The assessment

We measure how your IT and security stand, and give you the proof.

Your systems grew or got outsourced. A grown IT estate is quickly twenty years, forty tools, three migrations started and four people. That is arithmetic, not a failure, and nobody keeps track of it. The assessment measures the state. You get a findings report you put in front of the customer, the investor, the auditor or your management, before anyone asks. Read-only access, fixed price.

The assessment Fixed price, by system landscape 7,500 to 12,000 euros

Honesty

What we do not do is exactly as visible as what we do.

No incident response, no forensics, not even brokered. If you have an active incident right now, your cyber insurance is the first call, not us.

After an incident

The way back, in this order

  1. Cyber insurer your first call
  2. Forensics runs with their provider
  3. Assessment about two weeks, builds on the report
  4. Rebuild six to eight weeks: access, detection, the proof

The acute response belongs to your insurer. We come afterwards, with the forensic report as the base. You can also reach out while the forensics are still running; we then plan what follows. After an incident, the price follows the forensic report. This is how it went at the software company.

Read-only access

We work read-only during the assessment. Exports, configuration extracts, interviews. No domain admin, no changes to your systems.

There is no target architecture at the start. A target architecture built on a guess is an expensive misunderstanding. We start with what is actually running.

What you get

  • A gap and maturity analysis: every control from Annex A of ISO 27001:2022 on a capability scale from zero to five per ISO/IEC 33020, the result mapped to the Functions and Categories of NIST CSF 2.0. If a customer requires SOC 2, we add its Trust Services Criteria.
  • What is there. Tools, systems, contracts, and what overlaps.
  • What can die at the next renewal date.
  • What actually has an effect and what is only paper.
  • If a customer or your cyber insurer has sent you a security questionnaire, we fill it in as part of the assessment. No separate product, no extra invoice.
  • If your product is built on AI or LLMs, the questions a customer asks about it are in scope: what data the models see, which subprocessors are involved, how it is documented. We take those on.
  • A findings report you can put in front of them. You own it.

7,500 to
12,000 euros

Duration
About two weeks
Price
Fixed, by system landscape
Your effort
Two to three interviews
After that
You decide

No framework agreement, no automatic renewal. What comes next is your decision.

The price follows your system landscape, not your headcount. A grown on-prem estate, two to three interviews with the people responsible for your systems: 7,500 euros. Several large cloud environments: around 12,000 euros. That lets you place yourself before the call, even with a signing limit. Buy the ISO roadmap and the assessment is included, not billed again.

This is the smallest step you can start with, and the only one you need first. What comes after, and what it costs, is decided once the findings report is on the table.

Sample data, no client material

Excerpt from a findings report

RiskPriorityEffortCost
Backups are not testedhighlowlow
Admin accounts without multi-factor sign-inhighlowlow
No patch process for serversmediummediummedium
Legacy system with no support contractlowdrops away at the next renewal date

This is what the findings report looks like: risk, priority, effort, cost. Your report lists your systems, not these.

What we will not do. And what you keep.

We do not speak to your management without you.

The plan carries your name. You present it, we sit at the back.

You can stop after the first phase.

The findings go to you first. You read the draft before anyone else sees it.

What we hand over

You get the documentation, the access and the knowledge behind it. You retain ownership of your systems.

If something needs permanent support, we tell you beforehand. Then you decide whether we take it on.

What comes next

The route follows from what we find.

Which route it becomes is decided at the end of the assessment. All routes at a glance.

Intro call

hello@controlpunkt.com

We reply within one business day.

What to put in the first email

  • Who you are and your company.
  • What it is about: the trigger, the real problem. A sentence or two is enough.
  • If a customer, an investor or a regulator has set a deadline: add the date.
  • After an incident: where the forensics stand.