AICOMPLY360.COM | Security for startups

Security Design | Compliance | Implementation | 281.626.0886

ISO 27001:2022 Assessments

3 Plans

Essentials: Gap

$1,500–$2,500 flat fee

For Startups & SMEs beginning ISO 27001 journey

Scope focus: documentation, processes, technical controls

✓ Documentation Review

✓ Process Assessment

✓ Technical Control Mapping

  • ✓ Gap assessment report with prioritized findings
  • ✓ Readiness scorecard across documentation, process, and control domains
  • ✓ Recommended next steps for implementation or remediation

✓ Optional follow-up consultation (hourly rate applies

X Risk Assessment & Treatment

X Control Implementation & Automation

X Auditor Coordination

X Advisory on ISO Updates

Fixed-scope, 2–3 weeks

Add on: Policy drafting, automation setup

Implementation

$7,500–$12,000 flat fee

For SMEs preparing for formal certification

Scope focus: Full ISMS buildout, risk & control implementation

✓ Gap Assessment: Comprehensive, with remediation roadmap

✓ ISMS Documentation & Policy Development

✓ Information security policy

✓ Risk Assessment & Treatment Planning

✓ AI enabled scripts, integrations, checklists for evidence collection

✓ Internal Audit Preparation

✓ Progress Monitoring & Advisory

  • ✓ Full ISMS documentation package
  • ✓ Risk register and treatment plan
  • ✓ Control implementation checklist
  • ✓ Internal audit report and findings
  • ✓ Certification readiness summary

Milestone-based, 3–6 months

Add on: Pen testing, awareness training

Surveillance

$300–$600 monthly

For certified organizations maintaining compliance

Scope focus: Ongoing ISMS maintenance & audit readiness

✓ Pre-audit readiness checks to ensure continued compliance with ISO/IEC 27001 requirements

✓ Review and update of ISMS documentation, including policies, procedures, and risk treatment plans

✓ Evidence collection automation to streamline audit preparation

✓ Internal audit refreshes aligned with surveillance audit scope

✓ Coordination with external auditors to support Stage 1 and Stage 2 follow-ups or surveillance visits

✓ Advisory on changes to the ISO/IEC 27001:2022 standard and their impact on your ISMS

✓ Risk management requirements including risk assessment, treatment, review related to ISO 27001:2022 scope

Add on: Pen testing, awareness training

Questions? Email us at info@aicomply360.com or contact us here