Direct answer: Ongoing security and compliance retainers generally start in the four figures a month and are priced from the load, not from a tier sheet. The three things that move the number most are how many frameworks you are maintaining, whether an audit or observation window falls inside the term, and how much of the work your team can actually absorb. Ask for the scope in writing before the price, because two firms quoting the same monthly figure routinely mean completely different amounts of work.
Why nobody publishes a single number
A fixed-scope engagement can carry a published price because the deliverable is bounded. A gap analysis is a gap analysis. Ongoing work is not bounded in the same way. A company keeping one SOC 2 report alive with eight employees and one cloud account has a genuinely different monthly load from a company running SOC 2 and ISO 27001 together, with a vendor programme, an on-call rotation, and an enterprise deal arriving every quarter with a security review attached.
Firms that do publish a flat monthly number usually handle that variance one of two ways. Either the number is set high enough to cover the worst case, and light-usage clients quietly subsidise heavy ones, or the scope is narrow enough that everything real gets billed as an extra. Neither is dishonest, but both are worth knowing about before you sign.
What actually drives the price
Framework count, and the overlap between them. Two frameworks is not twice the work of one, because a large share of ISO 27001 Annex A maps onto the SOC 2 common criteria and evidence collected once counts for both. It is meaningfully more than one framework, though, because the management system requirements in ISO have no SOC 2 equivalent, and somebody has to run the internal audit and the management review.
Whether an audit falls inside the term. The months around fieldwork are heavier than the months between. Sampling gets negotiated, the request list gets worked, and questions come back that need answers the same week. A retainer priced on a quiet month and then hit with fieldwork is the most common source of a scope argument.
How much your team absorbs. If somebody internal owns the access reviews and actually does them, that is real hours off the retainer. If the honest answer is that nobody has done one since the last audit, the retainer is doing that work, and it should be priced for it.
Environment complexity. Three cloud accounts, a monorepo and forty people is a different evidence surface from one account and eight people. Not because the controls change, but because the number of places evidence has to be pulled from does.
Response commitments. If part of the retainer is being reachable when something breaks, that carries a cost whether or not anything breaks. You are paying for the capacity to be interrupted.
What belongs in the scope
A retainer that only produces a monthly call is not worth paying for. The scope should name work products, on a cadence, with an owner. The shape that holds up looks roughly like this.
Every month: access reviews and offboarding evidence produced and filed against the control they prove, scan findings triaged and tracked to closure, the evidence register kept current, and a working session with a written record of what moved.
Every quarter: vendor and third-party reviews, policy review and re-approval with version history intact, the risk register reassessed with owners and treatments rather than rewritten from memory, and an exercise of some kind, which is also the test record your framework asks for.
Every year: the penetration test scoped, run and retested, security awareness training completed with records, a recovery test that actually restores something, and the audit or surveillance cycle handled end to end.
On demand: security questionnaires answered when a deal brings one, and someone reachable when an incident starts.
How to compare two proposals
Put both scopes side by side before you look at either price, and ask four questions.
What happens when fieldwork lands? If the answer is that audit support is billed separately, the monthly number is not comparable to one that includes it, and the gap between them is usually larger than the difference in the headline price.
Who is the named person? A retainer staffed from a pool is a different product from one where the people who ran your readiness engagement stay on it. Both are legitimate. Only one of them knows why a control is scoped the way it is.
What is explicitly out? A scope that lists exclusions is a scope somebody has thought about. A scope with no exclusions means the argument happens later, during the month you can least afford it.
Is there a tool subscription underneath this? Many retainers assume you are separately paying five figures a year for a compliance platform to work in. That is a real cost and it belongs in the comparison. Ours includes the workspace, which is a genuine difference in total spend rather than a feature bullet.
What a retainer is not
It is not an insurance policy against a failed audit. Nobody can sell you that, and an audit that fails usually fails because a control genuinely was not operating, not because nobody noticed.
It is not a replacement for someone internal caring about security. The most effective retainers we run have a counterpart on the client side who owns the relationship, even if they own very little of the work. The least effective ones are where the retainer was bought so that nobody internally has to think about it, and the evidence requests sit unanswered for three weeks.
It is also not automatically the right answer. If you have one framework, no audit in the next two quarters, and somebody internal who has done this before, you probably need a few hours of advice a quarter and not a retainer. A firm that will tell you that is worth more than one that will not.
When the maths works
The clearest case is the year after a first report. The programme is built, the controls exist, and the risk is entirely that they quietly stop operating between now and the next audit. That is cheap to prevent and expensive to fix, because a control that stopped in month three cannot be retrofitted in month twelve. The evidence is dated, and a Type II attests to a period.
The second clearest case is a company where compliance keeps interrupting engineering. Every questionnaire, every review, every evidence request lands on the same senior engineer, and none of it is what you hired them for. Costing that out honestly, in engineering time diverted rather than in dollars, usually settles the decision quickly.
If you want a number for your situation, our retainer scoping is one call, and what comes back is a written scope, a monthly figure and a plan of approach before anything is signed.
What a month actually contains
Abstract scope lists are easy to agree to and hard to hold anyone to, so it helps to look at a real month. Take a forty-person SaaS company maintaining one SOC 2 Type II report, with two cloud accounts, an enterprise pipeline, and no internal security hire.
Week one goes on the access review: pulling the user lists from the identity provider, the cloud consoles, the code repository and the two production databases, reconciling them against the HR roster, chasing the four accounts that belong to people nobody recognises, and filing the result as dated evidence against the control it proves. That is not an hour of work. Done properly, on a real environment, it is most of a day, plus the follow-up when a manager takes six days to confirm whether a contractor still needs write access.
Week two is scan triage and whatever the pipeline threw up. Two questionnaires, one of which is a portal that will not accept an uploaded answer library and has to be typed into by hand, and a call with a prospect's security architect who wants to talk about tenant isolation. Week three is the vendor review that came due, one new subprocessor to assess, and a policy that needs re-approval because the old version references a tool the company stopped using in March. Week four is the working session, the written record of what moved, and closing out the corrective actions from the last quarter.
Add the fieldwork month and the shape changes entirely. Sampling gets negotiated, a request list of sixty items arrives with a two-week turnaround, and three of those items require someone to go and generate evidence that nobody thought to keep. This is why the audit-inclusive question matters more than any other line in the comparison.
Hour banks, deliverables, and outcome pricing
Retainers get structured three ways and the structure tells you more than the price does.
An hour bank. You buy a block of hours a month and draw against it. It is transparent and it is easy to compare, but it creates a bad incentive on both sides: you ration questions to preserve hours, and the provider has no reason to make the work more efficient, because efficiency reduces their revenue. Watch for whether unused hours roll over, and for how long.
Named deliverables on a cadence. You buy the access reviews, the vendor reviews, the evidence register, the policy cycle, the audit support, produced monthly, quarterly and annually. This is the structure we prefer, because the argument at renewal is about whether the work happened, which is checkable, rather than about how long it took, which is not.
Outcome pricing. You pay against a milestone, usually a clean report or a certificate. It sounds attractive and it is mostly a bad idea, because the outcome depends heavily on decisions the provider does not control, and any firm pricing this way will write the exclusions tightly enough to protect themselves. Read those exclusions and you will usually find you bought a deliverable retainer with extra steps.
Whichever structure you pick, get three contract terms right. The notice period, because twelve months with ninety days' notice is a very different commitment from month to month. The rate card for out-of-scope work, agreed at signature rather than negotiated in the month you need it. And who owns the artefacts, which should be you, in your own systems. A retainer where the policies, the register and the evidence live in the provider's tooling is a retainer you cannot leave without rebuilding. Our workspace is free and the data in it is yours, which removes that argument entirely.
The incident clause is not an incident response retainer
Nearly every compliance retainer includes some version of "reachable when something happens". Read that clause carefully, because it usually means advisory support during business hours, not a responder on a plane. A genuine incident response retainer commits to a response time, names the people, and carries forensic capability, and it is priced accordingly. If your risk assessment says a ransomware event would be existential, the compliance retainer is not the control you think it is, and the honest conversation is about a separate arrangement. We cover the difference in our incident response retainer buyer's guide, and it is worth reading before you assume you are covered.
The related trap is scope drift during a live incident. Something happens, everyone works the problem for two weeks, and then there is an awkward conversation about whether any of that was in the retainer. Agree in advance what the first forty-eight hours look like and at what point the engagement converts to a separately billed response.
Situations that quietly cost more than the quote assumed
Customer right-to-audit clauses. Enterprise contracts increasingly reserve the right for the customer to audit you directly. One customer exercising that right can consume more effort than your own annual audit, because their auditors have no obligation to be efficient with your time. If you have signed those clauses, say so during scoping.
Multiple legal entities. A Canadian parent with a US subsidiary and separate payroll, separate identity tenants and separate contracts is not one organisation for evidence purposes. Every recurring control has to be evidenced twice.
An acquisition, in either direction. Buying a company adds an environment nobody has assessed, on a timeline set by the deal. Being bought means a diligence process that will ask for two years of evidence in ten days.
A framework added mid-term. Adding ISO 27001 to an existing SOC 2 programme mid-retainer is a project, not an increment, because the management system requirements, the internal audit and the management review have no SOC 2 equivalent. Price it as a project and let the retainer absorb the maintenance afterwards.
Turnover on your side. When the internal counterpart leaves, the retainer absorbs the knowledge gap, and the months after a departure are consistently the heaviest.
Signals it is not working, and what to do about it
Set a review at six months and go into it with specific questions rather than a general sense of satisfaction. Is the evidence register current as of this week, and can you see it without asking? Have the recurring controls actually run on their stated cadence, with dated artefacts, or has one of them silently lapsed? Did the last questionnaire get answered from a maintained library or written from scratch again? When something urgent came up, how long did the reply take?
The most common failure is neither party's fault in isolation. The provider produces the artefacts and the client stops engaging, so the register slowly fills with documents that describe a company that no longer exists. Nothing looks wrong until the auditor asks a question about a system that was decommissioned in the spring. If that is where you are, the fix is a shorter working session more often, not a bigger retainer.
If you decide to leave, ask for a handover package: the current register, the policy set with version history, the open corrective actions, the vendor list with review dates, and the auditor contact. A firm that resists this is telling you something. A firm that has been keeping your material in your own systems all along has nothing to hand over, because you already have it.
Cheaper things worth trying first
Before you commit to a monthly figure, there are two lighter options that solve a real share of cases. The first is a fixed-scope project with a defined end, which is the right purchase when the need is bounded: a first report, a specific remediation, a single framework gap closed. Our fixed-scope work is priced that way on purpose so nobody buys a subscription to solve a project. The second is a small quarterly advisory arrangement where somebody experienced reviews what you have done, tells you what is drifting, and leaves. That costs a fraction of a full retainer and it is genuinely sufficient for a company with one framework, a competent internal owner and no audit in the next two quarters.
The moment to move up to a full retainer is when you can point at recurring work that keeps landing on someone who was hired to do something else, or when the calendar rather than the ambition is driving the programme. Until then, buying less is the right call, and any firm worth engaging will tell you that before it costs you a year of fees.
Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.
Talk to usOr talk about a retainerWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.