Add the frameworks you need. Only those.
$23,000/year for the Startup base plus one framework: $20,000 base + $3,000 per framework. For companies under $5M revenue or 50 staff. Independent audit and certification fees are separate. Enterprise pricing is custom.
New to startup compliance?
The Startup Compliance Atlas explains what applies, how controls and evidence work, and where to start with SOC 2 and other requirements.
Five frameworks, one programme.
Each framework has its own page - what it actually requires, how we run it, what it costs, and the questions everyone asks on the first call.
SOC 2
01The enterprise deal that stalled in vendor security review.
ISO 27001
02The international buyer who will not accept a US-only report.
HIPAA
03The health system that will not sign until your BAA holds up.
PCI DSS
04The acquirer or processor that just asked for your AOC.
GDPR
05The EU customer whose DPA review is holding up signature.
Something else
We run frameworks beyond these five, plus customer security questionnaires and your own internal control set. Ask on the call.
Ask about a framework (opens Google Calendar in a new tab)Not sure which one your buyers are actually asking for? That is the first thing we work out on the call - and we will tell you when the answer is "none yet."