| Feature / Deliverable | Essentials $3,000 |
Standard $5,000 |
Enterprise $7,000+ |
|---|---|---|---|
| Scope & Timeline | |||
Environment size Approximate user count |
Up to 50 users | 50–250 users | 250+ users |
Infrastructure complexity |
Single cloud platform | Multi-platform / hybrid | Complex / multi-site |
Review duration |
2–3 business days | 3–5 business days | 5+ business days |
Revision passes included |
1 (30 days) | 1 (30 days) | 2 (60 days) |
| Core Deliverables | |||
47-item evidence checklist |
✓ Included | ✓ Included | ✓ Included |
Executive evidence review report (insurance questionnaire-oriented language) |
✓ Included | ✓ Included | ✓ Included |
Evidence Coverage Summary — Internal Review Metric (not an insurer score) |
✓ Included | ✓ Included | ✓ Included |
Findings table (High / Medium / Low) |
✓ Included | ✓ Included | ✓ Included |
Evidence appendix (screenshots, exports) |
✓ Included | ✓ Included | ✓ Included |
Remediation roadmap |
✓ Included | ✓ Included | ✓ With effort estimates |
| Coverage Scope | |||
Azure / Entra ID / M365 |
✓ | ✓ | ✓ |
AWS (IAM, S3, EC2) |
– | ✓ | ✓ |
On-premises Active Directory |
◐ Limited | ✓ | ✓ |
Fortinet / Palo Alto / Cisco |
– | ✓ | ✓ |
Linux workloads / servers |
– | ◐ Scoped | ✓ |
| Optional Control Mapping | |||
Common cyber insurance questionnaire category alignment |
✓ | ✓ | ✓ |
HIPAA / HITECH informational control-reference mapping only; not a compliance assessment, attestation, or certification |
– | ✓ (if applicable) | ✓ |
PCI-DSS informational control-reference mapping only; not a compliance assessment, attestation, or certification |
– | ✓ (if applicable) | ✓ |
CMMC / DFARS informational control-reference mapping only; not a compliance assessment, attestation, or certification |
– | ◐ Limited | ✓ |
| Support & Communication | |||
Broker / underwriter discussion participation Joining review calls when scoped |
– | – | ✓ 1 session included |
MSP coordination |
◐ Email only | ✓ | ✓ |
Post-delivery Q&A window |
30 days | 30 days | 60 days |
What makes this different from other options.
Different teams can support this work. The key difference is whether the output is organized around evidence that supports common cyber insurance questionnaire categories.
- ✕Existing IT teams and MSPs often focus on operations, while cyber insurance evidence requires a separate documentation lens.
- ✕Screenshots, exports, or configuration evidence may not be gathered in a structured package.
- ✕Operational reports are not always organized for broker and underwriter discussion.
- ✕An independent second set of eyes can help clarify which answers are supportable with evidence.
- ✕Typically $15K–$50K+ for a full engagement
- ✕Not always scoped to common cyber insurance questionnaire categories
- ✕Delivers a security program, not a structured technical evidence package
- ✕Timeline weeks to months, not days
- ✕An independent second set of eyes can help business owners, brokers, and IT teams understand which answers are supportable with evidence.
- ✕Creates misrepresentation risk if controls aren't exactly as described
- ✕Self-attestation may be difficult to support later if screenshots, exports, or configuration evidence are missing.
- ✕Evidence expectations vary by policy, broker, and carrier
Why fixed-scope pricing?
Each engagement is scoped before work begins. Pricing depends on environment size, number of platforms, identity systems, backup architecture, endpoint coverage, and the amount of evidence that must be reviewed. The goal is to provide a clear technical evidence package and remediation roadmap — not to guarantee insurance approval, premium reduction, claim payment, regulatory compliance, or breach prevention.
Cyber Audit Pro provides technical evidence review and readiness support. We do not guarantee insurance approval, premium reduction, claim payment, regulatory compliance, or breach prevention. This service is a technical evidence review, not a formal audit, compliance certification, underwriting assessment, insurance advice, or legal advice. It is not a penetration test.
Start with a free scope call.
30 minutes. Fixed quote. No obligation. We'll tell you exactly what tier fits your environment and what you'll receive.