3 Plans
Essentials: Gap
$1,500–$2,500 flat fee
For Startups & SMEs beginning ISO 27001 journey
Scope focus: documentation, processes, technical controls
✓ Documentation Review
✓ Process Assessment
✓ Technical Control Mapping
- ✓ Gap assessment report with prioritized findings
- ✓ Readiness scorecard across documentation, process, and control domains
- ✓ Recommended next steps for implementation or remediation
✓ Optional follow-up consultation (hourly rate applies
X Risk Assessment & Treatment
X Control Implementation & Automation
X Auditor Coordination
X Advisory on ISO Updates
Fixed-scope, 2–3 weeks
Add on: Policy drafting, automation setup
Implementation
$7,500–$12,000 flat fee
For SMEs preparing for formal certification
Scope focus: Full ISMS buildout, risk & control implementation
✓ Gap Assessment: Comprehensive, with remediation roadmap
✓ ISMS Documentation & Policy Development
✓ Information security policy
✓ Risk Assessment & Treatment Planning
✓ AI enabled scripts, integrations, checklists for evidence collection
✓ Internal Audit Preparation
✓ Progress Monitoring & Advisory
- ✓ Full ISMS documentation package
- ✓ Risk register and treatment plan
- ✓ Control implementation checklist
- ✓ Internal audit report and findings
- ✓ Certification readiness summary
Milestone-based, 3–6 months
Add on: Pen testing, awareness training
Surveillance
$300–$600 monthly
For certified organizations maintaining compliance
Scope focus: Ongoing ISMS maintenance & audit readiness
✓ Pre-audit readiness checks to ensure continued compliance with ISO/IEC 27001 requirements
✓ Review and update of ISMS documentation, including policies, procedures, and risk treatment plans
✓ Evidence collection automation to streamline audit preparation
✓ Internal audit refreshes aligned with surveillance audit scope
✓ Coordination with external auditors to support Stage 1 and Stage 2 follow-ups or surveillance visits
✓ Advisory on changes to the ISO/IEC 27001:2022 standard and their impact on your ISMS
✓ Risk management requirements including risk assessment, treatment, review related to ISO 27001:2022 scope
Add on: Pen testing, awareness training
Questions? Email us at info@aicomply360.com or contact us here
