Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Pricing

Scope first. Price second.

Security assurance work is priced according to scope, organisation size, systems, locations, evidence maturity, regulatory complexity and the accountability Tech Turn is taking on.

Illustrative planning ranges.

These are planning ranges, not fixed quotations. Final pricing is confirmed after discovery and scope definition.

One-off

ISO 27001 Gap Assessment

Smaller scopes: approximately USD 1,500 to USD 5,000+. Includes scope definition, document/evidence review, interviews, gap register and prioritised roadmap.

Project

ISO 27001 Readiness Project

Approximately USD 5,000 to USD 20,000+ depending on scope. Includes ISMS and risk-process support, evidence structure and remediation tracking.

Assurance

Internal Audit

Approximately USD 1,000 to USD 5,000+ depending on audit scope, sampling and reporting requirements.

Recurring

Managed GRC

Initial planning benchmark from approximately USD 1,000+ per month for a small international client; higher accountability and multi-framework scope is priced materially higher.

Technical assessments.

Microsoft 365 and other technical-control assessments are quoted according to users, tenants, systems, evidence method and required reporting depth.

A narrow technical review can be used as the first engagement when the client is not yet ready for a full ISO 27001 project.

What drives cost.

Two companies with 50 employees can have very different assurance workloads.

Scope

Business units, locations, products and systems in the assessment boundary.

Evidence maturity

How much usable evidence already exists and how much must be reconstructed.

Complexity

Cloud, vendors, legacy systems, regulated data and custom applications.

Accountability

Readiness advice, technical remediation, assurance, recurring governance or multiple frameworks.