Cloud Sentry
Proof

The $48,000 line item.

A 100-employee company typically spends about $48,000 a year on this stack of tool subscriptions alone, before anyone operates any of it.

This page is the math behind that sentence. Seven subscription categories (one usually rides along inside the compliance platform, and another can ride inside your service desk if you pay to move up a tier), three spend scenarios, and a source with a date on every line. It was written to be forwarded. The people and the operated work sit in a second layer below it.

Prepared July 20267 line items, 3 scenariosUSD, annual

Where the typical year goes

In the typical scenario the tool stack comes to $48,000 a year. Compliance automation and questionnaire response together carry two thirds of it.

  • Service desk and portal$3,400 · 7.1%
  • IT asset management$3,000 · 6.3%
  • Compliance automation$20,000 · 41.7%
  • Risk register and GRC$0 · 0.0%
  • Security awareness training$3,000 · 6.3%
  • Access lifecycle$8,400 · 17.5%
  • Trust center and questionnaire response$10,200 · 21.3%

Shares are rounded to one decimal and may not sum to exactly 100.

Schedule ARef CS/PROOF/2026-07 · Rev C

Annual tool subscription spend, 100-employee baseline

Basis: published list prices and marketplace contract mediansScope: software subscriptions onlyCurrency: USD per yearPrepared: July 2026

Annual tool subscription spend for a 100-employee company across 7 categories, with low, typical, and high scenarios in US dollars per year, and the sources behind each line.
LineCategorySources and datesLowTypicalHigh
01Service desk and portalTicketing and a help center for a two-to-four-agent support team.Jira Service Management median actual contract $588 per year (Costbench, July 2026); Freshservice median $3,400 per year (Costbench); high derived from Zendesk Suite Professional at $115 per agent per month for four agents (zendesk.com, July 2026).$588$3,400$6,000
02IT asset managementA current inventory of hardware and software, each asset carrying an owner, a location, and a lifecycle state.Low is the free path: Snipe-IT self-hosted is free and open source with no asset or user cap (snipeitapp.com, July 2026), and Lansweeper's free tier covers up to 100 assets (Costbench, July 2026). Bundling into the service desk is the other cheap route, but it buys a tier upgrade rather than a free feature: Atlassian includes Assets in Jira Service Management Premium and Enterprise, not Standard (atlassian.com packaging update, October 2024). Typical rounds down from three standalone anchors: Lansweeper Starter at $2,868 per year for up to 2,000 assets (Costbench, July 2026), Device42 Core at $2,999 per year for 101 to 500 devices (published tier pricing), and the Asset Panda median of $3,506 per year across 43 recorded purchases (Vendr, fetched July 2026). High rounds up from the bottom of a dedicated ITAM platform's band, the $11,583 low outcome for Oomnitza rather than its $40,800 median across 59 recorded purchases (Vendr, fetched July 2026).$0$3,000$12,000
03Compliance automationControl monitoring and evidence collection for SOC 2 and ISO 27001.Vanta median $20,000 per year across 365 recorded purchases (Vendr, fetched July 2026); low anchored to the Secureframe low of $7,733 (Vendr, fetched July 2026); high is the top of the 50-200 employee band with per-framework add-ons.$7,500$20,000$35,000
04Risk register and GRCA living risk register with owners and review dates.Bundled inside the compliance platform at low and typical, though risk management is gated to Vanta's higher tiers (vanta.com/pricing, July 2026), so bundling can force a tier upcharge; high reflects a standalone tool at entry level, about $12,000 per year (estimated, third-party pricing guides).$0$0$12,000
05Security awareness trainingAnnual training campaigns and phishing simulation.KnowBe4 SAT Foundation list price of $1.97 per seat per month at 100 seats (knowbe4.com, May 2026 list); Hoxhunt median $13,625 (Vendr, fetched July 2026).$2,364$3,000$13,625
06Access lifecycleJoiner, mover, and leaver automation across the identity stack.JumpCloud lifecycle at $3 per user per month (jumpcloud.com, July 2026); Microsoft Entra ID Governance at $7 per user per month (microsoft.com); Okta lifecycle plus governance at about $14 per user per month (published list, April 2026).$3,600$8,400$16,800
07Trust center and questionnaire responsePublishing a security profile and answering customer questionnaires.Free publishing tiers exist (Conveyor and Whistic); HyperComply median $10,200 per year (Vendr, fetched July 2026); SecurityPal concierge median $33,000 per year (Vendr, fetched July 2026).$0$10,200$33,000
Total, tool subscriptions$14,052$48,000$128,425
Rounded for prose$14.1K$48.0K$128.4K

Contract medians courtesy of Vendr marketplace data, fetched July 2026. Vendr medians describe negotiated contracts across many buyer sizes, so they can run above what a 100-employee company usually signs; where that skew matters, the low column models beneath the median and the line says so.

Reconciliation to the headline number

The typical column totals $48,000. Everywhere else on this site we round that to about $48,000. Every dollar of it is subscription spend; the people to run these tools are the second layer below.

The low, typical, and high figures are Cloud Sentry estimates built on the anchors cited on each line. Prices drift, so check the dates before you circulate this.

The second layer

Then there are the people the schedule leaves out.

Schedule A is subscriptions only. Beneath every one of those tools sits work someone has to do, and above them sits the leadership that decides what to do. A company that assembles this itself either hires for that layer or retains it. Here is what it costs on the open market, held to the same sourcing discipline. We give ranges rather than one number, because this layer varies far more than software list prices do.

Fractional security and technology leadership

A named security and technology lead: virtual CISO work, plus the CTO, CIO, and AI-governance advisory that arrives in the same seat.

$85,000 to $145,000 a year

What a company this size typically pays for a fractional or virtual security executive; fractional CTO and CIO retainers sit in a broadly similar band. The full market runs wider on both ends.

vCISO market guides: SideChannel, CISONearMe, and Cynomi (2025 to 2026). These are vendor and advisory pricing guides rather than a statistical survey, so the figure is presented as a market range, not a point estimate.

Compliance operations labor

The hours behind the compliance platform: evidence collection, access reviews, and audit preparation.

$23,000 to $40,000 a year

Twelve working weeks a year, about a fifth of a full-time role, at a loaded compliance-analyst cost.

Twelve working weeks: Vanta State of Trust 2025. Salary basis: Robert Half compliance-analyst range $79,750 to $114,250 (2026) and the US Bureau of Labor Statistics median for information security analysts, $124,910 (BLS OEWS, May 2024). Loaded at 1.25x to 1.4x base, per BLS Employer Costs for Employee Compensation (March 2025).

IT operations labor

Day-to-day administration of endpoints, identities, and the ticket queue.

$60,000 to $95,000 a year

Modeled as roughly half to two-thirds of a full-time systems administrator for a 100-person estate; the share depends on your environment.

Systems-administrator basis: BLS median $96,800 (BLS OEWS, May 2024), loaded at 1.25x to 1.4x base per BLS Employer Costs for Employee Compensation (March 2025). The full-time-equivalent share is a Cloud Sentry estimate, not a sourced figure.

These are market and wage anchors, not a Cloud Sentry quote. The operated partnership carries this whole layer inside one retainer; your figure depends on what you run today.

Still deliberately excluded

These sit outside both layers above. Unlike the people, they persist no matter who runs your program, so we leave them out entirely and the baseline stays conservative.

CPA audit fees

The audit is a pass-through, typically $10,000 to $50,000 for a Type 2 in this segment. Compliance automation prepares the evidence; the CPA firm that signs the report bills separately.

Separately billed assessments

Penetration tests and other point-in-time assessments are quoted and invoiced on their own, outside every subscription above.

Detection and response tooling

The endpoint detection and response tooling ships inside the Microsoft 365 licensing you already keep. We run it; we do not resell it to you as a separate subscription, so it is not a line on the schedule.

Microsoft 365 and endpoint licensing

Productivity suites and device licensing sit beneath all seven categories and are not counted here. Remote monitoring and management tooling sits here too: it watches and patches a device, which is a different job from keeping the register of what you own, so it stays out of line 02.

Cyber insurance

The premium is its own line item and its own renewal; nothing above includes it.

Each exclusion pushes the real number up.

Ship status, stated plainly

How to read this against the platform

All seven categories are absorbed by the platform and its operators today; the risk register and the asset register both run natively in the platform, with operator review, and security awareness we operate as part of the service.

The schedule prices one layer of three. Beneath the subscriptions sit the processes they feed: access reviews, evidence collection, questionnaire answers, the tickets themselves. Above them sits the leadership that directs the program. The second layer on this page now puts sourced ranges on those people; the processes still travel with the renewals.

Two claims, each holding on its own: about $48,000 a year goes to the licenses, and the people to run and lead the program are a second cost the schedule leaves out.

That is the stack. Nobody in it is accountable for the outcome.

Seven line items, each with its own console, renewal, and vendor who assumes you brought your own staff, and a second layer of people the schedule leaves unpriced. Cloud Sentry runs IT, security, and compliance as one function, and the work shows up in one place you can see.

The operated partnership starts with a conversation about what you run today. Send us the renewal invoices and we will rebuild this schedule with your figures before anything gets signed.

Tour the operations platform: the requests, the evidence, and the live status of what the operators run for you.