VM3 Maturity Assessment
We score your vulnerability-management program across five levels and five operational dimensions, then hand you a ranked roadmap to the next level.
Best forTeams with a scanner and no program
From $4,500
Book an assessmentServices & Products
Focused assessments, ongoing vulnerability management, compliance readiness, and AI security — scoped to what you actually run. Every engagement is delivered by the practitioner who scoped it.
Platform AgnosticFrom maximizing your current tech stack and deploying our proprietary tools, to implementing enterprise-grade solutions, we build a plan tailored to all your needs in any budget.
Plain languageReports your board and your insurer can read, and a queue your engineers can work.
Senior deliveryThe engineer who scopes your work is the one who delivers it. No handoff to a junior, no account manager in between. English or Español.
Category 01
Our core practice, built on VM3 — our own published maturity model. For teams that scan but can’t prove risk is going down.
We score your vulnerability-management program across five levels and five operational dimensions, then hand you a ranked roadmap to the next level.
Best forTeams with a scanner and no program
From $4,500
Book an assessmentWe stand up the whole loop: asset coverage, scan cadence, triage rules, SLAs, exception handling, and reporting that survives an audit.
Best for25–250 staff, post-assessment
From $9,500
Request a quoteWe run the scan-to-fix loop on your existing tooling every cycle: triage, prioritized queue, remediation validation, and a VM3 re-score. We are not a SOC and this is not 24/7 monitoring — it is a program, run properly.
Best forOrganizations with no internal security staff
Category 02
Where most engagements start. Find out what you’re actually exposed to, in language you can take to a board or an insurer.
A full picture of your security posture: cloud and identity configuration review, external exposure scan, interviews, and a prioritized remediation plan with a plain-language readout.
Best forFirst-time buyers, 10–200 staff, insurer or customer driven
From $3,500
Get a quoteConfiguration and identity review across Microsoft 365, Entra ID, AWS, or GCP: privileged access, conditional access, logging coverage, external sharing, and misconfiguration remediation.
Best forCloud-first teams that grew faster than their config review
From $4,500
Get a quoteHands-on testing of a web or mobile application: authenticated and unauthenticated testing, access-control and business-logic flaws, API surface, and a report you can hand to a customer. Mobile testing available as an add-on.
Best forSaaS and product teams facing a customer security review
From $6,500
Scope your testWe do not offer internal network penetration testing or red-team engagements. When an engagement needs them, we say so and refer you to a vetted partner rather than stretching to cover it.
Category 03
For when a customer, an auditor, or a prime contractor is asking questions you can’t answer yet.
End-to-end Type I readiness: system description, Trust Services Criteria mapping, the full policy suite, evidence collection, vendor carve-outs, and auditor liaison. We take you to the audit, we don’t perform it.
Best forB2B SaaS with enterprise deals stalled on a report
From $12,000
Book a discovery callScope your CUI boundary, assess against NIST SP 800-171, calculate your SPRS score, and leave with an SSP outline and a POA&M. Led by a CyberAB Registered Practitioner.
Best forDefense subcontractors under DFARS pressure
From $6,500
Check eligibilityWe scope your cardholder data environment, assess it against PCI DSS v4.0, and hand you a gap report, a prioritized remediation plan, and support completing your SAQ. Our founder has run three full PCI DSS audit cycles across 300+ controls, so you get someone who has been through it rather than someone reading the standard for the first time. We prepare you for your assessment. We are not a QSA, we do not perform certified assessments, and we do not issue an Attestation of Compliance.
Best forMerchants and service providers facing an acquirer deadline or an annual SAQ
From $6,500
Get a quoteSenior security ownership without a full-time hire: roadmap, policy upkeep, vendor reviews, customer questionnaires, and a quarterly summary your board can read.
Best for25–250 staff making security decisions with nobody qualified to make them
Also available — usually added to an engagement rather than bought alone
Category 04
Two different problems. Securing the AI you’ve already switched on, and finding where AI would actually pay for itself. We do both, because we build agentic tooling ourselves — with containment boundaries and audit logging — and then we secure it.
You turned on Copilot, a chatbot, or an agent. We inventory where your data actually flows, review it against the OWASP LLM Top 10 and NIST AI RMF, check guardrails and audit logging, and tell you what to fix first.
Best forAnyone who adopted AI faster than they reviewed it
From $5,500
Book a reviewA time inventory of what your team repeats, scored on impact, confidence, and ease, and returned as a ranked automation roadmap. You find out what to automate first — and what to leave alone.
Best forOps-heavy small businesses; the buyer here is usually the owner, not IT
From $4,500
Map your opportunitiesWe build the workflow you picked from the map, with the security engineering baked in: explicit containment boundaries, human intervention points, least-privilege access, and append-only audit logging. Automation you can show an auditor.
Best forClients ready to build after an Opportunity Map
Category 05
Fixed scope, fixed price, no surprises. Tiers differ by what’s actually in scope — users, systems, cadence, depth — not by features invented to justify a bigger number.
Essential
$3,500
$2,625 during launch
Professional
$6,500
$4,875 during launch
Advanced
$11,500
$8,625 during launch
Managed VM — Essential
$1,500/mo
First month free
vCISO — Essential
$2,500/mo
First month free
vCISO — Professional
$4,500/mo
First month free
Advanced monthly tiers are available. Managed VM runs on your existing scanner — we don’t resell tooling. What moves a price: number of users, endpoints and locations; on-prem or hybrid; how many cloud platforms; testing depth; whether you need mapping to a named framework; reporting depth; regulated data such as CUI, PHI or cardholder data; and how fast you need it.
Launch offer
Celebrate our San Antonio launch with 25% off eligible cybersecurity services. Qualified engagements may also receive complimentary add-on services based on scope and availability. We deliver engagements in English or Spanish, year-round.
Add-ons are not automatic. They are subject to scope, eligibility, scheduling and availability, and we’ll tell you which apply before you sign. Eligible services and plans only; not combinable with other offers. Excludes third-party and pass-through costs such as audit fees, tooling and licences. Engagements must be signed by December 31, 2026. Invictus may decline or re-scope engagements that fall outside stated assumptions.
Questions
No. We test applications — web, mobile and API. Internal network penetration testing and red-team engagements are a different discipline and we don’t staff them. If your engagement needs one, we’ll say so and refer you to a vetted partner. We’d rather lose the work than deliver it thinly.
No. We are not a SOC and we don’t hold an incident response retainer. What we do is build and run vulnerability management programs, and prepare you for incidents — plans, playbooks and tabletop exercises that satisfy compliance controls like PCI DSS 12.10.
No, and we take no vendor commissions. We run programs on the tools you already own. If you genuinely need a tool you don’t have, we’ll tell you what to look for and leave the buying to you.
That’s our typical client. Most of our work is with organizations where security is somebody’s third job. We write for that reader, and we hand your engineers a queue rather than a PDF.
Both. We’re based in San Antonio and work on-site across the metro. Everything we deliver is remote-capable, and we work with clients outside Texas.
Sí. Podemos realizar la evaluación, la capacitación y los informes en español. No es parte de la promoción — es algo que siempre ofrecemos. / Yes. Assessments, training and reporting are available in Spanish year-round, not as a limited-time offer.
Usually within two days of a signed scope. We take on a limited number of engagements at a time deliberately — the person who scopes your work is the person who does it.
Yes to both. We carry errors and omissions, professional liability and general liability coverage, and we sign NDAs before scoping conversations as a matter of course.
That’s normal, and it’s the conversation we’re best at. Tell us what’s driving the work — an auditor, an insurer, a customer questionnaire, or a feeling that something’s been missed — and we’ll tell you honestly what you need, including when it isn’t us.