AsteronAsteron

    Pricing

    Common starting points

    The most common ways healthtech teams begin working with Asteron.

    Sprint Core

    ISO 27001

    €16,900
    €26,900
    10-50 employees51-150 employees

    Build the Asteron Compliance Core and prepare the first ISO 27001 management system for audit.

    • Compliance Core and management-system scope
    • Policies, controls and audit evidence
    • Internal audit and certification preparation

    Sprint Health

    ISO 27001 + IEC 81001-5-1

    €23,900
    €33,900
    10-50 employees51-150 employees

    Information security and health-software cybersecurity in one coordinated project.

    • Everything required for the first security framework
    • IEC 81001-5-1 cybersecurity processes
    • Health-software and notified-body evidence

    Sprint AI

    ISO 42001 + EU AI Act readiness

    €19,900
    €27,900
    10-50 employees51-150 employees

    Create the AI management system, oversight model and evidence needed for customer and regulatory review.

    • AI inventory, ownership and risk processes
    • Human oversight and supplier governance
    • ISO 42001 and EU AI Act readiness

    Sprint Privacy

    ISO 27001 + ISO 27701 + GDPR operations

    €27,900
    €39,900
    10-50 employees51-150 employees

    Build security and privacy operations together for health-data processing.

    • Security and privacy management systems
    • Controller, processor and health-data operations
    • GDPR and ISO 27701 evidence cycle

    What every certification sprint includes

    Applies to fixed-scope management-system and certification projects. Readiness screenings, Security Operations and Medical Device Track use their own defined scope.

    Human expert, built in

    A named senior specialist runs the work - not a platform you have to operate yourself.

    • Named senior expert - 1:1 in Slack or Teams
    • Project ownership - tasks, approvals and follow-ups managed end to end
    • Team workshops - practical guidance through new processes

    Automation under the hood

    Repetitive compliance work is automated wherever the client environment allows it.

    • Evidence workflows - connected and refreshed where supported
    • Tasks and approvals - owners and deadlines kept current
    • Risk, policy and supplier registers - structured around actual operations

    Audit preparation and accountability

    You do not face the auditor alone. We prepare the system, the evidence and your team.

    • Internal audit - completed before the certification audit
    • Certification-body coordination - selection support and timeline management
    • Team preparation - practical preparation for auditor questions
    • Audit support - Stage 1, Stage 2 and agreed remediation support

    Guarantee

    Contracted outcome guarantee

    If the agreed outcome is not reached because of Asteron deliverables, we correct the work at no additional cost within the contracted scope.

    Trust Center setup included

    BONUS

    A customer-facing security page your sales team can share during procurement and security reviews. It presents your certification status, scope and approved security information in one controlled place.

    Framework extensions from your Core

    Overlapping frameworks reuse your existing controls, evidence and operating processes. These extensions typically cost less and require less duplicate work than starting again.

    Existing-system mapping is included in the extension price when the current scope, controls and evidence are sufficiently current to reuse.

    Overlapping frameworks typically cost 40-60% less from an existing Compliance Core.
    IEC 81001-5-1
    From your existing Core
    €8,900
    As your first project
    €23,900€33,900
    Save €15,000Save €25,000
    • Reuse the security management system, evidence and operating processes
    ISO 27701 + GDPR operations
    From your existing Core
    €9,900
    As your first project
    €27,900€39,900
    Save €18,000Save €30,000
    • Reuse security controls, evidence and governance
    ISO 42001 + EU AI Act readiness
    From your existing Core
    €14,900
    As your first project
    €19,900€27,900
    Save €5,000Save €13,000
    • Reuse governance, suppliers, risks and evidence
    NEN 7510🇳🇱
    From your existing Core
    €9,900
    As your first project
    €19,900€29,900
    Save €10,000Save €20,000
    • Reuse most of the information-security operating model
    NIS2 readiness
    From your existing Core
    €6,900
    As your first project
    from €8,900from €8,900
    • Reduced discovery and implementation scope
    • Existing risks, suppliers and incident processes reused
    Cyberbeveiligingswet🇳🇱
    From your existing Core
    €6,900
    As your first project
    from €8,900from €8,900
    • Dutch NIS2 implementation built on existing security governance
    CRA readiness implementation
    From your existing Core
    from €6,900
    As your first project
    from €8,900from €8,900
    • Existing vulnerability, supplier and incident processes reused

    Standalone and specialist projects

    These projects depend more heavily on product, market or regulatory scope. An existing Compliance Core may reduce discovery work, but it does not automatically reduce the full project by 40-60%.

    Core certification

    ISO 27001
    €16,900€26,900

    Builds the first Asteron Compliance Core.

    Privacy and health data

    Operational governance for special-category health data. Not a certification.

    EHDS readiness
    from €6,900

    Applicability, data-flow and readiness mapping. Not an EHDS certification.

    AI governance

    EU AI Act readiness
    from €9,900

    Applicability, classification, gaps and evidence plan.

    EU regulatory and product security

    Product classification and applicability assessment.

    Traceability, vulnerability and decision evidence.

    National and market-specific

    NTA 7516🇳🇱
    from €6,900

    Secure communication of health information.

    DiGA🇩🇪
    from €9,900

    German digital-health operational readiness.

    HDS🇫🇷
    from €9,900

    French health-data hosting readiness.

    International

    SOC 2 preparation
    from €12,900

    CPA fees excluded. Type II normally requires 6-9 months in total.

    HIPAA readiness
    from €9,900

    US health-data operational readiness. Not a certification.

    Compliance Operations

    The managed service is the same at every band. Pricing scales with organisational complexity, framework load and operational volume.

    Up to 50 employees

    €2,400 / month
    per month, excl. VAT
    Company size
    Up to 50 employees
    Structure
    One legal entity and one main product
    Frameworks
    Up to two closely related frameworks
    Activity
    Standard questionnaire, supplier and audit volume
    Same managed service at every band. 12-month minimum.

    51-150 employees

    €3,900 / month
    per month, excl. VAT
    Company size
    51-150 employees
    Structure
    Several teams, products or more complex ownership
    Frameworks
    Up to three frameworks
    Activity
    Increased supplier, buyer and audit activity
    Same managed service at every band. 12-month minimum.

    Complex environment

    from €6,500 / month
    per month, excl. VAT
    Company size
    Typically 151+ employees
    Structure
    Multiple entities, products or regulated business lines
    Frameworks
    Four or more frameworks
    Activity
    Substantial audit, questionnaire, medical-device or high-risk AI workload
    Same managed service at every band. 12-month minimum.

    Employee count is one complexity indicator, not the only pricing factor. All three bands include the same essential operating service.

    Core onboarding included

    Included

    We map a current, reusable management system into the Asteron Compliance Core as part of every 12-month Compliance Operations engagement.

    Re-baseline work is scoped separately only when the existing system requires material recovery before it can be operated reliably.

    What Compliance Operations includes

    Operational ownership

    A named specialist keeps the system moving throughout the year.

    • Named senior compliance specialist
    • Annual operating calendar
    • Control-owner coordination
    • Management-review preparation

    Recurring compliance work

    The system stays current between audits.

    • Evidence collection and review
    • Access reviews
    • Supplier reviews
    • Asset and risk updates
    • Policy review and training cycle

    External reviews

    You are prepared before the questionnaire or auditor arrives.

    • Surveillance and recertification preparation
    • Security questionnaire support
    • Audit evidence pack
    • Auditor questions and agreed remediation
    • Certificate and scope-change coordination where applicable

    Guarantee

    The same managed service at every band

    Pricing changes with complexity and workload - not by removing essential compliance operations from the lower band.

    Systems and change - automation and regulatory tracking included

    INCLUDED

    Automation and recurring workflows, regulatory-change tracking, applicability decisions and tracked actions keep the system current as the company and regulatory environment change.

    Takeover and transitions

    Bring an outdated or partially maintained system back under control, or complete a required framework transition.

    Core onboarding

    Included

    Included with a 12-month Compliance Operations engagement or a framework extension when the existing management system is current and reusable.

    • Existing scope and control mapping
    • Evidence and ownership import
    • Audit-calendar setup
    • Compliance Operations onboarding

    Re-baseline

    from €3,900

    For systems that need evidence, scope, ownership, risks or documentation restored before ongoing operation or extension work can begin.

    • Scope and ownership review
    • Risk and asset refresh
    • Evidence status assessment
    • Priority remediation plan

    NEN 7510:2024 Transition

    from €6,900

    For organisations moving an existing NEN 7510 management system to the 2024 version.

    If the current system requires recovery first, Re-baseline is scoped separately.

    Need migration without an ongoing engagement or framework extension? Standalone adoption is scoped individually.

    Security Operations

    Add technical testing, vulnerability operations or senior security leadership when needed.

    Testing

    • Web application penetration testfrom €6,900
    • Mobile application penetration testfrom €7,900
    • API penetration testfrom €5,900
    • Combined product testfrom €11,900

    Ongoing security

    • Vulnerability Managementfrom €1,900 / month
    • vCISOfrom €3,900 / month
    • Incident Response Retainerfrom €2,400 / month
    • Incident response projectScoped individually

    Final penetration-testing scope depends on architecture, endpoints, roles, retesting and reporting requirements.

    We will confirm the technical scope, testing depth, retest requirements and fixed quote.

    Complex regulatory work

    Medical-device and complex regulatory work

    Medical-device scope depends on intended use, classification, product architecture and existing documentation. A fixed universal price would be misleading.

    Primary offer

    Medical Device Track
    from €30,000

    Larger, multi-product or higher-class engagements are scoped individually.

    Possible scope

    • ISO 13485
    • IEC 62304
    • ISO 14971
    • MDR or IVDR pathway
    • IEC 81001-5-1
    • Specialist co-delivery

    External costs and client responsibilities

    External certification audit

    The certification body must remain independent from Asteron. You contract and pay the accredited certification body directly, which protects the objectivity of the audit and avoids a conflict of interest.

    Asteron can help identify suitable certification bodies, compare proposals, coordinate the audit schedule and prepare every session. The audit payment never passes through Asteron.

    • €4,500-6,000 for 10-50 employees
    • €6,000-9,000 for 51-150 employees

    Technical implementation

    We identify the required technical changes and give your team clear implementation guidance. Changes that require production access - such as MFA configuration, logging, infrastructure hardening or access-control changes - remain with your engineering or DevOps team unless separately scoped with Asteron.

    This keeps access responsibilities clear and prevents an open-ended implementation scope.

    Independent assessment fees

    SOC 2 CPA fees, notified-body fees and other independent assessment charges are paid directly to the relevant assessor.

    These organisations must remain independent from the team preparing your system, and their fees depend on assessment scope, duration and audit model.

    Legal and regulatory opinions

    Asteron builds the operational compliance system and prepares the supporting evidence. Formal legal opinions, final medical-device classification, notified-body decisions or jurisdiction-specific interpretations may require external legal counsel or a specialist regulatory partner.

    Where needed, we coordinate this work through the same delivery plan.

    Payment terms for fixed-scope projects: 40% at signing, 40% at audit-ready and 20% after certification. Prices exclude VAT.

    Pricing FAQ

    The two primary prices reflect company size complexity. The first price applies to companies with 10-50 employees; the second applies to companies with 51-150 employees. Companies above 150 employees are scoped individually.

    Not sure which starting point fits your company?

    Tell us what you build, where you operate, which frameworks you already have and what is creating urgency. We will map the practical route and confirm the fixed scope.