Pricing

Real numbers, before the sales call.

These are anchors for a typical firm at each size. Anything unusual gets a fixed quote after a 20-minute call. There is no hourly billing on packages and no "call for pricing" on anything I can reasonably estimate.

Start here if unsure

Baseline Security Assessment

A two-week, CISSP-led review of your environment, policies, and legal obligations. You get a written findings report, a prioritized fix list, and a straight answer on which package, if any, you actually need.

Fully credited toward any package you start within 90 days.

$1,500 one-time

Book the assessment

WISP & Safeguards

WISP & FTC Safeguards

For tax preparers, CPAs, bookkeepers, RIAs, mortgage brokers, and dealerships.

About this program →

WISP Build

$3,500 one-time

A real Written Information Security Plan built for your firm, not a template with your name typed in.

  • Written risk assessment (required by the Rule and by IRS Pub. 4557)
  • WISP document mapped to all nine Safeguards Rule elements
  • Written incident response plan
  • Service-provider (vendor) inventory and oversight process
  • MFA, encryption, and access-control gap list with fixes
  • Live staff security training session (45 minutes)
  • PTIN-renewal data-security attestation support

Best for: Firms that need to be compliant this season and have never had a plan.

Talk about WISP Build
Most common

Qualified Individual Retainer

from $750 /month

The Rule requires you to designate a Qualified Individual. That can be me.

  • Named Qualified Individual of record
  • Annual written report to ownership (required by the Rule)
  • Semi-annual vulnerability scans and an annual testing plan
  • Quarterly WISP review and updates as your firm changes
  • Vendor contract review as you add tools
  • Breach triage and the 30-day FTC notification clock, if it ever happens
  • A direct line to me.

Best for: Any covered firm that would rather not become a part-time security officer.

Talk about Qualified Individual Retainer

Pricing assumes a firm of up to 15 people at one location. Larger or multi-office firms get a fixed quote after a 20-minute call.

vCISO

vCISO Retainers

For medical and dental practices, home health, RIAs, law firms, and any business whose insurer sent a questionnaire.

About this program →

Essentials

from $2,500 /month

A security program for a practice or firm with under about 20 staff.

  • HIPAA Security Rule risk analysis (or Reg S-P program for RIAs)
  • Policy set written for your practice, not a 200-page binder
  • Cyber-insurance questionnaire completed and defended
  • Quarterly review meeting with ownership
  • Vendor and Business Associate Agreement review
  • Staff training, twice a year
  • Incident response plan and first-call support

Best for: A single-location practice that needs a named security lead and a defensible program.

Talk about Essentials
Most common

Standard

from $4,500 /month

Everything in Essentials, with monthly cadence and hands-on remediation oversight.

  • Everything in Essentials
  • Monthly working session with your owner or office manager
  • Oversight of your IT provider or MSP on security work
  • Annual penetration test coordination and remediation tracking
  • Audit and OCR or SEC-exam preparation
  • Board- or partner-level reporting

Best for: Multi-provider practices, RIAs with SEC exam exposure, or anyone who has already had a scare.

Talk about Standard

Embedded

custom

Roughly a day a week. For organizations that need a CISO in the room but not on payroll.

  • Everything in Standard
  • Weekly presence, on-site or remote
  • Security architecture and vendor selection
  • New-location, new-system, or acquisition security reviews

Best for: Groups with 50+ staff, multiple locations, or active regulatory pressure.

Talk about Embedded

A full-time CISO in South Florida costs well over $200,000 a year plus benefits. Most practices need a fraction of that person.

CMMC Readiness

CMMC & NIST 800-171 Readiness

For aerospace, marine, and manufacturing subcontractors on the Treasure Coast and Palm Beach North.

About this program →

Level 1 Self-Assessment Package

$4,500 one-time

For suppliers handling only Federal Contract Information (FCI). Get your Level 1 self-assessment done right and affirmed in SPRS.

  • Scoping: what is in and out of your FCI boundary
  • Assessment against the 15 FAR 52.204-21 safeguarding requirements
  • Gap fixes you can implement with your current IT
  • SPRS submission and annual affirmation walkthrough

Best for: Machine shops, marine suppliers, and parts distributors with FCI but no CUI.

Talk about Level 1 Self-Assessment Package
Most common

Level 2 Readiness Project

from $25,000 per project

For suppliers that handle Controlled Unclassified Information (CUI). A full NIST SP 800-171 gap assessment, an honest SPRS score, and the documentation a C3PAO will ask for.

  • CUI scoping and enclave design (often the biggest cost saver)
  • Gap assessment against all 110 NIST SP 800-171 requirements
  • System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
  • Accurate SPRS score submission (DFARS 252.204-7019/7020)
  • Remediation roadmap with cost estimates
  • Prime-contractor flow-down and questionnaire responses

Best for: Tier 2 to Tier 4 suppliers to Pratt & Whitney, Sikorsky, L3Harris, Collins, and similar primes.

Talk about Level 2 Readiness Project

Continuous Compliance

from $1,500 /month

Keep the SSP, POA&M, and evidence current so the assessment is a formality, not a fire drill.

  • Quarterly control reviews and evidence collection
  • POA&M tracking to closure
  • Change reviews for new systems and vendors
  • Annual affirmation support
  • Assessment-day support when the C3PAO arrives

Best for: Any supplier that has finished a readiness project and wants to stay ready.

Talk about Continuous Compliance

Wirsing Security is not a C3PAO and does not certify anyone. Readiness work prepares you for the assessment; the assessment itself is performed by an accredited C3PAO.

What is not on this page

  • Managed IT. I do not sell helpdesk, licensing, or hardware. I work with your existing provider or introduce a good local one.
  • Penetration testing as a product. I coordinate and interpret tests inside a retainer. Standalone tests are quoted case by case.
  • Incident response for non-clients. If you are breached right now and not a client, email me anyway. I will point you to the right people fast.

FAQ

Questions people actually ask

Is this an IT company?

No. Wirsing Security is a security and compliance firm. I do not sell helpdesk, printers, or Microsoft licenses. I work alongside your existing IT provider and give them a clear, prioritized security list. If you need an MSP, I will introduce you to a good local one.

Who actually does the work?

I do. Ed Wirsing, CISSP. There is no account manager and no junior consultant learning on your dime. When you call, the person who built your program answers.

Why publish prices?

Because you should be able to tell whether this fits your budget before spending an hour on a sales call. Prices are anchors for typical firms. Unusual situations get a fixed quote after a 20-minute call, never an hourly surprise.

Do you work remotely or on-site?

Both. I am based in Port St. Lucie and cover the Treasure Coast and Palm Beach North in person. Remote engagements work anywhere in the U.S., and most of the work is remote anyway.

What is the Agnes Program?

If you are a grandma on the Treasure Coast, I will fix your computer problem for free. House calls included if you are close. It is in honor of my grandma Agnes. There is no catch and no upsell. Details on the Community page.

Get your program started

Talk to Ed

[email protected] · (772) 403-3088