Cost guide

How much does CISA-aligned cybersecurity work cost?

The honest answer: CISA's own guidance and scanning are free — you pay for implementation help. Start with the estimator, then see what drives the number.

Published sources and our labeled estimates put a CPG gap assessment at $15,000–$50,000, a zero-trust roadmap at $40,000–$150,000, and an incident-response retainer at $50,000–$200,000/year. CISA's Cyber Hygiene scanning: $0. Every figure below is labeled with its provenance.

CISA program cost estimator

How this estimate is calculated (formula & assumptions)

Bands are directory estimates (September 2026) unless labeled otherwise. Base assessment: $15k–$50k scaled by organization size. Zero-trust roadmap: +$40k–$150k for orgs over 200 staff with complex environments. IR retainer: $50k–$200k/year scaled by sector risk. vCISO: $8k–$20k/month if selected. CISA's own scanning and exercise packages: $0 — always subtract before hiring anyone.

Worked example (no JavaScript needed)

A 300-person regional utility aligning to the CPGs, starting from partial controls:

  • CPG gap assessment: $25,000–$40,000 (directory estimate band for this size)
  • Remediation consulting (6 months): $60,000–$120,000
  • CISA Cyber Hygiene scanning: $0
  • Total planning band: roughly $85,000–$160,000, excluding internal staff time and tooling.

Bands are directory estimates — see the formula disclosure above for the exact math.

Your estimate is a starting point. Bands are labeled estimates (see the 2026 pricing report). A scoped quote is what a firm actually charges you — get 2–3 and compare.

Get scoped quotes

Cost by organization size

Planning estimates for a first CPG-alignment program — not quotes, not measured averages. See the pricing report for provenance.

Organization sizeAssessmentImplementationFirst year, all in
~50 people (small operator)$15K–$25K$10K–$30K$25K–$75K
~200 people (mid-size)$25K–$40K$30K–$80K$75K–$200K
~1,000 people (large)$40K–$60K$80K–$200K$200K–$500K
Federal agency programScoped per vehicle$200K–$1M+Varies widely

What drives the number

Sources

Cost questions

What does a CPG gap assessment cost?

Our labeled estimates put it at $15,000–50,000 depending on organization size and scope — see the pricing report for provenance on every row.

Is any of this free?

Yes — CISA itself offers free vulnerability scanning (Cyber Hygiene), tabletop exercise packages, and assessments to eligible federal, SLTT, and critical-infrastructure organizations. Use the free tier before hiring a consultant.

What drives consulting cost up the most?

OT/ICS scope, cleared-staff requirements, starting posture (no asset inventory = more findings = more remediation), and geographic spread.

Do costs drop after the first year?

Typically yes — the assessment and roadmap are one-time; steady-state monitoring and annual reassessment cost a fraction of the first-year build-out.

How accurate are the estimator bands?

They are planning bands from labeled estimates (September 2026), not quotes. Real fees depend on scope, sector, and starting posture — get 2–3 scoped quotes and compare.