Pricing
Choose where you are starting
Building your first framework
We build the Compliance Core and prepare your first management system for audit.
View common starting pointsKeeping the system current
For certified teams that want Asteron to manage evidence, surveillance, questionnaires and regulatory change throughout the year.
View Compliance OperationsAdding another framework
Reuse your current controls and evidence. Existing-system mapping is included when the management system is current enough to build on.
View Core extensionsBringing an existing system under control
Re-baseline an outdated or poorly maintained management system, or prepare it for an upcoming framework transition.
View takeover and transitionsCommon starting points
The most common ways healthtech teams begin working with Asteron.
Sprint Core
ISO 27001
Build the Asteron Compliance Core and prepare the first ISO 27001 management system for audit.
- Compliance Core and management-system scope
- Policies, controls and audit evidence
- Internal audit and certification preparation
Sprint Health
ISO 27001 + IEC 81001-5-1
Information security and health-software cybersecurity in one coordinated project.
- Everything required for the first security framework
- IEC 81001-5-1 cybersecurity processes
- Health-software and notified-body evidence
Sprint AI
ISO 42001 + EU AI Act readiness
Create the AI management system, oversight model and evidence needed for customer and regulatory review.
- AI inventory, ownership and risk processes
- Human oversight and supplier governance
- ISO 42001 and EU AI Act readiness
Sprint Privacy
ISO 27001 + ISO 27701 + GDPR operations
Build security and privacy operations together for health-data processing.
- Security and privacy management systems
- Controller, processor and health-data operations
- GDPR and ISO 27701 evidence cycle
What every certification sprint includes
Applies to fixed-scope management-system and certification projects. Readiness screenings, Security Operations and Medical Device Track use their own defined scope.
Human expert, built in
A named senior specialist runs the work - not a platform you have to operate yourself.
- Named senior expert - 1:1 in Slack or Teams
- Project ownership - tasks, approvals and follow-ups managed end to end
- Team workshops - practical guidance through new processes
Automation under the hood
Repetitive compliance work is automated wherever the client environment allows it.
- Evidence workflows - connected and refreshed where supported
- Tasks and approvals - owners and deadlines kept current
- Risk, policy and supplier registers - structured around actual operations
Audit preparation and accountability
You do not face the auditor alone. We prepare the system, the evidence and your team.
- Internal audit - completed before the certification audit
- Certification-body coordination - selection support and timeline management
- Team preparation - practical preparation for auditor questions
- Audit support - Stage 1, Stage 2 and agreed remediation support
Guarantee
Contracted outcome guarantee
If the agreed outcome is not reached because of Asteron deliverables, we correct the work at no additional cost within the contracted scope.
Trust Center setup included
BONUSA customer-facing security page your sales team can share during procurement and security reviews. It presents your certification status, scope and approved security information in one controlled place.
Framework extensions from your Core
Overlapping frameworks reuse your existing controls, evidence and operating processes. These extensions typically cost less and require less duplicate work than starting again.
Existing-system mapping is included in the extension price when the current scope, controls and evidence are sufficiently current to reuse.
- As your first project
- €23,900
- Reuse the security management system, evidence and operating processes
- As your first project
- €27,900
- Reuse security controls, evidence and governance
- As your first project
- €19,900
- Reuse governance, suppliers, risks and evidence
- As your first project
- €19,900
- Reuse most of the information-security operating model
- As your first project
- from €8,900
- Reduced discovery and implementation scope
- Existing risks, suppliers and incident processes reused
- As your first project
- from €8,900
- Dutch NIS2 implementation built on existing security governance
- As your first project
- from €8,900
- Existing vulnerability, supplier and incident processes reused
Standalone and specialist projects
These projects depend more heavily on product, market or regulatory scope. An existing Compliance Core may reduce discovery work, but it does not automatically reduce the full project by 40-60%.
Core certification
Builds the first Asteron Compliance Core.
Privacy and health data
Operational governance for special-category health data. Not a certification.
Applicability, data-flow and readiness mapping. Not an EHDS certification.
AI governance
Applicability, classification, gaps and evidence plan.
EU regulatory and product security
Product classification and applicability assessment.
Traceability, vulnerability and decision evidence.
National and market-specific
Secure communication of health information.
German digital-health operational readiness.
French health-data hosting readiness.
International
CPA fees excluded. Type II normally requires 6-9 months in total.
US health-data operational readiness. Not a certification.
Ongoing compliance
Compliance Operations
The managed service is the same at every band. Pricing scales with organisational complexity, framework load and operational volume.
Up to 50 employees
- Company size
- Up to 50 employees
- Structure
- One legal entity and one main product
- Frameworks
- Up to two closely related frameworks
- Activity
- Standard questionnaire, supplier and audit volume
51-150 employees
- Company size
- 51-150 employees
- Structure
- Several teams, products or more complex ownership
- Frameworks
- Up to three frameworks
- Activity
- Increased supplier, buyer and audit activity
Complex environment
- Company size
- Typically 151+ employees
- Structure
- Multiple entities, products or regulated business lines
- Frameworks
- Four or more frameworks
- Activity
- Substantial audit, questionnaire, medical-device or high-risk AI workload
Employee count is one complexity indicator, not the only pricing factor. All three bands include the same essential operating service.
Core onboarding included
IncludedWe map a current, reusable management system into the Asteron Compliance Core as part of every 12-month Compliance Operations engagement.
Re-baseline work is scoped separately only when the existing system requires material recovery before it can be operated reliably.
What Compliance Operations includes
Operational ownership
A named specialist keeps the system moving throughout the year.
- Named senior compliance specialist
- Annual operating calendar
- Control-owner coordination
- Management-review preparation
Recurring compliance work
The system stays current between audits.
- Evidence collection and review
- Access reviews
- Supplier reviews
- Asset and risk updates
- Policy review and training cycle
External reviews
You are prepared before the questionnaire or auditor arrives.
- Surveillance and recertification preparation
- Security questionnaire support
- Audit evidence pack
- Auditor questions and agreed remediation
- Certificate and scope-change coordination where applicable
Guarantee
The same managed service at every band
Pricing changes with complexity and workload - not by removing essential compliance operations from the lower band.
Systems and change - automation and regulatory tracking included
INCLUDEDAutomation and recurring workflows, regulatory-change tracking, applicability decisions and tracked actions keep the system current as the company and regulatory environment change.
Takeover and transitions
Bring an outdated or partially maintained system back under control, or complete a required framework transition.
Core onboarding
Included with a 12-month Compliance Operations engagement or a framework extension when the existing management system is current and reusable.
- Existing scope and control mapping
- Evidence and ownership import
- Audit-calendar setup
- Compliance Operations onboarding
Re-baseline
For systems that need evidence, scope, ownership, risks or documentation restored before ongoing operation or extension work can begin.
- Scope and ownership review
- Risk and asset refresh
- Evidence status assessment
- Priority remediation plan
NEN 7510:2024 Transition
For organisations moving an existing NEN 7510 management system to the 2024 version.
If the current system requires recovery first, Re-baseline is scoped separately.
Need migration without an ongoing engagement or framework extension? Standalone adoption is scoped individually.
Security Operations
Add technical testing, vulnerability operations or senior security leadership when needed.
Testing
- Web application penetration testfrom €6,900
- Mobile application penetration testfrom €7,900
- API penetration testfrom €5,900
- Combined product testfrom €11,900
Ongoing security
- Vulnerability Managementfrom €1,900 / month
- vCISOfrom €3,900 / month
- Incident Response Retainerfrom €2,400 / month
- Incident response projectScoped individually
Final penetration-testing scope depends on architecture, endpoints, roles, retesting and reporting requirements.
We will confirm the technical scope, testing depth, retest requirements and fixed quote.
Complex regulatory work
Medical-device and complex regulatory work
Medical-device scope depends on intended use, classification, product architecture and existing documentation. A fixed universal price would be misleading.
Primary offer
Larger, multi-product or higher-class engagements are scoped individually.
Possible scope
- ISO 13485
- IEC 62304
- ISO 14971
- MDR or IVDR pathway
- IEC 81001-5-1
- Specialist co-delivery
External costs and client responsibilities
External certification audit
The certification body must remain independent from Asteron. You contract and pay the accredited certification body directly, which protects the objectivity of the audit and avoids a conflict of interest.
Asteron can help identify suitable certification bodies, compare proposals, coordinate the audit schedule and prepare every session. The audit payment never passes through Asteron.
- €4,500-6,000 for 10-50 employees
- €6,000-9,000 for 51-150 employees
Technical implementation
We identify the required technical changes and give your team clear implementation guidance. Changes that require production access - such as MFA configuration, logging, infrastructure hardening or access-control changes - remain with your engineering or DevOps team unless separately scoped with Asteron.
This keeps access responsibilities clear and prevents an open-ended implementation scope.
Independent assessment fees
SOC 2 CPA fees, notified-body fees and other independent assessment charges are paid directly to the relevant assessor.
These organisations must remain independent from the team preparing your system, and their fees depend on assessment scope, duration and audit model.
Legal and regulatory opinions
Asteron builds the operational compliance system and prepares the supporting evidence. Formal legal opinions, final medical-device classification, notified-body decisions or jurisdiction-specific interpretations may require external legal counsel or a specialist regulatory partner.
Where needed, we coordinate this work through the same delivery plan.
Payment terms for fixed-scope projects: 40% at signing, 40% at audit-ready and 20% after certification. Prices exclude VAT.
Pricing FAQ
Not sure which starting point fits your company?
Tell us what you build, where you operate, which frameworks you already have and what is creating urgency. We will map the practical route and confirm the fixed scope.
