Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

What a Security and Compliance Retainer Costs, and What Should Be In One

Direct answer: Ongoing security and compliance retainers generally start in the four figures a month and are priced from the load, not from a tier sheet. The three things that move the number most are how many frameworks you are maintaining, whether an audit or observation window falls inside the term, and how much of the work your team can actually absorb. Ask for the scope in writing before the price, because two firms quoting the same monthly figure routinely mean completely different amounts of work.

Why nobody publishes a single number

A fixed-scope engagement can carry a published price because the deliverable is bounded. A gap analysis is a gap analysis. Ongoing work is not bounded in the same way. A company keeping one SOC 2 report alive with eight employees and one cloud account has a genuinely different monthly load from a company running SOC 2 and ISO 27001 together, with a vendor programme, an on-call rotation, and an enterprise deal arriving every quarter with a security review attached.

Firms that do publish a flat monthly number usually handle that variance one of two ways. Either the number is set high enough to cover the worst case, and light-usage clients quietly subsidise heavy ones, or the scope is narrow enough that everything real gets billed as an extra. Neither is dishonest, but both are worth knowing about before you sign.

What actually drives the price

Framework count, and the overlap between them. Two frameworks is not twice the work of one, because a large share of ISO 27001 Annex A maps onto the SOC 2 common criteria and evidence collected once counts for both. It is meaningfully more than one framework, though, because the management system requirements in ISO have no SOC 2 equivalent, and somebody has to run the internal audit and the management review.

Whether an audit falls inside the term. The months around fieldwork are heavier than the months between. Sampling gets negotiated, the request list gets worked, and questions come back that need answers the same week. A retainer priced on a quiet month and then hit with fieldwork is the most common source of a scope argument.

How much your team absorbs. If somebody internal owns the access reviews and actually does them, that is real hours off the retainer. If the honest answer is that nobody has done one since the last audit, the retainer is doing that work, and it should be priced for it.

Environment complexity. Three cloud accounts, a monorepo and forty people is a different evidence surface from one account and eight people. Not because the controls change, but because the number of places evidence has to be pulled from does.

Response commitments. If part of the retainer is being reachable when something breaks, that carries a cost whether or not anything breaks. You are paying for the capacity to be interrupted.

What belongs in the scope

A retainer that only produces a monthly call is not worth paying for. The scope should name work products, on a cadence, with an owner. The shape that holds up looks roughly like this.

Every month: access reviews and offboarding evidence produced and filed against the control they prove, scan findings triaged and tracked to closure, the evidence register kept current, and a working session with a written record of what moved.

Every quarter: vendor and third-party reviews, policy review and re-approval with version history intact, the risk register reassessed with owners and treatments rather than rewritten from memory, and an exercise of some kind, which is also the test record your framework asks for.

Every year: the penetration test scoped, run and retested, security awareness training completed with records, a recovery test that actually restores something, and the audit or surveillance cycle handled end to end.

On demand: security questionnaires answered when a deal brings one, and someone reachable when an incident starts.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

How to compare two proposals

Put both scopes side by side before you look at either price, and ask four questions.

What happens when fieldwork lands? If the answer is that audit support is billed separately, the monthly number is not comparable to one that includes it, and the gap between them is usually larger than the difference in the headline price.

Who is the named person? A retainer staffed from a pool is a different product from one where the people who ran your readiness engagement stay on it. Both are legitimate. Only one of them knows why a control is scoped the way it is.

What is explicitly out? A scope that lists exclusions is a scope somebody has thought about. A scope with no exclusions means the argument happens later, during the month you can least afford it.

Is there a tool subscription underneath this? Many retainers assume you are separately paying five figures a year for a compliance platform to work in. That is a real cost and it belongs in the comparison. Ours includes the workspace, which is a genuine difference in total spend rather than a feature bullet.

What a retainer is not

It is not an insurance policy against a failed audit. Nobody can sell you that, and an audit that fails usually fails because a control genuinely was not operating, not because nobody noticed.

It is not a replacement for someone internal caring about security. The most effective retainers we run have a counterpart on the client side who owns the relationship, even if they own very little of the work. The least effective ones are where the retainer was bought so that nobody internally has to think about it, and the evidence requests sit unanswered for three weeks.

It is also not automatically the right answer. If you have one framework, no audit in the next two quarters, and somebody internal who has done this before, you probably need a few hours of advice a quarter and not a retainer. A firm that will tell you that is worth more than one that will not.

When the maths works

The clearest case is the year after a first report. The programme is built, the controls exist, and the risk is entirely that they quietly stop operating between now and the next audit. That is cheap to prevent and expensive to fix, because a control that stopped in month three cannot be retrofitted in month twelve. The evidence is dated, and a Type II attests to a period.

The second clearest case is a company where compliance keeps interrupting engineering. Every questionnaire, every review, every evidence request lands on the same senior engineer, and none of it is what you hired them for. Costing that out honestly, in engineering time diverted rather than in dollars, usually settles the decision quickly.

If you want a number for your situation, our retainer scoping is one call, and what comes back is a written scope, a monthly figure and a plan of approach before anything is signed.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.