Self-serve when you want. Expert help when you need it.
Productized, fixed-fee engagements — scoped and priced up front, delivered on top of the same Standpoint platform you'd use yourself. A readiness consultant typically runs $5,000–$25,000; a full ISO 42001 implementation, $20,000–$80,000. These start well below that, and you keep the tooling when we're done.
Audit-Ready in 60 Days
Most companies don't need a consultant for two months. They need someone to tell them exactly what to collect, check whether what they collected is good enough, and hand them something an auditor will accept. That's this.
"Why $2,500 when the software is $149 a month?" Because the software tells you where you stand. This tells you what to do about it, checks your work, and gives you something to hand an auditor. Twelve months of Core is included, so you're paying about $1,000 for the human part — against $5,000–$25,000 for a readiness consultant who leaves with the tooling.
Need more than a program? Fixed-fee engagements, scoped to your situation.
AI Governance Readiness Sprint
Your enterprise buyer sent an AI security questionnaire and nobody on your team knows how to answer it. We inventory your AI systems, map them to NIST AI RMF and ISO 42001, work out which EU AI Act obligations actually apply to you — Article 50 transparency lands 2 August 2026; the high-risk rules moved to December 2027 — and hand you a prioritized plan plus the evidence templates to close it.
Answers the questionnaire you have now. Prepares you for the obligations that arrive later.
SOC 2 / ISO 27001 Readiness
A guided path to your first audit — controls mapped, policies drafted, and evidence organized and indexed, so you're not assembling it during fieldwork.
Evidence Pack
We sit alongside your team and produce an audit-ready evidence pack for the framework you're chasing — you keep the templates and the muscle memory.
Executive Advisory
For teams carrying security and AI governance with no dedicated lead and no consultant already in place — quarterly reviews, a live roadmap, and support on call when a buyer or an auditor asks something you can't answer.
Already working with a vCISO or a consultant? Then you don't need this page. We'd rather equip the person who already knows your business than replace them — they can run Standpoint across their whole client book, white-labelled. See the partner program →
Who this isn't for
You already have a security lead or a consultant. Send them to the partner program instead.
You need a certificate this month. Readiness takes weeks and the audit itself takes longer. If someone has promised you faster, ask them who signs it.
You want someone to make the problem disappear. These are done-with-you engagements. You'll be in the working sessions, and your team will own the evidence afterward — that's the point.
Scoped and priced before we start
Free scoping call
A short call to understand the deal you're trying to unblock, your frameworks, and your timeline. You leave with a recommendation either way — including "you don't need us yet," if that's the answer.
Fixed-fee proposal
One page: scope, deliverables, timeline, and a fixed price. No hourly surprises, no open-ended retainer unless you ask for one.
Delivered in the platform
Everything lands in your Standpoint workspace. When the engagement ends you own the evidence, the plan, and the tooling — there's nothing to hand back.
What we are, precisely. Standpoint does readiness only. We are not a responsible party. Our platform is not a system of internal control — it is a data aggregator. We do not audit, certify or attest, and we never will.
These engagements prepare you for an audit; they are not an audit. The attestation or the certificate comes from a licensed CPA firm or an accredited certification body, engaged separately and independently of us. We'll introduce you to several, and we take no referral fee from any of them — in either direction.
Tell us where you're stuck
Scoped and priced up front — we usually reply within one business day.