How to buy compliance consulting.
What to ask, what pricing structure signals, and the four things that should end a conversation.
Most companies buy compliance consulting once or twice, which means they are negotiating against firms who do this weekly. A few questions and one structural preference will get you most of the way to a good outcome.
Start with scope. Ask the firm to define, in the proposal, which entities, systems, locations, and data types are in scope, and what happens if that scope changes. A firm that will not commit to a boundary before signing is telling you the boundary will be discovered on your budget. Scope is the single largest cost driver in every framework we run, and it is knowable in a two-hour session.
Then ask what you receive. Deliverables should be named as artifacts, not activities: a System Security Plan, a policy suite with a stated count, a Statement of Applicability, an evidence library with defined ownership per control. "Advisory support" is not a deliverable. "Weekly office hours" is a cadence, not an outcome.
Pricing structure carries more signal than the number. Fixed fee against a defined scope means the firm has done this often enough to estimate it and is willing to carry the risk of being wrong. Time and materials transfers that risk to you and rewards inefficiency — the longer it takes, the more the firm earns. There are legitimate uses for hourly work, mostly in genuinely undefined discovery, but a fixed-scope framework implementation is not one of them.
Ask who does the work. The people in the pitch should be the people in the weekly session. Ask directly whether any part of the engagement is subcontracted, and to whom. Ask how many times the firm has taken a client through this specific framework to a successful assessment, and ask for the failure cases too — the honest answer includes at least one.
Four things should end the conversation. A firm that offers to both prepare you and perform your formal assessment, in frameworks where the program prohibits it. A guarantee of certification, which no consultant can give. A proposal with no named scope boundary. And a pitch that leads with breach statistics rather than with your framework, your buyer, and your timeline.