How we estimate cost and effort
Every cost figure on this site follows one definition, so standards stay comparable. This page is that definition.
What the numbers mean
Typical cost is what an organization pays external parties for the validation itself, in a first cycle: assessor, auditor, or certification body fees, plus any scanning or testing the standard mandates. It is the number you can check against an assessor's quote.
Org effort is internal staff hours for a first cycle: preparation, evidence gathering, interviews, and working with the assessor.
Neither number includes remediation (building or fixing controls), tooling, readiness consulting, or the cost of operating controls year-round. Those surrounding costs are real, and for many organizations they are larger than the validation fee. Each standard's page and cost guide describe them separately, because they depend on your starting point in a way no shared range can honestly capture.
What the bounds mean
The headline range describes the most common externally audited path for the standard: a QSA-led ROC for PCI DSS, a Type 2 examination for SOC 2, a Level 2 C3PAO certification for CMMC. Within that path, the bounds cover roughly the middle 80% of organizations: the low end is a smaller, simpler, largely-ready organization, and the high end is a larger or more complex one. Outliers in both directions exist and are excluded; where they matter, the page says so in words.
Lighter paths exist for many standards, such as self-assessments or point-in-time reviews, and some cost nothing externally. Those appear as labeled scenarios under the range rather than being blended into it, so the headline number stays meaningful for the organizations most likely to be quoted for an audit.
Some standards, such as HIPAA, have no required audit or certification at all. Those pages show no typical-cost range, because there is no fee to show. Where organizations commonly buy an optional assessment, that market is presented as a labeled scenario instead.
Where the figures come from
We record the sources behind every researched range, in three tiers:
- Official: the standards body or regulator itself, including government cost estimates published with regulations. Most defensible, often coarse.
- Industry: published observations from established assessors, audit firms, and industry directories. We note who published each figure and when, and treat vendor incentives as part of reading them.
- Firsthand: Aeris Secure's own experience from client engagements and industry contacts. Least citable, most current. Always disclosed as ours.
Each standard's cost guide lists its sources with the figures they reported. We re-verify sources when a standard changes version and at least annually.
Read the ranges as orientation
Ranges are directional, not quotes. No published range, here or anywhere, replaces a scoped proposal for your environment. The honest use of these numbers is budgeting order of magnitude, comparing standards, and recognizing when a quote is far outside the market.
Infosec Standards is operated by Aeris Secure, a security audit and consulting firm. That relationship is where the firsthand data comes from, and it is disclosed wherever it informs a figure.