Published, in full
Assessment Pricing: CAF, GovAssure, Secure by Design and ITHC
Indicative fixed-scope prices for the four assessments we manage: the NCSC Cyber Assessment Framework, GovAssure, MOD Secure by Design and the CHECK-accredited IT Health Check. The whole field quotes only after a call, so we publish the ranges instead. Every assessment is performed by an accredited delivery partner and managed and quality-assured by CyPro, and your engagement is confirmed at scoping.
Indicative pricing
Four assessments, priced up front
Core assessment
CAF Assessment
Managed gap analysis against the NCSC Cyber Assessment Framework
From £6,500
fixed scope, indicative, ex VAT
- Assessment against the CAF outcomes and principles for the systems in scope
- Baseline CAF profile from £6,500; enhanced or multi-system engagements from £12,000
- A prioritised gap analysis showing where you stand and what to close first
- Performed by an accredited delivery partner, managed and quality-assured by CyPro
- A report written for your board, your regulator or your sponsoring department
GovAssure Support
Readiness plus independent assurance through the five stages
From £9,500
fixed scope, indicative, ex VAT
- Support through all five GovAssure stages, from scoping to the independent assurance review
- A CAF-based assessment tailored to your department or arm's length body
- Readiness work so the independent review meets the standard the first time
- Performed by an accredited delivery partner, managed and quality-assured by CyPro
- Built for central government departments and their arm's length bodies
MOD Secure by Design
Assurance for MOD suppliers and delivery teams
From £8,500
fixed scope, indicative, ex VAT
- Support with the Secure by Design activities, the security case and the evidence the MOD expects
- Banded by project size and Secure by Design tier
- For defence suppliers and delivery teams (this is the MOD scheme, not the police Secured by Design mark for physical security)
- Performed by an accredited delivery partner, managed and quality-assured by CyPro
IT Health Check (ITHC)
CHECK-accredited testing for public-sector assurance
From £4,500
fixed scope, indicative, ex VAT
- CHECK-accredited testing of the systems and IP ranges in scope
- Banded by the number of systems and IP ranges in scope
- For PSN connections, pension-dashboard links and public-sector assurance
- Performed by CHECK-accredited testers, managed and quality-assured by CyPro
- Findings mapped to the remediation your connection or authority requires
Combined programmes
More than one framework, scoped as one
Where a supplier needs, say, GovAssure readiness and an ITHC together
One quote
scoped together, indicative
Many government and defence suppliers carry more than one obligation: GovAssure is built on the CAF, and a PSN connection needs an ITHC alongside it. Where that applies, the assessments are scoped and priced as a single managed engagement rather than billed apart. How the process runs.
After remediation
Re-test and continued assurance
A return engagement once the gaps are closed
Per cycle
quoted per return engagement
Once you have closed the gaps, a re-test confirms the remediation has landed and, for GovAssure, supports the independent assurance stage. As the framework moves through its versions or your systems change, a re-assessment keeps your position current. Re-test and assurance.
What sets the fee, stated plainly
The figures above are indicative fixed-scope "from" prices, not quotes, and are confirmed for your organisation at scoping. What sets the fee is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Fees exclude VAT. Every assessment is performed by an accredited delivery partner and managed and quality-assured by CyPro; the programme names describe the framework assessed against, not a CyPro accreditation.
For comparison
Three ways to buy an assessment, side by side
This market is quote-only from end to end: the defence and assurance boutiques and the broad cyber consultancies alike hide the figure until you have had a call. A managed, partner-delivered assessment gives you the accredited delivery of a specialist with the scope certainty of a published price, and the table shows the differences.
| Quote-only boutique | Broad cyber consultancy | CAF Assessment by CyPro | |
|---|---|---|---|
| Pricing | Quoted only after a call, no figure published | Quoted after scoping, day-rate led | Indicative fixed-scope prices, published on this page |
| Who performs it | Their own consultants | Their own consultants, assessment is one of many services | An accredited delivery partner, managed and quality-assured by CyPro |
| Scope certainty | Unknown until you are quoted | Unknown until you are quoted | Fixed scope wherever possible, agreed before work starts |
| Frameworks covered | Often a single framework | Broad, but assessment is not the focus | CAF, GovAssure, MOD Secure by Design and ITHC in one place |
| What you leave with | A report | A report | A prioritised gap analysis, a remediation plan and a route back for re-test |
Asked about the fees
Pricing, explained further
Why publish prices when the whole field quotes?
Because a fixed-scope assessment has a knowable cost, and hiding the figure mostly serves the seller. Every competitor in this space quotes only after a call, so we publish indicative prices instead, the same publish-the-price stance CyPro takes across its specialist services. You can weigh the likely cost up front, with the final scope settled on the call.
Are these fixed prices?
They are indicative fixed-scope 'from' prices, not quotes. What sets the final figure is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Where the scope is clear, we hold the engagement to a fixed price rather than an open day rate, which is the whole point of publishing them.
Who actually carries out the assessment?
An accredited delivery partner performs the assessment; CyPro fronts, manages and quality-assures the engagement from the scoping call to the final report. For an IT Health Check the testing is done by CHECK-accredited testers. We use the programme names, CAF, GovAssure and MOD Secure by Design, to describe the framework we assess you against, never as a CyPro accreditation.
Which assessment do we need?
If you are a central government department or an arm's length body, GovAssure. If you supply the MOD, Secure by Design. If you need a CHECK IT Health Check for a PSN connection or a pension-dashboard link, the ITHC. If you need to know where you stand against the NCSC Cyber Assessment Framework more broadly, the CAF assessment. The scoping call confirms which one applies to you.
Does the price include remediation?
The fee covers the assessment and a prioritised remediation plan. Carrying out the fixes sits with your own team or provider; where you want hands-on support closing them, or a re-test to confirm they are done, we scope that as a return engagement. There is no hidden retainer folded into the figure above.
Prices published, scope confirmed on a call
Find the assessment that fits your obligation
One scoping call, taken by a consultant, confirms which framework applies to you, the profile, stage or tier you must meet, and the fixed-scope figure for a managed, partner-delivered assessment.