Retainer capacity is full until mid-2027.Fixed-scope projects available on request.
Security Path Calculator
Start with the right framework.
Answer on your size, sector, customers and goals. The result names one path - CIS Critical Controls, NIS2 supplier readiness or ISO 27001 - and shows its reasoning.
- 18 questions
- About 4 minutes
- Free, no sign-up
Your Security Path
NIS2 worth checking. Your sector, size, or supply-chain role may bring NIS2 into play - worth confirming whether you are directly in scope or pulled in through your customers' requirements.
Cyber Resilience Act
You place a product on the EU market, so the CRA is worth settling next. Six questions give you the scope verdict, the role you hold in law, and the product class that decides self-assessment against a notified body.
Run the CRA calculator, free →Additional regulations to check
A note on budget. The retainer starts at about €11,400/year, so your figure sits below a continuous engagement. A one-off Starter Assessment (€1,900) is the right first step - but lasting security is a programme that keeps running afterwards. One-time projects like a single pentest cost more and protect less. The strongest position is for management to allocate an annual security budget before we engage.
This is a starting point for a conversation. Real-world context - your stack, your customers, your risk appetite - shapes the actual path. The calculator gives you a direction to bring to the call. We agree the specifics together.
Placing a product on the EU market? The CRA calculator settles scope, legal role and product class in six questions, also free.