Pricing

Simple, transparent pricing.

We're one of the only compliance providers in Ireland and Northern Ireland who publishes their prices. Because we think you deserve to know.

Get certified

One fixed price. Audit included. No surprises.

NIS2 is now in force across Ireland. ISO 27001 covers 95% of what it requires. Our implementation packages are the fastest route to compliance for tech SMEs in Northern Ireland and the Republic of Ireland.

Micro

1–10 employees

£11,500+ VAT

Audit fees included. Most clients certified within 4–5 months.

Your price covers two things: our implementation work and the certification body's audit fees paid on your behalf. We'll give you a full breakdown of both on your discovery call.

  • Gap analysis and scoping
  • Full ISMS document suite (20+ policies)
  • Risk register and Statement of Applicability
  • Internal audit
  • Stage 1 audit (1 day) + Stage 2 audit (2 days) — fees included
  • Post-certification debrief
  • Typical audit days: 3–4
Best fit for most NI & ROI startups

Small

11–25 employees

£13,500+ VAT

Audit fees included. Most clients certified within 4–5 months.

Your price covers two things: our implementation work and the certification body's audit fees paid on your behalf. We'll give you a full breakdown of both on your discovery call.

Everything in Micro, plus:

  • Extended risk assessment covering larger team and system footprint
  • Stage 1 audit (1.5 days) + Stage 2 audit (2.5 days) — fees included
  • Supplier register review
  • Typical audit days: 4–5

Growth

26–50 employees

£16,500+ VAT

Audit fees included. Most clients certified within 4–5 months.

Your price covers two things: our implementation work and the certification body's audit fees paid on your behalf. We'll give you a full breakdown of both on your discovery call.

Everything in Small, plus:

  • Department-level risk assessment and control mapping
  • Staff awareness documentation pack
  • Stage 1 audit (2 days) + Stage 2 audit (3 days) — fees included
  • Typical audit days: 5–6

Pricing is for single-site organisations. Over 50 employees or multiple sites? Get in touch for a custom quote.

What's in the price?

Every Pillar implementation price includes two things: our work building and managing your ISMS, and the certification body's audit fees paid on your behalf. Most providers quote these separately — which means their headline price is never the real price. Ours is. We'll walk you through the full breakdown on your discovery call.

Stay certified

After certification, your ISMS needs to be maintained. Our subscriptions keep you audit-ready year-round.

For context: Vanta starts at $10,000/year and gives you software to manage compliance yourself. Pillar's Growth plan is £349/month — and we do the work for you.

Foundation

£149/mo

Your documents stay current. The rest is on you.

Best for: Clients confident managing day-to-day compliance.

  • Full document library access (always ISO 27001:2022 current)
  • Annual policy refresh — full document suite reviewed and rewritten
  • Surveillance audit calendar and deadline reminders
  • Standard update alerts when the standard changes
  • Email support (3 business day response)
Most popular

Growth

£349/mo

Pillar keeps your ISMS healthy. You stay focused on the business.

Best for: Clients who want ongoing tasks handled without hiring anyone.

  • Everything in Foundation
  • Annual internal audit conducted and reported by Pillar
  • Annual risk assessment review and update
  • Annual management review — agenda, facilitation, and minutes
  • Surveillance audit evidence pack prepared by Pillar
  • Quarterly 30-minute check-in call
  • Slack access for ad hoc questions (next business day)

Managed

£749/mo

Compliance is completely off your plate.

Best for: Clients who want a named person responsible for their compliance.

  • Everything in Growth
  • Named consultant — one person who knows your business and ISMS
  • Monthly 1-hour call (not quarterly)
  • Unlimited Slack and email support (same business day)
  • Supplier and vendor security reviews
  • Annual staff security awareness session (1-hour remote)
  • Incident response support
  • Full recertification management in year 3
  • Quarterly board-ready compliance summary

A note on surveillance audits: ISO 27001 certification requires surveillance audits in years two and three, conducted by your certification body. These are not included in our subscription plans — they are billed directly by the certification body. Our Growth and Managed subscribers receive full preparation support and evidence pack assembly for these audits as part of their plan.

All subscriptions are monthly, no lock-in contract. Cancel anytime.