Transparent Pricing

Fixed fees. No surprises.

Every engagement is scoped and quoted before we begin. You know the cost, timeline, and deliverables before signing anything.

// Engagement Tiers
Essentials Review
For smaller environments with a single cloud platform and under 50 users
$3,000
Fixed fee · Remote · 2–3 business days
Free 30-min discovery & scope call
47-item evidence checklist, completed
Executive evidence review report (PDF)
Findings by severity (High / Medium / Low)
Remediation roadmap
One revision pass (30 days)
Multi-platform (Azure + AWS + on-prem)
Informational control-reference mapping only; not a compliance assessment, attestation, or certification
Broker / underwriter discussion participation
Enterprise Review
For complex environments, 250+ users, or organizations with active broker or underwriter questions
$7,000+
Fixed fee · Remote · 5+ business days
Free 30-min discovery & scope call
47-item evidence checklist, completed
Executive evidence review report (PDF)
Findings by severity (High / Medium / Low)
Remediation roadmap with effort estimates
Two revision passes (60 days)
Multi-platform coverage (all vendors)
Informational control-reference mapping only; not a compliance assessment, attestation, or certification
Broker / underwriter discussion participation (1 session)
// Detailed Comparison
Feature / Deliverable Essentials
$3,000
Standard
$5,000
Enterprise
$7,000+
Scope & Timeline
Environment size
Approximate user count
Up to 50 users 250+ users
Infrastructure complexity
Single cloud platform Complex / multi-site
Review duration
2–3 business days 5+ business days
Revision passes included
1 (30 days) 2 (60 days)
Core Deliverables
47-item evidence checklist
✓ Included✓ Included
Executive evidence review report (insurance questionnaire-oriented language)
✓ Included✓ Included
Evidence Coverage Summary — Internal Review Metric (not an insurer score)
✓ Included✓ Included
Findings table (High / Medium / Low)
✓ Included✓ Included
Evidence appendix (screenshots, exports)
✓ Included✓ Included
Remediation roadmap
✓ Included✓ With effort estimates
Coverage Scope
Azure / Entra ID / M365
AWS (IAM, S3, EC2)
On-premises Active Directory
◐ Limited
Fortinet / Palo Alto / Cisco
Linux workloads / servers
Optional Control Mapping
Common cyber insurance questionnaire category alignment
HIPAA / HITECH informational control-reference mapping only; not a compliance assessment, attestation, or certification
PCI-DSS informational control-reference mapping only; not a compliance assessment, attestation, or certification
CMMC / DFARS informational control-reference mapping only; not a compliance assessment, attestation, or certification
Support & Communication
Broker / underwriter discussion participation
Joining review calls when scoped
✓ 1 session included
MSP coordination
◐ Email only
Post-delivery Q&A window
30 days60 days
// Why Not Alternatives?

What makes this different from other options.

Different teams can support this work. The key difference is whether the output is organized around evidence that supports common cyber insurance questionnaire categories.

Your MSP Doing It
Using existing operational resources
  • Existing IT teams and MSPs often focus on operations, while cyber insurance evidence requires a separate documentation lens.
  • Screenshots, exports, or configuration evidence may not be gathered in a structured package.
  • Operational reports are not always organized for broker and underwriter discussion.
  • An independent second set of eyes can help clarify which answers are supportable with evidence.
Result: Useful operational knowledge, but often missing the documentation lens needed for questionnaire support.
vCISO / Security Consultant
Broader security advisory services
  • Typically $15K–$50K+ for a full engagement
  • Not always scoped to common cyber insurance questionnaire categories
  • Delivers a security program, not a structured technical evidence package
  • Timeline weeks to months, not days
Result: Great for security maturity — overkill and wrong format for an insurance renewal deadline.
Self-Attestation
Answering the carrier questionnaire yourself
  • An independent second set of eyes can help business owners, brokers, and IT teams understand which answers are supportable with evidence.
  • Creates misrepresentation risk if controls aren't exactly as described
  • Self-attestation may be difficult to support later if screenshots, exports, or configuration evidence are missing.
  • Evidence expectations vary by policy, broker, and carrier
Result: May be acceptable in some cases, but supportability depends on the evidence retained with each answer.

Why fixed-scope pricing?

Each engagement is scoped before work begins. Pricing depends on environment size, number of platforms, identity systems, backup architecture, endpoint coverage, and the amount of evidence that must be reviewed. The goal is to provide a clear technical evidence package and remediation roadmap — not to guarantee insurance approval, premium reduction, claim payment, regulatory compliance, or breach prevention.

// Pricing FAQ
Yes — no credit card, no invoice. The 30-minute discovery call is purely for us to understand your environment, questionnaire context, and timeline so we can scope the engagement and give you a fixed quote. You're under no obligation to proceed.
Primarily user count, infrastructure complexity, and number of platforms. A 40-person company running Azure-only with a single MSP is typically Essentials. A 120-person company with Azure + Fortinet firewall + on-prem AD is Standard. We confirm the tier on the discovery call before you commit — there are no surprises.
50% upon signing the engagement letter, 50% upon delivery of the final report. We don't charge the full fee until you have your deliverables in hand. For broker-referred engagements, payment terms can be discussed.
We honor the fixed fee quoted in the engagement letter, even if the review takes longer than expected. If the scope meaningfully changes — for example, you disclose an additional cloud environment not mentioned during scoping — we discuss a scope amendment before proceeding. We don't issue surprise invoices.
Additional revision work beyond the included pass can be scoped and quoted separately based on the follow-up requested.
Any referral or repeat-engagement pricing is discussed during scoping and documented in the written engagement terms.

Cyber Audit Pro provides technical evidence review and readiness support. We do not guarantee insurance approval, premium reduction, claim payment, regulatory compliance, or breach prevention. This service is a technical evidence review, not a formal audit, compliance certification, underwriting assessment, insurance advice, or legal advice. It is not a penetration test.

Start with a free scope call.

30 minutes. Fixed quote. No obligation. We'll tell you exactly what tier fits your environment and what you'll receive.