Pricing

Choose how much ownership to hand over.

Every tier is senior-led, month to month, and scoped around outcomes rather than hours. Start where you are. Move tiers when the audit date or the funding round changes the math.

rm

Advisory

Your team executes. I set direction, review decisions, and keep you honest about risk.

from$2,500/ month
≈10 senior hours · billed monthly
  • Monthly security & risk review
  • 12-month roadmap, refreshed quarterly
  • Policy and control review
  • Audit and compliance guidance
  • Board-ready recommendations
  • Slack/email access, 48-hour SLA
Discuss scope
rm -rf

Embedded

I'm inside your operating cadence. For FedRAMP, IL4, AI-governance builds, tight audit dates or M&A.

Custom
typically $10,000+ / month
  • Everything in Managed, plus
  • Weekly cadence, incident command when needed
  • FedRAMP / IL4 authorization programs
  • ISO 42001 & AI governance build-out
  • Due diligence for fundraising or M&A
  • Hiring and mentoring your first security team
  • Same-day response
Talk through it

Month to month, 30 days notice. Annual billing saves 15%; cancel and the unused balance is refunded pro rata.

Prices are engagement baselines. Final scope depends on your environment, the frameworks in play, and how fast you need to move. One-time assessments and builds are quoted separately below.

Fixed-scope projects

Not ready for a retainer? Buy an outcome.

One deliverable, one scope, one deadline. Most retainers start with one of these. Third-party fees such as pentests, tooling and the auditor are passed through at cost.

Security assessment

from $3,000

What you get. A two-week posture review of cloud, identity, source and vendors, closed out with a risk-ranked roadmap that has an owner, a cost and a date on every line.

Pick it when. You suspect problems but can't rank them, an investor has asked "what's your security posture", or you want to try working with me before committing to a retainer.

SOC 2 / ISO 27001 program build

from $2,000

What you get. A readiness build scoped to your size and framework: policies written in your voice, controls mapped and owned, GRC tooling wired to real systems, evidence flowing, and an auditor selected.

Pick it when. A customer contract or a funding round has put a certificate on the calendar and nobody in-house has run an audit before.

AI risk assessment

from $2,000

What you get. An ISO 42001 and NIST AI RMF gap review plus a security pass over your LLM applications: prompt injection, data leakage, tool-call boundaries, logging. A model inventory and a prioritised fix list come with it.

Pick it when. LLM features are in production, an enterprise buyer has asked about AI governance, and the honest answer today is "we haven't looked".

Security questionnaire

scoped per questionnaire

What you get. SIG, CAIQ, VSAQ or the custom spreadsheet, answered from your actual environment with an evidence pack procurement can file. Answers are kept, so the next one is faster.

Pick it when. A deal is stuck in security review. Priced on the number of questions and the turnaround you need, so a 40-row CAIQ and a 400-row SIG on a two-day deadline aren't the same number. You get the figure before I start.

By the hour

$300 / hour

What you get. Senior security time with no scoping exercise. Architecture review, a second opinion before a board meeting, an auditor call you'd rather not take alone, or help answering one hard question properly.

Pick it when. The work is too small or too unpredictable to scope, or you want to test how I think before committing to anything larger. Billed in 30-minute increments against time actually used.

The alternative

What it costs to not do this.

Typical market ranges, not rmrfs claims. Your numbers will differ; the direction won't. A retainer is priced to sit well below any one of these.

$350K+ Typical full-time CISO compensation, $350–450K, before equity. Then a search that commonly runs about four months.
90days One enterprise deal slipping a quarter in security review. Common when nobody owns the questionnaire or the SOC 2 answer is "in progress".
3–12mo SOC 2 Type II observation window. The calendar starts when controls are operating, not when you decide to get audited.
48h Questionnaire turnaround on a Managed retainer. Without an owner, the same document typically takes teams two to four weeks.
Deliberately small

Four retainer seats. 4 open.

rmrfs is a solo practice on purpose: you work with the operator, not a delivery bench. That caps me at four concurrent retainers, so when I'm full I say so instead of subcontracting you out. Ask on the call and you'll get a straight answer on capacity and a start date.

Retainer capacitymax 4 concurrent
open
open
open
open
Engagementmonth to month
Notice period30 days
First replywithin 1 business day
Pricing FAQ

The money questions, answered plainly.

If yours isn't here, ask it on the call. I'd rather you know the terms before we start than discover them in month three.

01Why "from"? Why not one fixed price per tier?

Because a 40-person SaaS company with one AWS account and SOC 2 in flight is not the same engagement as a 250-person company chasing FedRAMP across three environments. The baseline covers the typical case. Additional frameworks, multiple environments, or a compressed timeline move the number. You get the exact figure in writing after the first call, and it doesn't change mid-engagement unless scope does.

02Can I start with a project and move to a retainer?

Yes, and it is the on-ramp I recommend. The security assessment is the natural first step: two weeks, a roadmap, and a clear number for what it takes to execute it. If you move to a retainer afterwards, that roadmap becomes month one, so nothing is repeated and nothing is billed twice.

03What's not included?

Third-party fees. Penetration tests, tooling licenses (Vanta, Drata, Secureframe, scanners) and the auditor's own fee are either passed through at cost or contracted by you directly. I'll recommend vendors, negotiate scope and manage them, but I don't mark them up. A 24/7 SOC is also out of scope; I'll introduce a partner if you need one.

04Do you invoice in USD? What are the payment terms?

Yes, USD. Retainers are invoiced on the first of the month, net 15. Bank transfer or card; Stripe is coming. Annual plans are invoiced up front with the 15% discount applied. Fixed-scope projects are 50% at kickoff, 50% on delivery.

05Can I pause?

On annual plans, yes: one month per contract year, with notice before that month starts, and the term extends by the paused month. Monthly plans don't pause; you cancel with 30 days notice and come back when you're ready, subject to an open seat.

06Do you take equity or offer discounted startup pricing?

Occasionally. If you're pre-seed with a clear enterprise path and a real deadline, ask. I'll consider a reduced cash fee with a small equity component, for one seat at a time. I don't do pure equity, and I don't discount because the pitch deck is good.

Next step

Get a scoped number in 30 minutes.

Bring the audit date, the frameworks in play and a rough count of who touches production. You leave the call with a tier and a price, confirmed in writing within 48 hours.

You leave the call with
  • 01A tier recommendation, and why not the one above or below it.
  • 02A price, not a range.
  • 03A start date and the read-only access I need for week one.
  • 04If it isn't a fit, the name of someone who is.
Prefer to write first? hiteshjain@rmrfs.com Reply within one business day, from me.