Free estimator
Compliance cost estimator
A budget range for getting certified and staying certified, with the recurring costs people forget until year two.
Run it now
Answer the questions and you get the number, the working behind it and what we would do about it. The calculation itself runs in your browser, so your answers stay with you.
What you tell it
- Target framework and certification scope
- Organisation size and number of in scope systems
- Whether you will hire, borrow from the team or bring in a consultant
- Tooling you already pay for, so it is not double counted
What you get back
- A low to high range for year one, itemised
- The annual cost of staying certified, which is the number that surprises people
- Certification body fees kept separate from advisory and remediation
- The tooling you can defer and the tooling you cannot
How the number is worked out
- 1
Certification body fees are taken from published Indian and international rate cards, refreshed each quarter.
- 2
Advisory effort is priced off the effort estimator, so the two agree with each other.
- 3
Remediation is the widest band by far. We show it as a range and say so rather than pretending to precision.
- 4
Year two onward assumes surveillance audits, evidence refresh and one internal audit cycle.
Where this stops being useful
Remediation cost depends entirely on what we find, and that is genuinely unknowable in advance. Treat the upper end of the range as the planning figure if you have never been audited before.
Other tools
- Compliance effort estimatorWork out roughly how many person days a certification will take your team before you commit to a date.Open it
- VAPT and security testing cost estimatorPrice a penetration test properly, by counting the things that actually drive effort rather than by counting IP addresses.Open it
- DPDP penalty exposure calculatorSee which penalty heads under the DPDP Act you are exposed to, and what the ceiling looks like for your organisation.Open it
The costs that a certification quote does not include
A certification body quote covers audit days. A consultancy quote covers advisory days. Between them they typically account for less than half of what the programme actually costs, which is why budgets set from quotes overrun.
The missing pieces, roughly in order of size: your own people's time, which is the largest and least visible; remediation work surfaced by the gap assessment; tooling you did not previously need, most often for logging, access management or vulnerability scanning; and the ongoing cost of keeping evidence current after certification.
That last one catches organisations repeatedly. Certification is not a project with an end date. Surveillance audits are annual, evidence collection is continuous, and a programme budgeted as a one-off will be underfunded from the second year onwards.
Where money is genuinely saved
Scope reduction, which is not a trick. Every system removed from scope removes its evidence, its controls and its audit time. On PCI DSS specifically, not holding cardholder data at all removes entire requirements rather than helping you satisfy them.
Automating evidence collection for anything a system already produces. Manual collection of machine generated evidence is the single largest waste in a compliance programme, and it recurs every cycle.
Running overlapping frameworks together. ISO 27001, SOC 2 and the DPDP Act share a substantial evidence base. Organisations that run them as separate programmes in separate rooms produce the same artefacts two or three times.
Starting the time-dimensioned evidence early, which costs nothing and removes the most common source of emergency spend near the audit date.
Where money is wasted
Tooling bought to answer a question that was really about ownership. A GRC platform does not create the discipline to keep a risk register current; it gives an undisciplined organisation a more expensive place to be undisciplined.
Consultancy that writes your documentation for you without your people involved. It produces a compliant-looking set of documents that describes an organisation that does not exist, and it fails at the first audit that asks somebody to explain their own process.
Certifying scope you do not need. Every additional site, entity or service in scope is paid for annually, forever.
Paying separately for retesting or for a second gap assessment because the first one was too shallow to act on.
How to use this estimate in a budget conversation
Present it as three lines rather than one: external cost, internal effort converted at a loaded rate, and ongoing annual cost. Boards approve programmes that are honestly costed and cancel programmes that overrun, so the conservative number defended early is the cheaper path.
Attach the driver to each line. If the estate complexity is what makes the number large, that is a conversation about architecture rather than about compliance, and it may be worth having separately.
If a certification is being pursued because a customer asked for it, quantify the revenue at stake. A programme with a named commercial trigger survives budget scrutiny; a programme justified by good practice usually does not.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












