vCISOs can be pretty heavy handed for a small company. Honestly, I’d push more control ownership across a few people to help delegate areas where you may not be an expert. Then leverage the Vanta community to help answer those “Easy questions”.
No certs planned, but I’m always learning.
AI Governance, Infrastructure (constant evolution), and anything to simplify and automate evidence collection are my current focus.
I’d start by doing a gap analysis of the requirements of CPRA/CCPA. I’d wager it’s easier to solo that pair first before going full US Data Privacy via Vanta - Just my $0.02.
The multiple frameworks aspect is entirely based on how many automated controls exist within their add-on frameworks. NIST-based ones have historically been lacking in automated controls, but have improved recently.