Published Pricing

What It Costs. Published, Not Quoted.

Most security firms make you sit through a call before they will name a number. Here is the starting price of every engagement we sell, taken from the same source as each service page, so you can work out your budget before you talk to anyone.

35 services with published prices. Every engagement is scoped and priced in writing before work begins, and you read the report before you pay.

Fixed price, in writing

Scoped and priced before kickoff. It does not move unless you change the scope.

Read it before you pay

The invoice follows delivery of the report, not the kickoff call.

Proposal in 24 hours

One scoping call, then a fixed number for your actual scope.

Security leadership

A named person accountable every month, rather than a project that ends.

ServiceStarts atBasisDetail
vCISO Services - Virtual CISO as a ServiceFrom $3,300per month · 3 tiersSee tiers

Audits and assessments

Find out where you actually stand, with evidence you can hand to a customer.

ServiceStarts atBasisDetail
Active Directory Security AssessmentFrom $5,000per engagement · 3 tiersSee tiers
Cloud Security ConsultingFrom $4,000per engagementSee tiers
Cybersecurity Maturity AssessmentFrom $4,000per engagementSee tiers
Cybersecurity Risk Assessment ServicesFrom $6,900fixed · 2 tiersSee tiers
DFNS & Stablecoin Configuration AuditFrom $30,000per engagement · 3 tiersSee tiers
GDPR Article 32 Security AssessmentFrom EUR 4,500fixed · 2 tiersSee tiers
IT Security AuditFrom $5,000per engagement · 3 tiersSee tiers
Microsoft 365 & Entra ID Security AuditFrom $1,450per project · 3 tiersSee tiers
NAID AAA Security Risk AssessmentFrom $3,500per location, per year · 2 tiersSee tiers
NIST SP 800-82 OT Security AuditFrom $18,000per site · 2 tiersSee tiers
SaaS Security AuditFrom $5,000per engagement · 2 tiersSee tiers
Vulnerability AssessmentFrom $3,500per engagementSee tiers

Penetration testing

A time-boxed attempt to break in, producing proof and attack paths.

ServiceStarts atBasisDetail
API Penetration TestingFrom $4,000per engagementSee tiers
Cloud Penetration TestingFrom $6,000per engagementSee tiers
Mobile App PentestingFrom $5,000per engagementSee tiers
Network & Infrastructure Penetration TestingFrom $5,000per engagementSee tiers
SaaS Penetration TestingFrom $6,000per engagementSee tiers
Web Application PentestingFrom $5,000per engagementSee tiers

Compliance readiness

Getting you to the point of passing someone else audit, on their deadline.

ServiceStarts atBasisDetail
CMMC Level 2 Certification ReadinessFrom $5,000per engagement · 3 tiersSee tiers
CSA STAR Level 2 ReadinessFrom $8,000per engagement · 3 tiersSee tiers
Cyber Resilience Act ReadinessFrom EUR 8,900fixed · 3 tiersSee tiers
DORA Compliance and ICT Risk Management FunctionFrom EUR 14,000single entity · 2 tiersSee tiers
eIDAS ComplianceFrom EUR 5,500per engagementSee tiers
External Data Protection Officer (DPO)From EUR 1,100per month · 2 tiersSee tiers
HITRUST CSF ReadinessFrom $9,000per engagement · 3 tiersSee tiers
ISO 27001 Internal AuditFrom $4,500per audit · 2 tiersSee tiers
ISO 27001 ReadinessFrom $8,000one-time · 3 tiersSee tiers
ISO 42001 ReadinessFrom $18,000fixed project · 2 tiersSee tiers
NIS 2 ComplianceFrom EUR 2,800per engagement · 2 tiersSee tiers
NIST 800-171 ReadinessFrom $5,700per engagement · 2 tiersSee tiers
SOC 2 ReadinessFrom $3,000per engagementSee tiers
TISAX Readiness ConsultingFrom EUR 11,000per location · 2 tiersSee tiers

Incident response and due diligence

When something has already happened, or when you are buying a company.

ServiceStarts atBasisDetail
AI Incident ResponseFrom $15,000fixed price · 3 tiersSee tiers
Cybersecurity Due DiligenceFrom $8,000per engagement · 3 tiersSee tiers

What actually changes the price

Five things move a quote. Knowing them lets you compare any two proposals properly, including ours against someone else.

01

How many people you have

Headcount drives the number of accounts, devices and systems in scope. It is the single biggest input, which is why every tier is banded by it.

02

How many environments are in scope

One cloud tenant is one price. AWS plus Azure plus an on-prem domain plus a factory network is four, and they do not share findings.

03

How many frameworks you are mapping to

SOC 2 and ISO 27001 overlap heavily, so the second one is far cheaper than the first. DORA and NIS 2 overlap on incident reporting and third-party risk. We reuse evidence across them rather than starting again.

04

Whether you want the fixes done or just named

An assessment that names the gaps costs less than an engagement that closes them with your team. Most of the price difference between our tiers is implementation, not analysis.

05

Whether someone else has set the date

A customer deadline or a regulator deadline compresses the schedule. We will say plainly if a date is not achievable rather than take the work and miss it.

When we are the wrong call

You need a certificate, not readiness. We prepare you and we sit with you through the audit, but an accredited body issues the certificate and a CPA firm signs the SOC 2 report. Any consultancy implying it does both should be asked to explain precisely how.

You want 24/7 monitoring. That is an MSSP or an MDR contract, priced per endpoint, and it is a different purchase. We will tell you which one you actually need first, because buying monitoring before you have fixed the configuration is the most common way security budget is wasted.

You are under 20 people with no compliance pressure. Start with the free configuration work. Our small business guide lists what to do yourself before paying anyone.

Pricing questions

Why does every price say "from"?

Because the honest number depends on scope, and anyone who gives you a firm figure before asking what you run is guessing, and the guess will be padded. The "from" price is the real starting point for the smallest version of that engagement. After a scoping call you get one fixed number for your actual scope.

Do you bill hourly?

No. Every engagement is scoped and priced before work begins, and the price does not move unless you change the scope in writing. No hourly billing, no scope creep, no surprise invoices.

When do I pay?

You read the report before you pay. The invoice follows delivery, not the kickoff call. That is the same on every assessment and readiness engagement we run.

What is the cheapest useful thing you sell?

A Microsoft 365 and Entra ID security audit from $1,450, or a SOC 2 readiness assessment from $3,000. Both give you a defensible answer to "are we secure" without committing to a programme.

How fast can you start?

A scoping call within a few days, a fixed-price proposal within 24 hours of that call, and kickoff as soon as you approve it. An IT security audit then delivers in 14 days.

Is a retainer cheaper than a project?

Per hour, yes. But buy a retainer only when you need decisions made continuously, which usually starts somewhere between 50 and 500 staff. Below that, a project plus a fix list is normally better value.

Get your number

One call to understand what you run, then a fixed-price proposal within 24 hours. If the honest answer is that you do not need us yet, you will get that instead.

  • Fixed price agreed in writing before work starts
  • You read the report before you pay
  • Led personally by a CISSP, CEH, CHFI and Mandiant certified consultant