Pricing
ISO certification work breaks into five modules with defined boundaries, so every one of them carries a published starting price. Government, critical infrastructure and international work turns on your environment, your regulator and your deadline, so it is priced in writing after a scoping call rather than guessed at here. Everything is fixed-price against a defined scope and built inside your own tenant — not a compliance platform you have to keep renting.
Take one module, combine several, or run the full lifecycle through to a certificate issued by an accredited certification body. Soveriq certifies against ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, ISO 9001, ISO/IEC 20000-1 and ISO 22301. Modules run consecutively are scoped as a single programme rather than added together, because consecutive modules remove duplicated discovery. All figures are from prices, excluding GST.
Certification body audit fees are separate and payable to that body directly — typically $8,000 to $20,000 across the initial three-year cycle depending on headcount, sites and standards in scope. We take no referral fee from any of them.
For agencies, departments and their contracted service providers carrying protective data security obligations to a state regulator.
VPDSS · OVIC PDSP · NSW CSP · QLD IS18 · SACSF · WA CSP · Essential Eight
This work is priced against your scope rather than published here. The cost turns on whether the submission covers one organisation or a shared service, the state of your information asset register before we start, the distance to your next attestation or submission window, and whether Essential Eight uplift sits inside or outside scope. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.
Engaged directly, or as a subcontractor to the prime holding your contract. Use Book to Scope and you will have a written scope and a fixed price within one business day. These frameworks are assessed and implemented, not certified — Soveriq is not an accredited certification body.
For Commonwealth entities, and for the vendors who must satisfy Commonwealth security requirements to hold or win the contract.
PSPF Release 2026 · ASD ISM · Essential Eight
This work is priced against your scope rather than published here. The cost turns on the size and classification of the system boundary, whether obligations apply to you directly or flow down by contract, how many of the mandatory plans already exist in usable form, and the annual reporting cycle you are working back from. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.
Engaged directly, or as a subcontractor to the prime holding the contract. Use Book to Scope and you will have a written scope and a fixed price within one business day. These frameworks are assessed and implemented, not certified — Soveriq is not an accredited certification body or an IRAP assessor.
Where the obligation is legislated, the report is board-approved, and the penalties are personal. Priced for the accountability that carries.
SOCI Act · CIRMP · AESCSF v2 · APRA CPS 230 · APRA CPS 234
This work is priced against your scope rather than published here. The cost turns on the number of responsible entities and risk management programs, whether operational technology sits inside the assessed estate, the Security Profile you are targeting and the distance you have to travel, and how many material service providers require assessment. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.
Multi-asset portfolios and operational technology environments are scoped on inspection. Board and risk committee reporting can be built into the engagement. Use Book to Scope and you will have a written scope and a fixed price within one business day. These obligations are assessed and implemented, not certified — Soveriq is not an accredited certification body.
For Australian businesses selling into North American, European and enterprise supply chains, where the buyer names the framework before they name the price.
SOC 2 · GDPR · PCI DSS v4.0.1 · NIST CSF 2.0 · NIST AI RMF
This work is priced against your scope rather than published here. The cost turns on the number of product environments and jurisdictions in scope, your merchant or service provider level where PCI DSS applies, the length of the observation window your buyer will accept, and whether one report or several regulatory scopes are required. Send us the framework, the deadline and the point you are starting from, and you will have a defined scope and a fixed price within one business day.
Quoted in Australian dollars. Audit, assessor and QSA fees are payable to those firms directly and sit outside our scope — we prepare you for those assessors and sit with you through the assessment, but we do not issue the report ourselves. Use Book to Scope and you will have a written scope and a fixed price within one business day.
Every figure is a genuine starting price for a defined scope. Scope is agreed on a free scoping call and fixed in the statement of work before any fee is payable. We do not raise a fixed price mid-engagement.
If Soveriq builds your system under Module 02, we cannot then provide independent audit, assurance or review of those same controls under Module 03. Impartiality requirements do not allow it. In that case Module 03 is delivered as readiness validation, labelled as such in writing, and genuine independence is supplied by someone independent of the build. We would rather lose the second engagement than compromise the first.
All prices exclude GST. Certification body, IRAP assessor, CPA firm and QSA fees are payable to those organisations directly — we take no referral fee from any of them. Travel outside Melbourne is charged at cost and agreed in advance. Software you already licence stays yours; we do not resell tooling.
Where an engagement genuinely suits time and materials rather than fixed price, commercial terms are set out in writing against the scope in front of us. Where fixed price would serve you better for the same outcome, we will say so before you commit to the other structure.
We work to the edition in force, not the one still sitting in old collateral. ISO/IEC 27701 moved to a standalone 2025 edition, superseding the 2019 extension. ISO 9001:2026 publishes on 16 September 2026. PCI DSS v4.0.1 is the only active version, and its once future-dated requirements have been mandatory since March 2025. If a scope statement or a competing proposal still cites the superseded edition, it is out of date.
Modules 01 and 02 together, or the full 01 to 05 lifecycle, are scoped as a single programme rather than added together. Running consecutive modules removes duplicated discovery, and the programme price reflects that. A second standard built on the same management system costs materially less than the first, because the shared clauses are already done.