100% Transparent. Zero Surprises.
YOUR JOURNEY
Start With Clarity. End With Certification. Stay Secure.
Every engagement follows the same proven path. Start anywhere. Each step credits to the next.
START HERE
Not Ready for an Engagement? Start With Dashr.
Dashr.ai Security Intelligence
$1,000/month or $10,000/year
- + Live technical security score
- + Multi-framework compliance mapping
- + Prioritized risk and action lists
- + Month-over-month maturity tracking
- + Engineer action board
- + Executive dashboard
Quick Fix 30 — Know Where You Stand
Assessments delivered in 30 days or less. Start here if you are unsure about your current security posture. 100% of your Quick Fix 30 fee credits toward Report Ready 90.
Risk Assessment
Comprehensive security risk evaluation. Architecture review, access controls, cloud configurations, data flows, business processes, and vendor relationships. Prioritized remediation roadmap and certification readiness score.
- +Architecture and configuration review
- +CIS 18 baseline measurement
- +Data flow mapping
- +Prioritized remediation roadmap
- +Certification readiness score
- +Dashr.ai populated with your data
Penetration Testing
We run the pentest. External networks, internal networks, web applications, cloud environments, and social engineering simulations. Four-phase methodology with step-by-step remediation and retesting.
- +External and internal network testing
- +Web application testing
- +Cloud environment testing
- +Social engineering simulation
- +Remediation guidance and retesting
Gap Analysis
Framework-specific gap analysis with exact scope and pricing for your certification path. Findings report, prioritized roadmap, and certification readiness score. The smartest first step.
- +Framework-specific control evaluation
- +Findings report with risk levels
- +Prioritized remediation roadmap
- +Certification readiness score
- +Credits 100% to certification
Attack Surface Assessment
External reconnaissance using attacker techniques. Domains, subdomains, exposed services, credential exposure, impersonation risk. Then we reduce the surface, not just document it.
- +External asset enumeration
- +Credential exposure monitoring
- +DNS and certificate analysis
- +Impersonation risk assessment
- +Surface reduction recommendations
Report Ready 90: Audit-Ready in 90 Days
Full-service certification. We do the work. Fixed price. 90-day guarantee. Money-back if we miss the deadline. 100% first-attempt pass rate across 50+ engagements.
SOC 2
Type I or Type II. The gold standard for SaaS companies selling to enterprise.
- +Full gap analysis
- +40+ customized policies
- +Control implementation
- +Evidence collection via Dashr.ai
- +Mock audit
- +Auditor coordination
- +Year 1 Dashr.ai included
ISO 27001
Complete ISMS implementation. Stage 1 and Stage 2 audit preparation. International recognition.
- +ISMS build from scratch
- +Annex A control implementation
- +Risk treatment plan
- +Internal audit
- +Certification body coordination
- +Year 1 Dashr.ai included
HIPAA
Complete HIPAA Security Rule compliance. Administrative, physical, and technical safeguards.
- +Risk analysis (Security Rule)
- +Privacy Rule implementation
- +BAA management
- +Administrative safeguards
- +Technical safeguards
- +Year 1 Dashr.ai included
PCI DSS
Payment card compliance. SAQ or ROC based on your processing volume and architecture.
- +Scoping and segmentation
- +Control implementation
- +Network security
- +Data encryption
- +QSA coordination
- +Year 1 Dashr.ai included
ISO 42001 (AI)
AI governance certification. Responsible AI framework. Few consultants can deliver this. First-mover advantage.
- +AI management system design
- +Responsible AI framework
- +AI risk assessment
- +Data governance controls
- +Certification body coordination
- +Year 1 Dashr.ai included
Multiple Frameworks
ISO 27001 + SOC 2 share approximately 80% control overlap. One implementation, two certifications. Also available: HIPAA + SOC 2, ISO 42001 add-on.
- +Single implementation timeline
- +Shared control mapping
- +Significant savings vs. separate
- +Ask about bundle pricing
Securely Ever After: Stay Certified. Stay Secure.
Certification was Day One. These ongoing services keep your environment hardened, monitored, and continuously compliant. Most firms disappear after the certificate. We stay.
vCISO Advisory
Embedded strategic security leadership. Board reporting, risk management, vendor oversight, compliance maintenance, incident response planning, team mentoring.
- +Board-ready security reporting
- +Security program strategy
- +Risk register management
- +Vendor security oversight
- +Incident response planning
- +Dashr.ai included
Managed Security (MSSP)
Full security operations. 24/7 monitoring, threat detection, incident response, vulnerability management, threat hunting. We operate your security program.
- +24/7 monitoring via Dashr.ai
- +Threat detection and response
- +Vulnerability management
- +Incident response
- +Monthly security reporting
- +Dashr.ai included
Compliance Maintenance
Keep certifications current without the annual scramble. Evidence collection, control monitoring, policy updates, risk assessment refresh, recertification prep.
- +Continuous evidence collection
- +Control monitoring and drift alerts
- +Annual policy review
- +Risk register maintenance
- +Recertification audit coordination
- +Dashr.ai included
Device and Endpoint Security
We operate SentinelOne, NinjaOne, M365 Defender, Intune, Google Workspace security. Patch compliance, threat detection, encryption verification, device inventory.
- +Endpoint detection and response
- +Patch compliance monitoring
- +Full disk encryption verification
- +Device compliance reporting
- +Dashr.ai included
Log Analysis and Monitoring
Hands-on log review across Microsoft, Google, AWS, Azure, and your SIEM. Authentication anomalies, privilege escalation, configuration drift, data movement.
- +Authentication anomaly detection
- +Privilege escalation monitoring
- +Configuration change tracking
- +SIEM rule tuning
- +Dashr.ai included
Attack Surface, Data, Privacy
Continuous attack surface monitoring, data security program management, privacy compliance maintenance (CCPA, HIPAA, GDPR), and annual penetration testing.
- +External attack surface monitoring
- +Credential exposure alerts
- +Data security management
- +Privacy compliance updates
- +Annual penetration testing
- +Dashr.ai included
Important Pricing Notes
No. Auditor fees are separate and paid directly to the audit firm. SOC 2 auditor fees typically range from $8K-$15K. ISO 27001 certification body fees range from $10K-$20K. We coordinate with the auditor on your behalf and manage the entire process.
Company size (employee count), infrastructure complexity (single cloud vs. multi-cloud vs. hybrid), number of locations, data sensitivity (PHI, PCI, PII), and the number of frameworks. We provide an exact quote after a 30-minute discovery call.
Not for full-service implementation. At that price point, you are getting a consultant who advises you on what to do. We do the actual work: write policies, implement controls, run pentests, collect evidence, coordinate with the auditor. That level of service requires the investment reflected in our pricing. The ROI typically pays for itself within 3-6 months through unlocked enterprise deals.
If we commit to a 90-day timeline and miss it due to our performance, you get your money back. This has never happened. 87-day average across 50+ engagements. Zero missed deadlines.
If you start with Dashr.ai ($1K/month), your Dashr investment credits toward a Quick Fix 30 engagement if you proceed within 90 days. If you start with Quick Fix 30, 100% of that fee credits toward a Report Ready 90 certification engagement if you proceed within 90 days. You never pay twice for the same work.
Usually not. We are tool-agnostic and maximize the security capabilities in the tools you already own. Most companies use 20-30% of what they are paying for. We activate and configure the rest before recommending anything new.
Dashr.ai is our security intelligence platform. It provides real-time security scoring, compliance readiness tracking, risk management, and prioritized action lists. It is not a SIEM. A SIEM watches for bad things happening. Dashr watches for good things not happening. It is included with every certification and ongoing engagement because it is the platform that makes continuous compliance possible.
Ready to Get Audit-Ready?
Book a free 30-minute consultation. We'll assess where you are and map your fastest path to certified.