TrustOps pricing
Your ISO 27001 and SOC 2 programme, run for you
TrustOps is Atoro’s managed compliance service. A named security lead in Ireland or the UK runs it end to end, from €1,500 a month, and the prices are on this page rather than behind a call.
What it costs
TRUST
OPS
Startup, €1,500/monthOne framework. GDPR baseline.
Growth, €3,000/monthTwo frameworks. Full privacy programme.
Complete, €4,500/monthUnlimited frameworks. Pen test included.
A named lead on every planIn Ireland or the UK, in your timezone.
01 The problem
The certificate was the easy part
Certification is a project. Staying certified is a function: access reviews, security questionnaires, vendor checks, your internal audit, the certification body’s annual visit. Most companies our size never built that function, so it landed on an engineer who already had a full-time job.
That has a running cost. It does not appear on any invoice, because it is paid in your most senior people’s time, which is why almost nobody has ever put a number on it. Work out what yours is.
02 The work
What a year of this actually looks like
Once the report or the certificate is in hand, the work does not stop. It changes character, from a project with an end date to a function that runs on a calendar.
| Recurring work | Annual volume at around 50 people |
|---|---|
| Access reviews across cloud, identity and core SaaS | 4 cycles |
| Evidence quality assurance | 12 cycles |
| Control drift triage | Continuous |
| Policy review and reissue | Full suite annually, ad hoc on change |
| Vendor and sub-processor risk assessment | Ongoing, spikes on new suppliers |
| Security awareness training | 1 cycle, plus joiners |
| Management review | 4 |
| Risk reassessment | 4 |
| Your internal audit | 1 |
| Certification body visit or Type 2 observation support | 1 |
| Customer security questionnaires and tenders | Continuous |
In steady state that is roughly 300 to 400 hours a year, or eight to ten working weeks.
That number sits in an awkward place. It is too much to absorb alongside a full-time engineering or IT job, which is how it usually gets done and why it usually slips. At roughly a quarter of a role, it does not justify a dedicated hire either, because you would be paying a full salary for something three-quarters idle.
That gap is the whole reason TrustOps exists.
03 Plans
Three plans. Same service, same named lead. The difference is scope.
Every plan includes the full run of your programme: platform administration, evidence quality checks, access reviews, alert triage, security questionnaire responses, vendor risk, staff training cycles, a public trust page kept current, and management of the certification body’s annual visit. Your internal audit is in there too, in every plan, which is worth saying out loud because it is commonly sold as an add-on and costs €3,000 to €5,000 bought on its own.
GDPR is in every plan, because for a European company that is not an optional extra. On Growth and Complete it is a full privacy programme rather than a baseline.
| Startup | GrowthRecommended | Complete | |
|---|---|---|---|
| €1,500/month | €3,000/month | €4,500/month | |
| Named security lead in Ireland or the UK | Yes | Yes | Yes |
| The full run of your programme | Yes | Yes | Yes |
| Your internal audit | Yes | Yes | Yes |
| Public trust page, kept current | Yes | Yes | Yes |
| GDPR | Baseline | Full programme | Full programme |
| We join your customers’ security review calls | No | Yes | Yes |
| Frameworks | 1 included, add more at €500/month | 2 included, third at €500/month | Unlimited |
| Annual web application penetration test | Add-on, from €3,000 | Add-on, from €3,000 | Included |
All plans run on a 12-month term, with a free exit in the first 90 days. Prices are for companies up to 50 people. Add €1,000 a month for each additional 50. Billed monthly, Net 30.
UK clients: we contract and invoice in sterling, at £1,300, £2,600 and £3,900 a month. Additional frameworks are £425 a month and each additional 50 people is £850 a month. These are fixed for your term, not converted at the day’s rate.
Prices last reviewed: 5 August 2026
04 Under the table
Anything we say is included has a written scope
Here are all of them.
We hold the management system owner role
This is the part most people are really buying. We own the running of the management system: we do the work, we chase the evidence, we keep the calendar. You designate one point of contact with the authority to approve, and approval authority stays with you throughout. It never transfers to Atoro.
It is the difference between someone telling you what needs doing and someone whose job it is that it got done.
We do not operate inside your infrastructure
We do not deploy agents, change your cloud configuration, patch systems or touch product code. Our remit is programme design, policy authorship, stakeholder coordination, evidence verification and audit management. Technical implementation happens in your environment, by your team, to our specification. Your engineers keep control of your estate, and there is no third party with production access to explain to your own customers.
What the GDPR baseline covers, and what full adds
The baseline on Startup is the privacy side your ISO 27001 or SOC 2 programme has to evidence anyway: privacy policy, lawful basis records, the data protection controls inside the management system.
Full, on Growth and Complete, is the privacy programme proper: data mapping and your record of processing activities, DPA and sub-processor review, data protection impact assessments where you need them, retention schedules, a working subject access request process and a tested breach procedure. Kept current, not written once and filed.
What we do on your customers’ security review calls
On Growth and Complete, when a prospect’s security team wants a call, your named security lead takes it instead of your CTO. We handle the security sections of RFPs and tenders the same way. Scheduled with reasonable notice, in our working hours. If you are running a competitive tender that needs dedicated resourcing, we will tell you and scope it rather than quietly doing half a job.
Written questionnaire responses are in every plan. It is the live calls and the tender work that sit on Growth and above.
Your trust page
A public page on your domain carrying your certifications, policies, sub-processors and current evidence status, built by us and kept current. Most security questionnaires get answered before anyone sends one.
Your platform stays yours
TrustOps runs on your Drata or Vanta instance and the licence is in your name, not folded into our fee. Already have one? Nothing changes and you pay nothing extra. Don’t have one? We will contract it for you at partner rates from €6,000 a year, invoiced separately from the plan.
We do it this way on purpose. A provider who bundles your platform licence into their monthly fee has made leaving them harder than it needs to be. Your compliance history should not be hostage to your consultancy.
Additional SOC 2 criteria cost nothing extra
Security, Availability, Confidentiality, Processing Integrity and Privacy are scope inside one SOC 2 report, not separate frameworks. Add the criteria your customers ask for and the plan price does not move. Only a genuinely separate framework, ISO 27001 alongside SOC 2 for example, counts towards your framework count.
Your headcount band, and how to hold it
Prices cover companies up to 50 people, with €1,000 a month added at each further 50. On a 12-month term your band is fixed for the year and re-measured at renewal. On a 36-month term it is fixed for the full three years, so you can cross 50, and then 100, without the price moving.
Three years is also the certification cycle: initial certification, two annual visits from the certification body, then recertification. If you are hiring through that window, the longer term is usually the cheaper one.
Unlimited means unlimited from us
Complete includes unlimited frameworks for our scope of work. If your platform licence prices per framework, that part sits between you and the vendor.
The base scope of the pen test included with Complete
One web application of up to 50 pages or routes and one API of up to 100 endpoints, across up to five user roles, in a single environment. Retest included. That band fits most platforms of this size. If your estate is larger, a bigger API footprint, multiple applications or an external infrastructure perimeter, we quote the difference from our published bands before any testing starts.
05 The lead
Who actually runs it
Every plan comes with a named security lead in Ireland or the UK. Same timezone, same working day, in a shared Slack channel with your team. You meet them on the discovery call, before you sign anything, and they stay with you through certification and the years after it.
Behind that person is the rest of the team: penetration testers, technical analysts, and our data protection and AI governance leads. That is the part one person cannot match. A fractional CISO takes holidays, hands in notice, or gets pulled onto something urgent. A team does not.
How the engagement runs
We start within five business days of signature. Through the build phases you get a weekly 30-minute progress review, dropping to fortnightly or monthly once the programme is in steady state. Day to day runs in a shared Slack channel with your team, answered the same business day.
What we need from you
One point of contact with the authority to approve, at around four hours a week, with more in the first fortnight. Engineering time to implement specific technical controls in your own environment. Decisions where only you can make them. Internal capacity is the single biggest variable in how fast this moves, so we would rather be straight with you about it up front than discover it in week six.
A vCISO advises. Your security lead does the work.
06 vCISO cost
How much does a vCISO cost?
A virtual CISO typically costs $3,000 to $20,000 a month, according to vCISO.com and Workstreet. That buys advice. TrustOps starts at €1,500 a month and buys execution: the reviews, evidence and questionnaire responses a vCISO would tell you to do.
07 Certification cost
How much does ISO 27001 certification cost?
Three separate costs get conflated. The certification body’s own fees, billed to you directly with no margin taken by us, covering the certification audit and each annual visit after it. The platform licence, which you hold in your own name, from around €6,000 a year. And the work of building and running the management system, which is the part people underestimate. TrustOps prices the third part flat: from €1,500 a month, everything on this page included.
The part people budget for once is the part that recurs. In years two and three the certification body comes back, and what it looks at is a full year of the programme running, not the push that got you the certificate.
08 Managed compliance
What are managed compliance services?
Managed compliance services run your security compliance programme for you: platform administration, evidence collection and quality checks, access reviews, questionnaire responses, vendor risk and the yearly assurance cycle. It sits between software, which collects evidence but does not review it, and a vCISO, who advises but does not operate. Sometimes called compliance as a service.
09 Comparison
What the same work costs, three ways
| Security hire | vCISO | TrustOps Growth | |
|---|---|---|---|
| Year-one cost | €90,000 to €100,000 base for a Security Manager in Dublin, before 11.25% employer PRSI (Morgan McKinley 2026 Salary Guide) | $36,000 to $240,000/yr (vCISO.com) | €36,000 |
| Who does the work | They do, once you have recruited them | You do; they advise | We do |
| Working from | 3 to 6 months to hire | Weeks | Kickoff within 5 business days of signature |
| Covers holidays and notice periods | No | Partly | Yes, it is a team |
| GDPR programme | Only if that is their background too | Rarely in scope | Full programme, in the fee |
| Your customers’ security review calls | They take the call | Within their retainer hours | We take the call |
| Your internal audit | They cannot audit their own work | Extra | In the fee |
| Platform licence | Extra, in your name | Extra, in your name | Extra, in your name |
| What it brings that the others do not | One accountable person, in the building, who learns your product | Senior strategic judgement on demand | A named lead in your timezone with a team behind them, at a fixed monthly number |
10 Proof
Why the price is possible
Atoro is an AI-native consultancy: the repeatable parts of compliance operations run through tooling we govern ourselves, and the judgement calls stay with named humans. We are Europe’s first ISO 42001 certified consultancy, which means our own AI management system passed the certification body’s inspection.
How the price holds
AI-native operationsThe repeatable work runs through tooling we govern.
Europe’s first ISO 42001 certified consultancyOur own AI management system passed inspection.
Your licence stays yoursNo third-party good marked up inside our fee.
11 FAQ
Pricing questions, answered plainly
Do you really publish your prices?
Yes. These are the prices. Proposals restate them; they do not renegotiate them. If your headcount or framework count changes, the price changes by the amounts on this page.
We already have Drata. Do we pay less?
No, and you do not pay more either. The licence was never inside the fee. You keep your own contract, we administer the instance, and the plan price is the same as it is for everyone else.
Which platforms do you work with?
We administer Drata and Vanta daily and hold partner status with both. The licence is yours: contract it directly, or we will contract it for you from €6,000 a year, invoiced separately from the plan.
Is our security lead full time on us?
No, and that is the point. The function is roughly a quarter of a role, which is exactly why hiring for it does not work: you would be paying a full salary for something three-quarters idle. Your lead carries a small portfolio, your programme is scheduled work rather than best effort, and the team behind them absorbs the peaks.
Do you act as our Data Protection Officer?
Not as part of these plans. We run the privacy programme a DPO would oversee, which for most companies our clients’ size is the thing that was actually missing. If you need a named DPO appointment under Article 37, raise it on the call and we will scope it.
A 12-month term and a 90-day exit? How do those fit together?
The term is twelve months because a compliance programme runs on an annual cycle; anything shorter sells you half a cycle. The exit exists because you should not need a full year to know whether it is working. If in the first 90 days you decide it is not, you leave. No exit fee, no remaining-term liability.
What is not included?
The certification body’s fees, billed to you directly with no margin to us. Your platform licence, which you hold in your own name. Penetration testing on Startup and Growth, and anything beyond the base scope on Complete. A named DPO appointment. Any remediation tooling your environment needs. Everything else on this page is in the monthly fee.
Have you ever failed to get a client certified?
No. We hold a 100% certification success record.
What is ISO 42001 and why would we add it?
The management system standard for AI governance. If you ship AI features, enterprise buyers are starting to ask. Adding it to an existing ISO 27001 programme shares most of the management system, so it costs far less than running it standalone.
We are not certified yet. Can you get us there?
Yes. Certification build programmes are scoped to your roadmap; book a discovery call.
12 Talk to us
Talk to the person who would run it
A discovery call is 30 minutes with Tom, not a sales development rep. Bring your framework list and headcount; leave with a number. It will match this page.

Tom McNamaraFounder and CEO, Atoro
Bring to the call
Your framework list (ISO 27001, SOC 2, ISO 42001, GDPR)
Your headcount
Whether you already run Drata or Vanta
Your next audit or surveillance date, if you have one