Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Pricing

Pricing and how we scope work

Each service below has a published starting price and a typical scoped range, so you can budget before you talk to anyone. Every engagement begins with a written scope and proposal.

How our pricing works

Starting price
The published starting point for a service. It helps you budget; it isn’t a quote.
Typical scoped range
The span that covers the usual differences in size and complexity. It’s a guide, not a ceiling: your proposal reflects your actual scope.
Written scope and proposal
Every engagement begins with a written scope and proposal. The proposal, not this page, sets your price.

What each service costs: starting prices and typical ranges

Amounts are in U.S. dollars. Select a service name to see what the work covers. Policy, control, and evidence design and vendor-risk reviews don’t have published prices; ask for a scoped proposal.

Assessments and reviews

Risk assessments and cloud security reviews.
ServiceBillingStarting priceTypical scoped range
NIST CSF / CIS Controls Risk AssessmentOne-time project$7,500$7,500 to $18,000
Cloud Security ReviewOne-time project$7,500$7,500 to $18,000

Penetration testing

Web application, API, and network penetration tests.
ServiceBillingStarting priceTypical scoped range
Web Application or API Penetration TestOne-time project$12,000$12,000 to $30,000
External Network Penetration TestOne-time project$6,000$6,000 to $12,000
Internal Network Penetration TestOne-time project$9,000$9,000 to $20,000

Penetration-test prices rest on the assumptions set out in what a penetration test price assumes.

Virtual CISO

Virtual CISO services, billed monthly.
ServiceBillingStarting priceTypical scoped range
vCISO AdvisoryMonthly$4,000/month$4,000 to $6,000/month
vCISO Program LeadershipMonthly$7,500/month$7,500 to $12,000/month

Compliance readiness

Readiness for SOC 2, ISO/IEC 27001, PCI DSS, HIPAA, and CMMC.
ServiceBillingStarting priceTypical scoped range
SOC 2 ReadinessOne-time project$10,000$10,000 to $25,000
ISO/IEC 27001 ReadinessOne-time project$15,000$15,000 to $35,000
PCI DSS ReadinessOne-time project$8,000$8,000 to $22,000
HIPAA Security ReadinessOne-time project$8,000$8,000 to $20,000
CMMC Level 1 ReadinessOne-time project$6,000$6,000 to $12,000
CMMC Level 2 Self-Assessment ReadinessOne-time project$15,000$15,000 to $40,000

What readiness pricing does and doesn’t cover is set out in what compliance readiness assumes.

Incident readiness

Response planning, tabletop exercises, and a priority advisory retainer.
ServiceBillingStarting priceTypical scoped range
Incident Response Plan and TabletopOne-time project$6,500$6,500 to $15,000
Priority Incident Advisory RetainerAnnual$18,000/year$18,000 to $60,000/year

About the retainer: Priority advisory for retainer clients, with after-hours paging from 6:00 a.m. to 10:00 p.m. Central Time every day and an acknowledgement target of 60 minutes during the contracted paging window. Not a round-the-clock service. Terms are set by the signed retainer.

What every price assumes

These qualifiers apply to the prices above, in full.

All services

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Penetration tests

Penetration-test pricing assumes authorized manual testing, an executive summary, a technical report, remediation guidance, and one retest within 60 days unless the proposal says otherwise.

All penetration testing requires written authorization, a signed scope, rules of engagement, approved targets, testing windows, emergency contacts, and stop conditions.

Compliance readiness

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

What changes the price

These are the factors named in our pricing qualifier, with what each one means in practice.

Environment size
How many people, devices, servers, and sites the work needs to cover.
Complexity
How many technologies, integrations, and business units are involved, and how well they're documented.
Testing depth
For penetration tests, how much manual testing each target gets and how many scenarios are in scope.
Locations
The offices, facilities, and cloud regions that fall within scope.
Applications
How many applications and APIs are in scope, and how large each one is.
Accounts
The number of cloud accounts, subscriptions, or tenants to review.
User roles
The permission levels an application test has to cover, such as customer, staff, and administrator.
Compliance objectives
Which frameworks you're preparing for, and whether you're working toward one or several at once.
Delivery timeline
When you need the work finished, and whether an audit date or contract deadline fixes the schedule.

No discounts, countdowns, or guaranteed outcomes

We don't use limited-time discounts, countdown timers, or false scarcity, and we don't guarantee outcomes such as passing an audit or assessment.

Rough scope estimator

Pick the services you’re weighing to see a combined typical range. One-time projects, monthly services, and the annual retainer are totaled separately because they’re billed differently.

Get a price for your actual scope

Tell us what you’re trying to achieve and what’s driving the timing. We respond to new inquiries Monday to Friday, 8:00 a.m. to 6:00 p.m. Central Time, excluding U.S. federal holidays. Best-effort triage. No emergency service level.