Pricing report

CISA consulting costs 2026: every figure, cited

A meta-analysis of cost data for CISA-guidance consulting work. One provenance label per row — published source or clearly-labeled directory estimate. No invented averages.

Cost itemRangeSourceSource dateScope
CISA Cyber Hygiene vulnerability scanning$0CISA2026Free for federal agencies, SLTT governments, and critical infrastructure
CISA tabletop exercise packages (CTEP)$0CISA2026Free facilitated exercise packages; travel not included
CPG gap assessment (consultant)$15,000–$50,000Directory estimateSeptember 2026Independent assessment against the CISA Cybersecurity Performance Goals
Zero-trust roadmap engagement$40,000–$150,000Directory estimateSeptember 2026Current-state assessment plus phased roadmap aligned to CISA ZTMM
NIST 800-171 readiness / gap assessment$15,000–$40,000Directory estimateSeptember 2026Pre-CMMC dry run: SSP review, control testing, POA&M
Incident-response retainer$50,000–$200,000 / yearDirectory estimateSeptember 2026Prepaid IR hours plus tabletop and readiness reviews
vCISO (fractional CISO)$8,000–$20,000 / monthDirectory estimateSeptember 2026Part-time security leadership; federal-adjacent programs skew higher
Penetration test (scoped)$15,000–$60,000Directory estimateSeptember 2026External + internal; OT/ICS testing costs more
FedRAMP authorization (adjacent, for context)$200,000–$500,000+Published planning ranges2025–20263PAO assessment plus remediation and PMO process; not a CISA program

How to read this table

Sources

Turn ranges into quotes

Estimates plan budgets. Scoped quotes set them — get 2–3, free.

Get a free quote