Skip to content
Osintpro

Cybersecurity Risk Assessment Cost: What US Providers Charge in 2026, by Assessment Type

Three US providers publish their rates. They do not agree, and the disagreement is the useful part: it tells you the number is set by scope definition rather than by your headcount. Here is what is published, and how to turn it into a quote you can actually compare.

  • Published
  • 8 min read
  • Pricing
  • Osintpro analyst notes

A cybersecurity risk assessment costs between $1,000 and $150,000 in the US in 2026. That range is useless to you, and it is also the honest answer, because almost every provider prices by scope rather than by a rate card. What follows is the published evidence from providers who do state numbers, where those numbers contradict each other, and the four scoping decisions that actually move the figure on your quote.

One thing to get straight before the numbers. "Cybersecurity risk assessment" is used loosely for at least five different pieces of work, and they are separated by roughly a factor of thirty in price. If you are collecting quotes and they range from $2,000 to $60,000, the providers are probably not bidding on the same job.

What three US providers publish, side by side

Most firms in this category quote per engagement and publish nothing. A minority put figures on their site. Here is what three of them state, as checked in September 2026.

Small business

Atlant Security
$3,000 to $10,000
BlackSheep
$5,000 to $15,000 (under 25 staff)
IBSS
$3,000 to $15,000 (1 to 50 staff)

Mid-market

Atlant Security
$10,000 to $50,000
BlackSheep
$15,000 to $35,000 (25 to 100 staff)
IBSS
$15,000 to $50,000 (51 to 500 staff)

Enterprise

Atlant Security
$50,000 to $150,000+
BlackSheep
$35,000 to $50,000+ (100+ staff)
IBSS
$50,000 to $100,000+ (500+ staff)

Worked example

Atlant Security
$15,000 for cloud plus full NIST 800-53 v5 at ~100 staff
BlackSheep
Software subscription at $249 a month as the alternative
IBSS
Regulated industries: add 35 to 45 percent

Look at the 100-employee company. Atlant puts it at $15,000 for a named scope. BlackSheep's band for 100-plus starts at $35,000. IBSS calls the same company mid-market at $15,000 to $50,000. Three providers, one company profile, and a spread from $15,000 to $50,000.

That is not one of them being expensive. It is three different jobs wearing the same name. Atlant is describing a controls assessment against a defined framework across cloud and infrastructure. BlackSheep's higher band assumes consultant time with interviews and evidence review. IBSS is quoting a range wide enough to include a compliance audit. Until a quote names the framework, the systems in scope and whether anything is tested rather than reviewed, you are not comparing prices at all.

The component prices, which are more useful than the size bands

IBSS publishes a breakdown by work type, and this is the more actionable view because it maps onto what you would actually ask for.

Basic vulnerability scan

Published range
$1,000 to $2,000
What you get
Automated tooling against a defined IP or host list, with the raw output

Comprehensive vulnerability assessment

Published range
$2,000 to $5,000
What you get
Scanning plus triage, false-positive removal and prioritized findings

Risk assessment and gap analysis

Published range
$3,000 to $50,000
What you get
Controls mapped against a framework, with the gaps written up

Penetration testing

Published range
$5,000 to $30,000
What you get
Manual exploitation by testers, scoped by target and by depth

Compliance audit

Published range
$15,000 to $100,000+
What you get
Evidence collection against a standard, usually with an attestation at the end

Managed detection and response

Published range
$10,000 to $100,000+ a year
What you get
Not an assessment at all. A monitoring subscription

Most organizations pay between $1,000 and $5,000 per assessment.

That figure from IBSS is worth holding onto, because it says something the size bands hide: the typical purchase in this market is a scan with triage, not a consultant-led program review. If your quotes are all above $20,000, check whether you asked for a gap analysis and are being sold a compliance audit.

Why the M&A specialists publish nothing at all

Search for cyber due diligence on an acquisition and the results are Kroll, Palo Alto's Unit 42, Sygnia and Charles River Associates. None of them publishes a figure. Unit 42's page describes a five-step engagement producing a cyber due diligence report, a compromise assessment report, attack surface mapping, a penetration testing report and an aggregated target briefing, and ends at a contact form.

That is not evasiveness, it is the honest consequence of the product. A deal engagement is scoped against a target whose estate nobody has seen yet, on a timetable set by a signing date, and the fee depends on things that cannot be known before the call. The practical effect for a buyer is still awkward: you cannot get a budget number for cyber diligence without a scoping conversation, and you often need the budget number before you have time for one.

The workaround most deal teams settle on is to split the work by what access it requires. The external, records-based layer runs immediately for a fixed subscription cost, and the engagement quote is only requested for targets that survive it. We wrote up how that split works across a deal timetable on the cybersecurity due diligence software page, including which findings each layer can and cannot produce.

The four things that actually move your quote

  1. Whether anything is tested or only reviewed. A review reads configurations, policies and evidence. A test attempts exploitation. Testing carries insurance, skilled labor and legal authorization, and it is the single biggest multiplier on a quote. Ask which one you are buying before you compare two numbers.
  2. The framework named in the scope. "Assess our security" is unpriceable. "Assess against NIST 800-53 v5 across our AWS estate and Microsoft 365" is a quote. Naming the framework is the cheapest thing you can do to make bids comparable, and it usually lowers the price because it removes the provider's uncertainty premium.
  3. Regulation. IBSS quotes a 35 to 45 percent premium for regulated industries, and that is a fair reflection of the evidence standard. Healthcare, financial services and anything touching CJIS or CMMC costs more because the documentation burden is higher, not because the technical work is harder.
  4. How many entities are really in scope. This is where quotes break. A company that describes itself as one business but runs four acquired brands on separate domains, separate mail and separate cloud tenants is four assessments. Providers discover this in week two and re-quote. Enumerating the estate before you request bids is worth doing for that reason alone.

The DIY option, and what it really costs

BlackSheep puts the spreadsheet approach at $0 to $500 in direct cost and 40 to 80 hours of internal labor. That is an honest framing from a company selling software, and the hours are not exaggerated. A NIST or CIS self-assessment done properly means chasing evidence from people who have other jobs.

The catch is not the hours, it is who accepts the output. A self-assessment is fine for internal prioritization and it is generally not accepted by a cyber insurer, an enterprise customer's vendor review, or a buyer's investment committee. If the reason you need an assessment is that somebody external asked for one, the DIY route does not answer the question, however carefully you fill in the spreadsheet.

A middle option has appeared in the last few years: continuous assessment software in the $249 to $2,000 a month range for mid-market tools, and $2,000 to $12,000 or more a month for enterprise platforms. These maintain a control posture year-round rather than producing a point-in-time snapshot, which is genuinely better for compliance upkeep. They still do not test anything, and most of them do not produce a document a third party will accept as evidence.

What to ask for before you request a single quote

  • The trigger. An insurer renewal, a customer's vendor review, a regulator, a board request and an acquisition all want different artifacts. Write the trigger down first, because it determines the deliverable and the deliverable determines the price.
  • The reader. If the output goes outside your organization, you are buying an independent report and the provider's name is part of what you are paying for. If it stays inside, you may be buying software instead.
  • The estate, enumerated. Domains, cloud tenants, subsidiaries, acquired brands. Providers cannot price what you cannot list, and the list is also the thing that gets re-quoted mid-engagement when it turns out to be longer.
  • The re-run interval. A point-in-time assessment answers a question once. If the trigger recurs annually, price two years, not one, and ask what a repeat engagement costs. Repeat rates are frequently much lower and are almost never volunteered.

That last point matters more than it looks. The buyers who get the worst value in this market are the ones who treat each assessment as a one-off emergency purchase, which is also how a small company acquiring another ends up commissioning a full engagement on a target it has not yet decided to buy. If you are on the acquiring side of a small software deal, the sequence that works is to screen the target against verified metrics first, run the external evidence layer second, and only commission the technical assessment once the deal is real.

How much does a cybersecurity risk assessment cost, in one paragraph

For a US business under 50 employees, expect $3,000 to $15,000 for a consultant-led risk assessment, or $1,000 to $5,000 if what you need is a scan with triage. Mid-market lands at $15,000 to $50,000. Enterprise scope with testing and compliance work runs $50,000 to $150,000 or more, and regulated industries add roughly 35 to 45 percent. Penetration testing is priced separately at $5,000 to $30,000. M&A cyber diligence specialists publish no rates and quote per engagement.

The number you can control is the scope. Name the framework, enumerate the estate, decide whether anything gets tested, and ask for the repeat price in the first call. Do that and three bids become comparable, which is the only thing that reliably reduces what you pay.

If the assessment was triggered by somebody else's diligence rather than your own program, the cheaper starting point is the external evidence layer: registration history, mail authentication posture, certificate surface and registry filings, collected passively and dated. That is what our cyber due diligence tooling produces, at published subscription pricing rather than a scoping call, and it is also the fastest way to find out whether you need the expensive version at all. Teams shopping the adjacent monitoring category will find the same pricing opacity mapped out in our note on attack surface management vendors.

See it produce one

Every habit in this post is what the sweep does automatically.

Declare a scope, run a domain, and read findings that already carry the raw record, the source endpoint and the UTC retrieval time. It takes a domain and never a person.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.