Ask five firms what a risk assessment costs and you’ll get five answers, usually after a sales call you didn’t want. Here’s how the price is actually built, and how to judge a quote when you get one.

How the price is built

For a small or mid-size business, a hands-on cybersecurity risk assessment scales with headcount and complexity. More people means more interviews, more accounts, and more evidence to verify. A serious firm scopes your environment first and then puts a fixed price in writing; be wary of any number quoted before someone has asked how many locations and systems you run.

Every properly scoped assessment includes the same deliverables: network map and asset inventory, internal and external vulnerability scans, policy review, staff interviews, a framework assessment against NIST CSF and CIS Controls, a scored risk register, and a 30/60/90 remediation roadmap. What scales with price is depth, not the list of deliverables.

What drives the price up

  • Locations. Each site adds physical review, network segments, and travel.
  • Regulated data. HIPAA, financial, or biotech data adds framework modules and evidence requirements.
  • Complexity. An EHR, heavy cloud, or many vendors means more attack surface to map.
  • Deadlines. A renewal or audit date compresses schedules. Book before it’s urgent and the price stays normal.

What a cheap assessment leaves out

There are cheap subscription tools and bargain “assessments” that email you a questionnaire. What they skip is exactly what regulators, insurers, and auditors ask about: someone actually verifying your controls, interviewing your staff, and building an evidence trail. A checklist you filled out yourself is a statement of hope, not an assessment.

At the other end, national consultancies quote engagements built for enterprise scope and budgets, often with a rotating project team and a report your IT can’t action.

Why we don’t publish a number here

Any figure printed on a page is either padded to cover the worst case or too low to be honest. A serious quote needs four facts first (headcount, locations, systems, and which compliance modules apply), and with those, the number takes one 30-minute briefing and arrives fixed, in writing. A price that exists before those questions is a guess you would end up paying for.

The real cost question

An assessment’s value is what it does to your next dollar of security spending. A ranked, priced roadmap means the most dangerous gap gets fixed first, instead of whatever a vendor was selling that quarter. That’s usually worth more than the assessment costs.

What happens after

The report ends with a walkthrough and a 30/60/90 roadmap. Some companies run it themselves; most put it under a fractional CISO retainer so the roadmap is managed, reported to leadership, and proven by a reassessment a year later.