Published, in full

Assessment Pricing: CAF, GovAssure, Secure by Design and ITHC

Indicative fixed-scope prices for the four assessments we manage: the NCSC Cyber Assessment Framework, GovAssure, MOD Secure by Design and the CHECK-accredited IT Health Check. The whole field quotes only after a call, so we publish the ranges instead. Every assessment is performed by an accredited delivery partner and managed and quality-assured by CyPro, and your engagement is confirmed at scoping.

Indicative pricing

Four assessments, priced up front

Core assessment

CAF Assessment

Managed gap analysis against the NCSC Cyber Assessment Framework

From £6,500

fixed scope, indicative, ex VAT

  • Assessment against the CAF outcomes and principles for the systems in scope
  • Baseline CAF profile from £6,500; enhanced or multi-system engagements from £12,000
  • A prioritised gap analysis showing where you stand and what to close first
  • Performed by an accredited delivery partner, managed and quality-assured by CyPro
  • A report written for your board, your regulator or your sponsoring department
What this covers

GovAssure Support

Readiness plus independent assurance through the five stages

From £9,500

fixed scope, indicative, ex VAT

  • Support through all five GovAssure stages, from scoping to the independent assurance review
  • A CAF-based assessment tailored to your department or arm's length body
  • Readiness work so the independent review meets the standard the first time
  • Performed by an accredited delivery partner, managed and quality-assured by CyPro
  • Built for central government departments and their arm's length bodies
What this covers

MOD Secure by Design

Assurance for MOD suppliers and delivery teams

From £8,500

fixed scope, indicative, ex VAT

  • Support with the Secure by Design activities, the security case and the evidence the MOD expects
  • Banded by project size and Secure by Design tier
  • For defence suppliers and delivery teams (this is the MOD scheme, not the police Secured by Design mark for physical security)
  • Performed by an accredited delivery partner, managed and quality-assured by CyPro
What this covers

IT Health Check (ITHC)

CHECK-accredited testing for public-sector assurance

From £4,500

fixed scope, indicative, ex VAT

  • CHECK-accredited testing of the systems and IP ranges in scope
  • Banded by the number of systems and IP ranges in scope
  • For PSN connections, pension-dashboard links and public-sector assurance
  • Performed by CHECK-accredited testers, managed and quality-assured by CyPro
  • Findings mapped to the remediation your connection or authority requires
What this covers

Combined programmes

More than one framework, scoped as one

Where a supplier needs, say, GovAssure readiness and an ITHC together

One quote

scoped together, indicative

Many government and defence suppliers carry more than one obligation: GovAssure is built on the CAF, and a PSN connection needs an ITHC alongside it. Where that applies, the assessments are scoped and priced as a single managed engagement rather than billed apart. How the process runs.

After remediation

Re-test and continued assurance

A return engagement once the gaps are closed

Per cycle

quoted per return engagement

Once you have closed the gaps, a re-test confirms the remediation has landed and, for GovAssure, supports the independent assurance stage. As the framework moves through its versions or your systems change, a re-assessment keeps your position current. Re-test and assurance.

What sets the fee, stated plainly

The figures above are indicative fixed-scope "from" prices, not quotes, and are confirmed for your organisation at scoping. What sets the fee is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Fees exclude VAT. Every assessment is performed by an accredited delivery partner and managed and quality-assured by CyPro; the programme names describe the framework assessed against, not a CyPro accreditation.

For comparison

Three ways to buy an assessment, side by side

This market is quote-only from end to end: the defence and assurance boutiques and the broad cyber consultancies alike hide the figure until you have had a call. A managed, partner-delivered assessment gives you the accredited delivery of a specialist with the scope certainty of a published price, and the table shows the differences.

Quote-only boutique Broad cyber consultancy CAF Assessment by CyPro
Pricing Quoted only after a call, no figure published Quoted after scoping, day-rate led Indicative fixed-scope prices, published on this page
Who performs it Their own consultants Their own consultants, assessment is one of many services An accredited delivery partner, managed and quality-assured by CyPro
Scope certainty Unknown until you are quoted Unknown until you are quoted Fixed scope wherever possible, agreed before work starts
Frameworks covered Often a single framework Broad, but assessment is not the focus CAF, GovAssure, MOD Secure by Design and ITHC in one place
What you leave with A report A report A prioritised gap analysis, a remediation plan and a route back for re-test

Asked about the fees

Pricing, explained further

Why publish prices when the whole field quotes?

Because a fixed-scope assessment has a knowable cost, and hiding the figure mostly serves the seller. Every competitor in this space quotes only after a call, so we publish indicative prices instead, the same publish-the-price stance CyPro takes across its specialist services. You can weigh the likely cost up front, with the final scope settled on the call.

Are these fixed prices?

They are indicative fixed-scope 'from' prices, not quotes. What sets the final figure is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Where the scope is clear, we hold the engagement to a fixed price rather than an open day rate, which is the whole point of publishing them.

Who actually carries out the assessment?

An accredited delivery partner performs the assessment; CyPro fronts, manages and quality-assures the engagement from the scoping call to the final report. For an IT Health Check the testing is done by CHECK-accredited testers. We use the programme names, CAF, GovAssure and MOD Secure by Design, to describe the framework we assess you against, never as a CyPro accreditation.

Which assessment do we need?

If you are a central government department or an arm's length body, GovAssure. If you supply the MOD, Secure by Design. If you need a CHECK IT Health Check for a PSN connection or a pension-dashboard link, the ITHC. If you need to know where you stand against the NCSC Cyber Assessment Framework more broadly, the CAF assessment. The scoping call confirms which one applies to you.

See how the process runs

Does the price include remediation?

The fee covers the assessment and a prioritised remediation plan. Carrying out the fixes sits with your own team or provider; where you want hands-on support closing them, or a re-test to confirm they are done, we scope that as a return engagement. There is no hidden retainer folded into the figure above.

Rocket above the CAF Assessment call to action

Prices published, scope confirmed on a call

Find the assessment that fits your obligation

One scoping call, taken by a consultant, confirms which framework applies to you, the profile, stage or tier you must meet, and the fixed-scope figure for a managed, partner-delivered assessment.