Fixed Scope · Fixed Price · No Retainer Lock-In
Every engagement scoped in writing before the first invoice. Smart contracts, cloud, PQC readiness, GEO Wireless, and EU regulatory compliance — one team, transparent rates.
Defined in writing before the first invoice. Price changes only if scope changes — and only with your sign-off.
One full re-test of all Criticals and Highs included in every engagement. We verify the fix, not just the intent.
Signed letter for investors, regulators, or your insurance broker — accepted across EU, US, and UA regulatory contexts.
Single engagement can map findings to NIS2, DORA, MiCA, EU AI Act, SOC 2, and ISO 27001 simultaneously.
One-Time Engagements
Pre-launch audits, compliance assessments, and cloud reviews. Scoped, priced, and delivered.
Starter
Smart Contract Audit
$4,500
Fixed price · Up to 500 LoC
Focused manual and automated review for single contracts or small protocol components. Covers Solidity, Rust, and Vyper.
Professional
Full Protocol Audit
$12,000
Fixed price · Up to 2,500 LoC
The complete engagement for DeFi protocols, multi-contract systems, or cloud infrastructure ahead of significant deployment or fundraising.
Cloud & Compliance
Cloud Security Review
$8,000
Fixed price · Up to 4 AWS/GCP/Azure accounts
IAM, network, secrets, and logging mapped to SOC 2, ISO 27001, or NIS2 controls where relevant.
Advanced & Emerging Technology
Beyond standard audits — deep-expertise engagements for post-quantum cryptography, GEO wireless, anti-gambling intelligence, and national defense-grade architecture.
$9,500 + scope
Fixed price baseline · Hardware add-ons scoped separately
NIST PQC migration readiness for cloud, IoT, and embedded systems. Covers ML-DSA-65 (CRYSTALS-Dilithium), ML-KEM (Kyber), SLH-DSA, and hybrid classical/PQC transition paths. Includes Qiskit Aer CUDA VQC validation for cryptographic strength under quantum adversary assumptions. Aligned to EU AI Act Annex III and ENISA PQC guidelines.
$6,800 + per-site
Baseline engagement · On-site survey add-ons quoted separately
WiFi/BLE triangulation, SDR-based spectrum analysis, and legal OSINT geolocation (Wigle + OpenCellID) for physical perimeter security. Identifies rogue APs, unauthorized transmitters, RF leakage across security zones, and wireless blind spots in your monitoring coverage. Evidence maps to ISO 27001 Annex A.7 physical controls and SOC 2 CC6.4.
$14,000 + data scope
MVP sprint 1–2 · Full OMNIVERSAL stack quoted on engagement
The OMNIVERSAL 5-layer architecture review for AML/CFT and anti-gambling platforms — from OSINT ingestion and Neo4j graph correlation through Kafka/Flink AML Risk Engine to Merkle-anchored audit trails on Hyperledger Fabric. Aligned to MiCA, 6th AML Directive, and FATF Travel Rule requirements for token issuers and DeFi operators.
Custom
12-month engagements · Ukraine Diia.City eligible · EU grant-fundable
Defense-grade security architecture review for national critical infrastructure, multi-bearer connectivity stacks (fiber + SATCOM + fallback), and space-system threat modelling (5-domain: space, launch, ground, terminals, governance). Includes Starshield / SATCOM supplier due diligence, hosted payload trust boundaries, and NIS2 incident notification workflow design. Directly applicable to UA defense contractors, EU public sector, and Diia.City registered entities.
EU & International Regulatory
Standalone compliance readiness assessments. Each engagement ends with a gap report, control mapping, and an evidence package your auditor or regulator can act on.
$7,200
Fixed · Article 21 + 23 coverage · Essential & Important entities
Gap assessment against all Article 21 security measures. Incident notification workflow design (24 h / 72 h / 1-month tiers). ICT supply chain due diligence checklist. Remediation roadmap with deadline mapping to enforcement dates.
$9,400
Fixed · Financial entities · Jan 2025 enforcement
ICT risk management framework assessment. Resilience testing (TLPT) scoping and preparation. Incident classification and reporting workflow. Third-party ICT provider register and contractual gap analysis.
$8,100
Fixed · Token issuers & CASPs · White paper review
MiCA Title II–V control mapping for asset-referenced tokens, e-money tokens, and crypto-asset services. White paper review against Article 19 disclosure requirements. On-chain AML/CFT control inventory and FATF Travel Rule gap analysis.
$6,800
Fixed · High-risk AI systems · Annex III coverage
Risk classification under Annex III. Technical documentation requirements (Article 11). Conformity assessment preparation. Bias, explainability, and robustness evaluation framework. Applicable to AI-assisted security tools, LLM-based audit platforms, and autonomous agent systems.
$7,500
Fixed · All 5 TSC · 90-day observation window prep
Automated evidence collection pipeline setup. Control testing and sampling design. Auditor-ready artefact repository. Gap assessment with prioritised remediation before the observation window opens. Reduces fieldwork time and auditor fees significantly.
$5,900
Fixed · Annex A · Certification path report
Full Annex A control gap analysis. Risk register population. ISMS documentation review and policy templates. Certification auditor selection guidance. Remediation roadmap prioritised by likelihood-of-auditor-flagging.
Ongoing Services
Security and compliance wired into your pipeline — not a once-a-year fire drill.
$2,500 /month
3-month minimum · Cancel with 30 days notice
SAST, DAST, dependency scanning, and secret detection on every pull request. Critical/High findings block merge. Mediums auto-filed as issues. Includes LLM-Bridge integration for AI-assisted finding triage.
$3,800 /month
6-month minimum · Includes annual audit support
Automated evidence collection, daily control monitoring, and auditor-ready artefact repository. Covers SOC 2, ISO 27001, NIS2, DORA, or a custom framework. Your next audit starts with a clean evidence base, not a manual scramble.
$1,800 /month
1-month minimum · Per protocol
Post-deployment on-chain monitoring for DeFi protocols. Real-time transaction analysis, anomalous fund flow detection, flash loan / MEV pattern recognition, and AML/CFT-aligned thresholds via the Kafka/Flink Risk Engine. Alert escalation to your team via PagerDuty, Slack, or Discord.
Custom
12-month agreements · Volume discounts · Diia.City eligible
Dedicated engagement for large protocols, regulated financial institutions, EU public sector entities, or government digital services. Covers audits, continuous compliance, monitoring, threat modelling, PQC migration, and executive reporting under a single agreement. Structured for Diia.City–registered entities and UA defense contractors.
What's Covered Where
Every audit engagement can be mapped to one or more frameworks simultaneously — no separate re-engagement required.
| Service | Base Price | NIS2 | DORA | MiCA | EU AI Act | SOC 2 | PQC |
|---|---|---|---|---|---|---|---|
| Smart Contract Audit (Starter) | $4,500 | — | — | ✓ Add-on | — | — | — |
| Full Protocol Audit (Professional) | $12,000 | ✓ | ✓ | ✓ | ✓ Add-on | — | + PQC |
| Cloud Security Review | $8,000 | ✓ | ✓ | — | — | ✓ | — |
| PQC Readiness Audit | $9,500 | ✓ | ✓ | — | ✓ | — | Native |
| GEO Wireless Stack Audit | $6,800 | ✓ | — | — | — | ✓ CC6.4 | — |
| AML / Anti-Gambling Audit | $14,000 | ✓ | ✓ | ✓ | — | — | + PQC |
| Defense / National Infrastructure | Custom | ✓ Art. 21 | ✓ TLPT | — | ✓ | — | ✓ PQC |
| Continuous Compliance Retainer | $3,800/mo | ✓ | ✓ | ✓ | ✓ | ✓ | Coming |
Common Questions
We scope it properly before you sign. For contracts above the listed LoC, we provide a custom quote — typically $80–$120 per additional 100 LoC for smart contracts, or a flat add-on for additional cloud accounts. You see the number before we start.
No. All engagements are fixed-price based on an agreed scope. If scope changes mid-engagement we issue a change order with the additional cost before doing the work.
We start with a full cryptographic inventory — every algorithm, key exchange, signing scheme, and protocol in scope. We then apply the NIST PQC migration framework (NIST IR 8547) against your current posture, use Qiskit Aer simulation to evaluate quantum adversary assumptions, and deliver a prioritised migration roadmap covering ML-DSA-65, ML-KEM, and hybrid transition strategies. For embedded targets (ESP32, RP2040), we include hardware feasibility benchmarks.
Yes. Many controls overlap — ICT risk management, incident notification, and third-party supplier assessment appear in both frameworks. We map findings once and generate dual-framework evidence artefacts, saving you from running two separate engagements. Our framework matrix above shows exactly which services cover which frameworks out of the box.
Diia.City registered entities operating in the defense, fintech, or public sector space often have obligations that intersect with EU NIS2 (as supply chain partners to EU entities) and Ukrainian cybersecurity law. We're familiar with both the regulatory context and the multi-bearer connectivity architecture (fiber + SATCOM + Starshield fallback) relevant to UA defense infrastructure. Contact us with your specific regulatory obligations and we'll scope appropriately.
A signed PDF confirming scope, finding summary by severity, re-test outcome, and our professional assessment of the system's security posture. Accepted by VCs, EU and UA regulators, and insurance brokers as proof of audit. For NIS2/DORA engagements the letter includes a statement on Article 21 measure coverage.
We review your OMNIVERSAL-style architecture layer by layer: OSINT ingestion security, Neo4j graph model logic, Kafka/Flink pipeline integrity, and the Merkle Tree + Hyperledger Fabric audit trail. The output is a MiCA and 6AMLD-aligned control report plus a prioritised remediation backlog structured as GitHub-ready RFCs your team can act on immediately.
Custom Scope
Not sure which track fits? Tell us what you're securing and we'll return a scoped proposal — usually within 24 hours.
Useful things to include: