The six artifacts a vCIO practice actually produces
Everything else is either an input to one of these or a meeting about one of these. If a deliverable is not on this list and not feeding one, ask why the client is paying for it.
- The quarterly business review: the meeting artifact. An executive summary in the client's language, a graded environment, the quarter's service performance, the decisions being asked for, and the status of last quarter's decisions.
- The technology roadmap: a dated, costed sequence of projects across the next 12 to 36 months, with the business reason for each one written next to it.
- The IT budget: opex and capex phased by quarter, with hardware refresh, licence renewals and planned projects on one sheet the client's finance person can read.
- The risk register: the open risks in the environment, each with an owner, a severity, and either a remediation date or an explicit client acceptance.
- The standards audit: the environment measured against your own baseline of what a client should have, which is what turns a subjective recommendation into a defensible one.
- The asset lifecycle plan: what is out of warranty, what ages out this year and next, and the budget consequence of each.
The cadence each artifact runs on
A vCIO practice fails on cadence more often than on content. Fixing the cadence is usually a scheduling problem, not a capability problem.
- Quarterly business review: quarterly for strategic accounts, twice yearly for mid-tier, annually for the long tail. Trying to run every client quarterly is the most common reason a practice collapses in its first year.
- Technology roadmap: reviewed at every QBR, rebuilt annually. A roadmap that never changes was never real.
- IT budget: built annually in the client's budget season, revisited at each quarterly review when a project moves.
- Risk register: reviewed quarterly, updated whenever a material change lands. This is the artifact most likely to matter in an incident.
- Standards audit: annually, or after any significant environment change. Running it more often produces noise rather than insight.
- Asset lifecycle plan: refreshed every quarter from live warranty and age data, because it moves on its own whether you look at it or not.
Where the hours actually go
The reason vCIO practices quietly stop happening is that the preparation is invisible in the schedule while the meeting is visible. These are working ranges to model against, not published benchmarks.
- Data collection: pulling ticket volumes, response and resolution times, SLA attainment, asset ages and warranty status. Commonly two to four hours per client per quarter when done by hand, and close to zero when computed from the PSA.
- Deck assembly: rebuilding the same slide structure with this quarter's numbers. Commonly two to three hours, and the single most automatable block on this list.
- Reconstructing last quarter: finding what was recommended, what was approved, and what got done. Commonly one hour, and it is pure waste: it exists only because nothing recorded the decisions.
- Analysis and recommendation: deciding what the numbers mean and what to propose. Commonly one to two hours, and this is the part clients pay for.
- The meeting itself: 45 to 60 minutes, plus follow-up.
- The honest total: six to ten hours per client per quarter, of which two to four are judgement and the rest is assembly.
Which deliverables can be computed and which cannot
This distinction decides what you can put a tool in front of and what will always cost you a person's attention.
- Computable from the PSA and RMM: ticket volume, response and resolution times, SLA attainment, asset age, warranty expiry, refresh budget arithmetic, licence counts. These are arithmetic on data you already hold and should never be retyped.
- Computable with a template: the standards audit, once your baseline is written down. The baseline is judgement, applying it is mechanical.
- Not computable: what to recommend and in what order, how to say it to this particular client, and what the business is trying to do next year. No tool produces these and any tool that claims to is generating text, not advice.
- The practical split: automate the first two so the vCIO's hours land on the third.
How many clients one vCIO can carry
At six to ten hours per client per quarter, a full-time vCIO with 25 hours a week of genuinely available time can carry somewhere between 30 and 50 clients on a quarterly cadence, and that assumes the assembly work is largely removed. With manual preparation the realistic number is closer to 15 to 20 before quality drops or reviews start slipping. If your ratio is worse than that, the constraint is almost always preparation time rather than the vCIO. That is a tooling problem with a known fix, not a hiring problem.
Packaging vCIO services so clients will buy them
Three approaches work, and they fail in different ways.
- Included in the managed services agreement: highest adoption because there is nothing to sell, but the work is invisible and the first thing dropped when the team is busy. If you do this, put the review cadence in the contract so it is a commitment rather than an intention.
- A separate retainer line: makes the value visible and the work defensible, but you have to sell it, and clients who decline it are the ones who most need it.
- Tiered by account: quarterly reviews and a full roadmap for strategic accounts, an annual review for the rest. This matches where the revenue actually is and is the model most MSPs converge on after trying the other two.
Keep recommendations reviewed and evidence explicit
QBR Studio computes service metrics and drafts client-facing summaries from connected data. Your MSP reviews the evidence, chooses every recommendation, and approves the final report before a client sees it.
What MSP teams usually ask
What services does a vCIO provide?
Six artifacts: the quarterly business review, a technology roadmap, an IT budget, a risk register, a standards audit against your own baseline, and an asset lifecycle plan. Everything else a vCIO does is either an input to one of those or a conversation about one of them.
How many hours does a vCIO spend per client?
Working ranges from MSP practice put it at six to ten hours per client per quarter on a quarterly cadence. Roughly two to four of those hours are judgement and the remainder is data collection and deck assembly, which is why the ratio improves so sharply when the assembly is computed rather than typed.
How many clients can one vCIO handle?
Roughly 30 to 50 on a quarterly cadence when preparation is automated, and closer to 15 to 20 when reviews are built by hand. If your number is at the low end, look at preparation time before you look at headcount.
Should vCIO services be included or charged separately?
Both work. Including it in the agreement gets the highest adoption and the lowest visibility. Charging separately makes the value explicit but has to be sold. Most MSPs end up tiering by account: quarterly reviews and a roadmap for strategic clients, annual reviews for the rest.
What is the difference between a vCIO and an account manager?
An account manager owns the commercial relationship: renewals, satisfaction, escalations, growth. A vCIO owns the technology decisions: the roadmap, the budget, the risk register and the standards. In small MSPs one person does both, which works until the technology decisions start losing to the commercial ones.
Do I need vCIO software to deliver these?
No, and plenty of MSPs deliver good reviews from a spreadsheet and a deck template. What software changes is the hours: the computable half of the list stops costing preparation time. The judgement half is unaffected, and any tool suggesting otherwise is worth distrusting.