I talk to founders on a daily basis who are considering the vCISO versus in-house route.
If you can guaranteed commit ~30 hours of time from your team for SOC 2 and 40-60 for ISO27001 - you could do it yourself. But if you can't find that time by your deadline - it might be better just to outsource.
You can also engage them for part of the project (e.g get them for an internal audit, scoping advice, pen test, help you resolve some security tasks). This makes the engagement cheaper while still helping you move along.