Published, in full
Assessment Pricing: CAF, GovAssure, Secure by Design and ITHC
Indicative fixed-scope prices for the four engagements we deliver: the NCSC Cyber Assessment Framework, GovAssure, MOD Secure by Design and IT Health Check readiness. The whole field quotes only after a call, so we publish the prices instead. Each engagement is delivered by CyPro, covering the gap analysis, the remediation plan and roadmap, and the work to close the gaps, with the final scope confirmed at the call.
Indicative pricing
Four assessments, priced up front
Core assessment
CAF Assessment
Gap analysis against the NCSC Cyber Assessment Framework, plus the plan to close it
From £9,600
fixed scope, indicative, ex VAT
- An internal assessment against the CAF outcomes and principles for the systems in scope
- A prioritised gap analysis showing where you stand and what to close first
- A remediation plan and roadmap, sequenced by risk and by what your team can actually absorb
- Support implementing the controls that close the gaps, not just a list of them
- A report written for your board, your regulator or your sponsoring department
GovAssure Support
Readiness through the five stages, up to the independent review
From £13,500
fixed scope, indicative, ex VAT
- Support through the GovAssure stages, from scoping to the Targeted Improvement Plan
- A CAF-based assessment tailored to your department or arm's length body
- Readiness work so the independent assurance review meets the standard the first time
- Hands-on help closing what the assessment and the improvement plan identify
- Built for central government departments and their arm's length bodies
MOD Secure by Design
Security case and evidence for MOD suppliers and delivery teams
From £8,500
fixed scope, indicative, ex VAT
- The Secure by Design activities, the security case and the evidence the MOD expects
- Priced by project size and the Secure by Design tier that applies
- For defence suppliers and delivery teams (this is the MOD scheme, not the police Secured by Design mark for physical security)
- Your delivery team prepared for each review point, with the gaps closed beforehand
IT Health Check (ITHC)
Getting the environment ready to pass a CHECK-scheme test
From £7,200
fixed scope, indicative, ex VAT
- An internal assessment of the systems and IP ranges in scope before the formal test
- Priced by the number of systems and IP ranges in scope
- For PSN connections, pension-dashboard links and public-sector assurance
- Remediation of what a CHECK test would raise, plus the scope and evidence the connection owner expects
- Support closing the tester's findings once the formal ITHC has run
Combined programmes
More than one framework, scoped as one
Where a supplier needs, say, GovAssure readiness and an ITHC together
One quote
scoped together, indicative
Many government and defence suppliers carry more than one obligation: GovAssure is built on the CAF, and a PSN connection needs an ITHC alongside it. Where that applies, the assessments are scoped and priced as a single managed engagement rather than billed apart. How the process runs.
After remediation
Re-test and continued assurance
A return engagement once the gaps are closed
Per cycle
quoted per return engagement
Once you have closed the gaps, a re-test confirms the remediation has landed and, for GovAssure, supports the independent assurance stage. As the framework moves through its versions or your systems change, a re-assessment keeps your position current. Re-test and assurance.
What sets the fee, stated plainly
The figures above are indicative fixed-scope "from" prices, not quotes, and are confirmed for your organisation at scoping. What sets the fee is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Fees exclude VAT. Every engagement is delivered by CyPro; any formal external assessment or audit sits outside the fee and is commissioned by you. The programme names describe the framework worked to, not a CyPro accreditation.
For comparison
Three ways to buy an assessment, side by side
This market is quote-only from end to end: the defence and assurance boutiques and the broad cyber consultancies alike hide the figure until you have had a call. We publish the price, name what is in scope and what is not, and put the same consultants on the gap analysis and on closing it. The table shows the differences.
| Quote-only boutique | Broad cyber consultancy | CAF Assessment by CyPro | |
|---|---|---|---|
| Pricing | Quoted only after a call, no figure published | Quoted after scoping, day-rate led | Indicative fixed-scope prices, published on this page |
| Who does the work | Their own consultants | Their own consultants, assessment is one of many services | CyPro's own consultants, the same team from gap analysis to closing the gaps |
| Scope certainty | Unknown until you are quoted | Unknown until you are quoted | Fixed scope wherever possible, agreed before work starts |
| Frameworks covered | Often a single framework | Broad, but assessment is not the focus | CAF, GovAssure, MOD Secure by Design and ITHC in one place |
| What you leave with | A report | A report | A prioritised gap analysis, a remediation plan and a route back for re-test |
Asked about the fees
Pricing, explained further
Why publish prices when the whole field quotes?
Because a fixed-scope assessment has a knowable cost, and hiding the figure mostly serves the seller. Every competitor in this space quotes only after a call, so we publish indicative prices instead, the same publish-the-price stance CyPro takes across its specialist services. You can weigh the likely cost up front, with the final scope settled on the call.
Are these fixed prices?
They are indicative fixed-scope 'from' prices, not quotes. What sets the final figure is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Where the scope is clear, we hold the engagement to a fixed price rather than an open day rate, which is the whole point of publishing them.
Who actually does the work?
CyPro, from the scoping call to the final report. We are the delivery partner, not a layer of project management on top of one: our consultants run the gap analysis, write the remediation plan and roadmap, and work alongside your team implementing the controls that close the gaps. What we do not do is sign off your compliance, because nobody credible marks their own homework. Any formal external assessment or audit, an appointed GovAssure independent reviewer, a certification auditor or a CHECK-accredited ITHC tester, is out of scope and commissioned by you when you are ready. We use the programme names, CAF, GovAssure and MOD Secure by Design, to describe the framework we work to, never as a CyPro accreditation.
Which assessment do we need?
If you are a central government department or an arm's length body, GovAssure. If you supply the MOD, Secure by Design. If you need a CHECK IT Health Check for a PSN connection or a pension-dashboard link, the ITHC. If you need to know where you stand against the NCSC Cyber Assessment Framework more broadly, the CAF assessment. The scoping call confirms which one applies to you.
Does the price include remediation?
The fee covers the gap analysis, the prioritised remediation plan and the roadmap, and it includes our support implementing the controls that close the gaps: defining them, helping your team stand them up and evidencing them. Where remediation runs well beyond the scope agreed at the outset, or you want a full internal audit once the work lands, we scope that as a return engagement. There is no hidden retainer folded into the figure above.
Prices published, scope confirmed on a call
Find the assessment that fits your obligation
One scoping call, taken by a consultant, confirms which framework applies to you, the profile, stage or tier you must meet, and the fixed-scope figure for the work to get you there.