What It Costs. Published, Not Quoted.
Most security firms make you sit through a call before they will name a number. Here is the starting price of every engagement we sell, taken from the same source as each service page, so you can work out your budget before you talk to anyone.
35 services with published prices. Every engagement is scoped and priced in writing before work begins, and you read the report before you pay.
Fixed price, in writing
Scoped and priced before kickoff. It does not move unless you change the scope.
Read it before you pay
The invoice follows delivery of the report, not the kickoff call.
Proposal in 24 hours
One scoping call, then a fixed number for your actual scope.
Security leadership
A named person accountable every month, rather than a project that ends.
| Service | Starts at | Basis | Detail |
|---|---|---|---|
| vCISO Services - Virtual CISO as a Service | From $3,300 | per month · 3 tiers | See tiers |
Audits and assessments
Find out where you actually stand, with evidence you can hand to a customer.
| Service | Starts at | Basis | Detail |
|---|---|---|---|
| Active Directory Security Assessment | From $5,000 | per engagement · 3 tiers | See tiers |
| Cloud Security Consulting | From $4,000 | per engagement | See tiers |
| Cybersecurity Maturity Assessment | From $4,000 | per engagement | See tiers |
| Cybersecurity Risk Assessment Services | From $6,900 | fixed · 2 tiers | See tiers |
| DFNS & Stablecoin Configuration Audit | From $30,000 | per engagement · 3 tiers | See tiers |
| GDPR Article 32 Security Assessment | From EUR 4,500 | fixed · 2 tiers | See tiers |
| IT Security Audit | From $5,000 | per engagement · 3 tiers | See tiers |
| Microsoft 365 & Entra ID Security Audit | From $1,450 | per project · 3 tiers | See tiers |
| NAID AAA Security Risk Assessment | From $3,500 | per location, per year · 2 tiers | See tiers |
| NIST SP 800-82 OT Security Audit | From $18,000 | per site · 2 tiers | See tiers |
| SaaS Security Audit | From $5,000 | per engagement · 2 tiers | See tiers |
| Vulnerability Assessment | From $3,500 | per engagement | See tiers |
Penetration testing
A time-boxed attempt to break in, producing proof and attack paths.
| Service | Starts at | Basis | Detail |
|---|---|---|---|
| API Penetration Testing | From $4,000 | per engagement | See tiers |
| Cloud Penetration Testing | From $6,000 | per engagement | See tiers |
| Mobile App Pentesting | From $5,000 | per engagement | See tiers |
| Network & Infrastructure Penetration Testing | From $5,000 | per engagement | See tiers |
| SaaS Penetration Testing | From $6,000 | per engagement | See tiers |
| Web Application Pentesting | From $5,000 | per engagement | See tiers |
Compliance readiness
Getting you to the point of passing someone else audit, on their deadline.
| Service | Starts at | Basis | Detail |
|---|---|---|---|
| CMMC Level 2 Certification Readiness | From $5,000 | per engagement · 3 tiers | See tiers |
| CSA STAR Level 2 Readiness | From $8,000 | per engagement · 3 tiers | See tiers |
| Cyber Resilience Act Readiness | From EUR 8,900 | fixed · 3 tiers | See tiers |
| DORA Compliance and ICT Risk Management Function | From EUR 14,000 | single entity · 2 tiers | See tiers |
| eIDAS Compliance | From EUR 5,500 | per engagement | See tiers |
| External Data Protection Officer (DPO) | From EUR 1,100 | per month · 2 tiers | See tiers |
| HITRUST CSF Readiness | From $9,000 | per engagement · 3 tiers | See tiers |
| ISO 27001 Internal Audit | From $4,500 | per audit · 2 tiers | See tiers |
| ISO 27001 Readiness | From $8,000 | one-time · 3 tiers | See tiers |
| ISO 42001 Readiness | From $18,000 | fixed project · 2 tiers | See tiers |
| NIS 2 Compliance | From EUR 2,800 | per engagement · 2 tiers | See tiers |
| NIST 800-171 Readiness | From $5,700 | per engagement · 2 tiers | See tiers |
| SOC 2 Readiness | From $3,000 | per engagement | See tiers |
| TISAX Readiness Consulting | From EUR 11,000 | per location · 2 tiers | See tiers |
Incident response and due diligence
When something has already happened, or when you are buying a company.
What actually changes the price
Five things move a quote. Knowing them lets you compare any two proposals properly, including ours against someone else.
How many people you have
Headcount drives the number of accounts, devices and systems in scope. It is the single biggest input, which is why every tier is banded by it.
How many environments are in scope
One cloud tenant is one price. AWS plus Azure plus an on-prem domain plus a factory network is four, and they do not share findings.
How many frameworks you are mapping to
SOC 2 and ISO 27001 overlap heavily, so the second one is far cheaper than the first. DORA and NIS 2 overlap on incident reporting and third-party risk. We reuse evidence across them rather than starting again.
Whether you want the fixes done or just named
An assessment that names the gaps costs less than an engagement that closes them with your team. Most of the price difference between our tiers is implementation, not analysis.
Whether someone else has set the date
A customer deadline or a regulator deadline compresses the schedule. We will say plainly if a date is not achievable rather than take the work and miss it.
When we are the wrong call
You need a certificate, not readiness. We prepare you and we sit with you through the audit, but an accredited body issues the certificate and a CPA firm signs the SOC 2 report. Any consultancy implying it does both should be asked to explain precisely how.
You want 24/7 monitoring. That is an MSSP or an MDR contract, priced per endpoint, and it is a different purchase. We will tell you which one you actually need first, because buying monitoring before you have fixed the configuration is the most common way security budget is wasted.
You are under 20 people with no compliance pressure. Start with the free configuration work. Our small business guide lists what to do yourself before paying anyone.
Pricing questions
Why does every price say "from"?
Because the honest number depends on scope, and anyone who gives you a firm figure before asking what you run is guessing, and the guess will be padded. The "from" price is the real starting point for the smallest version of that engagement. After a scoping call you get one fixed number for your actual scope.
Do you bill hourly?
No. Every engagement is scoped and priced before work begins, and the price does not move unless you change the scope in writing. No hourly billing, no scope creep, no surprise invoices.
When do I pay?
You read the report before you pay. The invoice follows delivery, not the kickoff call. That is the same on every assessment and readiness engagement we run.
What is the cheapest useful thing you sell?
A Microsoft 365 and Entra ID security audit from $1,450, or a SOC 2 readiness assessment from $3,000. Both give you a defensible answer to "are we secure" without committing to a programme.
How fast can you start?
A scoping call within a few days, a fixed-price proposal within 24 hours of that call, and kickoff as soon as you approve it. An IT security audit then delivers in 14 days.
Is a retainer cheaper than a project?
Per hour, yes. But buy a retainer only when you need decisions made continuously, which usually starts somewhere between 50 and 500 staff. Below that, a project plus a fix list is normally better value.
Get your number
One call to understand what you run, then a fixed-price proposal within 24 hours. If the honest answer is that you do not need us yet, you will get that instead.
- Fixed price agreed in writing before work starts
- You read the report before you pay
- Led personally by a CISSP, CEH, CHFI and Mandiant certified consultant