// Compliance

The frameworks that win deals, implemented from real expertise.

ISO 27001, ISO 9001, and NIST readiness, built by a senior operator who has implemented these systems, not a dashboard that leaves the actual work to you. We get you ready and stand beside you through the audit. We are the readiness partner, not the certifier.

A framework of security controls, verified

Frameworks

The standards that win you deals and satisfy your contracts, implemented by someone who has done it, not a dashboard that leaves the controls to you.

ISO 27001 Readiness

$15,000–$30,000 full readiness

The full ISMS: scope, risk assessment, Statement of Applicability, Annex A controls, policies, internal audit, and support through the Stage 1 and Stage 2 certification audits. Gap assessment from $3,500.

ISMS maintenance $1,500–$3,500/mo.

The accredited certification-body audit is separate and paid directly: roughly $6,000–$12,000 initial, $12,000–$22,000 over the three-year cycle. We are the readiness partner, not the certifier.

ISO 9001 Readiness

$7,500–$18,000 full readiness

The full quality management system: scope, quality policy and objectives, process maps built with your team, a risks-and-opportunities register, internal audit, management review, and support through the Stage 1 and Stage 2 certification audits. Gap assessment from $2,500.

QMS maintenance $1,000–$2,500/mo.

The accredited certification-body audit is separate and paid directly: typically $3,000–$8,000 initial, roughly $8,000–$18,000 over the three-year cycle for a small business. We are the readiness partner, not the certifier.

NIST 800-171 Readiness

$15,000–$35,000 full readiness

The full implementation program for defense-adjacent work: CUI flow-mapping and right-scoping, a gap assessment across all 110 controls, a System Security Plan, a plan of action with owners and dates, technical control implementation, and self-assessment support with artifacts on file.

Where a contract requires an independent third-party assessment, the assessor is engaged and paid directly. We are the readiness partner, not the assessor.

ISO/IEC 20000-1 Readiness

$12,000–$28,000 full readiness

The certifiable standard for IT service management, and the rare certificate that wins IT service bids: a service catalogue, measurable SLAs, and the incident, change, release, and continuity processes stood up in your existing tooling, through internal audit, management review, and the Stage 1 and Stage 2 audits. Gap assessment from $3,500. Already run an ISO 27001 ISMS with us? The two standards share half their machinery, and the scope and price drop with it.

Service management system maintenance $1,000–$2,500/mo, usually combined with ISMS maintenance.

The accredited certification-body audit is separate and paid directly: typically $3,000–$15,000 initial, roughly $10,000–$25,000 over the three-year cycle. We are the readiness partner, not the certifier.

Where a control calls for vulnerability management, we run it with Microsoft Defender tooling inside your own tenant. Where an auditor requires independent penetration testing, a specialist performs it under their own agreement: we scope and coordinate, we don’t perform it ourselves.

Advisory

Senior security leadership and AI governance, without a full-time hire.

AI Policy Pack

$2,500–$3,500 fixed

An AI acceptable-use policy, approved-tools list, data-handling rules, human-review requirements, an AI inventory, and a short rollout session, mapped to the NIST AI Risk Management Framework. Written for your business, not a template.

vCISO subscription

from $1,500/mo

Senior security leadership on a monthly subscription, from someone who can actually implement ISO 27001 and NIST 800-171/800-53, not just advise on them.

Lite$1,500/mo

Monthly security report and decision ledger, quarterly policy review, written vendor risk reviews, written answers to security questions (one-business-day target), annual board summary.

Standard$3,500/mo

Active program management, full policy program, vendor risk, IR plan and tabletop, quarterly board-ready reporting.

Plus$7,000/mo

Embedded leadership, bespoke policy authoring, board and investor reporting, cyber-insurance review, on-call IR.

vCISO program setup, one-time $5,000–$8,500: builds the 12-month security roadmap, core policy set, and risk register your subscription then maintains. The on-ramp into any tier.

Why readiness with us

// Real standards depth

ISO 27001, ISO 9001, ISO/IEC 20000-1, and NIST 800-171/800-53 implemented, not resold. The person scoping the work is the person doing it.

// Readiness, not certification

We prepare your controls and documentation and stand beside you through the audit. We are not an auditor or a registrar, which keeps us on your side of the table.

// Priced in the open

Ranges on this page, then a fixed written quote. Platform and audit fees are paid directly to those providers. They never touch our invoice and we never mark them up.

// No fear, no filler

No scare stats, no "compliance on autopilot." An honest timeline and the concrete deliverables, in plain English.

Not sure where to start?

Tell us which framework you are working toward and where you are today. We will tell you what readiness looks like and what to close first.

Get Started →