The $48,000 line item.
This page is the math behind that sentence. Seven subscription categories (one usually rides along inside the compliance platform, and another can ride inside your service desk if you pay to move up a tier), three spend scenarios, and a source with a date on every line. It was written to be forwarded. The people and the operated work sit in a second layer below it.
Where the typical year goes
In the typical scenario the tool stack comes to $48,000 a year. Compliance automation and questionnaire response together carry two thirds of it.
- Service desk and portal$3,400 · 7.1%
- IT asset management$3,000 · 6.3%
- Compliance automation$20,000 · 41.7%
- Risk register and GRC$0 · 0.0%
- Security awareness training$3,000 · 6.3%
- Access lifecycle$8,400 · 17.5%
- Trust center and questionnaire response$10,200 · 21.3%
Shares are rounded to one decimal and may not sum to exactly 100.
Annual tool subscription spend, 100-employee baseline
Basis: published list prices and marketplace contract mediansScope: software subscriptions onlyCurrency: USD per yearPrepared: July 2026
| Line | Category | Sources and dates | Low | Typical | High |
|---|---|---|---|---|---|
| 01 | Service desk and portalTicketing and a help center for a two-to-four-agent support team. | Jira Service Management median actual contract $588 per year (Costbench, July 2026); Freshservice median $3,400 per year (Costbench); high derived from Zendesk Suite Professional at $115 per agent per month for four agents (zendesk.com, July 2026). | $588 | $3,400 | $6,000 |
| 02 | IT asset managementA current inventory of hardware and software, each asset carrying an owner, a location, and a lifecycle state. | Low is the free path: Snipe-IT self-hosted is free and open source with no asset or user cap (snipeitapp.com, July 2026), and Lansweeper's free tier covers up to 100 assets (Costbench, July 2026). Bundling into the service desk is the other cheap route, but it buys a tier upgrade rather than a free feature: Atlassian includes Assets in Jira Service Management Premium and Enterprise, not Standard (atlassian.com packaging update, October 2024). Typical rounds down from three standalone anchors: Lansweeper Starter at $2,868 per year for up to 2,000 assets (Costbench, July 2026), Device42 Core at $2,999 per year for 101 to 500 devices (published tier pricing), and the Asset Panda median of $3,506 per year across 43 recorded purchases (Vendr, fetched July 2026). High rounds up from the bottom of a dedicated ITAM platform's band, the $11,583 low outcome for Oomnitza rather than its $40,800 median across 59 recorded purchases (Vendr, fetched July 2026). | $0 | $3,000 | $12,000 |
| 03 | Compliance automationControl monitoring and evidence collection for SOC 2 and ISO 27001. | Vanta median $20,000 per year across 365 recorded purchases (Vendr, fetched July 2026); low anchored to the Secureframe low of $7,733 (Vendr, fetched July 2026); high is the top of the 50-200 employee band with per-framework add-ons. | $7,500 | $20,000 | $35,000 |
| 04 | Risk register and GRCA living risk register with owners and review dates. | Bundled inside the compliance platform at low and typical, though risk management is gated to Vanta's higher tiers (vanta.com/pricing, July 2026), so bundling can force a tier upcharge; high reflects a standalone tool at entry level, about $12,000 per year (estimated, third-party pricing guides). | $0 | $0 | $12,000 |
| 05 | Security awareness trainingAnnual training campaigns and phishing simulation. | KnowBe4 SAT Foundation list price of $1.97 per seat per month at 100 seats (knowbe4.com, May 2026 list); Hoxhunt median $13,625 (Vendr, fetched July 2026). | $2,364 | $3,000 | $13,625 |
| 06 | Access lifecycleJoiner, mover, and leaver automation across the identity stack. | JumpCloud lifecycle at $3 per user per month (jumpcloud.com, July 2026); Microsoft Entra ID Governance at $7 per user per month (microsoft.com); Okta lifecycle plus governance at about $14 per user per month (published list, April 2026). | $3,600 | $8,400 | $16,800 |
| 07 | Trust center and questionnaire responsePublishing a security profile and answering customer questionnaires. | Free publishing tiers exist (Conveyor and Whistic); HyperComply median $10,200 per year (Vendr, fetched July 2026); SecurityPal concierge median $33,000 per year (Vendr, fetched July 2026). | $0 | $10,200 | $33,000 |
| Total, tool subscriptions | $14,052 | $48,000 | $128,425 | ||
| Rounded for prose | $14.1K | $48.0K | $128.4K | ||
Contract medians courtesy of Vendr marketplace data, fetched July 2026. Vendr medians describe negotiated contracts across many buyer sizes, so they can run above what a 100-employee company usually signs; where that skew matters, the low column models beneath the median and the line says so.
Reconciliation to the headline number
The typical column totals $48,000. Everywhere else on this site we round that to about $48,000. Every dollar of it is subscription spend; the people to run these tools are the second layer below.
The low, typical, and high figures are Cloud Sentry estimates built on the anchors cited on each line. Prices drift, so check the dates before you circulate this.
The second layer
Then there are the people the schedule leaves out.
Schedule A is subscriptions only. Beneath every one of those tools sits work someone has to do, and above them sits the leadership that decides what to do. A company that assembles this itself either hires for that layer or retains it. Here is what it costs on the open market, held to the same sourcing discipline. We give ranges rather than one number, because this layer varies far more than software list prices do.
Fractional security and technology leadership
A named security and technology lead: virtual CISO work, plus the CTO, CIO, and AI-governance advisory that arrives in the same seat.
$85,000 to $145,000 a year
What a company this size typically pays for a fractional or virtual security executive; fractional CTO and CIO retainers sit in a broadly similar band. The full market runs wider on both ends.
vCISO market guides: SideChannel, CISONearMe, and Cynomi (2025 to 2026). These are vendor and advisory pricing guides rather than a statistical survey, so the figure is presented as a market range, not a point estimate.
Compliance operations labor
The hours behind the compliance platform: evidence collection, access reviews, and audit preparation.
$23,000 to $40,000 a year
Twelve working weeks a year, about a fifth of a full-time role, at a loaded compliance-analyst cost.
Twelve working weeks: Vanta State of Trust 2025. Salary basis: Robert Half compliance-analyst range $79,750 to $114,250 (2026) and the US Bureau of Labor Statistics median for information security analysts, $124,910 (BLS OEWS, May 2024). Loaded at 1.25x to 1.4x base, per BLS Employer Costs for Employee Compensation (March 2025).
IT operations labor
Day-to-day administration of endpoints, identities, and the ticket queue.
$60,000 to $95,000 a year
Modeled as roughly half to two-thirds of a full-time systems administrator for a 100-person estate; the share depends on your environment.
Systems-administrator basis: BLS median $96,800 (BLS OEWS, May 2024), loaded at 1.25x to 1.4x base per BLS Employer Costs for Employee Compensation (March 2025). The full-time-equivalent share is a Cloud Sentry estimate, not a sourced figure.
These are market and wage anchors, not a Cloud Sentry quote. The operated partnership carries this whole layer inside one retainer; your figure depends on what you run today.
Still deliberately excluded
These sit outside both layers above. Unlike the people, they persist no matter who runs your program, so we leave them out entirely and the baseline stays conservative.
CPA audit fees
The audit is a pass-through, typically $10,000 to $50,000 for a Type 2 in this segment. Compliance automation prepares the evidence; the CPA firm that signs the report bills separately.
Separately billed assessments
Penetration tests and other point-in-time assessments are quoted and invoiced on their own, outside every subscription above.
Detection and response tooling
The endpoint detection and response tooling ships inside the Microsoft 365 licensing you already keep. We run it; we do not resell it to you as a separate subscription, so it is not a line on the schedule.
Microsoft 365 and endpoint licensing
Productivity suites and device licensing sit beneath all seven categories and are not counted here. Remote monitoring and management tooling sits here too: it watches and patches a device, which is a different job from keeping the register of what you own, so it stays out of line 02.
Cyber insurance
The premium is its own line item and its own renewal; nothing above includes it.
Each exclusion pushes the real number up.
Ship status, stated plainly
How to read this against the platform
All seven categories are absorbed by the platform and its operators today; the risk register and the asset register both run natively in the platform, with operator review, and security awareness we operate as part of the service.
The schedule prices one layer of three. Beneath the subscriptions sit the processes they feed: access reviews, evidence collection, questionnaire answers, the tickets themselves. Above them sits the leadership that directs the program. The second layer on this page now puts sourced ranges on those people; the processes still travel with the renewals.
Two claims, each holding on its own: about $48,000 a year goes to the licenses, and the people to run and lead the program are a second cost the schedule leaves out.
That is the stack. Nobody in it is accountable for the outcome.
Seven line items, each with its own console, renewal, and vendor who assumes you brought your own staff, and a second layer of people the schedule leaves unpriced. Cloud Sentry runs IT, security, and compliance as one function, and the work shows up in one place you can see.
The operated partnership starts with a conversation about what you run today. Send us the renewal invoices and we will rebuild this schedule with your figures before anything gets signed.
Tour the operations platform: the requests, the evidence, and the live status of what the operators run for you.