Skip to content

Pricing

What this costs, and why it is shaped this way

Every engagement starts with a fixed-price assessment. Implementation is quoted as a range until that assessment is done — not to be evasive, but because scope for this work is genuinely unknowable before anyone has seen what is on the network.

Assessment first, always

Every engagement starts with a fixed-price assessment. It is the only honest way to scope access control work, and it leaves the client with something useful even if they stop there. Nobody is asked to commit to an implementation before anyone knows what is on the network.

Fixed price where scope is knowable

Assessments and design engagements are fixed price. The scope is bounded, so the risk of getting it wrong is ours to carry rather than the client's.

Ranges where it is not

Implementation is quoted as a range until the assessment is done. Device diversity drives cost far more than headcount or site count — a ten-thousand-device estate of standard laptops is simpler than a two-thousand-device estate with clinical or industrial equipment on it.

No licence resale margin

We do not resell hardware or licences, so there is no incentive to specify more of either than the design needs. Clients buy those direct or through their existing reseller.

Engagements

Where each of these starts

Ordered by how most engagements begin. The assessment is a complete piece of work in its own right — the findings are yours whether or not you continue.

Get ISE enforcing

You own Cisco ISE and it has never actually blocked anything.

Start here · fixed price

Access Control Current-State Assessment

$28,500

3 weeks

  • Full device discovery and profiling across the in-scope estate
  • Assessment of the existing deployment against what it is capable of today
  • Would-have-denied analysis and triaged exception list by device class
  • A phased enforcement plan with defined success criteria per stage

Then · scoped from the assessment

Phased Enforcement Programme

from $95,000

3-6 months

Scoped from the assessment. Range driven by device diversity and site count.

Comply-to-Connect enablement

A C2C requirement has landed on your component or your prime needs the scope covered.

Start here · fixed price

Comply-to-Connect Readiness Assessment

$46,000

4-5 weeks

  • Current position against C2C steps 1-5
  • Inventory of compliance signals available from existing tooling (SCCM, ACAS, EPO, MDE)
  • Device classes that cannot comply, with a designed authorisation path for each
  • Integration design and a staged remediation plan

Then · scoped from the assessment

C2C Implementation

from $215,000

6-12 months

Federal scope. Priced commercially — Concise holds no GSA schedule or other vehicle, so subcontract rates are negotiated per prime.

Zero Trust for a flat network

Anything on your network can reach anything else, and you know it.

Start here · fixed price

Segmentation Assessment & Architecture

$78,000

6 weeks

  • Device discovery and behavioural profiling
  • Trust boundary model and identity-driven segmentation design
  • PKI and certificate lifecycle design
  • Phased rollout roadmap with rollback defined per stage

Then · scoped from the assessment

Segmentation Rollout

from $185,000

6-12 months

Scoped from the architecture phase.

Access control audit readiness

An assessment is scheduled and access control is the part you are least sure about.

Start here · fixed price

Access Control Gap Analysis

$24,500

2-3 weeks

  • Control review against your applicable framework
  • Evidence inventory — what exists, what an assessor will ask for, what is missing
  • Prioritised remediation plan with the reasoning shown
  • Findings written in the language the assessment will use

Then · scoped from the assessment

Remediation & Evidence Programme

from $65,000

2-4 months

Post-merger network consolidation

An acquisition just doubled your device estate and nobody trusts the other network.

Start here · fixed price

Dual-Estate Discovery

$34,000

3-4 weeks

  • Discovery and profiling across both estates
  • Comparison of what each network currently trusts, and why
  • Common access control model and interim interconnect design
  • Staged consolidation roadmap

Then · scoped from the assessment

Consolidation Programme

from $145,000

4-9 months

Rate card

For work outside a package

For advisory, expert witness, and work outside a packaged engagement. Travel billed at cost; remote delivery wherever the work allows it.

RoleHourlyDailyTypically
Principal Consultant / Security Architect$375$3,000Architecture, policy authority, C2C strategy, executive and assessor-facing work
Senior Network Security Engineer$285$2,280ISE build, 802.1X and certificate implementation, integration engineering
Compliance & Risk Analyst$225$1,800Control mapping, evidence packs, gap analysis, BCP/DR documentation
Operations Engineer$195$1,560Policy lifecycle, certificate rotation, day-to-day platform operations

Ongoing

Retainers

Advisory Retainer

Ongoing architecture and policy authority without a delivery programme

from $9,500

per month

  • 24 principal hours per month
  • Design review
  • Escalation support

The small print

What these numbers assume

  • Remote delivery wherever the work allows; travel billed at cost and agreed in advance.
  • Hardware and licences are purchased by the client directly — we do not resell.
  • Prices exclude applicable taxes.
  • Assessment findings belong to the client, including if they take them elsewhere.

Published figures are "from" prices and ranges. Final pricing follows the assessment — that is deliberate, not evasive: scope for this work is genuinely unknowable before device discovery, and a fixed number quoted blind is either padded or a loss.

Not sure which assessment applies?

Describe what prompted you to look. That is usually enough to identify the right starting point — and occasionally enough to tell you that you do not need one.

Start a conversation