TL;DR (for those of us short on time)
If you are in a hurry, this is what I cover:
- The question is badly framed, and that is why nobody answers it. A «cybersecurity audit» is at least six different services with prices ranging from €800 to more than €25,000.
- For a typical Spanish SME (10–50 employees), what you almost always need costs between €1,500 and €7,000: a situation assessment, not a pentest.
- The price comes out of a simple formula: person-days × daily rate. If a quote does not tell you how many days it involves, it is not telling you the price.
- The audit is 20 % of the spend. The other 80 % is fixing whatever it finds. Budgeting only for the audit is the most expensive and most common mistake.
- There are recognisable red flags: a closed price with no questions asked, «free audits», a 200-page report with no prioritisation, no results meeting.
- There is a calculator to check whether the quote you were given matches the days it claims to include.
- On public grants: Spain's Kit Consulting closed applications on 31 March 2025 and there is no new call. On the rest, I'll spare you my opinion.
- At the end you get the eight questions to ask any provider before you sign, what you can do today for zero euros and a FAQ on prices, timings and obligations.
If you have a quarter of an hour, let's take it slowly. 👇
Before we start: where these figures come from
Let me be transparent about the method, because this is a mess of a topic.
The ranges you will see are built by crossing three sources: prices published by Spanish consultancies during 2025 and 2026, market rates for technical consulting profiles in Spain, and my own experience scoping and delivering this kind of work.
None of those three sources is neutral, and the first one least of all. Almost all published content about cybersecurity pricing is written by someone who wants to sell you the service they are describing, and that biases figures systematically upwards (if you sell large projects) or downwards (if your model is to win the client and then extend the scope). I have taken that into account when building the brackets, and that is why they are brackets and not exact figures.
They are what they are: an order of magnitude so nobody takes you for a ride, not a quote. If a serious provider gives you a number outside these ranges, it does not mean they are ripping you off: it means something in your case justifies the difference, and you should ask them to explain it.
The underlying problem: there is no such thing as «the cybersecurity audit»
There is a conversation that keeps repeating itself.
A company asks for three quotes for «a cybersecurity audit». Three numbers come back: €1,200, €4,800 and €19,000. And they sit there staring at them, understanding nothing, with the uncomfortable feeling that somebody is taking advantage of them and no idea which of the three smells wrong.
All three are fine (usually). They are quoting three different things.
Comparing those three quotes is like asking for a quote for «a renovation» and getting one for painting the living room, another for rewiring the electrics and a third for knocking down walls.
«Cybersecurity audit» is a commercial label that has been stretched to cover services with nothing in common: not in method, not in duration, not in professional profile and, of course, not in price.
So the first useful question is not how much does it cost. It is which of these six things do I need.
The six things sold as an «audit»
Here they are at a glance, with their indicative range. Click any of them to jump to the detail:
A tool sweeps your systems and returns a list of known flaws. Useful, cheap and very incomplete.
€800 – €2,500Someone with offensive skills tries to break something specific. The most expensive per day and the one most often bought without needing it.
€2,000 – €15,000How what you already own is set up: tenant, directory, firewall, backups, remote access. Less glamorous, more profitable.
€1,500 – €5,000The full picture against a reference framework, plus a prioritised plan. The default starting point for an SME.
€1,500 – €8,000An accredited body verifies that you meet a standard and issues (or withholds) the certificate. It does not advise you: it verifies.
€3,000 – €25,000You do not buy it, it is imposed on you. The main cost is your internal time, which nobody ever budgets for.
However long your own people take to answer questionnaires01 · Vulnerability scan
An automated tool (Nessus, OpenVAS, Qualys and so on) sweeps your exposed systems and returns a list of known flaws: unpatched versions, open services, expired certificates, weak configurations.
It is useful, it is cheap and it makes a good periodic check-up. It is not an audit. It is the equivalent of a blood test: it gives you indicators, not a diagnosis. The tool does not know what is critical to your business, does not understand your application logic and produces false positives that somebody has to weed out by hand.
The real value is in the interpretation afterwards. If they sell you the PDF the tool spits out as the final product, they are selling you the blood test without the doctor.
Indicative range: €800 – €2,500. One-off. As a recurring quarterly service it usually works out better on a subscription, or even by licensing the tool itself as SaaS from the vendor.
02 · Penetration test (pentesting)
Here a person with offensive knowledge tries to break something specific: your website, your application, your internal network, your Active Directory. They combine tooling with manual technique and look for what no scanner finds: chains of minor flaws that together allow entry, business logic errors, badly assigned permissions.
It is the most expensive service per day and the one that requires the most skill. It is also the one most frequently bought by people who do not need it.
A penetration test answers the question «can someone get in through here?». That is a great question once you have the basics covered. If you do not have MFA enabled, or verified backups, or any idea what assets you own, the pentest will confirm in exquisite technical detail something you already knew: that yes, someone can get in. You will have paid €5,000 for a certainty.
| Type of pentest | Indicative range (Spain, 2026) |
|---|---|
| Simple website, small scope | €2,000 – €6,000 |
| Standard web application (OWASP Top 10 + business logic) | from €3,500 |
| Internal/external infrastructure, Active Directory | from €4,000 |
| Mobile application (static + dynamic + APIs) | from €5,000 |
| Complex environments, several assets | from €15,000 |
Personal opinion: costs are coming down and will keep declining because of all the automation and AI-driven exercises.
03 · Technical configuration review
Less glamorous and, in an SME, almost always more profitable. It consists of reviewing how what you already own is configured: the Microsoft 365 or Google Workspace tenant, the active directory, the firewall, the backups, remote access, permissions on shared folders.
It is not looking for exotic vulnerabilities. It looks for the configuration decisions that leave you exposed, which are the ones the attacks Spanish SMEs actually suffer take advantage of. Phishing and fraud —not the sophisticated APT— are still the dominant vector, and a pentest does not protect you against that: a decent configuration and properly deployed MFA do.
Indicative range: €1,500 – €5,000, depending on the number of environments.
04 · Situation assessment (gap analysis)
This is the full picture: where you stand against a reference framework (ISO 27001, Spain's ENS, TISAX, NIS2, the INCIBE master plan) and what you are missing to get where you want to be.
It combines interviews, document review, asset inventory and a maturity rating by domain. Its deliverable is not a list of technical flaws: it is a prioritised plan with estimated effort and cost.
For the vast majority of SMEs that «want to do something about cybersecurity» and do not know where to start, this is the right service. It is the one that turns diffuse anxiety into a budget you can defend in front of a board or an owner.
Indicative range: €1,500 – €4,000 for an initial assessment; €3,000 – €8,000 if it includes a detailed master plan and support with prioritisation.
Here cost, value and quality come down to the number of auditors and their experience multiplied by the time spent auditing. The more we can stop and look, the more expensive it gets — but above all, the better the quality.
This is, by some distance, the work I have done most
Of everything I have touched in GRC over these years, the situation assessment —the gap analysis— is probably what I have delivered most often: interviews, document review, inventory, maturity rating and the prioritised plan at the end.
It is also what helps a company most. It is the only one of the six services that turns «I don't know where to start» into a list of concrete actions, ordered by what can actually hurt you and with a cost next to each one.
Tell me where you stand →05 · Certification audit
This is the only one that technically deserves the name «audit» in the strict sense: an accredited body verifies that you comply with a standard and issues (or withholds) a certificate. It does not advise you, it does not help you, it does not propose improvements. It verifies.
Whoever helps you prepare cannot be the one who certifies you. Those are separate invoices from separate companies, and many «certification» quotes only include one of them. It is the most common budgeting mistake in this whole block.
And there is a third one almost nobody counts: before the external audit you need an internal review, and it cannot be run by whoever implemented the system. Nobody audits their own work, so that is another provider and another invoice. Three, not two.
Each framework asks for it in its own way: clause 9.2 of ISO 27001 requires internal audits by impartial auditors —if the certification auditor sees your own implementer ran it, it gets thrown out—; TISAX starts from the VDA ISA self-assessment before the assessment itself; and article 31 of Spain's Royal Decree 311/2022 requires an ordinary audit at least every two years, with the basic category accredited through self-assessment. Under ENS, moreover, the annual internal audit is no longer mandatory since the latest update to the CCN guides.
- 01ISMS implementationThe preparation consulting. This is the long part: months of work.
- €6,000 – €15,000
- 02Prior internal auditRequired by clause 9.2, and by a provider other than the implementer. One to three days.
- €800 – €2,500
- 03Certification auditThe accredited body that verifies and issues the certificate.
- €3,000 – €5,500
This is the sum of the three lines above, not a catalogue figure: published totals usually stop at €10,000 – €20,000 because they do not count the internal audit. With a broad scope it goes to €35,000. Annual surveillance audits run at 30 % – 40 % of the initial one.
- BBasic categoryAccredited through self-assessment, at least every two years.
- No external audit
- MMedium category, small organisationThe audit alone, mandatory at least every two years.
- €3,000 – €8,000
- FFull process in an SMEAdaptation and audit, depending on scope.
- €8,000 – €25,000
If somebody quotes you a certification audit for a basic category system, ask them why.
- SCompany with 10 to 50 employees
- €3,000 – €8,000
- MCompany with 50 to 250 employees
- €8,000 – €25,000
NIS2 is not certifiable: there is no badge to hang, what you pay for is the adaptation. And with ISO 27001 already in place the cost can be halved, because a good part of the work is done.
Look at the orders of magnitude in the first card, because this is what surprises people most: the certification audit is the small invoice. The expensive part is building the system, and the certification body is not the one who does that.
And be careful with the totals doing the rounds out there: almost all of them add up implementation and certification and leave the internal audit out. Add it yourself from the start, because it is not optional and the team building your system cannot be the one to run it.
06 · The audit your customer demands
You do not buy this one, it is imposed on you. A large customer sends you a sixty-question security questionnaire, or requires you to evidence controls, or simply sends a third party to review you.
This is growing very fast because of the cascade effect of NIS2 and DORA: the entities in scope pass requirements down their supply chain, and that is where thousands of SMEs land — technically outside the directive's scope, but firmly inside their customers'.
The cost here is mainly your internal time, which nobody budgets for and which is very real. If you need help answering, count on €1,000 to €3,000 per questionnaire the first time. The second time is much cheaper, because the material already exists.
The ranges, at a glance
The same figures as above, plotted on a single axis. It is the fastest way to see that an assessment and a certification are not playing in the same league:
And the same picture, with the question that really matters: when each one makes sense.
| Service | When does it make sense? |
|---|---|
| Vulnerability scan | Periodic check-up, complement to something else |
| Technical configuration review | Almost always: it is the first technical step |
| Assessment / gap analysis | The default starting point |
| Full master plan | When you need to justify a multi-year investment |
| Web / infrastructure pentest | Once the basics are already covered |
| NIS2 adaptation | If you are in scope or a customer requires it |
| ISO 27001, first year | If the market or a customer requires it |
| ENS medium, full process | If you sell to the Spanish public sector |
If I had to bet on a single figure for a Spanish SME of 10 to 50 employees that wants to start putting its security in order: between €2,000 and €5,000, for an assessment with a technical review and a prioritised plan. It is the work that returns the most per euro invested, and curiously it is almost never what gets quoted when somebody asks for «an audit».
Where the price comes from: the formula nobody teaches you
Behind any professional services quote lies the same elementary arithmetic:
Price = person-days × daily rate + management margin
The daily rate for a technical security consulting profile in Spain moves, broadly speaking, between €400 and €900 per day depending on seniority and the provider's structure. A freelancer with solid experience sits in the low-to-mid range; a consultancy with structure, offices and a sales team needs to be at the top end to sustain its costs. Neither option is a trick: you are paying for different things.
Penetration testing plays in a different rate league: in Spain the usual figure is €700 to €1,500 per day, because the profile is scarcer. That is why the slider below goes up to €1,500 and not to €900.
Person-days are the variable that really drives the price, and the one that almost never appears in the quote. An assessment for a small SME is 4 to 8 days. A serious web pentest, 5 to 10. An ISMS implementation, 20 to 40 spread over months.
Check your quote with this calculator
Do the multiplication yourself. Move the two sliders, or pick the type of work you have been quoted, and compare the result with the number on your desk:
Pick a type of work or move the sliders by hand. This is not a quote: it is the arithmetic behind any quote, so you can check whether the one on your desk adds up.
This is the usual bracket for a situation assessment in a small SME.
- Below €1,500 you are buying two or three days. That can be perfectly honest for a narrow, one-off review, but it cannot be comprehensive.
- This is the usual bracket for a situation assessment in a small SME, or for a technical configuration review.
- This range covers a full master plan, a serious web pentest or a NIS2 adaptation for a company under 50 employees.
- We are in large project territory: an ISMS implementation, ENS medium category or several assets in scope. Ask for the breakdown by phase.
- More than €15,000 in an SME is only justified by a broad, multi-year scope. The right question is not «why so expensive?», but «how many days is that, and where do they go?».
Rates exclude VAT. The management margin, coordination and report writing are usually already inside the billed day; if they are charged separately, they should appear in the quote.
If a €3,500 quote implies 5 days, the maths works. If somebody offers you «a complete audit of your company» for €900, you are buying one to two days of work. That can be perfectly honest —there are narrow reviews that fit in a day— but it cannot be complete. And if you are quoted €18,000 for a twenty-person company, the right question is not «why so expensive?» but «how many days is that, and where do they go?».
That is, for me, the most useful question in this whole article. A provider who cannot or will not break down the days either has not scoped the work, or does not want you to compare.
What pushes a quote up?
What adds days
Number of environments and sites. Every tenant, every domain, every branch multiplies the fieldwork.
Custom-built applications. A standard ERP is reviewed with a checklist; an in-house application has to be understood before it can be audited.
Industrial/OT/ICS environments. Another world, another profile, another rate.
Starting from zero. With no asset inventory, no policies and nobody who knows how the thing is put together, the first days go entirely on understanding the terrain.
Tight deadlines. «I need it by the 30th» has a price.
What removes days
Having the inventory ready. If you turn up with the list of systems, users, suppliers and access, you save days of discovery. You can prepare this yourself, for free.
A single, available point of contact. The biggest hidden cost in these projects is waiting for answers. Availability is not only the consultants' problem: not being able to move forward and having them idle means the consultancy loses money.
A bounded, phased scope. Starting with what is critical and extending later almost always beats a huge scope badly delivered.
Already having a framework in place. ISO 27001 makes NIS2 cheaper, and TISAX much cheaper. NIS2 makes ENS cheaper, and ENS is probably the most expensive in Spain along with DORA. The work compounds.
Repeating provider. The second review with the same team should cost considerably less than the first. If it does not come down, ask why.
Seven red flags in a quote
After seeing a fair number of quotes in this sector, these are the patterns that make me suspicious:
A closed price without a single meeting
If you have not even seen the face of whoever is quoting you, be suspicious. Nobody can scope work they have not looked at.
«Free audit» or one sold at a loss
Nobody likes losing money. It is a sales action, and its outcome will be, with very high probability, that you need exactly what that company sells. It can be useful as a first contact, but do not mistake it for an independent assessment.
The deliverable is a tool's output
An automatically generated 200-page PDF, with CVEs sorted by severity and not one line written by a human about your business, is not an audit.
There is no prioritisation
A hundred «critical» findings equal zero critical findings. A good report tells you what to do on Monday, what this quarter and what can wait until next year. If everything is urgent, nobody will do anything.
There is no executive report
If the result can only be understood by a technical profile, it will never reach the person who signs off the next budget.
There is no results presentation meeting
Emailing the report and disappearing is simply sad. (Anecdote: it was done to me while I was the consultant. They wanted an audit for a cyber insurance policy, but they did not really want to be cyber-secure.)
Nobody names who does the work
Asking about the profile and certifications of the person who will actually deliver —not of the sales director— is entirely legitimate. Being sold a senior and delivered an intern is a classic.
The cost that is not in the quote
This is the part almost nobody writes about, and it is the most important.
The audit is the diagnosis. The real spend is in remediating the findings.
A €3,000 assessment in an SME that has never worked on its security will return, at a conservative estimate, between twenty and forty actions. Some are free and take an afternoon: enabling MFA, reviewing who holds administrator permissions, switching off legacy protocols, removing accounts belonging to people who no longer work there. Others cost real money: licences, replacing the firewall, a decent backup solution, training, a monitoring service.
Public grants for cybersecurity
I'll spare you my opinion. Draw whatever conclusions you find convenient.
Kit Consulting stopped accepting applications on 31 March 2025, and the deadline to formalise agreements with digital advisors closed on 31 May 2026. As of today there is no new call published. If somebody still offers it to you as a funding route, check the Red.es page before counting on it.
The eight questions to ask before you sign
Copy this and send it as it is to the three providers you are considering. The answers will tell you more than the prices.
- What type of service is this exactly: a scan, a configuration review, a pentest, a compliance assessment or a certification audit?
- How many person-days does it include and how are they distributed?
- Which profile delivers the work, and what experience and certifications do they have? The people named in the quote should be the people doing the work.
- What is in scope and, above all, what is explicitly out of scope?
- What deliverables do I get? Is there an executive report as well as the technical one?
- Are findings prioritised by real business risk or only by technical severity?
- Does it include a results presentation meeting with management?
- Is there a follow-up review to verify what has been fixed, and what does it cost?
If a provider answers all eight with specifics, their price is probably fair even if it is the highest of the three.
What you can do today, for zero euros
Before spending anything, there is work only you can do and it will save you money later:
A spreadsheet with your systems, applications, users, suppliers with access and sensitive data. It is the first thing anyone will ask you for, and the one that eats the most days if it does not exist.
Start with email. It is the single measure with the best protection-to-cost ratio in existence and it is still switched off across a huge share of Spanish businesses.
And remove everyone who does not need it today. Admin permissions get handed out in two minutes and stay in place for years.
Former employee accounts, old supplier access, ghost licences. It is usually the most uncomfortable list to review and the most profitable.
If you do these four things and then buy an assessment, the conversation starts from a much more advanced point and the quote goes down. If you cannot buy anything at all, at least you will have closed the doors people actually come through.
In summary
Stop asking how much a cybersecurity audit costs. Ask what you need to verify and why, and the price will appear on its own.
For a Spanish SME starting out, the answer is almost always an assessment costing €2,000 to €5,000 that produces a prioritised plan. Not a pentest. Not a certification. A plan you can defend in front of whoever signs and deliver within twelve months.
And set aside budget to fix what you find, because a report with no money behind it is an expensive document about problems you are going to keep having.
Frequently asked questions
How much does a cybersecurity audit cost for an SME in Spain?
It depends on what you call an audit. A vulnerability scan runs from €800 to €2,500; a technical configuration review, €1,500 to €5,000; an assessment or gap analysis, €1,500 to €4,000, and up to €8,000 with a master plan. For a 10-to-50-employee SME starting out, the sensible bracket for what it actually needs sits between €1,500 and €7,000.
What is the difference between a vulnerability scan, a pentest and an audit?
The scan is run by a tool and returns known flaws: it is an indicator, not a diagnosis. The pentest is a person trying to break in, answering «can it be done?». An audit in the strict sense is an accredited body verifying that you meet a standard. Three different services, three different prices, all sold under the same label.
How much does ISO 27001 certification cost for an SME?
Three invoices: ISMS implementation (€6,000 – €15,000), prior internal audit (€800 – €2,500) and certification audit (€3,000 – €5,500). The full first year comes to €10,000 – €23,000, and can reach €35,000 with a broad scope. Annual surveillance audits run at 30 % – 40 % of the initial one.
Can the same company implement the system and audit it?
No. Clause 9.2 of ISO 27001 requires the internal audit to be run by impartial auditors, and whoever implements cannot review their own work. Nor can the company that prepared you certify you: that is done by an independent accredited body. In practice that means three providers, or at the very least three clearly separated roles.
Is an internal audit still mandatory before the external one?
Under Spain's ENS, no longer. In June 2026 the National Cryptologic Centre updated a package of its 800-series guides —among them CCN-STIC 808, on compliance verification— and dropped the mandatory annual internal audit: its frequency is now flexible under the proportionality principle. Nothing has changed for ISO 27001: clause 9.2 still requires them, and without them the certification body will not certify you.
That said, at ACBSEC I still recommend running it even when the standard no longer forces you to. It is the only way to learn about the findings before the certification auditor tells you, it costs considerably less than a non-conformity, and it leaves you room to fix things calmly instead of in a rush. Losing the obligation does not make it dispensable: it makes it your call.
Is an external audit mandatory for Spain's ENS?
For basic category, no: it is accredited through self-assessment, repeated at least every two years. For medium and high category you do need a certification audit by an accredited body, also at least every two years, at around €3,000 – €8,000 in a small organisation. The full adaptation plus audit runs between €8,000 and €25,000.
How much does NIS2 adaptation cost?
Between €3,000 and €8,000 for companies with 10 to 50 employees, and €8,000 to €25,000 for 50 to 250. NIS2 is not certifiable —there is no badge— so what you pay for is the adaptation, not an exam. If you already have ISO 27001 in place, the cost can be halved because much of the work is done.
How long does a cybersecurity audit take?
An SME assessment is 4 to 8 person-days, which in calendar terms usually means two to four weeks including interviews and review. A serious web pentest, 5 to 10 days. An ISMS implementation, 20 to 40 spread over months. If a quote does not say how many days it includes, it is not telling you the price.
What should an audit report include?
A technical report and an executive report, findings prioritised by real business risk rather than technical severity alone, one concrete recommendation per finding with estimated effort, and a results presentation meeting with management. If it also includes a follow-up review to verify what has been fixed, better still: ask what that costs.
Are there public grants to pay for a cybersecurity audit in Spain?
Kit Consulting closed applications on 31 March 2025 and there is no new call published. Regional programmes come and go. My opinion on them is a few paragraphs above, and it is short.
How often should an audit be repeated?
A vulnerability scan makes sense quarterly or continuously. An assessment, once a year or whenever something significant changes. ISO 27001 certification requires annual surveillance and renewal every three years; ENS, an audit at least every two. And always after a substantial change to the systems.
Got a quote on your desk and no idea whether it is reasonable? Write to me and we will look at it together, no strings attached.
SME audit pricingCibersafety · Hard2Bit · Iberia Intel · SYRA360 (ES)
Penetration testingVulnerabbit · Secra · Hard2Bit · CISEC (ES)
ISO 27001Novaciber · Delbion · Step Quality · Clause 9.2, internal audit
ENSRoyal Decree 311/2022, consolidated text · Update to guides CCN-STIC 802, 808, 809 and 825 (June 2026) · Audidat · Ángel Ortega Castro · NexENS (ES)
NIS2Adaptation cost · Prices by company size · Delbion (ES)
TISAXVDA ISA questionnaire and official ENX documentation
Public grantsRed.es, Kit Consulting application deadline · Programme page · Status and next call (ES)
These ranges were last reviewed in August 2026. They are market orders of magnitude, not a rate card, and almost every pricing source is a company selling the service it describes: always check against at least three real quotes before deciding.