How much does CISA-aligned cybersecurity work cost?
The honest answer: CISA's own guidance and scanning are free — you pay for implementation help. Start with the estimator, then see what drives the number.
Published sources and our labeled estimates put a CPG gap assessment at $15,000–$50,000, a zero-trust roadmap at $40,000–$150,000, and an incident-response retainer at $50,000–$200,000/year. CISA's Cyber Hygiene scanning: $0. Every figure below is labeled with its provenance.
CISA program cost estimator
How this estimate is calculated (formula & assumptions)
Bands are directory estimates (September 2026) unless labeled otherwise. Base assessment: $15k–$50k scaled by organization size. Zero-trust roadmap: +$40k–$150k for orgs over 200 staff with complex environments. IR retainer: $50k–$200k/year scaled by sector risk. vCISO: $8k–$20k/month if selected. CISA's own scanning and exercise packages: $0 — always subtract before hiring anyone.
Worked example (no JavaScript needed)
A 300-person regional utility aligning to the CPGs, starting from partial controls:
- CPG gap assessment: $25,000–$40,000 (directory estimate band for this size)
- Remediation consulting (6 months): $60,000–$120,000
- CISA Cyber Hygiene scanning: $0
- Total planning band: roughly $85,000–$160,000, excluding internal staff time and tooling.
Bands are directory estimates — see the formula disclosure above for the exact math.
Your estimate is a starting point. Bands are labeled estimates (see the 2026 pricing report). A scoped quote is what a firm actually charges you — get 2–3 and compare.
Get scoped quotesCost by organization size
Planning estimates for a first CPG-alignment program — not quotes, not measured averages. See the pricing report for provenance.
| Organization size | Assessment | Implementation | First year, all in |
|---|---|---|---|
| ~50 people (small operator) | $15K–$25K | $10K–$30K | $25K–$75K |
| ~200 people (mid-size) | $25K–$40K | $30K–$80K | $75K–$200K |
| ~1,000 people (large) | $40K–$60K | $80K–$200K | $200K–$500K |
| Federal agency program | Scoped per vehicle | $200K–$1M+ | Varies widely |
What drives the number
- OT/ICS scope. Operational technology assessments cost more — specialized assessors, safety constraints, passive monitoring tooling.
- Cleared staff. Engagements requiring security clearances carry a premium and longer lead times.
- Starting posture. No asset inventory and no MFA means the assessment finds more — and remediation costs more.
- Geographic spread. Multi-site and field operations add travel and coordination cost.
Sources
- CISA — Cybersecurity Performance Goals (cisa.gov, updated 2025)
CISA's own baseline: the CPGs are voluntary goals for critical infrastructure — no fee, no certification attached. - CISA — Binding Operational Directives (cisa.gov)
BODs are mandatory for federal agencies (e.g. KEV remediation, asset management) — compliance cost sits in agency operations budgets, not a certification fee. - CISA — Free Cyber Hygiene services (cisa.gov)
CISA offers free vulnerability scanning and assessments to federal, SLTT, and critical-infrastructure organizations — $0. - Directory estimates (September 2026)
Advisory engagement bands synthesized from published consulting-rate data and firm planning ranges; labeled estimates, not quotes.
Cost questions
What does a CPG gap assessment cost?
Our labeled estimates put it at $15,000–50,000 depending on organization size and scope — see the pricing report for provenance on every row.
Is any of this free?
Yes — CISA itself offers free vulnerability scanning (Cyber Hygiene), tabletop exercise packages, and assessments to eligible federal, SLTT, and critical-infrastructure organizations. Use the free tier before hiring a consultant.
What drives consulting cost up the most?
OT/ICS scope, cleared-staff requirements, starting posture (no asset inventory = more findings = more remediation), and geographic spread.
Do costs drop after the first year?
Typically yes — the assessment and roadmap are one-time; steady-state monitoring and annual reassessment cost a fraction of the first-year build-out.
How accurate are the estimator bands?
They are planning bands from labeled estimates (September 2026), not quotes. Real fees depend on scope, sector, and starting posture — get 2–3 scoped quotes and compare.