Pricing
Fixed Scope. Fixed Price. No Hourly Games.
We do not publish rates. Every engagement is fixed scope and fixed price, scoped in one short call and put in writing before you commit to anything.
Four Practice Areas, Priced on a Call
We do not publish rates. The right number depends on your situation, and a public price would either set the wrong expectation or guess at work we have not seen yet. Once we understand the work, it is fixed scope and fixed price.
Fractional CISO & Hardening
We run your security program on an ongoing basis: board and executive reporting, SOC 2 and cyber insurance prep, vendor reviews, and scoped hardening engagements.
AI Plan and Build
Honest AI assessments, twelve-week builds that go live, and shared AI platforms for companies with several teams using AI. Built on a production AI service we operate today.
Architecture & Observability
Architecture and security reviews for decisions you cannot easily reverse, plus focused observability build-outs. Stack picks, platform migrations, monolith splits, cloud patterns.
CMMC Readiness
Gap analysis against CMMC Level 2 and NIST SP 800-171, SPRS score, System Security Plan support, POA&M documentation, and a prioritized remediation roadmap. Implementation support available.
Let's Talk
Tell us what you are dealing with on a thirty-minute call. We will tell you which engagement fits, what does not, and send a written scope and fixed price within a few business days. No hourly billing, no obligation.
Schedule a CallHow Engagements Work
Same flow for every engagement. You know what you are buying before you commit.
Thirty minutes. You describe the situation. We tell you which engagement fits and what does not.
One-page scope with deliverables, timeline, and fixed price. Sent within a few business days of the call.
The person who scoped the work does the work. No handoffs to associates or offshore teams.
Common Questions
Why are there no prices on the site?
Because any number we published would either set the wrong expectation or guess at scope we have not seen. A fractional CISO retainer, a twelve-week AI sprint, and a CMMC program are very different sizes of work. Even within one offering, the price moves with company size, regulatory exposure, how deep the integration goes, and how much of your team works alongside us. Once we understand the work, it is fixed scope and fixed price. One short call gets you a written scope and a number before you commit to anything.
How is an engagement scoped and priced?
A thirty-minute call to understand the situation, then a one-page written scope with deliverables, timeline, and a fixed price within a few business days. You decide from there. No hourly billing and no surprise invoices.
What is included in the CMMC readiness assessment?
The assessment covers all 110 NIST SP 800-171 controls, produces a SPRS score, documents your gaps, and gives you a prioritized remediation roadmap. Implementation support to close those gaps is available as a separate scoped engagement.
How fast can we get started?
Architecture and security reviews typically start within one week of booking. CMMC programs and fractional CISO retainers begin within two weeks of scoping. AI sprints kick off within two to three weeks. We move fast because most clients come to us with a deadline in mind.
Do you work with companies outside of defense contracting?
Yes. Fractional CISO, AI, and architecture engagements cover mid-market companies dealing with SOC 2, cyber insurance, enterprise customer security questionnaires, pressure to show AI results, or board-level oversight. CMMC work is specific to DoD contractors.
Do you do hourly or time-and-materials work?
No. Every engagement is fixed scope and fixed price. If we underestimate, that is our problem, not yours. If the scope changes materially mid-engagement, we re-scope in writing.
Not sure which engagement fits?
Start with a call. We will tell you what makes sense for what you are dealing with.