Step 1 of 6
Tell us about your organisation
Organisation size affects pricing across all services. Select the tier that best fits your company today.
Startup
Up to 30 people
Pre-Series B · no dedicated security team · compliance for first fundraise
SMB
31 – 150 people
Growing team · first compliance certification · investor-driven requirements
Scale-up
151 – 500 people
Established product · regulatory obligations · hiring security talent
Enterprise
500+ people
Complex environments · multiple frameworks · board-level security governance
Skip to summary →
Next: Penetration Testing →
Step 2 of 6
Penetration Testing
Select the test types you need. For each one, we’ll ask a few scope questions that determine the price range.
Application complexity
SimpleLogin + CRUD
MediumMulti-role · APIs
ComplexPayments · integrations
Number of user roles
1 – 2
3 – 5
6+
Authenticated endpoints / pages
< 20
20 – 50
50+
Test type
Grey-box
Black-box
White-box
Number of API endpoints
< 20
20 – 50
50 – 100
100+
API type
REST
GraphQL
Mixed
Authentication complexity
Basic (API key)
OAuth 2.0 / JWT
Complex (mTLS, SAML)
Number of hosts / IP addresses
< 20
20 – 100
100 – 500
500+
Scope
External only
Internal only
Both
Active Directory in scope?
No
Yes – small domain
Yes – complex / multi-domain
Platforms
iOS or Android
Both platforms
App complexity
Simple
Medium
Fintech / payments
Backend API included?
Mobile only
Include backend API
Cloud provider(s)
Single provider
Two providers
Three providers
Number of accounts / projects
1 – 3
4 – 10
10+
Containers / Kubernetes in scope?
No
Yes
Codebase size (lines of code)
< 10K LOC
10K – 50K
50K – 200K
200K+
Number of repos
1 repo
2 – 5
5+
Number of AI models / features
1 model
2 – 4
5+
RAG / data access?
No
Yes (RAG / tools)
Target audience size
< 50 people
50 – 200
200+
Number of locations
1 site
2 – 3 sites
4+ sites
Engagement tier
Basic (office)
Advanced (HQ/vault)
Campaign duration
15 days
20 days
30 days
← Back
Skip this section
Next: Compliance →
Step 3 of 6
Security Compliance
Select the frameworks you need to achieve or maintain. Use the duration control to set your engagement length.
ISO 27001
Information Security Management
International
SOC 2
Trust Service Criteria
US · International
SOC 1
Financial Reporting Controls
US · International
NIS2
Network & Information Security
European Union
DORA
Digital Operational Resilience Act
European Union · Financial
PCI-DSS
Payment Card Industry Standard
International
MiCA
Markets in Crypto-Assets Regulation
European Union · Crypto
VARA
Virtual Assets Regulatory Authority
UAE · Dubai
CSA STAR
Cloud Security Alliance
International · Cloud
Cyber Essentials / CE+
UK Government Baseline
United Kingdom
Gap Assessment
Compliance Maturity & Gap Analysis
Framework-agnostic · entry point
← Back
Skip this section
Next: Advisory →
Step 4 of 6
Advisory Services
Security leadership and governance on a retainer or annual basis.
Virtual CISO (vCISO)
Monthly retainer · security strategy · board reporting · vendor oversight
€3,000 – 6,000 / month
Virtual DPO
Monthly retainer · GDPR · DPIA · breach notification · regulatory liaison
€1,500 – 3,000 / month
Board / NED Advisory
Annual engagement · cybersecurity governance at board level · risk oversight
€5,000 – 15,000 / year
Incident Response Retainer
Annual retainer · 4h SLA · tabletop exercise · IR plan included
€5,000 – 10,000 / year
← Back
Skip this section
Next: Managed & Training →
Step 5 of 6
Managed Security & Training
Ongoing security operations or one-off training programmes.
← Back
Skip this section
View Your Estimate →
Your Estimate
Here’s your security budget
Based on your selections. All figures are indicative — final pricing confirmed after a 30-minute scoping call.