Total the annual cost of a compliance programme across audit fees, consultancy, internal effort, tooling and evidence, per employee and per framework.
The single biggest hidden line in most programmes is evidence collection, because it is spread across dozens of people in hours nobody books to compliance, and annualising the quarterly figure at a blended rate usually produces the largest surprise. The overlap saving reflects a real property of the frameworks: ISO 27001, SOC 2 and PCI DSS ask for the same access reviews and change records in different words. Compliance budgets are argued over audit fees, which are usually the smallest controllable line, while the internal effort that dwarfs them never appears in a business case. These are cost estimates from your own inputs, not quotes.
Compliance Cost
Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each.
Overlap and automation savings
Control mapping saving = 8% of total cost per additional framework, capped at 30%, on the basis that overlapping frameworks share most of their control tests.
Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each. The single biggest hidden line in most programmes is evidence collection, because it is spread across dozens of people in hours nobody books to compliance, and annualising the quarterly figure at a blended rate usually produces the largest surprise. The overlap saving reflects a real property of the frameworks: ISO 27001, SOC 2 and PCI DSS ask for the same access reviews and change records in different words.
Compliance budgets are argued over audit fees, which are usually the smallest controllable line, while the internal effort that dwarfs them never appears in a business case. These are cost estimates from your own inputs, not quotes.
This calculator takes 13 inputs: Frameworks in scope, Employees in the organisation, Systems in audit scope, External audit and certification fees, Consultancy days used, Consultancy day rate, Full-time equivalents on compliance, Fully loaded cost per FTE, GRC tooling and licences, Hours spent collecting evidence each quarter, Blended internal hourly cost, Penetration tests per year, Cost per penetration test. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
It is here, deliberately, as a blunt unit cost — but the marginal cost of a second framework is much lower than the first because the control set overlaps heavily. Use the overlap saving line for the marginal question and the per-framework figure only for comparing your programme with a peer's.
That is the upper end of what continuous control monitoring typically delivers, and only for controls whose evidence is machine-generated: access reviews, configuration baselines, patch levels, backup success. Controls that depend on human judgement, like risk assessment or supplier due diligence, barely improve.