Published, in full

Assessment Pricing: CAF, GovAssure, Secure by Design and ITHC

Indicative fixed-scope prices for the four engagements we deliver: the NCSC Cyber Assessment Framework, GovAssure, MOD Secure by Design and IT Health Check readiness. The whole field quotes only after a call, so we publish the prices instead. Each engagement is delivered by CyPro, covering the gap analysis, the remediation plan and roadmap, and the work to close the gaps, with the final scope confirmed at the call.

Indicative pricing

Four assessments, priced up front

Core assessment

CAF Assessment

Gap analysis against the NCSC Cyber Assessment Framework, plus the plan to close it

From £9,600

fixed scope, indicative, ex VAT

  • An internal assessment against the CAF outcomes and principles for the systems in scope
  • A prioritised gap analysis showing where you stand and what to close first
  • A remediation plan and roadmap, sequenced by risk and by what your team can actually absorb
  • Support implementing the controls that close the gaps, not just a list of them
  • A report written for your board, your regulator or your sponsoring department
What this covers

GovAssure Support

Readiness through the five stages, up to the independent review

From £13,500

fixed scope, indicative, ex VAT

  • Support through the GovAssure stages, from scoping to the Targeted Improvement Plan
  • A CAF-based assessment tailored to your department or arm's length body
  • Readiness work so the independent assurance review meets the standard the first time
  • Hands-on help closing what the assessment and the improvement plan identify
  • Built for central government departments and their arm's length bodies
What this covers

MOD Secure by Design

Security case and evidence for MOD suppliers and delivery teams

From £8,500

fixed scope, indicative, ex VAT

  • The Secure by Design activities, the security case and the evidence the MOD expects
  • Priced by project size and the Secure by Design tier that applies
  • For defence suppliers and delivery teams (this is the MOD scheme, not the police Secured by Design mark for physical security)
  • Your delivery team prepared for each review point, with the gaps closed beforehand
What this covers

IT Health Check (ITHC)

Getting the environment ready to pass a CHECK-scheme test

From £7,200

fixed scope, indicative, ex VAT

  • An internal assessment of the systems and IP ranges in scope before the formal test
  • Priced by the number of systems and IP ranges in scope
  • For PSN connections, pension-dashboard links and public-sector assurance
  • Remediation of what a CHECK test would raise, plus the scope and evidence the connection owner expects
  • Support closing the tester's findings once the formal ITHC has run
What this covers

Combined programmes

More than one framework, scoped as one

Where a supplier needs, say, GovAssure readiness and an ITHC together

One quote

scoped together, indicative

Many government and defence suppliers carry more than one obligation: GovAssure is built on the CAF, and a PSN connection needs an ITHC alongside it. Where that applies, the assessments are scoped and priced as a single managed engagement rather than billed apart. How the process runs.

After remediation

Re-test and continued assurance

A return engagement once the gaps are closed

Per cycle

quoted per return engagement

Once you have closed the gaps, a re-test confirms the remediation has landed and, for GovAssure, supports the independent assurance stage. As the framework moves through its versions or your systems change, a re-assessment keeps your position current. Re-test and assurance.

What sets the fee, stated plainly

The figures above are indicative fixed-scope "from" prices, not quotes, and are confirmed for your organisation at scoping. What sets the fee is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Fees exclude VAT. Every engagement is delivered by CyPro; any formal external assessment or audit sits outside the fee and is commissioned by you. The programme names describe the framework worked to, not a CyPro accreditation.

For comparison

Three ways to buy an assessment, side by side

This market is quote-only from end to end: the defence and assurance boutiques and the broad cyber consultancies alike hide the figure until you have had a call. We publish the price, name what is in scope and what is not, and put the same consultants on the gap analysis and on closing it. The table shows the differences.

Quote-only boutique Broad cyber consultancy CAF Assessment by CyPro
Pricing Quoted only after a call, no figure published Quoted after scoping, day-rate led Indicative fixed-scope prices, published on this page
Who does the work Their own consultants Their own consultants, assessment is one of many services CyPro's own consultants, the same team from gap analysis to closing the gaps
Scope certainty Unknown until you are quoted Unknown until you are quoted Fixed scope wherever possible, agreed before work starts
Frameworks covered Often a single framework Broad, but assessment is not the focus CAF, GovAssure, MOD Secure by Design and ITHC in one place
What you leave with A report A report A prioritised gap analysis, a remediation plan and a route back for re-test

Asked about the fees

Pricing, explained further

Why publish prices when the whole field quotes?

Because a fixed-scope assessment has a knowable cost, and hiding the figure mostly serves the seller. Every competitor in this space quotes only after a call, so we publish indicative prices instead, the same publish-the-price stance CyPro takes across its specialist services. You can weigh the likely cost up front, with the final scope settled on the call.

Are these fixed prices?

They are indicative fixed-scope 'from' prices, not quotes. What sets the final figure is the size of your organisation, the CAF profile (baseline or enhanced), the GovAssure stage coverage or Secure by Design tier, and the number of systems or IP ranges in scope. Where the scope is clear, we hold the engagement to a fixed price rather than an open day rate, which is the whole point of publishing them.

Who actually does the work?

CyPro, from the scoping call to the final report. We are the delivery partner, not a layer of project management on top of one: our consultants run the gap analysis, write the remediation plan and roadmap, and work alongside your team implementing the controls that close the gaps. What we do not do is sign off your compliance, because nobody credible marks their own homework. Any formal external assessment or audit, an appointed GovAssure independent reviewer, a certification auditor or a CHECK-accredited ITHC tester, is out of scope and commissioned by you when you are ready. We use the programme names, CAF, GovAssure and MOD Secure by Design, to describe the framework we work to, never as a CyPro accreditation.

Which assessment do we need?

If you are a central government department or an arm's length body, GovAssure. If you supply the MOD, Secure by Design. If you need a CHECK IT Health Check for a PSN connection or a pension-dashboard link, the ITHC. If you need to know where you stand against the NCSC Cyber Assessment Framework more broadly, the CAF assessment. The scoping call confirms which one applies to you.

See how the process runs

Does the price include remediation?

The fee covers the gap analysis, the prioritised remediation plan and the roadmap, and it includes our support implementing the controls that close the gaps: defining them, helping your team stand them up and evidencing them. Where remediation runs well beyond the scope agreed at the outset, or you want a full internal audit once the work lands, we scope that as a return engagement. There is no hidden retainer folded into the figure above.

Rocket above the CAF Assessment call to action

Prices published, scope confirmed on a call

Find the assessment that fits your obligation

One scoping call, taken by a consultant, confirms which framework applies to you, the profile, stage or tier you must meet, and the fixed-scope figure for the work to get you there.