Use code LIVING102 for a free 30-minute consultation
Assessment-prep pricing ยท transparent, no procurement back-channels

Pricing

Every tier includes the Grade-1 cryptographic vault, hash-chained audit log, and continuous monitoring infrastructure. Tier selection determines the level of practitioner involvement.

Annual billing displayed.Monthly pricing is also available on each card.
Other engagement modes

Fractional vCISO, strategic advisory, and federal subcontracting are custom-scoped, not priced on this page. Engagements are sized to the program โ€” start with a discovery call to confirm fit, scope, and the right commitment shape.

HIPAA ยท Health Insurance Portability and Accountability Act

Aegis

PHI security under HIPAA Security Rule (ยง164.308โ€“.312) and the Privacy Rule.

Aegis details โ†’
AegisSelf-Service
$319/month
or $3,420/year (11% off)

Your HIPAA starting block โ€” full Security Rule + Privacy Rule policy library and evidence vault with hash-chained audit log. Same regulator-ready foundation that Audit Co-Pilot signs at the top of the ladder.

  • โœ“Full HIPAA policy library (Security Rule + Privacy Rule)
  • โœ“Risk assessment workbook (annual)
  • โœ“Evidence vault with hash-chained audit log
  • โœ“Accounting-of-Disclosures register (ยง164.528)
  • โœ“Up to 5 user seats
Start Aegis Self-Service
AegisGuided
$639/month
or $6,950/year (9% off)

Aegis Self-Service + 2 monthly Consultant Review hours and Tammie AI advisor (HIPAA-tuned). Quarterly readiness reports with practitioner sign-off โ€” Mission Brief's regulator-grade artifact, now on a recurring cadence.

  • โœ“Everything in Aegis Self-Service
  • โœ“2 Consultant Review hours per month
  • โœ“Tammie AI compliance advisor (HIPAA-tuned)
  • โœ“Quarterly readiness reports with practitioner sign-off
  • โœ“Global Review Queue (4-day SLA)
Start Aegis Guided
Most popular
AegisManaged
$1,295/month
or $13,900/year (11% off)

Concierge HIPAA. Quarterly risk assessments, BAA reviews, incident response retainer (ยง164.308(a)(6)), and direct OCR audit response support. Priority Global Review Queue with next-business-day SLA โ€” your practitioner sits inside the engagement, not on a ticket queue.

  • โœ“Everything in Aegis Guided
  • โœ“Quarterly risk assessments and BAA reviews
  • โœ“Incident response retainer (ยง164.308(a)(6))
  • โœ“Direct OCR audit response support
  • โœ“Priority Global Review Queue (next-business-day SLA)
Start Aegis Managed
AegisAudit Co-Pilot
$1,925/month
or $20,850/year (10% off)

Built for the moment OCR shows up. Every HIPAA artifact signed by a named practitioner, hashed at server-side ingest, anchored to an RFC 3161 timestamp, and verifiable independently of Key 102.

  • โœ“Everything in Aegis Managed
  • โœ“Recipient-verifiable Master Audit Report (SHA-256 + Report ID)
  • โœ“Public verify endpoint independent of Key 102 clock/database
  • โœ“RFC 3161 TSA anchor on every report
  • โœ“Practitioner Sign & Seal embedded in tier
Start Aegis Audit Co-Pilot
PCI-DSS ยท Payment Card Industry Data Security Standard v4.0.1

Vault

PCI-DSS v4.0.1 evidence collection, SAQ assistance, and AoC readiness.

Vault details โ†’
VaultSelf-Service
$429/month
or $4,600/year (11% off)

PCI v4.0.1 task library + evidence vault, calibrated for all 51 future-dated requirements now mandatory under v4.0.1. SAQ-A through SAQ-D applicable. Foundation tier โ€” upgrade path delivers QSA-grade recipient-verifiable AoC.

  • โœ“Full PCI v4.0.1 task library (Requirements 1โ€“12, all future-dated controls in scope)
  • โœ“SAQ-A / SAQ-D guidance and templates
  • โœ“Evidence vault with hash-chained audit log
  • โœ“ASV scan tracking and reminders
  • โœ“Up to 5 user seats
Start Vault Self-Service
VaultGuided
$849/month
or $9,295/year (9% off)

Vault Self-Service + SAQ-D walkthrough, quarterly ASV scan review, annual penetration test scoping, and Cardholder Data Environment mapping. Your practitioner walks Req 1โ€“12 with you before submission.

  • โœ“Everything in Vault Self-Service
  • โœ“SAQ-D walkthrough and submission assistance
  • โœ“Quarterly ASV scan review with consultant
  • โœ“Annual penetration test scoping
  • โœ“Cardholder Data Environment (CDE) mapping support
Start Vault Guided
Most popular
VaultManaged
$1,925/month
or $21,400/year (7% off)

Year-round PCI v4.0.1 evidence collection with practitioner + customer two-party AoC attestation. QSA gets a redacted external-share variant with byte-level hash; auditor gets the full canonical bundle. Both verify themselves against the same source of truth.

  • โœ“Everything in Vault Guided
  • โœ“Year-round evidence auditing
  • โœ“Tier 2 PCI Deliverable โ€” signed PDF bundle of SAQ-D + AoC with practitioner + customer two-party attestation
  • โœ“External-share redacted variant for QSA/acquirer handoff (evidence excerpts kept internal)
  • โœ“QSA-handoff-ready bundle and pre-audit dry-runs
  • โœ“Grade-1 server-mediated upload for in-scope evidence
Start Vault Managed
VaultAudit Co-Pilot
$2,895/month
or $32,100/year (8% off)

Built for the moment your QSA reviews the submission. Tier 2 PCI Deliverable cover-stamped + byte-hashed, with an external-share redacted variant the QSA hits via independent verify endpoint. Acquirer sees the same canonical hash. No vendor-trust required.

  • โœ“Everything in Vault Managed
  • โœ“Tier 2 PCI Deliverable โ€” cover-stamped + byte-hashed + external-share variant, each independently verifiable
  • โœ“Recipient-verifiable AoC + Master Audit Report (SHA-256 + Report ID)
  • โœ“Public verify endpoint independent of Key 102 clock/database
  • โœ“RFC 3161 TSA anchor on every report and AoC
  • โœ“QSA-direct verification page on every audit-facing PDF
Start Vault Audit Co-Pilot
CMMC ยท Cybersecurity Maturity Model Certification 2.0

Fortress

CMMC 2.0 Level 2 (Advanced) on NIST SP 800-171 Rev. 2.

Fortress details โ†’
FortressGuided
$1,295/month
or $13,900/year (11% off)

CMMC 2.0 Level 2 starting block โ€” NIST 800-171 Rev. 2 task library (110 controls, 14 families), SPRS calculator + submission, SSP template, POA&M tracker. Foundation tier โ€” upgrade path delivers full RP-signed deliverables.

  • โœ“NIST 800-171 Rev. 2 task library (110 controls, 14 families)
  • โœ“SPRS score calculator and submission guidance
  • โœ“System Security Plan (SSP) template and drafting support
  • โœ“Plan of Action and Milestones (POA&M) tracker
  • โœ“Quarterly readiness reports
Start Fortress Guided
Most popular
FortressManaged
$3,749/month
or $40,650/year (10% off)

Full CMMC L2 SSP management with practitioner sign-off. C3PAO pre-audit readiness assessment, POA&M management, C3PAO-handoff-ready bundle. Your practitioner owns the SSP โ€” not a template.

  • โœ“Everything in Fortress Guided
  • โœ“Full System Security Plan management (drafting, review, updates)
  • โœ“C3PAO pre-audit readiness assessment
  • โœ“Practitioner review and sign-off
  • โœ“C3PAO-handoff-ready bundle
Start Fortress Managed
FortressAudit Co-Pilot
$7,495/month
or $81,320/year (10% off)

DoD-assessor-grade CMMC deliverables. Practitioner sign-off, RFC 3161 TSA anchor on every SSP / POA&M / SPRS revision, public C3PAO verification page on every assessor-facing PDF. The assessor verifies you without asking us anything.

  • โœ“Everything in Fortress Managed
  • โœ“Recipient-verifiable SSP, POA&M, and Master Audit Report
  • โœ“SHA-256 + Report ID on every PDF; public verify endpoint
  • โœ“RFC 3161 TSA anchor on every report โ€” DoD assessor-grade proof
  • โœ“Practitioner Sign & Seal embedded in tier
  • โœ“C3PAO-direct verification page on every assessor-facing PDF
Start Fortress Audit Co-Pilot
Logistics ยท Surface Transportation Cybersecurity

Nexus

TSA Security Directive 1580/82, FMCSA, and Pipeline Safety cybersecurity.

Nexus details โ†’
NexusGuided
$959/month
or $10,490/year (9% off)

TSA SD-1580/82 + FMCSA + PHMSA task libraries, Tammie AI advisor (Logistics-tuned), and 2 monthly Consultant Review hours. Mission Brief's TSA-aligned artifact on a recurring cadence โ€” incident playbook stays current with the 72-hour clock.

  • โœ“TSA SD-1580/82 incident reporting templates
  • โœ“FMCSA cybersecurity baseline checklists
  • โœ“PHMSA Pipeline Safety control library
  • โœ“Tammie AI advisor (Logistics-tuned)
  • โœ“2 Consultant Review hours per month
Start Nexus Guided
Most popular
NexusManaged
$2,679/month
or $28,890/year (10% off)

Outsourced Cybersecurity Coordinator embedded in your TSA / FMCSA / PHMSA operations. Priority Global Review Queue (next-business-day SLA), TSA incident response coordination, quarterly regulator-ready summary reports. When the 72-hour clock starts, your coordinator's already on the line.

  • โœ“Everything in Nexus Guided
  • โœ“Outsourced Cybersecurity Coordinator
  • โœ“Priority Global Review Queue (next-business-day SLA)
  • โœ“TSA incident response coordination
  • โœ“Quarterly regulator-ready summary reports
Start Nexus Managed
NexusAudit Co-Pilot
$5,349/month
or $57,800/year (10% off)

TSA / FMCSA / PHMSA-grade regulator deliverables. Practitioner sign-off on every incident summary, RFC 3161 TSA anchor on every report, public verify endpoint on every regulator-facing PDF. When the 72-hour clock ends, your submission is already verified.

  • โœ“Everything in Nexus Managed
  • โœ“Recipient-verifiable incident summaries + Master Audit Report
  • โœ“SHA-256 + Report ID on every PDF; public verify endpoint
  • โœ“RFC 3161 TSA anchor on every report โ€” regulator-grade proof
  • โœ“TSA-aware practitioner Sign & Seal embedded in tier
  • โœ“Direct verification page on every regulator-facing PDF
Start Nexus Audit Co-Pilot
Lowest-risk entry point

Start with a Mission Brief โ€” $674

Diagnostic engagement with Tammie and a practitioner. We map your scope, identify control gaps, and deliver your regulator-ready artifact โ€” HIPAA SRA, PCI SAQ-D, CMMC Level 1 SPRS affirmation, or Logistics SD-1580 alignment. Credit converts 1:1 into any annual subscription within 14 days.

Start your Mission Brief โ†’
Engagement levels

Four levels of practitioner involvement.

Self-Service
You drive. You review.

Portal access, full task library, evidence vault, and audit log. Your team operates the framework end-to-end. Practitioner support is available via the Global Review Queue when needed.

Guided
You drive. We review.

2 Consultant Review hours per month, Tammie AI advisor tuned to your framework, and quarterly readiness reports with practitioner sign-off. Your team executes; we validate.

Managed
We drive. You review.

Concierge engagement with monthly assessments, direct regulator liaison, and priority Global Review Queue (24-hour SLA). We operate the framework on your behalf; you attest.

Audit Co-Pilot
We drive. The auditor verifies.

Managed-grade delivery plus recipient-verifiable PDFs. Every Master Audit Report, AoC, and SSP carries a SHA-256 and Report ID resolvable against Key 102's public verify endpoint โ€” independent of any link, email, or trust in our clock or database. The auditor self-services attestation. See it on our own: portal.key102consulting.com/verify/sprs/SPRS-L1-2026-CXH6GR.