Pricing

Our prices are on this page. All of them.

Most firms in this space make you sit through two calls before anyone says a number. We’d rather you work out whether we’re in your range before you spend an hour with us — so everything is published, including what isn’t included.

Prices are per month unless stated otherwise, in USD, and exclude platform licensing. Scoping determines which of these actually apply to you — most clients need two or three, not all of them.

How pricing works

Three ways things are priced, for three different reasons.

Nothing here is priced per user just because that’s the fashion. Each offering is priced the way its cost actually behaves — which is also why the cheapest-looking line isn’t always the cheapest outcome.

Per user

Secure Enclave, security monitoring

Every seat carries a real cost — a desktop, licensing, an agent on each machine. More people genuinely costs more, so the price follows headcount, and the rate drops as volume rises.

Flat

Compliance App, vCISO Small Business

One control set, one policy suite, one program. The practitioner effort is the same whether you have eight people or thirty, so headcount doesn’t change the price.

Banded

AI implementation

Governance work steps up at certain sizes rather than rising with each hire. Bands reflect that, and you only reprice if you cross a threshold meaningfully.

The numbers

What things cost.

Setup fees are one-time. Recurring prices are monthly. Platform licensing — GCC High, Google, Copilot — is separate, and you can bring your own or buy it through us.

Security monitoring

Per user & per server

Managed EDR, managed SIEM, vulnerability management, and awareness training with phishing simulation — run by us, on the environment you already have.

Per user
UsersSetup — one timePer user, per month
1–15$1,500$36
16–40$2,500$32
41–75$3,750$28
76+QuotedQuoted
Per server — priced by device, not headcount
ServersOnboarding — one timePer server, per month
1–5$250 each$75
6–15$250 each$65
16+Quoted$55

Already included if you have an enclave. Security monitoring comes with both the CUI and commercial Secure Enclave — the rates above are for monitoring your existing environment, without one.

Servers are priced per device because server count doesn’t track headcount, and a server carries more licensing cost, more log volume, and a different response path than a workstation. Setup covers agent deployment, baseline tuning, alert routing, and reporting. Penetration testing, incident response, and cyber risk assessments are priced separately — testing and assessments per engagement, incident response through Expert Blocks. Coverage hours, response times, and escalation paths are defined in your agreement rather than implied here.

Secure Enclave

Per user

Built in your own tenant — GCC High or Google Assured Controls for CUI, commercial for everything else. Security monitoring is included in both. The CUI seat is all-in.

Setup — one time
UsersCUI / exportCommercial
1–15$4,500$2,500
16–40$7,500$4,000
41–75$11,000$6,000
76+QuotedQuoted
Recurring — per user, per month
Seat typePriceNotes
CUI / export controlled$325Personal persistent desktop, security monitoring, the full CUI compliance program, and the Compliance App — nothing else to add
Commercial$125Pooled virtual desktop and security monitoring
Power, dev, or GPU seatQuotedSized to the workload
Monthly minimum$500Applies to every enclave. A single-seat enclave pays the minimum rather than the per-user rate.
Co-managed CUI endpoints
ItemPriceNotes
Managed CUI endpoint$150 / user / moPhysical machines with CUI at rest — CAD, engineering, graphics
Endpoint onboarding$250 one-timePer endpoint — agent deployment, baseline, validation

On CUI seats. They aren’t pooled, and that’s deliberate. A cheaper CUI seat elsewhere may be sharing a host between users, which creates attribution and separation problems at assessment. Worth asking any provider directly.

The CUI seat is all-in. $325 per user covers the desktop, security monitoring, the full compliance program — controls against NIST SP 800-171, SSP, policy suite, POA&M, evidence, SPRS support — and the Compliance App. There is no separate App subscription to add on top. Platform licensing is the only thing billed separately. A $500 monthly minimum applies to every enclave, and setup is the same across the band — the environment costs the same to build and run whether one person or fifteen are working in it.

Compliance App

Flat

Your control set, evidence, and status in one place, with credentialed practitioner review behind it. Already included if you have a CUI enclave — the rates below are for clients running it on their own environment.

TierPriceScope
CMMC Level 1$199 / moL1 scope, self-assessment support, knowledgebase, training
CUI / Level 2$600 / moFull L2 control set, evidence management, POA&M, RPA support
First additional framework+$200 / moBeyond your base tier scope
Each additional after+$150 / moOr take the pack below
Multi-framework pack$450 / moAny three additional frameworks

No setup fee, 12-month term, 10% off if you prepay annually. And an important distinction: the App is not done-for-you. You do the work in the tool and our practitioners review and support it. If you’d rather we produce the artifacts, that’s Expert Blocks — a clean handoff rather than a surprise on your invoice.

AI implementation and governance

Banded

Inventory, governance framework, technical configuration, monitoring, and documentation — then ongoing management.

Setup — one time
UsersCommercialCUI / DIB
1–15$3,500$5,500
16–40$4,500$7,500
41–75$6,000$9,500
76+QuotedQuoted
Recurring — per month
UsersCommercialCUI / DIBCUI, enclave attach
1–15$700$1,100$700
16–40$1,200$1,600$1,000
41–75$2,000$2,500$1,500
76–150$3,100$3,700$2,200
150+QuotedQuotedQuoted

Already have a Secure Enclave? The enclave attach rate applies — the boundary, identity, and monitoring are already ours to run, so governing AI inside it costs less than governing it across an environment we didn’t build.

Secure AI Readiness Assessment — $4,500, credited against setup if you proceed within 60 days. Two exclusions worth knowing up front: end-user training and custom agent builds route to Expert Blocks, and SharePoint permission remediation is scoped separately — assistants surface anything a user can already reach, and most tenants carry years of oversharing.

vCISO

Flat & retainer

Fractional security leadership in two tiers, with a deliberate gap between them.

TierPriceWhat it covers
Small Business$500 / moCIS control tracking in our workbook, a 20-minute weekly check-in with your technical lead, and a quarterly risk assessment. Advisory during the scheduled call.
StandardFrom $2,250 / mo10 hours per month at $225/hr with a named practitioner. Overage billed at the same rate. No rollover.

Small Business is tracking, not implementation. Incident response, document production, third-party risk work, questionnaires over about fifteen questions, and out-of-band requests are billed as Expert Blocks. We’d rather write that down than have the conversation later. Security monitoring is a separate service — a vCISO decides what should happen; the Cybersecurity practice is what runs it.

Expert Blocks and fixed-fee work

Per engagement

Bounded professional services for anything outside a subscription.

ItemPriceNotes
Half day$1,1004 hours
Full day$2,0008 hours
Week$9,00040 hours
Affirmation Defensibility Review$3,500Fixed fee — documentation and evidence review behind your SPRS self-assessment
Secure AI Readiness Assessment$4,500Credited against AI setup on conversion within 60 days

Typical uses: incident response, policy and artifact production, migration into the enclave, custom agent builds, training and workshops, and vCISO overage. Every agreement names Expert Blocks as the destination for out-of-scope work, so the handoff is contractual rather than a negotiation mid-project.

The fine print, up front

What’s not included.

The number that matters is the one on your invoice in month four, not the one in the proposal. These are the things that surprise people, so they’re here rather than in a footnote.

Billed separately

Real costs that aren’t ours to absorb, and that you can often supply yourself.

Platform licensing Copilot and AI licenses Bring your own, or buy through us

Deliberately out of scope

Work we don’t do, so you can plan for who does.

General IT helpdesk Hardware and OS lifecycle End-user application support

Routes to Expert Blocks

Bounded and quoted, so nothing bleeds quietly into a retainer.

Incident response Artifact production Migration Training and workshops

On helpdesk specifically. We don’t run one, and we’d rather say so than do it badly. Most clients keep their existing IT provider or MSP and we work alongside them — we’ll document the boundary between the two firms so nothing lands in the gap. If you don’t have one, we can point you at MSPs who know this space.

Pricing questions

Things people ask before committing.

Everything on this page is published. These are the questions that come up anyway.

Do I have to start with a roadmap?
No. Start wherever the pressure actually is — a questionnaire you can’t answer, a prime pushing a requirement, an assessment coming up. A roadmap is worth it when you genuinely don’t know what you owe or what shape you’re in, and it’s a fixed fee with a deliverable that’s yours to keep whether or not you continue with us. Nothing on this page requires you to buy anything else first.
What’s included in the Secure Enclave price?
Both flavours include security monitoring — EDR, SIEM, vulnerability management, and awareness training. The CUI enclave also includes the full compliance program: control implementation against NIST SP 800-171, SSP, policy suite, POA&M, evidence collection, and SPRS support. The Compliance App is included too — the CUI seat is all-in at $325, with no separate App subscription to add. Platform licensing is the only thing billed separately.
How does the setup fee work?
The one-time setup fee and your first month are due before we begin. Setup covers real build labour — standing up the tenant, hardening it, deploying agents, and validating it before go-live. It’s priced close to cost, not as an onboarding tax, which is also why it isn’t discounted. Ask at scoping if the timing is difficult; we can sometimes arrange something.
What if we add users later?
Enclave and monitoring pricing is per in-scope user, so it scales as you grow. Bands run 1–15, 16–40, 41–75, and 76+, and crossing a band moves you to that band’s rate for all seats. There’s no per-seat setup fee for users added after initial deployment — they join the environment that already exists.
What counts as an “in-scope” user?
The people who actually access, store, process, or transmit the regulated data — not your whole company. Because pricing follows in-scope users, getting this right is what keeps both your cost and your assessment small. It’s the first thing we work out together at scoping, and it’s where we most often save people money.
Why do servers cost more than users?
Server agents carry higher licensing cost, servers generate far more log volume into the SIEM, and an alert on a file server holding CUI is a different response than an alert on a laptop. Server count also doesn’t track headcount — a ten-person engineering firm may run more servers than a forty-person services firm. So servers are priced per device rather than folded into a per-seat rate.
Is there a minimum contract term?
The Compliance App runs on a 12-month term with 10% off if you prepay annually. Other subscriptions are quoted with the term stated in your agreement — we’ll be explicit about it at scoping rather than burying it. Project work like penetration testing and Expert Blocks carries no ongoing commitment.
What’s not included in any of these prices?
Platform licensing — GCC High, Google, Copilot — which you can buy through us or bring your own. General IT helpdesk, hardware and OS lifecycle, and end-user application support, which we deliberately don’t do. And anything outside a subscription’s scope routes to Expert Blocks, quoted up front, so nothing bleeds quietly into a retainer.
What if I just need help with one specific thing?
That’s what Expert Blocks are for — a half day, a day, or a week of practitioner time pointed at exactly the work in front of you, with no package and no commitment. Typical uses: incident response, artifact production, migration, custom agent builds, training, and vCISO overage. Every block is scoped before we start.
Are C3PAO assessment fees included?
No, and they can’t be. C3PAO fees are paid directly to the independent assessor, and the amount depends on your scope and the assessor you choose. Greypike is not a C3PAO — our work is led by a Cyber AB Registered Practitioner Advanced, and we prepare you for the assessment that someone independent then conducts. That separation is what keeps your evidence defensible.

Start here

Get a number that fits your situation.

Bring your headcount, your contracts, and what your customers are asking for. We’ll put the actual figures together and tell you which lines you don’t need. No obligation.

Veteran-founded · Cyber AB RPA-led · Government contractors only