shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / Cybersecurity / post · s-cost
CybersecurityRisk AssessmentNIST CSF 2.0Security Leadership

What a Cybersecurity Risk Assessment Includes and Costs

What a cybersecurity risk assessment actually delivers, the evidence it runs on, what separates it from an audit or a penetration test, and what moves the price.

D
By the DSE practice team
Operator-led practice · how we research & review
July 19, 2026
12 min · 2,594 words

By the DSE practice team · published July 19, 2026 · reviewed July 19, 2026

A cybersecurity risk assessment is a point-in-time review of a defined environment that produces four things: an evidence register of what was actually examined, an assessed position against a named framework, severity-ranked findings, and a prioritized remediation roadmap with owners and sequence. Everything else — the interviews, the config exports, the policy reads — is the means. If a proposal does not name those four outputs, it is selling activity rather than a deliverable.

To see what those four outputs actually read like on the page, our synthetic assessment sample excerpt shows the structure with entirely invented data.

We get asked two questions before anyone asks about method: what is in it, and what does it cost. This guide answers both, and is explicit about the boundary between an assessment and the things buyers frequently assume they are also buying.

The four outputs that define the deliverable

A scoping statement. Which entities, systems, tenants, sites, and data types are in scope, and — just as importantly — which are not. Scope is a fence, not a floor. An assessment of one cloud tenant and forty endpoints is a legitimate deliverable; an assessment described as “comprehensive” is not, because no point-in-time review of a live environment is exhaustive.

An evidence register. A line-per-item record of what was requested, what was provided, what was observed, and what could not be verified. The register is the part that survives contact with a diligence questionnaire or a board question six months later, because it distinguishes “this control is in place” from “we were told this control is in place.” Gaps in the register are findings in their own right.

An assessed position against a named framework. Most mid-market work anchors to the NIST Cybersecurity Framework (CSF) 2.0, published February 26, 2024. CSF 2.0 organizes outcomes under six Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER — and asks an organization to express where it is (a Current Profile) and where it intends to be (a Target Profile). The gap between those two profiles is the assessment’s analytical core, and NIST’s own Organizational Profile process treats gap analysis plus a prioritized action plan as steps four and five.

A prioritized roadmap. Findings ranked by severity are useful; findings sequenced by dependency, effort, and owner are actionable. A roadmap that says “implement MFA” without naming who, on which identity surface, ahead of what else, has moved the work rather than reduced it.

What an assessment is not

This is where most disappointment originates, so we put it in the statement of work rather than the footnotes.

Buyers sometimes expect What it actually is Why the difference matters
An audit or certification An advisory review Certification and attestation come from accredited bodies and auditors, not consultancies. We prepare organizations for review; we do not certify them.
A penetration test An evidence and configuration review Testing exploitability is separate scope with its own authorization paperwork. A risk assessment tells you where controls are absent or unowned, not whether a specific path is exploitable today.
Continuous monitoring A point-in-time snapshot Findings reflect the environment as configured during the engagement window and can be invalidated by any change made afterward.
Remediation A roadmap for remediation Implementation is a separately scoped engagement. Assessing and fixing in the same breath removes the independence that makes the finding credible.

The evidence an assessment runs on

The single largest driver of both cost and calendar is how quickly an organization can produce evidence. Assessments do not stall on analysis; they stall waiting for exports. What a competent scoping call asks for:

Organizations that assemble this before kickoff routinely compress the fieldwork window. Organizations that assemble it during kickoff pay for the wait.

What actually drives the price

Assessment pricing is not driven by headcount. It is driven by these, roughly in order of impact:

Driver Increases cost when
Scope breadth Multiple legal entities, multiple cloud tenants, OT or lab environments, or recently acquired subsidiaries with separate identity estates
Evidence readiness No asset inventory, no policy set, no named owner to route requests to
Regulatory overlay An obligation regime attaches specific required elements, so the framework mapping is additive rather than substitutional
Depth of testing Configuration review versus hands-on validation of specific control operation
Audience of the deliverable An internal working document is cheaper than a board- and diligence-ready package with an executive brief
Remediation support Roadmap only, versus roadmap plus scoped oversight of the first remediation cycle

Two of those are worth expanding. Regulatory overlay is the one buyers underestimate: if the organization is a non-banking financial institution under the FTC Safeguards Rule, the rule at 16 CFR 314.4 already prescribes a written risk assessment with specific evaluation criteria, encryption of customer information in transit and at rest, multi-factor authentication, a written incident response plan, service-provider oversight, and an at-least-annual written report from a designated Qualified Individual to the board. That is not extra work invented by the assessor; it is a compliance surface that has to be evidenced. The same logic applies to organizations handling protected health information under the HIPAA Security Rule at 45 CFR Part 164 Subpart C, where HHS publishes a free Security Risk Assessment Tool that is a reasonable starting structure for smaller covered entities.

Audience is the one buyers underestimate in the other direction. A findings spreadsheet and a document an insurer, an acquirer, or an audit committee will read are different artifacts with different review cycles.

Published price anchors, and where they stop

We publish what we can stand behind. Our entry Security Posture Assessment starts from $1,500 for a standardized small-business scope, and the Atlanta-local Security Readiness Check is a one-to-two-day engagement in a published $1,250–$1,500 band. The deeper national cybersecurity risk assessment is quoted after a scoping conversation rather than listed, because the drivers above vary too widely for a list price to be honest. The engagement models and market-estimate ranges page carries the current published bands; ranges there are estimates, not quotes, and a final fee is fixed in writing after scoping.

If you are comparing proposals, the useful normalization question is not “what does it cost” but “what are the four outputs, over what scope, at what evidence depth, for which audience.” Two proposals that differ threefold on price usually differ on those axes, not on quality.

Sequencing: what to do with the result

A finished assessment that nobody sequences becomes a shelf document. The pattern that works:

  1. Close the register gaps first. Anything marked “could not be verified” is either a fast fix or a real control gap. Resolving those is cheap and sharpens the roadmap.
  2. Fix the identity surface before the tooling wishlist. Identity is where the highest-severity findings concentrate in mid-market environments, which is why we broke it out in the Microsoft 365 security assessment checklist.
  3. Prove recovery before buying detection. An organization that cannot evidence a restore is buying alerting it cannot act on. See how to prove your backups will actually restore.
  4. Set a re-assessment trigger, not just a date. Material acquisitions, a new production system holding regulated data, or a significant incident should each re-open the profile ahead of the calendar.

For organizations building the roadmap into a multi-quarter program rather than a punch list, the NIST CSF 2.0 roadmap for a 50 to 500 employee organization covers the sequencing across all six Functions.

FAQ

What is included in a cybersecurity risk assessment?

A defensible assessment includes a written scoping statement naming what is and is not in scope, an evidence register recording what was requested, provided, observed, and left unverified, an assessed position against a named framework such as NIST CSF 2.0 expressed as a Current Profile and a Target Profile, severity-ranked findings, and a prioritized remediation roadmap with owners and sequence. Interviews, configuration exports, and policy review are the inputs that produce those outputs.

How much does a cybersecurity risk assessment cost?

Price is driven by scope breadth, evidence readiness, whether a regulatory regime adds required elements, the depth of control validation, the audience for the deliverable, and whether remediation oversight is included — not by headcount. DSE publishes an entry Security Posture Assessment from $1,500 for a standardized small-business scope and a $1,250–$1,500 Atlanta Security Readiness Check; deeper national scopes are quoted after scoping because the drivers vary too widely for a list price to be accurate.

Is a cybersecurity risk assessment the same as a penetration test?

No. A risk assessment reviews evidence, configuration, and governance to identify where controls are missing, misconfigured, or unowned. A penetration test attempts to demonstrate exploitability against a defined target under separate authorization. They answer different questions and are scoped, priced, and contracted separately.

Does a risk assessment make us compliant or certified?

No. An assessment is advisory work that prepares an organization for review and produces evidence a reviewer will recognize. Certification and attestation are issued by accredited certification bodies and auditors, not by consultancies, and compliance remains the organization’s own legal status.

How often should we reassess?

Most mid-market programs run an annual cycle, with an event-driven trigger in between: a material acquisition, a new production system holding regulated data, a significant change to the identity or network architecture, or a security incident. Regulated entities should align the cadence to whatever their applicable rule requires — the FTC Safeguards Rule, for example, requires periodic reassessment and an at-least-annual written report to the board or a senior officer.

What this guide is / What it is not

What it is: A practitioner explanation of assessment scope, evidence, and cost drivers, anchored to NIST CSF 2.0 (NIST CSWP 29, February 26, 2024), the FTC Safeguards Rule at 16 CFR Part 314, and the HIPAA Security Rule at 45 CFR Part 164 Subpart C. What it is not: Legal advice, an audit, a certification, an attestation, or a guarantee of any compliance, insurance, or examination outcome. An assessment is a point-in-time review of the scoped environment as configured during the engagement window; findings can be invalidated by later changes. DSE prepares organizations for review and does not certify them. Consult qualified counsel on the legal questions a regulatory overlay raises.

The Bottom Line

Buy the four outputs, not the activity. A cybersecurity risk assessment earns its fee when the evidence register is honest about what could not be verified, the profile gap is expressed in a framework a third party already recognizes, and the roadmap sequences work by dependency rather than by severity alone. Price follows scope, evidence readiness, and audience — and the fastest way to reduce it is to have the inventory, policy set, and named owner ready before the first working session.

Sequenced next steps: assess against a scope you can defend, close the register gaps, then take the roadmap into a governance cadence that keeps it current rather than annual.

Next step · scope it honestly

Thirty minutes to find out what your scope should be.

Bring your environment as it actually is. We will tell you what a defensible scope looks like, what evidence to assemble first, and whether an assessment is even the right next spend.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly — or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter