Pricing
Real numbers, before the sales call.
These are anchors for a typical firm at each size. Anything unusual gets a fixed quote after a 20-minute call. There is no hourly billing on packages and no "call for pricing" on anything I can reasonably estimate.
Start here if unsure
Baseline Security Assessment
A two-week, CISSP-led review of your environment, policies, and legal obligations. You get a written findings report, a prioritized fix list, and a straight answer on which package, if any, you actually need.
Fully credited toward any package you start within 90 days.
$1,500 one-time
Book the assessmentWISP & Safeguards
WISP & FTC Safeguards
For tax preparers, CPAs, bookkeepers, RIAs, mortgage brokers, and dealerships.
WISP Build
$3,500 one-time
A real Written Information Security Plan built for your firm, not a template with your name typed in.
- ✓Written risk assessment (required by the Rule and by IRS Pub. 4557)
- ✓WISP document mapped to all nine Safeguards Rule elements
- ✓Written incident response plan
- ✓Service-provider (vendor) inventory and oversight process
- ✓MFA, encryption, and access-control gap list with fixes
- ✓Live staff security training session (45 minutes)
- ✓PTIN-renewal data-security attestation support
Best for: Firms that need to be compliant this season and have never had a plan.
Talk about WISP BuildQualified Individual Retainer
from $750 /month
The Rule requires you to designate a Qualified Individual. That can be me.
- ✓Named Qualified Individual of record
- ✓Annual written report to ownership (required by the Rule)
- ✓Semi-annual vulnerability scans and an annual testing plan
- ✓Quarterly WISP review and updates as your firm changes
- ✓Vendor contract review as you add tools
- ✓Breach triage and the 30-day FTC notification clock, if it ever happens
- ✓A direct line to me.
Best for: Any covered firm that would rather not become a part-time security officer.
Talk about Qualified Individual RetainerPricing assumes a firm of up to 15 people at one location. Larger or multi-office firms get a fixed quote after a 20-minute call.
vCISO
vCISO Retainers
For medical and dental practices, home health, RIAs, law firms, and any business whose insurer sent a questionnaire.
Essentials
from $2,500 /month
A security program for a practice or firm with under about 20 staff.
- ✓HIPAA Security Rule risk analysis (or Reg S-P program for RIAs)
- ✓Policy set written for your practice, not a 200-page binder
- ✓Cyber-insurance questionnaire completed and defended
- ✓Quarterly review meeting with ownership
- ✓Vendor and Business Associate Agreement review
- ✓Staff training, twice a year
- ✓Incident response plan and first-call support
Best for: A single-location practice that needs a named security lead and a defensible program.
Talk about EssentialsStandard
from $4,500 /month
Everything in Essentials, with monthly cadence and hands-on remediation oversight.
- ✓Everything in Essentials
- ✓Monthly working session with your owner or office manager
- ✓Oversight of your IT provider or MSP on security work
- ✓Annual penetration test coordination and remediation tracking
- ✓Audit and OCR or SEC-exam preparation
- ✓Board- or partner-level reporting
Best for: Multi-provider practices, RIAs with SEC exam exposure, or anyone who has already had a scare.
Talk about StandardEmbedded
custom
Roughly a day a week. For organizations that need a CISO in the room but not on payroll.
- ✓Everything in Standard
- ✓Weekly presence, on-site or remote
- ✓Security architecture and vendor selection
- ✓New-location, new-system, or acquisition security reviews
Best for: Groups with 50+ staff, multiple locations, or active regulatory pressure.
Talk about EmbeddedA full-time CISO in South Florida costs well over $200,000 a year plus benefits. Most practices need a fraction of that person.
CMMC Readiness
CMMC & NIST 800-171 Readiness
For aerospace, marine, and manufacturing subcontractors on the Treasure Coast and Palm Beach North.
Level 1 Self-Assessment Package
$4,500 one-time
For suppliers handling only Federal Contract Information (FCI). Get your Level 1 self-assessment done right and affirmed in SPRS.
- ✓Scoping: what is in and out of your FCI boundary
- ✓Assessment against the 15 FAR 52.204-21 safeguarding requirements
- ✓Gap fixes you can implement with your current IT
- ✓SPRS submission and annual affirmation walkthrough
Best for: Machine shops, marine suppliers, and parts distributors with FCI but no CUI.
Talk about Level 1 Self-Assessment PackageLevel 2 Readiness Project
from $25,000 per project
For suppliers that handle Controlled Unclassified Information (CUI). A full NIST SP 800-171 gap assessment, an honest SPRS score, and the documentation a C3PAO will ask for.
- ✓CUI scoping and enclave design (often the biggest cost saver)
- ✓Gap assessment against all 110 NIST SP 800-171 requirements
- ✓System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
- ✓Accurate SPRS score submission (DFARS 252.204-7019/7020)
- ✓Remediation roadmap with cost estimates
- ✓Prime-contractor flow-down and questionnaire responses
Best for: Tier 2 to Tier 4 suppliers to Pratt & Whitney, Sikorsky, L3Harris, Collins, and similar primes.
Talk about Level 2 Readiness ProjectContinuous Compliance
from $1,500 /month
Keep the SSP, POA&M, and evidence current so the assessment is a formality, not a fire drill.
- ✓Quarterly control reviews and evidence collection
- ✓POA&M tracking to closure
- ✓Change reviews for new systems and vendors
- ✓Annual affirmation support
- ✓Assessment-day support when the C3PAO arrives
Best for: Any supplier that has finished a readiness project and wants to stay ready.
Talk about Continuous ComplianceWirsing Security is not a C3PAO and does not certify anyone. Readiness work prepares you for the assessment; the assessment itself is performed by an accredited C3PAO.
What is not on this page
- Managed IT. I do not sell helpdesk, licensing, or hardware. I work with your existing provider or introduce a good local one.
- Penetration testing as a product. I coordinate and interpret tests inside a retainer. Standalone tests are quoted case by case.
- Incident response for non-clients. If you are breached right now and not a client, email me anyway. I will point you to the right people fast.
FAQ
Questions people actually ask
Is this an IT company?
No. Wirsing Security is a security and compliance firm. I do not sell helpdesk, printers, or Microsoft licenses. I work alongside your existing IT provider and give them a clear, prioritized security list. If you need an MSP, I will introduce you to a good local one.
Who actually does the work?
I do. Ed Wirsing, CISSP. There is no account manager and no junior consultant learning on your dime. When you call, the person who built your program answers.
Why publish prices?
Because you should be able to tell whether this fits your budget before spending an hour on a sales call. Prices are anchors for typical firms. Unusual situations get a fixed quote after a 20-minute call, never an hourly surprise.
Do you work remotely or on-site?
Both. I am based in Port St. Lucie and cover the Treasure Coast and Palm Beach North in person. Remote engagements work anywhere in the U.S., and most of the work is remote anyway.
What is the Agnes Program?
If you are a grandma on the Treasure Coast, I will fix your computer problem for free. House calls included if you are close. It is in honor of my grandma Agnes. There is no catch and no upsell. Details on the Community page.