TrustOps pricing

Your ISO 27001 and SOC 2 programme, run for you

TrustOps is Atoro’s managed compliance service. A named security lead in Ireland or the UK runs it end to end, from €1,500 a month, and the prices are on this page rather than behind a call.

What it costs

TRUST
OPS

Startup, €1,500/monthOne framework. GDPR baseline.

Growth, €3,000/monthTwo frameworks. Full privacy programme.

Complete, €4,500/monthUnlimited frameworks. Pen test included.

A named lead on every planIn Ireland or the UK, in your timezone.

01 The problem

The certificate was the easy part

Certification is a project. Staying certified is a function: access reviews, security questionnaires, vendor checks, your internal audit, the certification body’s annual visit. Most companies our size never built that function, so it landed on an engineer who already had a full-time job.

That has a running cost. It does not appear on any invoice, because it is paid in your most senior people’s time, which is why almost nobody has ever put a number on it. Work out what yours is.

02 The work

What a year of this actually looks like

Once the report or the certificate is in hand, the work does not stop. It changes character, from a project with an end date to a function that runs on a calendar.

Recurring workAnnual volume at around 50 people
Access reviews across cloud, identity and core SaaS4 cycles
Evidence quality assurance12 cycles
Control drift triageContinuous
Policy review and reissueFull suite annually, ad hoc on change
Vendor and sub-processor risk assessmentOngoing, spikes on new suppliers
Security awareness training1 cycle, plus joiners
Management review4
Risk reassessment4
Your internal audit1
Certification body visit or Type 2 observation support1
Customer security questionnaires and tendersContinuous

In steady state that is roughly 300 to 400 hours a year, or eight to ten working weeks.

That number sits in an awkward place. It is too much to absorb alongside a full-time engineering or IT job, which is how it usually gets done and why it usually slips. At roughly a quarter of a role, it does not justify a dedicated hire either, because you would be paying a full salary for something three-quarters idle.

That gap is the whole reason TrustOps exists.

03 Plans

Three plans. Same service, same named lead. The difference is scope.

Every plan includes the full run of your programme: platform administration, evidence quality checks, access reviews, alert triage, security questionnaire responses, vendor risk, staff training cycles, a public trust page kept current, and management of the certification body’s annual visit. Your internal audit is in there too, in every plan, which is worth saying out loud because it is commonly sold as an add-on and costs €3,000 to €5,000 bought on its own.

GDPR is in every plan, because for a European company that is not an optional extra. On Growth and Complete it is a full privacy programme rather than a baseline.

StartupGrowthRecommendedComplete
€1,500/month€4,500/month
Named security lead in Ireland or the UKYesYes
The full run of your programmeYesYes
Your internal auditYesYes
Public trust page, kept currentYesYes
GDPRBaselineFull programme
We join your customers’ security review callsNoYes
Frameworks1 included, add more at €500/monthUnlimited
Annual web application penetration testAdd-on, from €3,000Included

All plans run on a 12-month term, with a free exit in the first 90 days. Prices are for companies up to 50 people. Add €1,000 a month for each additional 50. Billed monthly, Net 30.

UK clients: we contract and invoice in sterling, at £1,300, £2,600 and £3,900 a month. Additional frameworks are £425 a month and each additional 50 people is £850 a month. These are fixed for your term, not converted at the day’s rate.

Prices last reviewed: 5 August 2026

04 Under the table

Anything we say is included has a written scope

Here are all of them.

We hold the management system owner role

This is the part most people are really buying. We own the running of the management system: we do the work, we chase the evidence, we keep the calendar. You designate one point of contact with the authority to approve, and approval authority stays with you throughout. It never transfers to Atoro.

It is the difference between someone telling you what needs doing and someone whose job it is that it got done.

We do not operate inside your infrastructure

We do not deploy agents, change your cloud configuration, patch systems or touch product code. Our remit is programme design, policy authorship, stakeholder coordination, evidence verification and audit management. Technical implementation happens in your environment, by your team, to our specification. Your engineers keep control of your estate, and there is no third party with production access to explain to your own customers.

What the GDPR baseline covers, and what full adds

The baseline on Startup is the privacy side your ISO 27001 or SOC 2 programme has to evidence anyway: privacy policy, lawful basis records, the data protection controls inside the management system.

Full, on Growth and Complete, is the privacy programme proper: data mapping and your record of processing activities, DPA and sub-processor review, data protection impact assessments where you need them, retention schedules, a working subject access request process and a tested breach procedure. Kept current, not written once and filed.

What we do on your customers’ security review calls

On Growth and Complete, when a prospect’s security team wants a call, your named security lead takes it instead of your CTO. We handle the security sections of RFPs and tenders the same way. Scheduled with reasonable notice, in our working hours. If you are running a competitive tender that needs dedicated resourcing, we will tell you and scope it rather than quietly doing half a job.

Written questionnaire responses are in every plan. It is the live calls and the tender work that sit on Growth and above.

Your trust page

A public page on your domain carrying your certifications, policies, sub-processors and current evidence status, built by us and kept current. Most security questionnaires get answered before anyone sends one.

Your platform stays yours

TrustOps runs on your Drata or Vanta instance and the licence is in your name, not folded into our fee. Already have one? Nothing changes and you pay nothing extra. Don’t have one? We will contract it for you at partner rates from €6,000 a year, invoiced separately from the plan.

We do it this way on purpose. A provider who bundles your platform licence into their monthly fee has made leaving them harder than it needs to be. Your compliance history should not be hostage to your consultancy.

Additional SOC 2 criteria cost nothing extra

Security, Availability, Confidentiality, Processing Integrity and Privacy are scope inside one SOC 2 report, not separate frameworks. Add the criteria your customers ask for and the plan price does not move. Only a genuinely separate framework, ISO 27001 alongside SOC 2 for example, counts towards your framework count.

Your headcount band, and how to hold it

Prices cover companies up to 50 people, with €1,000 a month added at each further 50. On a 12-month term your band is fixed for the year and re-measured at renewal. On a 36-month term it is fixed for the full three years, so you can cross 50, and then 100, without the price moving.

Three years is also the certification cycle: initial certification, two annual visits from the certification body, then recertification. If you are hiring through that window, the longer term is usually the cheaper one.

Unlimited means unlimited from us

Complete includes unlimited frameworks for our scope of work. If your platform licence prices per framework, that part sits between you and the vendor.

The base scope of the pen test included with Complete

One web application of up to 50 pages or routes and one API of up to 100 endpoints, across up to five user roles, in a single environment. Retest included. That band fits most platforms of this size. If your estate is larger, a bigger API footprint, multiple applications or an external infrastructure perimeter, we quote the difference from our published bands before any testing starts.

05 The lead

Who actually runs it

Every plan comes with a named security lead in Ireland or the UK. Same timezone, same working day, in a shared Slack channel with your team. You meet them on the discovery call, before you sign anything, and they stay with you through certification and the years after it.

Behind that person is the rest of the team: penetration testers, technical analysts, and our data protection and AI governance leads. That is the part one person cannot match. A fractional CISO takes holidays, hands in notice, or gets pulled onto something urgent. A team does not.

How the engagement runs

We start within five business days of signature. Through the build phases you get a weekly 30-minute progress review, dropping to fortnightly or monthly once the programme is in steady state. Day to day runs in a shared Slack channel with your team, answered the same business day.

What we need from you

One point of contact with the authority to approve, at around four hours a week, with more in the first fortnight. Engineering time to implement specific technical controls in your own environment. Decisions where only you can make them. Internal capacity is the single biggest variable in how fast this moves, so we would rather be straight with you about it up front than discover it in week six.

A vCISO advises. Your security lead does the work.

06 vCISO cost

How much does a vCISO cost?

A virtual CISO typically costs $3,000 to $20,000 a month, according to vCISO.com and Workstreet. That buys advice. TrustOps starts at €1,500 a month and buys execution: the reviews, evidence and questionnaire responses a vCISO would tell you to do.

07 Certification cost

How much does ISO 27001 certification cost?

Three separate costs get conflated. The certification body’s own fees, billed to you directly with no margin taken by us, covering the certification audit and each annual visit after it. The platform licence, which you hold in your own name, from around €6,000 a year. And the work of building and running the management system, which is the part people underestimate. TrustOps prices the third part flat: from €1,500 a month, everything on this page included.

The part people budget for once is the part that recurs. In years two and three the certification body comes back, and what it looks at is a full year of the programme running, not the push that got you the certificate.

08 Managed compliance

What are managed compliance services?

Managed compliance services run your security compliance programme for you: platform administration, evidence collection and quality checks, access reviews, questionnaire responses, vendor risk and the yearly assurance cycle. It sits between software, which collects evidence but does not review it, and a vCISO, who advises but does not operate. Sometimes called compliance as a service.

09 Comparison

What the same work costs, three ways

Security hirevCISOTrustOps Growth
Year-one cost€90,000 to €100,000 base for a Security Manager in Dublin, before 11.25% employer PRSI (Morgan McKinley 2026 Salary Guide)$36,000 to $240,000/yr (vCISO.com)
Who does the workThey do, once you have recruited themYou do; they advise
Working from3 to 6 months to hireWeeks
Covers holidays and notice periodsNoPartly
GDPR programmeOnly if that is their background tooRarely in scope
Your customers’ security review callsThey take the callWithin their retainer hours
Your internal auditThey cannot audit their own workExtra
Platform licenceExtra, in your nameExtra, in your name
What it brings that the others do notOne accountable person, in the building, who learns your productSenior strategic judgement on demand

10 Proof

Why the price is possible

Atoro is an AI-native consultancy: the repeatable parts of compliance operations run through tooling we govern ourselves, and the judgement calls stay with named humans. We are Europe’s first ISO 42001 certified consultancy, which means our own AI management system passed the certification body’s inspection.

How the price holds

AI-native operationsThe repeatable work runs through tooling we govern.

Europe’s first ISO 42001 certified consultancyOur own AI management system passed inspection.

Your licence stays yoursNo third-party good marked up inside our fee.

11 FAQ

Pricing questions, answered plainly

Do you really publish your prices?

Yes. These are the prices. Proposals restate them; they do not renegotiate them. If your headcount or framework count changes, the price changes by the amounts on this page.

We already have Drata. Do we pay less?

No, and you do not pay more either. The licence was never inside the fee. You keep your own contract, we administer the instance, and the plan price is the same as it is for everyone else.

Which platforms do you work with?

We administer Drata and Vanta daily and hold partner status with both. The licence is yours: contract it directly, or we will contract it for you from €6,000 a year, invoiced separately from the plan.

Is our security lead full time on us?

No, and that is the point. The function is roughly a quarter of a role, which is exactly why hiring for it does not work: you would be paying a full salary for something three-quarters idle. Your lead carries a small portfolio, your programme is scheduled work rather than best effort, and the team behind them absorbs the peaks.

Do you act as our Data Protection Officer?

Not as part of these plans. We run the privacy programme a DPO would oversee, which for most companies our clients’ size is the thing that was actually missing. If you need a named DPO appointment under Article 37, raise it on the call and we will scope it.

A 12-month term and a 90-day exit? How do those fit together?

The term is twelve months because a compliance programme runs on an annual cycle; anything shorter sells you half a cycle. The exit exists because you should not need a full year to know whether it is working. If in the first 90 days you decide it is not, you leave. No exit fee, no remaining-term liability.

What is not included?

The certification body’s fees, billed to you directly with no margin to us. Your platform licence, which you hold in your own name. Penetration testing on Startup and Growth, and anything beyond the base scope on Complete. A named DPO appointment. Any remediation tooling your environment needs. Everything else on this page is in the monthly fee.

Have you ever failed to get a client certified?

No. We hold a 100% certification success record.

What is ISO 42001 and why would we add it?

The management system standard for AI governance. If you ship AI features, enterprise buyers are starting to ask. Adding it to an existing ISO 27001 programme shares most of the management system, so it costs far less than running it standalone.

We are not certified yet. Can you get us there?

Yes. Certification build programmes are scoped to your roadmap; book a discovery call.

12 Talk to us

Talk to the person who would run it

A discovery call is 30 minutes with Tom, not a sales development rep. Bring your framework list and headcount; leave with a number. It will match this page.

Tom McNamara, Founder and CEO of Atoro

Tom McNamaraFounder and CEO, Atoro

Bring to the call

Your framework list (ISO 27001, SOC 2, ISO 42001, GDPR)

Your headcount

Whether you already run Drata or Vanta

Your next audit or surveillance date, if you have one