| Engagement | Delivery | Price (€/mo.) |
|---|---|---|
Advisor Two days per month of senior expertise on tap. For organisations whose own staff drive the work, we make sure it’s driven with confidence. Methodology and framework selection, design and document reviews, a monthly working session, ad-hoc questions, and preparation for audits and board reporting. Your team delivers the results, we provide the assurance. | Remote induction with annual on-site presence. Scheduled monthly sessions. Response to ad-hoc requests within two business days. | 2,560 |
Architect One day per week of expert delivery. For organisations that need hands-on support on top of expert guidance. Strategies, frameworks, policies, processes, as well as metrics and reports — all tailored to your needs. We design the system, you run the function. | Remote induction with semi-annual on-site presence. Scheduled coordination sessions. Response to ad-hoc requests within two business days. | 5,500 * 4,700 |
Executive Two days per week of embedded leadership. For organisations that need someone to establish and carry the security or risk function. Management presence, programme ownership, vendor risk management, customer-facing representation, board reporting, as well as audit leadership. And should you ever decide to bring the function in-house, we support the transition — from hiring to handover. You decide the direction, we manage the execution. | On-site induction with quarterly on-site presence. Weekly team meetings and scheduled management alignment. Response to ad-hoc requests within one business day. | 11,000 * 9,400 |
All packages are applicable to either information security or risk management, and can be extended with additional capacity.
What’s included:
- Rapid induction in month one, including up to two extra days of discovery at no additional cost.
- Quick access through our EU-hosted collaboration platform.
- Rolling monthly engagement with one month notice period.
- Discounted rates (-15%) from month four, on any contract that includes more than four days per month.
Implementation projects
Projects are scoped engagements with the objective of implementing a given framework and developing sustainable capability for operating it. Compliance readiness projects come in two flavours: managed and guided. The former is suitable for customers who need end-to-end management of the project, while the latter is more appropriate for customers who manage the implementation themselves but need continual subject-matter guidance and support.
The prices below are indicative, based on typical service costs for small and medium enterprises (SMEs). Each project is scoped individually, and its cost depends on your needs, organisational complexity and context, including factors such as your current practices, maturity of the business processes, existing documentation, etc. Projects are billed time & materials at a rate of 1,280 €/day . All offers include a binding cost cap ensuring the cost never exceeds an agreed maximum.
| Project | Delivery | Typically (€) |
|---|---|---|
Integrated risk management framework (IRMF) Scalable framework suitable for organisations with no formal risk management practice, as well as those looking to consolidate risk management across business functions. Includes framework implementation — establishing a risk governance structure, methodology adaptation, definition of workflows — as well as hands-on team training through one cycle of risk appetite elicitation, risk assessment, and management reporting. | Remote, with one to three on-site sessions depending on scope: kick-off, risk assessment, management report & closing. Duration 2 – 6 months | 15,300 – 43,500 |
Information security management system (ISMS) A pragmatic system based on ISO/IEC 27001, with reduced overhead. Suitable for organisations lacking formal security management, as well as those with a defined practice looking to increase their maturity. Includes ISMS implementation — strategic alignment, scoping, establishing a security governance structure, system adaptation, definition of workflows — as well as hands-on team training through one cycle of risk assessment, control selection & design, and management reporting. Designed to extend to a certification-ready ISMS without rework. | Remote, with one to three on-site sessions depending on scope: kick-off, risk assessment, management report & closing. Duration 3 – 9 months | 25,600 – 53,700 |
ISO/IEC 27001 compliance readiness (managed) End-to-end managed project that aligns your internal practices with the requirements of ISO/IEC 27001. Typically sought by organisations with established security management that want formal recognition, but can also be applied to organisations with no formal security practice. Includes ISMS implementation — organisational context analysis, scoping, gap analysis, establishing a security governance structure, risk assessment support, risk treatment planning, statement of applicability (SOA), policy development, control selection & design, control implementation support, evidence management, stakeholder training — as well as management reporting and audit support. | Remote, with two to four on-site sessions: kick-off, risk assessment & treatment plan approval, management review and audit support. Duration 3 – 12 months | 25,600 – 98,500 |
ISO/IEC 27001 compliance readiness (guided) Suitable for organisations with established security management capability needing expert advice on ISO/IEC 27001 alignment and certification. Includes guidance on ISO/IEC 27001 requirements, overview of the certification process, gap analysis, regular progress check-ins, as well as on-demand reviews and advice. | Remote, with optional paid on-site presence for key events. | 12,800 – 38,400 |
Compliance readiness (managed or guided) Suitable for organisations targeting compliance with one of the supported frameworks: GDPR, DORA, NIS2, CRA, PCI DSS, PCI Secure SLC, etc. Includes gap analysis & remediation plan, implementation support, documentation and evidence management, team training, as well as audit support where applicable. For ISO/IEC 27001 compliance, please refer to the dedicated services above. | Remote, with one to four on-site sessions depending on scope. | Framework-dependent |
When planning, you should account for expenses beyond what we bill, such as internal staff effort, auditors, tooling, as well as certification-body fees where applicable. For example, the total cost of an ISO/IEC 27001 certification initiative typically lands at four to five times the consulting fee. The following article by PentesterWorld provides one of the best analyses on the matter, including guidance on how to budget properly for success.
If something looks too good to be true, then it almost certainly is!
When researching implementation costs and timelines, make sure you rely on credible sources. There is a lot of misinformation on the internet, including AI-generated content on the topic in which the numbers simply don’t add up — we have nothing against the use of AI, but we are strongly against misinformation.
The same goes for tools and template packs that promise almost instant compliance. While tools and templates are very useful, signing off a policy without implementing it in practice is one of the worst offences in security compliance, and a recipe for failure. Your customers, the industry and public authorities are interested in pragmatic but real security — not security theater .
Not ready to commit to a project timeline?
The same capabilities can be developed gradually using our Architect retainer .
Need to meet a compliance deadline?
If you’re facing regulatory deadlines or certification requirements with tight timelines, compressed implementation is possible. Feasibility and time gained depend on resource availability, your commitment, and risk tolerance. We concentrate the work into higher monthly intensity with a primary focus on meeting requirements efficiently, de-prioritising capability development.
Total cost typically remains similar to that of a standard timeline. What changes is delivery speed at the expense of knowledge transfer and overall maturity. Note that if you choose this route, you should plan for a follow-up after reaching your milestone in order to achieve sustainable capability — often required for continued compliance. We don’t recommend this approach unless you absolutely need it.
Not every question needs a project. Short, one-off consultations are free of charge. For deeper engagements, advisory work is available as a retainer , with monthly capacity sized to fit. Below we list services with predefined deliverables, offered at fixed prices and credited against projects that build on them.
| Service | Deliverables | Price (€) |
|---|---|---|
Gap analysis Assessment of current practices against a single supported framework, such as ISO/IEC 27001, PCI DSS or NIS2. Used either to scope an upcoming initiative or verify readiness before certification. Based on documentation review and stakeholder interviews. Up to 20 documents and 4 stakeholders. | Gap report with prioritised recommendations. | 5,100 |
Risk appetite elicitation Facilitated articulation of the risk your organisation is willing to accept, grounded in a structured analysis of your organisational context: market and regulatory environment, industry forces, and key internal dependencies. Used to gain strategic clarity, as well as to formalise risk criteria. Up to one business domain and 4 stakeholders. | Context analysis summary and risk appetite statement with quantified risk tolerance criteria. | 6,400 |
Risk quantification Quantification and aggregation of already identified and analysed risks. Used to communicate risk in a common, unambiguous language, consolidate assessments made in silos across business functions, and understand your overall exposure. Based on structured sessions with each register’s owner. Main price is for one risk register with up to 30 entries. | Quantified risk report with loss exceedance curves, input assumptions, and confidence notes. | 3,800 + 1,900 |
Policy & procedure review Focused review of a small set of related documents against a standard’s requirement or your own goal definition. Where gap analysis looks at the overall picture covered by a given framework, this service is used to validate your ongoing work. Up to 5 documents on a single topic. | Summary report on whether the documents fulfil their purpose, with the main issues listed, as well as the documents returned with comments in context. | 1,500 |
Quick consultation Expert opinion and guidance, when all you need is a chat on a security or risk issue. Available as capacity allows. | Free |
Other fixed-price deliverables, such as security architecture development or review, business impact analyses (BIA), and maturity reviews, can be arranged on request.
If you are a charity, cooperative, social enterprise, or any organisation genuinely advancing human welfare and environmental protection, we offer up to 30% lower rates. Legal structure is not what qualifies you — actual practice is. Reach out and we can check if our values align.