Services & Pricing

Smart packages. Clear value.

Effective information security without the consultant overhead.

Fixed-price security analysis and implementation.
No hourly billing surprises. AI-assisted efficiency, expert-verified quality.

Our information security packages

From free Discovery to complete Transformation. All packages are aligned with ISO/IEC 27001.

You can find an overview of the included features of each package and optionally available add-ons in our comparison table below.

0

DISCOVERY

Delivered within 3 business days.

New to us? Get a fast, no-commitment security snapshot to identify your most important risks and compliance blind spots.

  • 2-page executive security snapshot (delivered as PDF)
  • Organizational context analysis
  • High-level compliance highlights
  • High-level threat and risk identification based on your industry, operating regions and publicly available information
  • Top quick-win recommendations

Your Benefit
Clear understanding of your biggest security and compliance risks.

Best for: Organizations that are curious about their security exposure and want a no-risk look before committing.

1,900

Foundation

Delivered within 5 business days.

Establish your security baseline and define a concrete improvement plan aligned to ISO 27001, enabling you to focus on your business.

  • Comprehensive security report (~20 pages), incl. executive summary
  • Review of up to 30 pages of your documents (policies, system documentation etc.)
  • Full SWOT/PESTLE analysis & stakeholder context
  • Compliance requirements overview
  • Risk register with likelihood & impact ratings
  • Strategic security requirements based on your posture
  • Tailored short-, mid- and long-term recommendations
  • Included: Kickoff call and 30-min debriefing workshop
  • Included: Information Security Policy draft

Your Benefit
Clear baseline, prioritized risks, and actionable next steps.

Best for: Organizations starting structured security improvement – especially those preparing for compliance audits or responding to customer security questionnaires.

4,000

Acceleration

Delivered within 15-20 business days.

Design your ISO 27001–aligned ISMS with a complete risk-based structure and a clear path to audit readiness.

  • Everything in the Foundation package PLUS:
  • 30-min scoping call + 2×2-hour interactive virtual workshops
  • Expanded document review (up to 100 pages)
  • ISO 27001 gap analysis & maturity assessment
  • ISMS design & project setup (ISO 27001 Clauses 4–6)
  • Risk treatment & action plan mapped to controls
  • Full Statement of Applicability (Annex A mapping)
  • Roadmap with milestones toward audit readiness
  • Training, awareness, change management & documentation strategy
  • Included: Executive presentation & strategic guidance
  • Included: Three tailored security policies (e.g. AI Usage Policy)

Your Benefit
Operational ISMS framework ready for implementation, with documented risk treatments, ISO 27001-compliant controls, and a clear path to certification audit.

Best for: Organizations looking to improve their security posture, moving from assessment to structured ISMS design – especially those with client requirements for ISO 27001.

from € 9,000

Transformation

End-to-end ISO 27001 planning and implementation, from gap analysis to implementation support. Delivered by an experienced security professional.

  • Everything in the Acceleration package PLUS:
  • End-to-end ISMS implementation support throughout your rollout
  • In-depth review of your existing documentation, assets & controls
  • Risk assessment & treatment workshops with your team
  • Detailed implementation roadmap with clear timeline
  • Training, awareness and communication plans & execution
  • Detailed change, documentation and records management plans
  • Performance management & monitoring setup
  • Management review & Internal audit process setup & training
  • Continual improvement process setup
  • Included: Four 2-hour planning & implementation workshops
  • Included: Comprehensive ISMS documentation suite (10+ documents)

Your Benefit
Fully operational ISMS with implemented controls, prepared audit evidence, and your organization ready for ISO 27001 certification.

Best for: Organizations with complex environments requiring hands-on implementation support – especially those with compliance deadlines or client requirements.

Final pricing & delivery timeline depends on organizational size, control complexity, and implementation.

All prices are net and exclude VAT. Our services are offered to businesses only.

Feature comparison

Compare what’s included in each package

Discovery

Snapshot

0
Start free Discovery
Foundation⭐

Baseline

1,900
Start with Foundation
Acceleration

Design

4,000
Start with Acceleration
Transformation

Implementation

from

9,000
Request a quote

Assessment

Executive security snapshot

Business & Risk context (SWOT/PESTLE)

High-Level

Stakeholder context

High-Level

Compliance requirements

High-Level

Threat & risk identification

High-Level

Strategic security requirements

High-Level

Preliminary gap analysis

Comprehensive assessment report

Executive presentation & decision template

Choose your package
Start free Discovery
Start with Foundation
Start with Acceleration
Request a quote

Not sure which package fits? Contact us for a quick recommendation.

Managed Services for your ISMS

Information security is not a one-time project. Threats evolve, requirements change, and controls require continuous attention.

Our managed services help you ensure your security framework and measures remain effective, compliant, and audit-ready – without requiring permanent internal resources. Our different support levels have been developed to accommodate your individual needs.

Essentials Care

400 /month

Ideal for small teams that want peace of mind without big budgets.

  • Monthly compliance & threat intelligence digest
  • Quarterly compliance status review
  • Policy updates (minor revisions)
  • Support via email
  • Response within 3 business days
  • 1 hour consulting/month included
  • Save 10% on all additional consulting hours

Compliance+ ⭐

900 /month

For SMEs that need an audit-ready ISMS without hiring full-time staff

  • Everything in the Essentials Care package PLUS:
  • 1-hour alignment session every two weeks
  • Quarterly awareness & training sessions
  • Change monitoring & proactive compliance impact notifications
  • Nonconformity tracking, corrective actions & continual improvement log
  • Priority support via email & Microsoft Teams
  • Response within 1 business day
  • 2 hours consulting/month included
  • Save 15% on all additional consulting hours

Managed ISMS

2,400 /month

For organizations that need dedicated ISMS leadership without full-time CISO costs

  • Everything in the Compliance+ package PLUS:
  • Dedicated named ISMS manager (virtual CISO)
  • 4-business-hours response SLA for critical incidents
  • Ongoing risk register updates
  • Continuous ISMS KPI monitoring
  • Monthly ISO 27001 maturity status report
  • Semi-annual management review preparation & facilitation
  • Annual internal audit (remote, ISO 27001 aligned)
  • Annual full-day workshop (on-site or virtual)
  • 4 hours consulting/month included
  • Save 20% on all additional consulting hours

All services are provided on a monthly basis and can be upgraded with additional modules & consulting based on your individual needs, e.g. surveillance/recertification audit support packages. All prices are net and exclude VAT. Our services are offered to businesses only.

Important: Managed services require an established ISMS baseline. For new clients with an existing ISMS, onboarding begins with a Foundation assessment (included with a 12-month commitment).

Individual consulting & expert support

Can’t find the right package for your situation, need highly specialized guidance, or more workshops than included? A senior architect designs each engagement around your specific needs. We scope and price each engagement individually based on your goals, timeline, and complexity.

Elbphilharmonie

Dedicated Senior Expertise

From the first hour to the last, you benefit from concentrated expertise that directly advances your goals. Each consulting day is dedicated to your priorities – focused value, not overhead.

Flexible Engagement

Consulting projects can be structured as intensive sprints or distributed over time to match your team’s capacity. We adapt the engagement model to your project and your team’s rhythm.

Tailored to Your Projects

Every consulting engagement is aligned with your specific context – from M&A carve-outs to cloud security or optimization of your AI agents. No generic checklists, only targeted expertise where you need it most.

Frequently Asked Questions (FAQ)

How do we get started with Wissario?

We typically begin with a Discovery or Foundation assessment to establish transparency and define next steps.

Organizations with a clear understanding of their requirements may also
choose to start directly with the Acceleration package (ISMS design) or Transformation project (guided implementation).

What do you need from us?

All packages are designed to keep the effort on your side to a minimum.

For the Discovery assessment we only need basic details about your organization – we derive the rest from industry knowledge, regional regulations and publicly available information. A debriefing call afterwards is optional.

Every paid engagement starts with a dedicated scoping call and concludes with a structured debriefing. Acceleration and Transformation packages additionally include intermediate workshops, so you can steer the direction before the final delivery.

Paid packages also include analysis of relevant documents you provide – typically policies, internal guidelines, asset inventories, system documentation, or existing ISMS material. We may follow up with a short questionnaire. Both are optional, but they significantly improve the quality of what you receive.

Managed Services are built to take information security management off your desk as far as possible and keep your involvement minimal. Automatic or manual notifications about changes or incidents keep your security posture current and respond to relevant changes. We will be glad to implement the best working solution together with you.

Can services be combined?

Yes. Our packages, managed services, and individual consulting can be combined flexibly and tailored to your specific needs – either sequentially or in parallel.

Common combinations:

Do you guarantee ISO/IEC 27001 certification?

No. We prepare and support you throughout the certification process to ensure your ISMS is audit-ready for the scope provided, but certification decisions are always made by independent auditors.

That said, organizations that implement our recommendations will be well-prepared for successful certification. If findings are identified during certification, we’ll be glad to support your corrective action response.

Can I upgrade, downgrade, or change my engagement later?

Yes. While project-based engagements are scoped and contracted upfront and cannot be downgraded once started, you can upgrade to a higher-tier package during delivery by paying only the difference.

Ongoing managed services, however, are flexible and can be upgraded, downgraded, adjusted and cancelled at any time with 30 days’ notice unless agreed otherwise. Changes take effect at the start of your next billing cycle.

Optional Add-Ons can be added anytime, subject to availability.

Do managed services require an existing ISMS?

Not necessarily. A fully mature ISMS is not required, but we do need an established security and ISMS baseline before ongoing managed services can begin.

If no suitable baseline exists yet, we typically establish it through one of our project packages. If you already operate an ISMS, we begin with a Foundation assessment to validate the baseline, align expectations and define the ongoing support scope.

How are your services billed?

All prices are net and exclude VAT. Our services are offered exclusively to businesses (Unternehmer within the meaning of §14 BGB).

You will receive an invoice compliant with German requirements (§14 UStG) once agreed project milestones or deliverables have been completed. German VAT is added where applicable. For business clients in other EU member states holding a valid VAT identification number, the reverse-charge procedure applies. Without a valid VAT ID, German VAT is charged. For clients outside the EU, our services are generally not subject to German VAT.

Managed services are billed monthly in advance, with discounted rates available for annual prepayment.

Depending on your location, payment is possible via:

  • Bank transfer (SEPA) for EU payments
  • Stripe – Secure online payment portal, providing local payment instructions for international clients and supporting both bank transfers and credit cards

Unless stated otherwise on the invoice, payment is due within 14 days of the invoice date.

Purchase orders (POs) are supported where required. Work begins after written confirmation of the proposed scope and pricing.

What if we’re not aiming for certification?

That’s a common and perfectly reasonable position – and our packages are built for it.

Our objective is to improve your security posture in a way that supports your business rather than obstructing it. An ISO 27001-aligned ISMS is an effective vehicle for getting there: it provides structure, prioritisation and evidence. But the certificate itself is a by-product, not the goal.

A customer sent a security questionnaire, an investor asked during due diligence, NIS2 brought them into scope, or an incident made the gaps visible: In each case the work is the same, the certificate is optional.

If you later decide to certify, most of the work will already be done. The structure is already in place.