Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

What Flat-Rate Pricing Actually Means in Compliance Consulting

A number on a page is a claim about knowledge

Every price is a statement about what the seller knows. A plumber quoting to replace a tap is firm on the price because the work is visible from where they are standing. When the same plumber quotes to find out why the basement is damp, the honest version is a diagnostic fee first and a repair quote after, because nobody prices a repair to a wall they have not opened.

Compliance consulting has the same structure. A SOC 2 or ISO 27001 engagement contains one body of work that is knowable before anyone starts, and a second body of work that is not knowable until the first one finishes. A quote that prices only the first part is making a claim it can support. A quote that prices both parts in one figure is making a claim about work nobody has looked at yet.

That is not an accusation. Bundled numbers are common, sometimes reasonable, and plenty of buyers prefer them. The point here is narrower: a single number spanning readiness, remediation and testing has exactly two possible resolutions, and you should know which one you are in before you sign, not eleven weeks later when you have an audit date and a board update due.

What a fixed-scope Phase 1 actually contains

Start with the part that can be priced honestly, because its shape is fixed before the work begins.

A gap assessment is a defined piece of work with defined outputs. The consultant conducts interviews with the people who actually run the systems, usually engineering, IT, HR and whoever owns vendor relationships. They review the existing control set against the framework's criteria, one criterion at a time. They inventory what evidence exists today, in what form, and whether it can be produced again on demand for an audit period. Then they write a findings register: every gap, what the framework requires, what exists now, and what closing it would involve.

Every one of those activities has a knowable size. The number of interviews is a function of headcount and system count. The control review is bounded by the framework, and the framework does not change based on what the review finds. The evidence inventory is bounded by the systems in scope. Somebody who has run this work before can count the moving parts and quote it without guessing.

That is why readiness engagements can carry a real number. SOC 2 readiness from $3,000, ISO 27001 readiness from $3,000, PIPEDA readiness from $2,500. Those are prices for a defined piece of diagnostic work with a defined deliverable, not prices for an outcome.

Why remediation cannot honestly carry a price yet

Now consider what Phase 2 involves, and why it resists pricing until Phase 1 is done.

Remediation is whatever the findings say it is. Two companies of identical size in the identical industry can finish a gap assessment with wildly different Phase 2 scopes. One has centralised identity, logging that already retains what an auditor will ask for, an offboarding process that produces a trail, and a vendor list someone maintains. Its remediation is policy work, a risk assessment, some access review cadence, and evidence discipline. The other has four identity sources that do not talk to each other, logging that rolls off before an audit period closes, offboarding that lives in somebody's memory, and no vendor inventory. Its remediation includes actual engineering.

Same framework. Same headcount. Different work by a large multiple.

This is why remediation is scoped and priced from the findings register rather than from the sales call. Nobody knows the gaps at quoting time, including the consultant, and a number produced before they are known is a forecast wearing the clothes of a price. Producing the findings first means the client sees the real figure for the expensive half of the engagement before committing to it, with the register explaining where the figure comes from.

The two resolutions of a bundled number

Here is the structural part, stated plainly.

If a single flat figure covers readiness, remediation and testing, the person who wrote it had to make an assumption about how much remediation your environment will need. They had no findings register, so the assumption is all they had. There are only two directions that assumption can go.

The buffer is generous. The quoter priced for something close to the worst case they typically see, because a fixed price they cannot exceed is a risk they are carrying, and carrying risk costs money. This is rational pricing behaviour, and it is not dishonest. But it means the price is an average across their client base, and averages have two sides. A company that has already done the unglamorous work, centralised its identity, kept its logs, written its policies, maintained its vendor list, pays for remediation it does not need. The buffer is real money and it transfers from the tidy client to the messy one.

The buffer is thin. The quoter priced closer to the likely case, either to win the work or because they were optimistic about what they would find. If your environment turns out to be heavier than assumed, the gap has to be resolved somewhere. It gets resolved through a scope conversation. Scope conversations are not inherently unfair, but the timing of this one matters enormously: it happens after you have paid a deposit, after you have told your largest prospect the certificate is coming, after an audit window has been booked, and after switching providers would cost you the calendar. You have a deadline and nowhere else to go. That is not a good moment to negotiate the second half of a contract.

Neither resolution requires anyone to have behaved badly. Both follow from pricing work before looking at it. The buyer deserves to know which one they are in, and that is answerable with a question rather than an accusation: is the remediation effort in this number capped, or estimated?

The fair case for genuine fixed pricing

It would be a distortion to suggest fixed prices are a problem in themselves. They are not, and treating every flat rate as a warning sign will lead you to overpay for hourly work that should have been quoted.

Fixed pricing is correct whenever the work is genuinely bounded at quoting time. Completing a customer security questionnaire is bounded: the questionnaire exists, it has a known number of items, and the work is answering them. From $1,000 is a real price. An incident response tabletop is bounded: one day, a defined scenario, a defined set of participants, a written after-action report. Auditor management is bounded by the audit cycle, a technical due diligence review by its five business day window, a Law 25 readiness sprint by four weeks of defined scope.

What these have in common is that the deliverable does not expand based on what the work discovers. A tabletop that surfaces ugly findings is still one day.

The distinction is not fixed versus variable pricing. It is whether the fixed price spans work whose size is unknown when the number is written. A flat rate over a defined deliverable is a service. A flat rate over an unknown quantity of remediation is a bet, and the buyer is a party to it whether or not anybody said so out loud.

Why the gap assessment protects you more than it protects us

It is worth being direct about who benefits from the two-phase structure, because the obvious reading is that it benefits the consultant, and the obvious reading is wrong.

A consultant who quotes one large bundled number books more revenue per signature, gets it committed earlier, and never has to justify the second figure on its own merits. Splitting the engagement gives that up. It creates a decision point where the client can read the findings register, see the Phase 2 number, and decline.

That decision point is the protection. With the register in hand you can do things that are impossible before it exists. You can take remediation in house where you have the capacity, and many teams close a meaningful share of findings themselves once somebody has written down precisely what is missing. You can sequence the work across two budget cycles instead of one. You can show your board the actual position rather than a promise. You can compare Phase 2 quotes on a like-for-like basis, because everyone is quoting against the same document instead of against their own guess about your environment. You can also discover that your exposure is smaller than feared.

None of that is available to a buyer who committed to the whole engagement on day one. The commitment was made at the moment of least information, which is the worst possible moment to make it.

There is a knock-on benefit on the audit side. A documented readiness position, showing what was found and what was closed, changes the conversation with the licensed CPA firm that performs the audit, because there is less unknown for them to price into their own quote. We have written up a case where that documentation took $11,000 off an audit quote, at /blog/auditor-vetting-readiness-case-study. Audit fees are separate from readiness fees in any event, but the quality of what you hand the auditor is within your control and it has a price attached.

The same problem, different shape: pricing a penetration test before scoping

The identical structure shows up in penetration testing, and it catches more buyers because the work sounds more standardised than it is.

A penetration test price is a function of scope, and scope means specific things: how many applications, how many distinct user roles, whether the authenticated surface is tested or only the anonymous one, whether the API is in scope separately from the web front end, whether cloud configuration is included, how many external hosts, whether anything is tested from inside the network, and whether retesting after fixes is included or billed again.

Change any one of those and the effort changes materially. An unauthenticated external test against a handful of hosts and a full authenticated test across three user roles, an API and a cloud environment are not the same engagement, and no single number covers both without either a large buffer or a later conversation. A test price quoted before anyone has asked those questions carries the same two resolutions as the bundled compliance number. The buffer absorbs it, or the scope conversation happens later. The honest sequence is a scoping conversation, then a quote for the agreed scope, then a report, then a retest of the items you fixed. Testing from $1,000 means that: a real starting point for a scoped piece of work, not a flat rate covering whatever turns out to be in your environment.

One caution about market context. Public figures for a Canadian tester day sit roughly between $1,500 and $2,800 CAD. That is useful for sanity-checking whether a quote implies a plausible number of days for the scope described, and that is all it is useful for. It is market context, not any given provider's rate, and the two should not be conflated.

Five questions to ask before you sign

These work on any quote, from anyone, and none of them are adversarial. A provider who prices carefully will have ready answers, because these are the questions they asked themselves while writing the number.

What exactly is in scope for this figure? Ask for a list of deliverables, not a paragraph of outcomes. "SOC 2 readiness" is a category. "Interviews, control review against the trust services criteria, evidence inventory, findings register, and a remediation plan" is a scope.

What happens if you find more than expected? The answer reveals the structure. It is either "the price holds and we absorb it", which tells you a buffer is in there, or "we would come back to you with a scope change", which tells you the timing risk sits with you. Both are workable. Not knowing which is not.

Is remediation effort capped or estimated? A cap is a commitment and should be written as one, stated in hours or days. An estimate is a forecast, and should be budgeted as one.

Who decides when something is out of scope? In practice: what is the written definition, and what happens when the two parties disagree. A scope defined only by the provider's judgement is not a scope.

Can I see the findings before committing to Phase 2? This is the one that matters most. If yes, you learn what you are buying before you commit to buying it. If no, you are committing to the expensive half of the engagement at the moment you know least about it.

A few adjacent questions are worth the breath: has the firm completed engagements in Canada it can point to, who signs the audit and can they be referenced, which entity signs the contract and under which province's law, and where engagement data is stored.

What "from $3,000" is meant to mean

Our published prices carry the word "from" deliberately, and it is worth saying what it does and does not claim.

"From $3,000" is the starting price for Phase 1, the gap assessment, at the smaller end of the range of environments we see. It scales with the real drivers: the number of systems in scope, the number of physical locations, headcount, and whether more than one framework is running at once. What it does not include is Phase 2, because Phase 2 is priced from the findings, and it does not include the audit fee, because the audit is performed by an independent licensed CPA firm and certification by an accredited certification body. Those are separate invoices from separate organizations, by design.

The fractional CISO line works differently. From $3,000 a month buys ongoing capacity, not a defined deliverable, and it is priced as a retainer because that is what it is.

The parallel SOC 2 Type II and ISO 27001 engagement we ran for a Waterloo data centre operator across three physical sites, written up at /blog/soc-2-iso-27001-parallel-case-study, would not have been priceable in one figure before the assessment. Three sites, two frameworks, physical and logical controls both in scope. The gap assessment made the rest of it quotable.

Where to go next

If you are holding a quote right now, take the five questions to whoever wrote it. The answers will tell you which structure you are looking at in about ten minutes, which beats comparing headline numbers built on different assumptions.

Our published pricing, with the phase split shown explicitly, is at /pricing. To talk through a specific quote, or work out what your Phase 1 scope would actually be, book a readiness call at /free-readiness-call. For penetration testing, scope comes first and the quote follows it.

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.