Services & Pricing

Security Leadership on Your Terms

Transparent, right-sized CISO engagements for regulated businesses and mission-driven organizations. Whether you're a growing company or a non-profit protecting stakeholder trust — we have a model that fits.

Not Sure Which Tier You Need?
Start with the free 2-minute NIST readiness assessment.
Get your A–F score across all 6 NIST functions — then pick the tier that matches your gaps.
Take the Free Assessment →

Three standardized subscription tiers. Fixed-fee & custom engagements for everything else.

Continuous monitoring runs on three standardized tiers. Bespoke CISO leadership and one-off assessments are scoped per engagement.

Self-Service
Continuous Monitoring
$$399 /mo
Billed monthly · annual save available
  • Quarterly NIST CSF 2.0 self-check
  • Progress dashboard and gap report
  • Policy updates delivered monthly
  • CISA KEV monitored against your stack
  • Email support
Start Self-Service →
CMMC Module (Advisor-Led)
CMMC 2.0 Level 1/2 readiness for defense contractors
$$1,899 /mo
Billed monthly · 3-month minimum
  • NIST SP 800-171 control mapping for CMMC Level 1/2
  • Quarterly advisor-led review tied to the CMMC SSP/SRP cadence
  • DoD-prime-ready posture summary for contracting officers
  • KEV/incident-response escalation against CUI handling
Start CMMC Module →
Fractional CISO
Bespoke CISO leadership for higher-acuity environments
Custom
Scoped per engagement
  • Bespoke engagement scoping
  • Senior advisor assigned to your account
  • Standing advisory cadence
  • Board-ready executive briefings
  • Incident response & escalation
View Plans →
NIST Policy Package (Starter)
AI-customized NIST CSF policy package
$$299 one-time
AI-generated in under 60 seconds
  • 8 NIST CSF-aligned security policies
  • AI-generated in under 60 seconds
  • Industry / size / regulatory customization
  • Instant portal access
Get Your Policies →
NIST Policy Package (Pro)
AI-customized NIST CSF policy package with extended scope
$$599 one-time
AI-generated in under 60 seconds
  • Everything in Starter
  • Extended scope (DIB, healthcare, fintech templates)
  • Annual refresh entitlement
Get Pro Package →
DevSecOps
AI Governance & NIST AI RMF compliance for engineering teams
$$149 /mo
Billed monthly · annual save available
  • AI Governance & NIST AI RMF compliance
  • Machine-readable policies
  • .cursorrules generation
  • CI/CD policy gates
Learn about NIST AI RMF →
AI Module
Audit-ready AI compliance evidence
$$349 /mo
Billed monthly · 14-day trial
  • Audit-ready control evidence in 60 seconds
  • NIST CSF 2.0 + AI RMF + CMMC crosswalk
  • Re-runnable on regulatory updates (NIST CSF 2.1, EU AI Act)
  • Driven by the same 8-question intake as /assess
  • Stacks with Self-Service + Advisor-Led
Start AI Module →
CMMC & Non-Profit SKUs
Vertical SKUs for non-profits and defense contractors
Notify me
Roadmap · launch window Q4 2026
  • CMMC Level 1 / Level 2 monitoring
  • Donor DB & PCI-for-nonprofit coverage
  • Grant-compliance mapping
  • Volunteer access governance
  • Incident response for donor breach
Notify me when available →
Eligible non-profit rate

Self-Service Continuous Monitoring for Colorado 501(c)(3) organizations

Verified Colorado 501(c)(3) non-profits are eligible for our eligible-rate continuous monitoring subscription at $$199/mo (billed annually at $$1,990). Confirmation requires an active EIN and current IRS determination letter — submit on the next step.

NIST Security Policy Package

Stop paying consultants $20,000 to draft policies you'll spend 6 months reviewing. Our AI engine generates 8 NIST CSF-aligned security policies — customized to your industry, company size, regulatory environment, and risk appetite. Done in under 60 seconds.

  • 📈
    Access Control Policy
  • 🛡
    Incident Response Policy
  • 🔒
    Data Protection Policy
  • Risk Management Policy
  • 🎓
    Security Awareness & Training Policy
  • 💾
    Asset Management Policy
  • 🔁
    Business Continuity Policy
  • 🤝
    Vendor Risk Management Policy
AI-generated in under 60 seconds
DevSecOps Tier — $$149/mo

AI Governance & NIST AI RMF compliance for engineering teams using Copilot, Cursor, and production AI — includes machine-readable policies, .cursorrules generation, and CI/CD policy gates. Learn about NIST AI RMF →

See how the RhodigitalOS AI Module attacks the $10K–$25K/yr Drata / Vanta / Thoropass band — three positioning gaps, feature & pricing treatments: /ai-module product page →

One-Time Purchase

NIST Policy Package

Access Control Incident Response Data Protection Risk Management Security Training Asset Management Business Continuity Vendor Risk Mgmt
Starting at $$299 one-time
Generation fee scoped to profile depth; one-time, instant portal access.
Get Your Policies

What's included

Every engagement is built around your business, not a template. Here's what you get regardless of tier.

🌟

Senior Security Executive

Not a project manager or junior analyst. You work directly with a practitioner who has built and run security programs at scale.

📋

Clear Documentation

Policies, procedures, and roadmaps you can actually use. No binders collecting dust on a shelf.

💬

Direct Communication

Slack, email, and calls — not a ticketing system. You reach the person doing the work.

📊

Progress Reporting

Quarterly reviews with metrics that matter to your business, not generic compliance checklists.

🛡

Incident Response

When something goes wrong, you have a seasoned responder on the line — not a panic button that rings an answering service.

🌐

Flexible Engagement

Scale up or down as your needs evolve. No multi-year contracts locking you in before you've seen results.

Powered by RhodigitalOS — generated policies, scoring, continuous monitoring.

Backed by Rhodigital Limited — advisor calls, board briefings, escalation. Brian Rhodes, Founder, is the principal on every advisor-led engagement.

Find the right fit for your organization

A free 30-minute assessment to map your security needs to the right tier. Whether you're a growing business or a mission-driven non-profit — no pitch deck, no pressure. Just a conversation about where you are and where you need to go.

Book a Free Assessment
Typical response within 24 hours

Common questions

Straight answers to the questions we hear most from prospects evaluating fractional CISO services.

All tiers are month-to-month after an initial 3-month term. We ask for 90 days to establish baseline and show meaningful progress — after that, you're free to adjust or exit with 30 days notice.
Managed security providers (MSSPs) operate tools and respond to alerts. We provide strategic direction — the person who decides which tools to buy, what compliance means for your roadmap, and how to communicate security to your board. Think of us as the CISO, not the SOC.
Self-Service tier works best for early-stage companies and small nonprofits under 50 people establishing security foundations. Advisor-Led is designed for 50–500 person organizations — scaling businesses and mid-size nonprofits navigating compliance, donor data protection, or SOC 2. Fractional CISO engagements are built for organizations with complex regulatory requirements, board-level reporting needs, or significant third-party risk exposure.
Yes. The NIST Policy Package is available standalone starting at $$299 and is included at no additional cost in Advisor-Led and Fractional CISO engagements — we build it into your program from the start as your policy foundation.
Yes. We routinely sign BAAs for HIPAA-regulated clients and can accommodate other standard contractual security requirements. Fractional CISO engagements typically include a full security questionnaire response process.
Common scenario. We embed as a senior advisor who mentors your team, fills gaps in expertise (cloud security, incident response, compliance), and handles things your team doesn't have bandwidth for. You keep the institutional knowledge; we bring the depth.