.0 puts Govern and Identify first, and CISA's performance goals name the early controls.
    • Closed gaps, not identified gaps. A findings list at day 90 is a diagnosis presented as treatment.
    • The clearest bad signal is a deliverable set made entirely of policy documents with no owners, no dates, and no evidence that anything changed.
    • Ask for the artifacts by name in the engagement schedule before you sign, not at the first review.

    Why the buyer's version of this checklist is different

    Search for a security leader's 90-day plan and you will find plenty of good material aimed at the leader: build relationships, learn the business, do not reorganize in month one. Useful advice, and useless to you, because you cannot audit relationship-building.

    The buyer's version has to be about artifacts, because artifacts are the only thing you can inspect. A vCISO who spent 90 days having excellent conversations and produced nothing you can hand to an auditor has delivered something real and unfalsifiable, which is the same problem as delivering nothing. So the gates below are deliberately concrete, and each one has a "what worries me" test attached.

    Days 1 to 30: find out what you actually have

    The first month is discovery, and its output is an inventory in three parts.

    Assets. Every system, cloud account, repository, endpoint, and data store, with an owner. CISA's performance goals put a maintained asset inventory near the front of the list for a reason: you cannot protect, patch, or monitor what nobody has written down. Most companies discover in this exercise that they own two or three cloud accounts nobody was tracking and at least one production system whose owner left.

    Vendors. Every third party with access to your data or your systems, with what they can reach, what contract governs it, and what security evidence you hold for them. This list is almost always longer than the finance-system vendor list, because it includes the free tools individual teams adopted. Our vendor risk management guide is the longer treatment.

    Access. Who has administrative rights to what, which accounts are shared, which are service accounts, where multi-factor authentication is enforced and where it is not, and whether offboarding actually removes access. This is the part that most reliably produces an uncomfortable meeting in week three.

    Alongside the inventory, expect an early read on obligations: which frameworks apply, what customers have contractually committed you to, what regulators are in scope, and what your insurance policy requires. That last one gets skipped constantly and is exactly where overstated attestations surface, which is the subject of answering a cyber insurance questionnaire honestly.

    What worries me at day 30: a maturity score with no inventory behind it. Scores are easy to produce from an interview. An inventory takes real work, which is why its absence is diagnostic.

    Days 31 to 60: a risk assessment that makes decisions, and a roadmap with money on it

    Month two turns the inventory into a decision document. Not a heat map for its own sake: a prioritized list of what could go wrong, how bad it would be, what it would take to address, and in what order.

    Three properties separate a useful risk assessment from a decorative one.

    It is specific to you. "Ransomware" is not a risk statement. "A single shared administrative credential to the production database, with no MFA and no session logging, held by four people including one contractor" is. Generic risk registers are the tell that an assessment was assembled from a template rather than from your inventory.

    Every item has an owner and a rough cost. Owners make the roadmap executable; costs make it a budget conversation instead of a wish list. Rough is fine at this stage. Absent is not.

    It is sequenced by risk reduction per unit of effort, not by severity alone. A critical finding requiring a six-month architecture change and a moderate finding fixable in a day are not competing for the same slot, and a roadmap that sorts purely by severity will leave easy wins on the table for a quarter.

    Month two is also when the framework decision should be made and defended, if you have one pending. Which framework, what scope, what timeline, what it will cost, and what it will not cover. A vCISO who leaves that open past day 60 is deferring the decision that drives the next year of work.

    What worries me at day 60: a roadmap with no dates, no owners, and no costs. That is a findings list wearing a roadmap's clothes, and it puts every subsequent prioritization argument back on you.

    Days 61 to 90: things that are actually fixed

    The third month is where a good engagement separates itself, because the deliverable is closed gaps rather than identified ones.

    The specific set varies, but the early wins cluster around the controls that public guidance and insurance underwriting both prioritize:

    • Multi-factor authentication enforced on email, remote access, and administrative accounts.
    • Endpoint detection and response deployed and actually alerting somewhere a human looks.
    • Backups that have been restored in a test rather than merely configured.
    • End-of-life systems either replaced or explicitly isolated and accepted.
    • Offboarding that reliably removes access.
    • A written incident response plan that names people and phone numbers.

    Two things about that list are worth saying plainly. First, it is short and boring, and that is the point: the CISA performance goals exist because a small number of unglamorous controls carry a disproportionate share of the risk reduction for smaller organizations. Second, it is close to what a cyber insurer will ask you to attest to, so closing these gaps has an immediate second payoff at renewal.

    A written and exercised incident response plan belongs in this window too. Not just written: run a tabletop, even a short one, because the plan's defects only appear when someone has to use it. If your provider is advisory-only on incidents, this is the quarter to establish the responder relationship rather than during the event, which when to call an incident response firm covers in more detail.

    What worries me at day 90: everything is "in progress". Some things will be, legitimately. If nothing has closed, the engagement is producing analysis, not change.

    The fourth artifact: a report you can hand to someone else

    The last deliverable is the one buyers forget to ask for and then need urgently. By day 90 you should hold a written summary that states where the program stands, what the top risks are, what was closed in the first quarter, what the roadmap is for the next two, and what it will cost.

    The test is whether you could hand it, essentially unedited, to a board member, an investor doing diligence, an enterprise customer's security team, or an insurance underwriter. Those four audiences want the same document, and a security leader who cannot produce it is missing the part of the job that is not technical. What security posture to present, and how covers the economics that usually belong alongside it.

    When 90 days of a vCISO is not what you should buy

    Against our own interest, three cases.

    You have no obligations yet. No customer diligence, no regulator, no insurance requirement, no certification. Then a 90-day program build is premature. Spend the quarter closing the CISA baseline yourself: MFA everywhere, managed devices, tested backups, and a named owner for offboarding. Come back when something external is asking.

    You need a single certification and nothing else. Buy that as a scoped project. A 90-day leadership onboarding costs more and answers a broader question than the one you have.

    Nobody internally can execute the roadmap. A vCISO produces a plan and drives it; they do not, in a fractional engagement, personally implement most of it. If no engineering time is allocated for remediation, day 90 will produce a beautiful roadmap and a quarter of no change, and you will reasonably conclude the engagement failed when the missing input was internal capacity.

    There is a fourth case that is a different question rather than a smaller one. If what you are weighing is a compliance manager on payroll instead, the first 90 days do not compare like for like, because you are measuring a new employee's onboarding against a provider's kickoff rather than a security leader's mandate against a checklist. That comparison is worked through in hire a compliance manager or outsource, and it is the better article to read first if the decision is still headcount versus retainer.

    Where Top Floor fits

    Our vCISO engagements put the four artifacts in the schedule before signature, with the gates at 30, 60, and 90 days written as deliverables rather than as intentions, so a slipped gate is a contractual conversation and not a matter of interpretation. Where the driver is a framework rather than leadership as such, compliance as a service usually scopes it better, and where the trigger is an incident, incident response is a different engagement with a different clock.

    How to decide this week

    If you are still choosing a provider, ask each one for their first-90-days deliverable list in writing, and compare it against the four artifacts above. Then ask that the gates be written into the engagement schedule with dates.

    If you are already 90 days in, do the audit rather than the vibe check. Open the shared drive and look for the inventory, the risk assessment, the roadmap with owners and costs, the evidence that specific gaps closed, and the report. Missing one is a conversation. Missing three is a decision, and the honest version of that conversation starts with asking what got in the way, because sometimes the answer is that your team never gave them the access or the hours to work with.

    Frequently asked questions

    What should a vCISO deliver in the first 90 days?

    Four artifacts: a complete inventory of assets, vendors, and access with owners; a risk assessment specific to your environment with a prioritized roadmap carrying owners and rough costs; a first tranche of actually closed gaps rather than identified ones, typically clustered around MFA coverage, endpoint detection, tested backups, offboarding, and a written incident response plan; and a written report you could hand unedited to a board member, an investor, an enterprise customer, or an insurance underwriter. Ask for those four by name in the engagement schedule before you sign.

    Is it normal to only get policies in the first 90 days?

    It is common and it is not good. Policy documents are a legitimate part of the work and a poor summary of it, because policies without an inventory, owners, dates, and evidence of change are a statement of intent rather than a program. If day 90 produced a policy set and nothing else, ask which specific gaps were closed and which risks were assessed against your actual environment. If the answer is that the remediation work was blocked internally, that is a resourcing conversation rather than a provider failure.

    How do I know if my vCISO engagement is going badly?

    Three signals, in order of seriousness. At day 30, a maturity score or a framework gap list produced without a real asset, vendor, and access inventory behind it. At day 60, a roadmap with no owners, no dates, and no costs. At day 90, nothing closed and everything "in progress". Any single signal is worth a direct question; all three together mean the engagement is producing analysis rather than change, and the conversation should happen before renewal rather than after.

    Should the first 90 days include a penetration test?

    Usually not in the first quarter, unless a customer or a framework deadline forces it. A test run before the obvious gaps are closed spends manual testing hours rediscovering things an inventory already told you, and produces a report full of findings you had already scheduled. The better sequence is inventory, close the baseline controls, then test, so the penetration test is measuring the program you built rather than the one you inherited.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.