Search for the cost of a Cyber Security audit and you will find almost nothing useful. Page after page explains why audits matter, then asks you to get in touch.

There is a reason, and it is not entirely cynical: audits genuinely vary. An audit of eight laptops and a Microsoft 365 tenant is a different exercise from an audit of three sites, a server room and forty cloud services, and any provider quoting both at the same price is guessing at one of them.

But “it depends” is not an answer, and it leaves buyers unable to tell a serious quote from a cheap one. So here is what actually determines the number, and further down, what we charge and what a five or ten day engagement costs.

£900Per day + VAT, because audits are days of work
ScopeThe single biggest driver of the figure
FixedThe price should be agreed before work starts

What you are actually buying

An audit is skilled time, not a licence. The cost is therefore a function of how many days of skilled time the work needs, and what happens to the findings afterwards.

Broadly, the days go on four things: gathering evidence about how your environment is configured; examining it against a defined standard; writing the findings up so they can be acted on; and presenting them to you. A quote that is unusually low has almost always shortened one of those, and it is rarely the first one.

The seven things that drive the price

  • How many devices, users and sites. The obvious one, though less linear than people expect. Fifty identical, centrally managed laptops take less time than fifteen unmanaged ones that were all built differently.
  • How many cloud services are in scope. Each service has its own configuration, its own permission model and its own set of things to check. Ten services is not ten times one service, but it is not one service either.
  • How much is documented. An organisation that can produce an asset list, a network diagram and an account inventory saves the auditor a day of archaeology. One that cannot is paying for that day.
  • Depth against breadth. A review of identity, patching and backups costs less than one that also covers network segmentation, supplier access, physical controls and incident readiness. Both are legitimate; they are not the same engagement.
  • Remote or on site. Most audit work is remote. Where being on site genuinely adds value, or the estate cannot be examined any other way, travel and time are part of the cost and should be stated rather than absorbed and recovered elsewhere.
  • What the deliverable is. A findings list is cheaper to produce than a prioritised report with evidence, business context and a remediation plan. Ask which you are being quoted for.
  • Whether a retest is included. Verifying that fixes worked is part of the value. If it is excluded, the quote is lower and the outcome is worse.

How to compare two quotes fairly

Two proposals with different numbers are usually not the same work. Four questions expose the difference quickly.

“How many days is this, and who is doing them?” This converts an opaque price into something comparable. It also reveals whether the senior name in the proposal is doing the work or introducing it.

“What proportion is automated?” Tooling belongs in an audit and should be used. If the answer is that tooling does most of it, you are being quoted for a scan.

“What exactly do we receive?” Report structure, evidence, prioritisation, and whether somebody presents it. We set out what a good report contains in what a penetration test report should contain, and the same principles apply to audit reporting.

“What is excluded?” The gap between quotes is often sitting in the exclusions rather than the price.

The buying rule

Compare the days, the people and the deliverable, not the total. A cheaper audit that produces a list nobody can act on has not saved you anything; it has cost you the budget and left you where you started, with a document that implies otherwise.

Three signs an audit is too cheap to be an audit

It is priced before anyone has asked about your environment. A fixed price quoted without a scoping conversation is either padded to cover the worst case, or it will be delivered to the level the price allows regardless of what your estate turns out to be.

It is being sold by the people who will fix the findings. An audit conducted by a provider whose remediation services follow it has an obvious pull on what the findings say and how urgent they sound. Independence is the product; a vendor-neutral audit has nothing to upsell.

The deliverable is a tool export. Automated output with a cover page is a vulnerability assessment being sold as an audit. Both have value, they are not the same thing, and we wrote about the difference separately.

What it should include at any price

Regardless of what you spend, the engagement should give you: a scope agreed and written down before work starts; a fixed price with travel and expenses stated; findings ranked by risk to your business rather than by a generic severity score; evidence for each finding; remediation advice specific to your environment; and a conversation where somebody who did the work explains what matters most.

If a proposal is missing several of those, the price is not the problem with it.

What we charge

Our audit work is £900 + VAT per day. That is the whole rate card, and it makes the arithmetic straightforward once the number of days is agreed.

EngagementDaysCost
Focused audit5 days£4,500 + VAT
Broader audit10 days£9,000 + VAT

Those are illustrations rather than a price list, and it would be dishonest to present them as anything else. A five day engagement suits a smaller organisation with a single site, a cloud-first estate and a clear question to answer. Ten days suits a larger or multi-site organisation, more cloud services, more systems, and more depth across areas such as network segmentation, supplier access and incident readiness.

What decides where you land is genuinely nuanced: the type of audit, the size of the organisation, the complexity of the environment, and what you are trying to achieve. An organisation of forty people with one office and Microsoft 365 is a different exercise from an organisation of forty people with three sites, an on-premises server estate, an operational technology network and a supply chain to satisfy. Both are legitimate five to ten day conversations; only one of them is five days.

So the days are agreed, not assumed. We scope first and quote second, and the price is fixed before any work begins: a short conversation about your size, your systems and what you actually need to know, followed by a written proposal setting out the days, the scope, the deliverable and the cost. No discovery-phase surprises, and no number quoted before we understand what it is for.

If a scoping conversation shows an audit is not what you need yet, we will say so. For organisations that have never had an independent look, it often is; for organisations that have never done the basics, Cyber Essentials is usually the better place to start and the cheaper way to find the same problems.

Get in touch or call 01722 445972 for a scoped quote. More detail on the service is on our independent security audit page, and if you want the wider picture first, our guide to Cyber Security audits covers what one involves.