Ask five firms what a risk assessment costs and you’ll get five answers, usually after a sales call you didn’t want. Here’s how the price is actually built, and how to judge a quote when you get one.
How the price is built
For a small or mid-size business, a hands-on cybersecurity risk assessment scales with headcount and complexity. More people means more interviews, more accounts, and more evidence to verify. A serious firm scopes your environment first and then puts a fixed price in writing; be wary of any number quoted before someone has asked how many locations and systems you run.
Every properly scoped assessment includes the same deliverables: network map and asset inventory, internal and external vulnerability scans, policy review, staff interviews, a framework assessment against NIST CSF and CIS Controls, a scored risk register, and a 30/60/90 remediation roadmap. What scales with price is depth, not the list of deliverables.
What drives the price up
- Locations. Each site adds physical review, network segments, and travel.
- Regulated data. HIPAA, financial, or biotech data adds framework modules and evidence requirements.
- Complexity. An EHR, heavy cloud, or many vendors means more attack surface to map.
- Deadlines. A renewal or audit date compresses schedules. Book before it’s urgent and the price stays normal.
What a cheap assessment leaves out
There are cheap subscription tools and bargain “assessments” that email you a questionnaire. What they skip is exactly what regulators, insurers, and auditors ask about: someone actually verifying your controls, interviewing your staff, and building an evidence trail. A checklist you filled out yourself is a statement of hope, not an assessment.
At the other end, national consultancies quote engagements built for enterprise scope and budgets, often with a rotating project team and a report your IT can’t action.
Why we don’t publish a number here
Any figure printed on a page is either padded to cover the worst case or too low to be honest. A serious quote needs four facts first (headcount, locations, systems, and which compliance modules apply), and with those, the number takes one 30-minute briefing and arrives fixed, in writing. A price that exists before those questions is a guess you would end up paying for.
The real cost question
An assessment’s value is what it does to your next dollar of security spending. A ranked, priced roadmap means the most dangerous gap gets fixed first, instead of whatever a vendor was selling that quarter. That’s usually worth more than the assessment costs.
What happens after
The report ends with a walkthrough and a 30/60/90 roadmap. Some companies run it themselves; most put it under a fractional CISO retainer so the roadmap is managed, reported to leadership, and proven by a reassessment a year later.