Skip to content

Pricing

Priced so you can actually start.

Security work has been priced for funded enterprises for years, which is why most teams put it off until a deal is already stalling. Fixed scope, fixed price, published in the open, and an entry point that a team still building its MVP can afford.

What we sell

innsecs provides services, not certificates. We build your management system, run the testing and prepare you for audit. The certificate itself is issued by an accredited certification body, and a SOC 2 report by a licensed CPA firm, both of which must stay independent of whoever implemented your controls. We help you choose and engage them.

Start here

Launch Review

For MVPs and pre-seed teams.

from$1,500one-off

You're shipping fast and someone just asked a security question you can't answer.

  • Security review of your app and cloud
  • Prioritised fix list your devs can action
  • We answer your first security questionnaire
  • Credits in full against a later programme

Certification Readiness

Audit-ready on one framework.

from$9,500fixed scope

A deal is blocked on ISO 27001 or SOC 2 and you need it done properly.

  • ISO 27001 or SOC 2, end to end
  • Full ISMS, policies and risk register
  • Internal audit and management review
  • Stage 1 and Stage 2 audit support
Most chosen

Audit-Ready & Secure

Audit-ready, and proof it means something.

from$16,000fixed scope

One team runs certification and testing, so the pentest feeds your evidence.

  • Everything in Certification Readiness
  • Manual penetration testing included
  • Cloud assessment across your platforms
  • Free retest and attestation letter

Continuous Assurance

Keep it true after you're certified.

from$1,200per month

You're certified and need it to stay that way without hiring a team.

  • Named security lead on retainer
  • Surveillance and annual internal audit
  • Recurring penetration testing
  • Questionnaires answered for you

Figures are starting points for a typical SaaS engagement and exclude the certification body’s own audit fees, which are paid directly to them and never marked up by us. Your exact price depends on headcount, environments and starting maturity, the scoping call and written proposal cost nothing.

How this compares

Roughly half the going rate.

Not because the work is lighter, but because we don't carry a sales team, an office or a bench of juniors to keep busy. Market figures below are 2026 published ranges.

innsecs pricing compared with published 2026 market ranges
EngagementTypical marketinnsecs
ISO 27001, consultant-led$15,000 – $30,000from $9,500
Startup web app pentest$5,000 – $15,000from $4,500
Cloud security assessment$7,000 – $15,000from $3,500
Compliance platform + advisory$7,500 – $15,000 / yrfrom $14,400 / yr

Market ranges are published 2026 figures for consultant-led ISO 27001 implementation, scoped startup web application penetration testing, and compliance platform plus advisory bundles. Certification body audit fees are excluded from both columns.

Compare in detail

Exactly what each engagement includes.

No asterisks, no 'contact us for details'. If it isn't in this table, it isn't in the price.

Launch Review

Certification

  • Gap analysis against ISO 27001:2022 or SOC 2light
  • ISMS scope and Statement of ApplicabilityNot included
  • Risk methodology, register and treatment planNot included
  • Full policy and procedure set, fitted to youNot included
  • Evidence pack mapped control-by-controlNot included
  • Internal audit and management reviewNot included
  • Certification body selection and liaisonNot included
  • Stage 1 and Stage 2 audit supportNot included

Security testing

  • Application and cloud security reviewIncluded
  • Prioritised remediation list for your engineersIncluded
  • Manual web and API penetration testingNot included
  • Multi-tenancy and authorization boundary testingNot included
  • Cloud security assessment across all supported platformslight
  • Threat model feeding your risk registerNot included
  • Free retest of every findingNot included
  • Customer-shareable attestation letterNot included

Ongoing support

  • Named senior security leadNot included
  • Shared Slack or Teams channelIncluded
  • Customer security questionnaires and CAIQ / SIGone
  • Enterprise prospect security calls attendedNot included
  • Incident response plan and tabletop exercisesNot included
  • Quarterly board-level reportingNot included
Certification Readiness

Certification

  • Gap analysis against ISO 27001:2022 or SOC 2Included
  • ISMS scope and Statement of ApplicabilityIncluded
  • Risk methodology, register and treatment planIncluded
  • Full policy and procedure set, fitted to youIncluded
  • Evidence pack mapped control-by-controlIncluded
  • Internal audit and management reviewIncluded
  • Certification body selection and liaisonIncluded
  • Stage 1 and Stage 2 audit supportIncluded

Security testing

  • Application and cloud security reviewIncluded
  • Prioritised remediation list for your engineersIncluded
  • Manual web and API penetration testingNot included
  • Multi-tenancy and authorization boundary testingNot included
  • Cloud security assessment across all supported platformsNot included
  • Threat model feeding your risk registerNot included
  • Free retest of every findingNot included
  • Customer-shareable attestation letterNot included

Ongoing support

  • Named senior security leadduring engagement
  • Shared Slack or Teams channelIncluded
  • Customer security questionnaires and CAIQ / SIGNot included
  • Enterprise prospect security calls attendedNot included
  • Incident response plan and tabletop exercisesNot included
  • Quarterly board-level reportingNot included
Audit-Ready & Secure

Certification

  • Gap analysis against ISO 27001:2022 or SOC 2Included
  • ISMS scope and Statement of ApplicabilityIncluded
  • Risk methodology, register and treatment planIncluded
  • Full policy and procedure set, fitted to youIncluded
  • Evidence pack mapped control-by-controlIncluded
  • Internal audit and management reviewIncluded
  • Certification body selection and liaisonIncluded
  • Stage 1 and Stage 2 audit supportIncluded

Security testing

  • Application and cloud security reviewIncluded
  • Prioritised remediation list for your engineersIncluded
  • Manual web and API penetration testingIncluded
  • Multi-tenancy and authorization boundary testingIncluded
  • Cloud security assessment across all supported platformsIncluded
  • Threat model feeding your risk registerIncluded
  • Free retest of every findingIncluded
  • Customer-shareable attestation letterIncluded

Ongoing support

  • Named senior security leadduring engagement
  • Shared Slack or Teams channelIncluded
  • Customer security questionnaires and CAIQ / SIGNot included
  • Enterprise prospect security calls attendedNot included
  • Incident response plan and tabletop exercisesNot included
  • Quarterly board-level reportingNot included
Continuous Assurance

Certification

  • Gap analysis against ISO 27001:2022 or SOC 2annual
  • ISMS scope and Statement of Applicabilitymaintained
  • Risk methodology, register and treatment planmaintained
  • Full policy and procedure set, fitted to youmaintained
  • Evidence pack mapped control-by-controlIncluded
  • Internal audit and management reviewannual
  • Certification body selection and liaisonIncluded
  • Stage 1 and Stage 2 audit supportsurveillance

Security testing

  • Application and cloud security reviewIncluded
  • Prioritised remediation list for your engineersIncluded
  • Manual web and API penetration testingrecurring
  • Multi-tenancy and authorization boundary testingrecurring
  • Cloud security assessment across all supported platformsannual
  • Threat model feeding your risk registerIncluded
  • Free retest of every findingIncluded
  • Customer-shareable attestation letterIncluded

Ongoing support

  • Named senior security leadIncluded
  • Shared Slack or Teams channelIncluded
  • Customer security questionnaires and CAIQ / SIGIncluded
  • Enterprise prospect security calls attendedIncluded
  • Incident response plan and tabletop exercisesIncluded
  • Quarterly board-level reportingIncluded

Standalone

Just need the testing?

Both are available on their own, and both credit against a certification programme if you start one within six months.

Penetration test

Web, API, mobile or a combination. Retest included as standard, never billed separately.

$4,500
per engagement
Details

Cloud security assessment

AWS, Azure, Google Cloud, DigitalOcean, Linode or Vultr. Attack-path analysis, not a scanner export.

$3,500
per environment
Details

What you're actually choosing between

A consultancy, a platform, or a large audit firm.

All three get sold into the same problem. They solve genuinely different parts of it, and the honest comparison is below.

Scopes your ISMS and writes the Statement of Applicability

innsecs
Yes
Compliance platform
No
Large audit firm
Yes

Runs a defensible risk assessment on your actual architecture

innsecs
Yes
Compliance platform
Partial
Large audit firm
Yes

Policies written for your business, not templates

innsecs
Yes
Compliance platform
No
Large audit firm
Partial

Manual penetration testing included in the same engagement

innsecs
Yes
Compliance platform
No
Large audit firm
No

Findings retested and verified closed, at no extra cost

innsecs
Yes
Compliance platform
No
Large audit firm
No

Named senior consultant for the whole engagement

innsecs
Yes
Compliance platform
No
Large audit firm
No

Reads your Terraform and reviews your pull requests

innsecs
Yes
Compliance platform
No
Large audit firm
No

Continuous evidence collection and drift monitoring

innsecs
Partial
Compliance platform
Yes
Large audit firm
No

Fixed price, held for the engagement

innsecs
Yes
Compliance platform
Yes
Large audit firm
No

Can issue your certificate

innsecs
No
Compliance platform
No
Large audit firm
No

The last row is not a typo. No consultancy, platform or audit firm can issue your ISO 27001 certificate, only an accredited certification body can, and it must be independent of whoever built your controls. Anyone claiming otherwise is misrepresenting how the standard works.

Our commitments

Four promises, including one that costs us money.

01

Fixed price, held

The figure in your proposal is the figure you pay. Anything genuinely outside scope gets quoted separately, never invoiced quietly.

02

Retesting included

Every finding is retested and the report reissued with verified fix status. A finding isn't closed because it was reported.

03

We'll tell you not to buy

If certification is premature for your stage, or your timeline isn't achievable, we say so before the contract, not after Stage 1.

04

The people you met do the work

You get the consultant you scoped with. No junior handoff after kickoff, no rotating bench mid-engagement.

Questions

About the money.

There isn't one, but there is a reason. Consultant-led ISO 27001 typically runs $15,000–$30,000 and a startup pentest $5,000–$15,000, because those firms carry sales teams, account managers, offices and a bench of juniors. We carry none of that. The consultant who scopes your engagement is the one who does the work, and the saving goes to you rather than into a funnel.

The Launch Review is, and probably nothing else yet. For $1,500 we review your app and cloud, hand your engineers a prioritised fix list, and answer the first security questionnaire that lands. Certification at that stage is usually premature and we will say so. It credits in full against a certification programme later, so nothing is wasted.

Headcount, number of environments, product complexity, how many frameworks you're pursuing, and your starting maturity. A 15-person single-product SaaS on one AWS account sits at the bottom of the range. A 200-person company with three products, four environments and an acquisition to integrate does not.

Yes. We quote a defined scope for a defined figure and we hold it. If something genuinely outside that scope emerges, we tell you and quote it separately rather than quietly expanding the engagement and invoicing later.

Those are separate and paid directly to them. We never mark them up. Budget roughly $8,000–$25,000 for a first ISO 27001 certification depending on your size and the body you choose, plus $4,000–$10,000 a year for surveillance audits. We'll help you get comparable quotes, and for a small team the lower end is realistic.

Engagements are billed in three milestones rather than up front, and retainers are monthly. If cash flow is the blocker rather than the price, say so on the call. We would rather structure it than lose the work.

Get a real number in writing.

Tell us your headcount, environments and what's being asked of you. You'll have a fixed-price proposal within three working days.

Get a proposalsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.