Certification
SIAS certification pricing
List prices for SIAS readiness reviews and assessments, in U.S. dollars. Fees are set in a written proposal before the assessment starts. They cover the assessment, not a result, and are payable whatever the outcome.
List prices
Readiness reviews and assessments
One-time fees. Certification assessment tiers describe how broad the scope is, not a grade.
| Service | Scope | Outcome | List price (USD) |
|---|---|---|---|
| SIAS Readiness Review | Gap analysis against SIAS v1.0, findings and a roadmap | None: advisory work, no SIAS level | $4,950 |
| SIAS limited-scope assessment | One SecurityInspect Verified profile (VP-EXT, VP-APP or VP-CLD) on a clearly defined, limited technical scope | SecurityInspect Verified | $8,950 |
| SIAS certification assessment, Core | One company, one product, one production environment, up to 50 staff | SecurityInspect Certified | $18,950 |
| SIAS certification assessment, Growth | Up to three products or environments, up to 250 staff | SecurityInspect Certified | $37,950 |
| SIAS certification assessment, Advanced | Complex SaaS, regulated data, multiple clouds or legal entities | SecurityInspect Certified | from $62,950 |
| SIAS certification assessment, Enterprise | Multinational, extensive sampling, on-site work | SecurityInspect Certified | from $95,000 |
Renewals
A full reassessment each year, when the scope is materially unchanged.
| Service | Scope | List price (USD) |
|---|---|---|
| Renewal, Core | Full reassessment of a materially unchanged Core scope | about $12,950 |
| Renewal, Growth | Full reassessment of a materially unchanged Growth scope | about $24,950 |
| Renewal, Advanced and Enterprise | Full reassessment after the scope is reviewed again | quoted after rescoping |
A material change in scope (new products, environments, entities, data types or clouds) is rescoped and quoted.
Optional continuous monitoring
Monthly fees, set per engagement.
| Service | Scope | List price (USD) |
|---|---|---|
| Core monitoring | Continuous monitoring for a Core scope | $649/month |
| Growth monitoring | Continuous monitoring for a Growth scope | $1,595/month |
| Advanced monitoring | Continuous monitoring for an Advanced scope | $3,150/month |
| Enterprise monitoring | Continuous monitoring for an Enterprise scope | from $6,500/month |
Continuous monitoring never changes any control’s evidence requirements or pass criteria, and it does not replace the renewal assessment. It only lets evidence that SecurityInspect has already validated be reused, on the same terms available to every holder.
Add-ons
Added to an assessment fee when the scope needs them.
| Service | Scope | List price (USD) |
|---|---|---|
| Additional product or major environment | Each product or major environment beyond the tier | +20–35% |
| Additional legal entity | Each legal entity beyond the first | +15–25% |
| Additional cloud provider | Each cloud provider beyond the first | +10–15% |
| Sensitive health, payment or financial-data scope | Scopes that store or process these data types | +15–25% |
| Additional retesting, beyond the one included round | Further retest rounds within the program's limits | $1,595 per day |
| On-site assessment | Assessment work at your premises | assessor fees plus travel at cost |
Remediation consulting: $1,795–$2,250 per day. Never for the in-scope systems of an applicant with an open SIAS assessment, or of a holder while its certificate is valid.
Procurement pack: $1,950–$4,950. Limited to the content of the verification record, the fixed framework disclaimer and the published standard; SecurityInspect doesn’t answer a holder’s customer questionnaires or vouch for the holder beyond the record.
Penetration tests are priced as published on our main pricing page, with their own scope and retest terms. Penetration testing prices
What the certification fee covers
- Initial scope and eligibility review.
- Automated software and configuration analysis.
- Manual evidence assessment across the applicable SIAS domains.
- Interviews and sampling.
- Findings and a formal assessment report.
- An independent certification decision.
- One retest round, if it is requested within 45 days of the findings report. The program allows up to 2 retest rounds per finding within 90 days of the findings report; rounds beyond the included one are billed at the day rate.
- The certificate, a badge license and a public verification record.
- Twelve months of certification validity, subject to surveillance and the revocation rules.
The fee buys the assessment, not a result
The fee buys the assessment, not a result. It is payable whether the applicant passes, fails or withdraws. There is no “pay only if you pass” option, because tying fees to outcomes would compromise impartiality.
We don't use limited-time discounts, countdown timers, or false scarcity, and we don't guarantee outcomes such as passing an audit or assessment.
Payment terms
Billing: 40% when the assessment is booked, 40% when evidence review begins, and 20% before the certification decision is released. The fee is due regardless of outcome.
The Readiness Review
The Readiness Review is a gap analysis against SIAS v1.0 with findings and a roadmap. It is advisory work, so it produces no SIAS level, and the people who perform it never take part in that organization’s SIAS assessment, quality review or decision.
We don’t start a SIAS assessment of a scope within 12 months of a SIAS Readiness Review we performed for it.
Tiers are scope breadth, not a grade
Core, Growth, Advanced and Enterprise describe how broad the assessed scope is. A verification record shows it as Single-product scope, Multi-product scope, Complex-environment scope or Enterprise scope. It is not a security grade: every SecurityInspect Certified certificate met the same published requirements of SIAS v1.0.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Get a written proposal for your scope
Tell us what you want assessed, and we’ll start with the scope.