What this actually costs
No 'contact us for a custom quote' games. Here are the real ranges, what's included, and what's not.
Compliance Sprint
$3K–$10Kone-time
SOC 2 or ISO 27001 readiness, implementation, and audit prep. Fixed scope, fixed timeline.
What's included
- Gap assessment against your target framework
- Policy and procedure drafting from scratch
- GRC platform setup and configuration
- Control implementation and evidence collection
- Auditor coordination and audit fieldwork support
- Final report delivery and remediation guidance
Not included
- Ongoing program management after certification
- Security questionnaires for sales deals
- Incident response planning and tabletop exercises
vCISO Retainer
$3K–$6K/mo
Ongoing security leadership, program management, compliance maintenance, and customer trust support.
What's included
- Fractional CISO leadership and board reporting
- Ongoing compliance program management
- GRC platform monitoring and failing-control remediation
- Policy maintenance and annual reviews
- Security questionnaire support for sales
- Vendor risk assessments and access reviews
- Security awareness guidance
Not included
- Dedicated incident response retainer (available as add-on)
- Penetration testing fees (passed through at cost)
vCISO Retainer
$6K–$12K/mo
The same retainer, scaled for larger environments — more frameworks, more stakeholders, more surface area.
What's included
- Everything in the smaller retainer, scaled up
- Multi-framework compliance management
- Additional stakeholders and cross-functional coordination
- More complex GRC platform environments
- Customer trust and enterprise security reviews
- Board and executive reporting at higher cadence
- Security architecture review and roadmap
Not included
- Dedicated incident response retainer (available as add-on)
- Penetration testing fees (passed through at cost)
Pricing depends on scope, frameworks, and environment complexity. These are starting ranges. We'll give you a fixed quote on the call.
Book a Free ConsultationPricing FAQ
Why ranges instead of fixed prices?
Because scope varies. A SOC 2 sprint for a 20-person SaaS company with a clean AWS environment is different from a 150-person healthtech company juggling HIPAA, SOC 2, and ISO 27001 simultaneously. We'll give you a fixed quote on the first call, once we understand your environment.
Is there a long-term contract?
Retainers are month-to-month. We earn the next month by doing the work, not by locking you in. The Compliance Sprint is a fixed-scope engagement with milestones, not a subscription.
What if we need both a sprint and ongoing management?
Most clients start with a sprint to get through their first audit, then move to a retainer to keep the program running. We'll scope both together if you know that's the plan from the start.
Do you charge extra for the GRC platform?
No. Your platform subscription (Vanta, Drata, or whichever you choose) is billed directly to you by the vendor. Our pricing covers the setup, configuration, and ongoing management of whatever platform you're running.
What about add-ons?
Penetration testing coordination, incident response retainers, and ad-hoc assessments are available outside the standard tiers. Pen testing fees are passed through at cost — we don't mark them up. Incident response retainers are quoted separately based on your environment and risk profile.
How does the free consultation work?
A 30-minute call. We ask about your environment, your timeline, what's driving the conversation, and whether we're the right fit. If we are, you get a fixed quote within a day. If we're not, we tell you that too and point you in the right direction.