
Fixed packages. Prices you can see before you call.
Early customers can still get the full sprint as a pilot in exchange for honest feedback. Everything else is fixed-price and confirmed in writing before work starts.
Four ways to work with us.
All prices exclude VAT. No hourly creep, no automatic renewal, no long-term lock-in.
Pilot readiness sprint
Limited places · in exchange for feedback
Test the full process and customer comprehension.
First reference customers who want the full sprint at no cost.
- Full 10-day readiness sprint
- All six modules
- Management report + 30/60/90 roadmap
- Structured feedback session
Readiness Sprint
Fixed price, excl. VAT
The full fixed-scope sprint, delivered in 10 business days.
SMEs that want a clear picture of where they stand, fast.
- Fixed 10-business-day scope
- All six weighted modules
- Reviewed findings before delivery
- Management presentation
- Evidence mapping annex
- 30/60/90 remediation roadmap
Sprint + Industrial/OT
Fixed price, excl. VAT
The full sprint plus a safe industrial readiness annex.
Manufacturing and automation SMEs with connected production.
- Everything in the Readiness Sprint
- Safe industrial/OT readiness annex
- Downtime scenario checklist
- Integrator access review
Continuous readiness
Available after a completed sprint
Keep the score and the evidence current between sprints.
Teams that need their score and evidence to stay current.
- Quarterly re-scoring
- Remediation support
- Evidence upkeep
- Named readiness contact
Pricing is confirmed in writing before any work starts. Travel is only charged if an on-site day is agreed in advance.
From call to fixed price in a week.
- 1A 20-minute discovery call about your size, sector and systems.
- 2A short written scope: modules covered, what we need, the fixed price.
- 3You confirm in writing. We agree the two working sessions.
- 4Ten business days later you get the report, roadmap and presentation.
What is not included
- Penetration testing or offensive security work
- Certification, audit or legal sign-off
- Tool licences, hardware or third-party subscriptions
- Hands-on remediation inside your systems
- 24/7 monitoring or incident response retainers
We say so openly because a readiness sprint is a decision tool, not a certification or a replacement for specialist testing.
Commercial questions we hear most.
Do you certify us for NIS2 or ISO/IEC 27001?
No. Cybnivo provides cybersecurity readiness assessments and evidence-gap mapping. NIS2 is a regulatory obligation for organizations within scope; Cybnivo does not issue a NIS2 certification. ISO/IEC 27001 certification, where pursued, is a separate process handled by an appropriate certification body.
Will you test or scan our systems?
Only with written authorization and an agreed scope. External exposure checks are permission-based and non-intrusive. We never run active tests on production or industrial systems.
Is the report written by AI?
AI drafts explanations and structure. The Cybnivo cybersecurity lead reviews and approves every customer-facing finding before it reaches you. That review gate is not optional.
How much of our time does the sprint need?
The sprint is designed to minimize customer effort: a kick-off, the questionnaire, two short interviews and the final 60-minute management readout. Exact customer time is confirmed during scoping and will be measured during our pilot phase.
We already have an IT provider. Does this replace them?
No. We give you a neutral picture and a prioritized plan. Your MSP or internal IT can use the roadmap to prioritize implementation.
Do you work outside Germany?
The technical readiness model is international. Germany and the EU are our first markets; the regulatory mapping layer changes by country and framework.
Pilot slots are limited per month.
We only run a small number of sprints at a time so each one gets a proper review before delivery.
Permission-based · Reviewed before delivery
