Cybersecurity SMEs Budget Compliance

How much does a cybersecurity audit cost for an SME?

Quick summary

TL;DR (for those of us short on time)

If you are in a hurry, this is what I cover:

  • The question is badly framed, and that is why nobody answers it. A «cybersecurity audit» is at least six different services with prices ranging from €800 to more than €25,000.
  • For a typical Spanish SME (10–50 employees), what you almost always need costs between €1,500 and €7,000: a situation assessment, not a pentest.
  • The price comes out of a simple formula: person-days × daily rate. If a quote does not tell you how many days it involves, it is not telling you the price.
  • The audit is 20 % of the spend. The other 80 % is fixing whatever it finds. Budgeting only for the audit is the most expensive and most common mistake.
  • There are recognisable red flags: a closed price with no questions asked, «free audits», a 200-page report with no prioritisation, no results meeting.
  • There is a calculator to check whether the quote you were given matches the days it claims to include.
  • On public grants: Spain's Kit Consulting closed applications on 31 March 2025 and there is no new call. On the rest, I'll spare you my opinion.
  • At the end you get the eight questions to ask any provider before you sign, what you can do today for zero euros and a FAQ on prices, timings and obligations.

If you have a quarter of an hour, let's take it slowly. 👇

Before we start: where these figures come from

Let me be transparent about the method, because this is a mess of a topic.

The ranges you will see are built by crossing three sources: prices published by Spanish consultancies during 2025 and 2026, market rates for technical consulting profiles in Spain, and my own experience scoping and delivering this kind of work.

The bias, out in the open

None of those three sources is neutral, and the first one least of all. Almost all published content about cybersecurity pricing is written by someone who wants to sell you the service they are describing, and that biases figures systematically upwards (if you sell large projects) or downwards (if your model is to win the client and then extend the scope). I have taken that into account when building the brackets, and that is why they are brackets and not exact figures.

They are what they are: an order of magnitude so nobody takes you for a ride, not a quote. If a serious provider gives you a number outside these ranges, it does not mean they are ripping you off: it means something in your case justifies the difference, and you should ask them to explain it.

The underlying problem: there is no such thing as «the cybersecurity audit»

There is a conversation that keeps repeating itself.

A company asks for three quotes for «a cybersecurity audit». Three numbers come back: €1,200, €4,800 and €19,000. And they sit there staring at them, understanding nothing, with the uncomfortable feeling that somebody is taking advantage of them and no idea which of the three smells wrong.

All three are fine (usually). They are quoting three different things.

Keynote

Comparing those three quotes is like asking for a quote for «a renovation» and getting one for painting the living room, another for rewiring the electrics and a third for knocking down walls.

«Cybersecurity audit» is a commercial label that has been stretched to cover services with nothing in common: not in method, not in duration, not in professional profile and, of course, not in price.

So the first useful question is not how much does it cost. It is which of these six things do I need.

The six things sold as an «audit»

Here they are at a glance, with their indicative range. Click any of them to jump to the detail:

01 · Vulnerability scan

An automated tool (Nessus, OpenVAS, Qualys and so on) sweeps your exposed systems and returns a list of known flaws: unpatched versions, open services, expired certificates, weak configurations.

It is useful, it is cheap and it makes a good periodic check-up. It is not an audit. It is the equivalent of a blood test: it gives you indicators, not a diagnosis. The tool does not know what is critical to your business, does not understand your application logic and produces false positives that somebody has to weed out by hand.

The real value is in the interpretation afterwards. If they sell you the PDF the tool spits out as the final product, they are selling you the blood test without the doctor.

Indicative range: €800 – €2,500. One-off. As a recurring quarterly service it usually works out better on a subscription, or even by licensing the tool itself as SaaS from the vendor.

02 · Penetration test (pentesting)

Here a person with offensive knowledge tries to break something specific: your website, your application, your internal network, your Active Directory. They combine tooling with manual technique and look for what no scanner finds: chains of minor flaws that together allow entry, business logic errors, badly assigned permissions.

It is the most expensive service per day and the one that requires the most skill. It is also the one most frequently bought by people who do not need it.

A penetration test answers the question «can someone get in through here?». That is a great question once you have the basics covered. If you do not have MFA enabled, or verified backups, or any idea what assets you own, the pentest will confirm in exquisite technical detail something you already knew: that yes, someone can get in. You will have paid €5,000 for a certainty.

Type of pentestIndicative range (Spain, 2026)
Simple website, small scope€2,000 – €6,000
Standard web application (OWASP Top 10 + business logic)from €3,500
Internal/external infrastructure, Active Directoryfrom €4,000
Mobile application (static + dynamic + APIs)from €5,000
Complex environments, several assetsfrom €15,000

Personal opinion: costs are coming down and will keep declining because of all the automation and AI-driven exercises.

03 · Technical configuration review

Less glamorous and, in an SME, almost always more profitable. It consists of reviewing how what you already own is configured: the Microsoft 365 or Google Workspace tenant, the active directory, the firewall, the backups, remote access, permissions on shared folders.

It is not looking for exotic vulnerabilities. It looks for the configuration decisions that leave you exposed, which are the ones the attacks Spanish SMEs actually suffer take advantage of. Phishing and fraud —not the sophisticated APT— are still the dominant vector, and a pentest does not protect you against that: a decent configuration and properly deployed MFA do.

Indicative range: €1,500 – €5,000, depending on the number of environments.

04 · Situation assessment (gap analysis)

This is the full picture: where you stand against a reference framework (ISO 27001, Spain's ENS, TISAX, NIS2, the INCIBE master plan) and what you are missing to get where you want to be.

It combines interviews, document review, asset inventory and a maturity rating by domain. Its deliverable is not a list of technical flaws: it is a prioritised plan with estimated effort and cost.

For the vast majority of SMEs that «want to do something about cybersecurity» and do not know where to start, this is the right service. It is the one that turns diffuse anxiety into a budget you can defend in front of a board or an owner.

Indicative range: €1,500 – €4,000 for an initial assessment; €3,000 – €8,000 if it includes a detailed master plan and support with prioritisation.

Here cost, value and quality come down to the number of auditors and their experience multiplied by the time spent auditing. The more we can stop and look, the more expensive it gets — but above all, the better the quality.

Speaking from experience

This is, by some distance, the work I have done most

Of everything I have touched in GRC over these years, the situation assessment —the gap analysis— is probably what I have delivered most often: interviews, document review, inventory, maturity rating and the prioritised plan at the end.

It is also what helps a company most. It is the only one of the six services that turns «I don't know where to start» into a list of concrete actions, ordered by what can actually hurt you and with a cost next to each one.

Tell me where you stand →

05 · Certification audit

This is the only one that technically deserves the name «audit» in the strict sense: an accredited body verifies that you comply with a standard and issues (or withholds) a certificate. It does not advise you, it does not help you, it does not propose improvements. It verifies.

Segregation of duties

Whoever helps you prepare cannot be the one who certifies you. Those are separate invoices from separate companies, and many «certification» quotes only include one of them. It is the most common budgeting mistake in this whole block.

And there is a third one almost nobody counts: before the external audit you need an internal review, and it cannot be run by whoever implemented the system. Nobody audits their own work, so that is another provider and another invoice. Three, not two.

Each framework asks for it in its own way: clause 9.2 of ISO 27001 requires internal audits by impartial auditors —if the certification auditor sees your own implementer ran it, it gets thrown out—; TISAX starts from the VDA ISA self-assessment before the assessment itself; and article 31 of Spain's Royal Decree 311/2022 requires an ordinary audit at least every two years, with the basic category accredited through self-assessment. Under ENS, moreover, the annual internal audit is no longer mandatory since the latest update to the CCN guides.

ISO 27001 SME with 10 to 25 employees · first year
01ISMS implementationThe preparation consulting. This is the long part: months of work.
€6,000 – €15,000
02Prior internal auditRequired by clause 9.2, and by a provider other than the implementer. One to three days.
€800 – €2,500
03Certification auditThe accredited body that verifies and issues the certificate.
€3,000 – €5,500

Approximate split of the spend. Certification —the invoice everyone asks for first— is the smallest of the three.

Total first year €10,000 – €23,000

This is the sum of the three lines above, not a catalogue figure: published totals usually stop at €10,000 – €20,000 because they do not count the internal audit. With a broad scope it goes to €35,000. Annual surveillance audits run at 30 % – 40 % of the initial one.

ENS Spain's National Security Framework
BBasic categoryAccredited through self-assessment, at least every two years.
No external audit
MMedium category, small organisationThe audit alone, mandatory at least every two years.
€3,000 – €8,000
FFull process in an SMEAdaptation and audit, depending on scope.
€8,000 – €25,000

If somebody quotes you a certification audit for a basic category system, ask them why.

NIS2 Adapting to the directive
SCompany with 10 to 50 employees
€3,000 – €8,000
MCompany with 50 to 250 employees
€8,000 – €25,000

NIS2 is not certifiable: there is no badge to hang, what you pay for is the adaptation. And with ISO 27001 already in place the cost can be halved, because a good part of the work is done.

Look at the orders of magnitude in the first card, because this is what surprises people most: the certification audit is the small invoice. The expensive part is building the system, and the certification body is not the one who does that.

And be careful with the totals doing the rounds out there: almost all of them add up implementation and certification and leave the internal audit out. Add it yourself from the start, because it is not optional and the team building your system cannot be the one to run it.

06 · The audit your customer demands

You do not buy this one, it is imposed on you. A large customer sends you a sixty-question security questionnaire, or requires you to evidence controls, or simply sends a third party to review you.

This is growing very fast because of the cascade effect of NIS2 and DORA: the entities in scope pass requirements down their supply chain, and that is where thousands of SMEs land — technically outside the directive's scope, but firmly inside their customers'.

The cost here is mainly your internal time, which nobody budgets for and which is very real. If you need help answering, count on €1,000 to €3,000 per questionnaire the first time. The second time is much cheaper, because the material already exists.

The ranges, at a glance

The same figures as above, plotted on a single axis. It is the fastest way to see that an assessment and a certification are not playing in the same league:

Market ranges · Spanish SME, 2026
  • Vulnerability scan€800 – €2,500
  • Technical configuration review€1,500 – €5,000
  • Assessment / gap analysis€1,500 – €4,000
  • Full master plan€3,000 – €8,000
  • Web / infrastructure pentest€2,000 – €15,000
  • NIS2 adaptation€3,000 – €25,000
  • ISO 27001, full first year€10,000 – €23,000
  • ENS medium, full process€8,000 – €25,000

The bar marked with the triangle is the one I recommend by default to an SME starting out.

And the same picture, with the question that really matters: when each one makes sense.

ServiceWhen does it make sense?
Vulnerability scanPeriodic check-up, complement to something else
Technical configuration reviewAlmost always: it is the first technical step
Assessment / gap analysisThe default starting point
Full master planWhen you need to justify a multi-year investment
Web / infrastructure pentestOnce the basics are already covered
NIS2 adaptationIf you are in scope or a customer requires it
ISO 27001, first yearIf the market or a customer requires it
ENS medium, full processIf you sell to the Spanish public sector
Keynote

If I had to bet on a single figure for a Spanish SME of 10 to 50 employees that wants to start putting its security in order: between €2,000 and €5,000, for an assessment with a technical review and a prioritised plan. It is the work that returns the most per euro invested, and curiously it is almost never what gets quoted when somebody asks for «an audit».

Where the price comes from: the formula nobody teaches you

Behind any professional services quote lies the same elementary arithmetic:

The formula
Price = person-days × daily rate + management margin

The daily rate for a technical security consulting profile in Spain moves, broadly speaking, between €400 and €900 per day depending on seniority and the provider's structure. A freelancer with solid experience sits in the low-to-mid range; a consultancy with structure, offices and a sales team needs to be at the top end to sustain its costs. Neither option is a trick: you are paying for different things.

Penetration testing plays in a different rate league: in Spain the usual figure is €700 to €1,500 per day, because the profile is scarcer. That is why the slider below goes up to €1,500 and not to €900.

Person-days are the variable that really drives the price, and the one that almost never appears in the quote. An assessment for a small SME is 4 to 8 days. A serious web pentest, 5 to 10. An ISMS implementation, 20 to 40 spread over months.

Check your quote with this calculator

Do the multiplication yourself. Move the two sliders, or pick the type of work you have been quoted, and compare the result with the number on your desk:

Day-rate calculator

Pick a type of work or move the sliders by hand. This is not a quote: it is the arithmetic behind any quote, so you can check whether the one on your desk adds up.

€3,300 days × rate, excluding VAT and management margin

This is the usual bracket for a situation assessment in a small SME.

Rates exclude VAT. The management margin, coordination and report writing are usually already inside the billed day; if they are charged separately, they should appear in the quote.

Does the number you were given fall outside this? Send it over and I'll tell you where the mismatch is →

If a €3,500 quote implies 5 days, the maths works. If somebody offers you «a complete audit of your company» for €900, you are buying one to two days of work. That can be perfectly honest —there are narrow reviews that fit in a day— but it cannot be complete. And if you are quoted €18,000 for a twenty-person company, the right question is not «why so expensive?» but «how many days is that, and where do they go?».

That is, for me, the most useful question in this whole article. A provider who cannot or will not break down the days either has not scoped the work, or does not want you to compare.

What pushes a quote up?

Pushes it up

What adds days

Number of environments and sites. Every tenant, every domain, every branch multiplies the fieldwork.

Custom-built applications. A standard ERP is reviewed with a checklist; an in-house application has to be understood before it can be audited.

Industrial/OT/ICS environments. Another world, another profile, another rate.

Starting from zero. With no asset inventory, no policies and nobody who knows how the thing is put together, the first days go entirely on understanding the terrain.

Tight deadlines. «I need it by the 30th» has a price.

Brings it down

What removes days

Having the inventory ready. If you turn up with the list of systems, users, suppliers and access, you save days of discovery. You can prepare this yourself, for free.

A single, available point of contact. The biggest hidden cost in these projects is waiting for answers. Availability is not only the consultants' problem: not being able to move forward and having them idle means the consultancy loses money.

A bounded, phased scope. Starting with what is critical and extending later almost always beats a huge scope badly delivered.

Already having a framework in place. ISO 27001 makes NIS2 cheaper, and TISAX much cheaper. NIS2 makes ENS cheaper, and ENS is probably the most expensive in Spain along with DORA. The work compounds.

Repeating provider. The second review with the same team should cost considerably less than the first. If it does not come down, ask why.

Seven red flags in a quote

After seeing a fair number of quotes in this sector, these are the patterns that make me suspicious:

Flag 01

A closed price without a single meeting

If you have not even seen the face of whoever is quoting you, be suspicious. Nobody can scope work they have not looked at.

Flag 02

«Free audit» or one sold at a loss

Nobody likes losing money. It is a sales action, and its outcome will be, with very high probability, that you need exactly what that company sells. It can be useful as a first contact, but do not mistake it for an independent assessment.

Flag 03

The deliverable is a tool's output

An automatically generated 200-page PDF, with CVEs sorted by severity and not one line written by a human about your business, is not an audit.

Flag 04

There is no prioritisation

A hundred «critical» findings equal zero critical findings. A good report tells you what to do on Monday, what this quarter and what can wait until next year. If everything is urgent, nobody will do anything.

Flag 05

There is no executive report

If the result can only be understood by a technical profile, it will never reach the person who signs off the next budget.

Flag 06

There is no results presentation meeting

Emailing the report and disappearing is simply sad. (Anecdote: it was done to me while I was the consultant. They wanted an audit for a cyber insurance policy, but they did not really want to be cyber-secure.)

Flag 07

Nobody names who does the work

Asking about the profile and certifications of the person who will actually deliver —not of the sales director— is entirely legitimate. Being sold a senior and delivered an intern is a classic.

The cost that is not in the quote

This is the part almost nobody writes about, and it is the most important.

Where the money really goes
20 % 80 %
The auditThe diagnosis: consulting days, report and results meeting. It is the only part usually budgeted for.
The remediationFixing what shows up: licences, replacing the firewall, decent backups, training, monitoring. Almost never budgeted for.

The audit is the diagnosis. The real spend is in remediating the findings.

A €3,000 assessment in an SME that has never worked on its security will return, at a conservative estimate, between twenty and forty actions. Some are free and take an afternoon: enabling MFA, reviewing who holds administrator permissions, switching off legacy protocols, removing accounts belonging to people who no longer work there. Others cost real money: licences, replacing the firewall, a decent backup solution, training, a monitoring service.

Public grants for cybersecurity

I'll spare you my opinion. Draw whatever conclusions you find convenient.

The one useful fact

Kit Consulting stopped accepting applications on 31 March 2025, and the deadline to formalise agreements with digital advisors closed on 31 May 2026. As of today there is no new call published. If somebody still offers it to you as a funding route, check the Red.es page before counting on it.

The eight questions to ask before you sign

Copy this and send it as it is to the three providers you are considering. The answers will tell you more than the prices.

To paste into an email
  1. What type of service is this exactly: a scan, a configuration review, a pentest, a compliance assessment or a certification audit?
  2. How many person-days does it include and how are they distributed?
  3. Which profile delivers the work, and what experience and certifications do they have? The people named in the quote should be the people doing the work.
  4. What is in scope and, above all, what is explicitly out of scope?
  5. What deliverables do I get? Is there an executive report as well as the technical one?
  6. Are findings prioritised by real business risk or only by technical severity?
  7. Does it include a results presentation meeting with management?
  8. Is there a follow-up review to verify what has been fixed, and what does it cost?

If a provider answers all eight with specifics, their price is probably fair even if it is the highest of the three.

What you can do today, for zero euros

Before spending anything, there is work only you can do and it will save you money later:

€0
Build the inventory

A spreadsheet with your systems, applications, users, suppliers with access and sensitive data. It is the first thing anyone will ask you for, and the one that eats the most days if it does not exist.

€0
Enable MFA everywhere you can

Start with email. It is the single measure with the best protection-to-cost ratio in existence and it is still switched off across a huge share of Spanish businesses.

€0
Review who is an administrator

And remove everyone who does not need it today. Admin permissions get handed out in two minutes and stay in place for years.

€0
Offboard whoever has left

Former employee accounts, old supplier access, ghost licences. It is usually the most uncomfortable list to review and the most profitable.

If you do these four things and then buy an assessment, the conversation starts from a much more advanced point and the quote goes down. If you cannot buy anything at all, at least you will have closed the doors people actually come through.

In summary

Stop asking how much a cybersecurity audit costs. Ask what you need to verify and why, and the price will appear on its own.

For a Spanish SME starting out, the answer is almost always an assessment costing €2,000 to €5,000 that produces a prioritised plan. Not a pentest. Not a certification. A plan you can defend in front of whoever signs and deliver within twelve months.

And set aside budget to fix what you find, because a report with no money behind it is an expensive document about problems you are going to keep having.

Frequently asked questions

How much does a cybersecurity audit cost for an SME in Spain?

It depends on what you call an audit. A vulnerability scan runs from €800 to €2,500; a technical configuration review, €1,500 to €5,000; an assessment or gap analysis, €1,500 to €4,000, and up to €8,000 with a master plan. For a 10-to-50-employee SME starting out, the sensible bracket for what it actually needs sits between €1,500 and €7,000.

What is the difference between a vulnerability scan, a pentest and an audit?

The scan is run by a tool and returns known flaws: it is an indicator, not a diagnosis. The pentest is a person trying to break in, answering «can it be done?». An audit in the strict sense is an accredited body verifying that you meet a standard. Three different services, three different prices, all sold under the same label.

How much does ISO 27001 certification cost for an SME?

Three invoices: ISMS implementation (€6,000 – €15,000), prior internal audit (€800 – €2,500) and certification audit (€3,000 – €5,500). The full first year comes to €10,000 – €23,000, and can reach €35,000 with a broad scope. Annual surveillance audits run at 30 % – 40 % of the initial one.

Can the same company implement the system and audit it?

No. Clause 9.2 of ISO 27001 requires the internal audit to be run by impartial auditors, and whoever implements cannot review their own work. Nor can the company that prepared you certify you: that is done by an independent accredited body. In practice that means three providers, or at the very least three clearly separated roles.

Is an internal audit still mandatory before the external one?

Under Spain's ENS, no longer. In June 2026 the National Cryptologic Centre updated a package of its 800-series guides —among them CCN-STIC 808, on compliance verification— and dropped the mandatory annual internal audit: its frequency is now flexible under the proportionality principle. Nothing has changed for ISO 27001: clause 9.2 still requires them, and without them the certification body will not certify you.

That said, at ACBSEC I still recommend running it even when the standard no longer forces you to. It is the only way to learn about the findings before the certification auditor tells you, it costs considerably less than a non-conformity, and it leaves you room to fix things calmly instead of in a rush. Losing the obligation does not make it dispensable: it makes it your call.

Is an external audit mandatory for Spain's ENS?

For basic category, no: it is accredited through self-assessment, repeated at least every two years. For medium and high category you do need a certification audit by an accredited body, also at least every two years, at around €3,000 – €8,000 in a small organisation. The full adaptation plus audit runs between €8,000 and €25,000.

How much does NIS2 adaptation cost?

Between €3,000 and €8,000 for companies with 10 to 50 employees, and €8,000 to €25,000 for 50 to 250. NIS2 is not certifiable —there is no badge— so what you pay for is the adaptation, not an exam. If you already have ISO 27001 in place, the cost can be halved because much of the work is done.

How long does a cybersecurity audit take?

An SME assessment is 4 to 8 person-days, which in calendar terms usually means two to four weeks including interviews and review. A serious web pentest, 5 to 10 days. An ISMS implementation, 20 to 40 spread over months. If a quote does not say how many days it includes, it is not telling you the price.

What should an audit report include?

A technical report and an executive report, findings prioritised by real business risk rather than technical severity alone, one concrete recommendation per finding with estimated effort, and a results presentation meeting with management. If it also includes a follow-up review to verify what has been fixed, better still: ask what that costs.

Are there public grants to pay for a cybersecurity audit in Spain?

Kit Consulting closed applications on 31 March 2025 and there is no new call published. Regional programmes come and go. My opinion on them is a few paragraphs above, and it is short.

How often should an audit be repeated?

A vulnerability scan makes sense quarterly or continuously. An assessment, once a year or whenever something significant changes. ISO 27001 certification requires annual surveillance and renewal every three years; ENS, an audit at least every two. And always after a substantial change to the systems.


Got a quote on your desk and no idea whether it is reasonable? Write to me and we will look at it together, no strings attached.

Sources consulted

SME audit pricingCibersafety · Hard2Bit · Iberia Intel · SYRA360 (ES)

Penetration testingVulnerabbit · Secra · Hard2Bit · CISEC (ES)

ISO 27001Novaciber · Delbion · Step Quality · Clause 9.2, internal audit

ENSRoyal Decree 311/2022, consolidated text · Update to guides CCN-STIC 802, 808, 809 and 825 (June 2026) · Audidat · Ángel Ortega Castro · NexENS (ES)

NIS2Adaptation cost · Prices by company size · Delbion (ES)

TISAXVDA ISA questionnaire and official ENX documentation

Public grantsRed.es, Kit Consulting application deadline · Programme page · Status and next call (ES)

These ranges were last reviewed in August 2026. They are market orders of magnitude, not a rate card, and almost every pricing source is a company selling the service it describes: always check against at least three real quotes before deciding.

← All articles

Keep reading

Got a quote on your desk?

I'll tell you whether that number makes sense, without selling you anything

I scope and deliver this kind of work, so I know how to read an audit quote from the inside: how many days sit behind it, what falls outside the scope and what you will run into afterwards. If you are comparing proposals and cannot tell which one smells wrong, send them over.

And if what you need is the assessment itself, let's talk about your situation before anyone quotes you anything. I answer personally, no fluff and no strings attached.

Let's talk about your case →