Three ways to buy.

The kit content is identical across tiers. The difference is how much help you want with the implementation work. Pick the tier that matches your time, your starting place, and your appetite for working alongside a Foxtrot consultant.


The three tiers.

Self-Service

$499 / one-time

plus $99 / year maintenance

The complete kit. The implementation guide, all 48 templates, every framework crosswalk, the state safe harbor self-attestation, and 12 months of updates. You implement at your own pace, with the guide as your partner.

For owners, operators, IT managers, and operations leads with the time and capacity to work through the 90-day program independently.

  • 174-page implementation guide
  • All 48 supporting templates
  • Framework crosswalks (CIS · NIST · SOC 2)
  • State safe harbor self-attestation
  • 12 months of updates included
Buy Self-Service Not sure this fits? Book a 15-min scoping call.

Onboarding

$748 / one-time

plus $99 / year maintenance

Everything in Self-Service, plus a one-hour scoping call with a Foxtrot consultant. We walk through your environment, point you at the right starting place in the implementation guide, and answer the questions that come up before you begin.

For buyers who want a quick human check before they start.

  • Everything in Self-Service
  • One-hour scoping call
  • Implementation start-point guidance
  • Pre-launch Q&A
Buy Onboarding

Managed Implementation

$1,999 / one-time

plus $99 / year maintenance

Everything in Self-Service, plus eight hours of consulting time. A Foxtrot consultant inventories your environment, customizes the Phase 1 templates for your business, and works alongside you through the foundational controls (Days 1-30).

For buyers who want a partner alongside them for the heaviest phase.

  • Everything in Self-Service
  • Eight hours of Phase 1 consulting
  • Environment inventory
  • Phase 1 templates customized for you
  • Hands-on through Day 30
Buy Managed Implementation

Not sure which tier? Tell us your situation

Side by side.

Tier comparison
Self-Service Onboarding Managed Implementation
Price (one-time)$499$748$1,999
Maintenance (per year)$99$99$99
Implementation guide (174 pages)
48 supporting templates
Framework crosswalks (CIS · NIST · SOC 2)
State safe harbor self-attestation
12 months of updates
One-hour scoping call
Phase 1 hands-on consulting8 hours
Customized Phase 1 templates
Right forSelf-implementersQuick check before startingHands-on partner

The kit, in every tier.

Every tier ships with the same content, sized for 5-99 employee businesses. Tiers don't change what you get; they change how much help you get implementing it.

The implementation guide. 174 pages, nine sections, organized around the 90-day program.

15 policies. Each one a template you customize and adopt.

18 procedures. Each one referenced from a specific point in the implementation guide.

12 questionnaires and checklists. Including the cyber insurance application cheat sheet, the customer questionnaire response template, the vendor security questionnaire, and the quarterly compliance health check.

3 framework crosswalks. CIS Controls to NIST CSF 2.0, CIS Controls to SOC 2 Trust Services Criteria, and the state safe harbor crosswalk for Texas, Connecticut, Ohio, and Utah.

Delivery as a downloadable archive (Word and Markdown formats) plus a PDF implementation guide. A license key arrives by email.

The annual maintenance plan.

Your first year of updates is included in the purchase price. After that, the maintenance plan is $99 per year and renews automatically.

What you get for $99 per year

Every kit update we ship during the year. CIS Controls revisions when CIS publishes them. Updated framework crosswalks when NIST CSF or SOC 2 change. New stakeholder communication templates as buyer patterns surface. New FAQ entries based on what buyers actually ask.

Why it's a separate plan

Compliance frameworks change. State safe harbor statutes get amended. New threats emerge. The kit you buy on Day 1 should not be the same kit you have on Day 365 of Year 5. The maintenance plan funds the work of keeping the kit current.

What happens if you let it lapse

Your kit content is yours forever. The maintenance plan covers updates. If you let maintenance lapse, you can re-up at any time, but you pay catch-up for missed years (capped at two years). You don't lose what you bought; you just don't get newer versions until you renew.

Cancelling

Cancel any time from the customer dashboard. No phone call required.

You can upgrade later.

If you buy Self-Service and decide a few weeks in that you'd benefit from a scoping call, you can add the Onboarding tier for $249. Available within 12 months of your original purchase.

Upgrades from Self-Service to Managed Implementation are also available; pricing reflects the difference between the two tiers ($1,500). Talk to us first to schedule the consulting time.

Questions before you buy.

Is there a free trial?

No. The kit is a delivered product, not a subscription, so a trial doesn't fit the structure. What we do instead: a sample chapter from the implementation guide is available on the Kit page, and the FAQ answers most of the "is this for me?" questions you'd otherwise ask in a trial.

Can I see a sample before I buy?

Yes. Read a sample chapter from the implementation guide on the Kit page.

Do you offer refunds?

Yes. If the kit doesn't fit your business, request a refund within 30 days of purchase. Refunds are full and processed within five business days.

Is the price per business or per user?

Per business. One license covers everyone in your organization who needs access to the kit content.

Can my MSP or consultant buy this on my behalf?

Yes. The buyer field on the purchase form accepts a different name and email than the licensee. If you're an MSP buying for a client, talk to us first about whether a multi-client arrangement makes sense.

What if I'm a contractor with NIST 800-171 or CMMC needs?

TACSOP doesn't address CMMC specifically; ComplianceForge does. But if you have secondary compliance needs (cyber insurance, customer questionnaires, state safe harbor), TACSOP serves those alongside CMMC-specific documentation. See the Honest Scoping section on the home page.

What if my practice is healthcare or handles PHI?

TACSOP doesn't address the HIPAA Security Rule specifically. Specialized HIPAA documentation vendors handle that framework. If your practice has secondary compliance needs (cyber insurance, vendor security questionnaires, state safe harbor), TACSOP serves those alongside HIPAA-specific documentation. The kit covers what's adjacent to HIPAA, not HIPAA itself.

What about attorney-client privilege at my law firm?

TACSOP doesn't determine privilege questions; those remain a matter for counsel. The kit's documentation is your firm's documentation, written for your business by your business. How privilege applies to the documentation, and to any incident response work that draws on it, is a question for your firm's professional responsibility process. We can speak to how other law practices have approached this on a scoping call.

What if my business has OT, ICS, or specialized industrial systems?

TACSOP documents the IT side of your security program. OT and ICS systems (PLCs, SCADA, plant-floor controls) need vendor-specific guidance the kit doesn't replace, and Managed Implementation focuses on IT scope as well. If your environment includes OT or specialized industrial systems, talk to us first; we'll let you know honestly whether the kit and the consulting hours are the right fit before you buy.

What's included in the Managed Implementation hours? Do they expire?

The eight hours cover Phase 1 work: inventorying your environment, customizing the Phase 1 templates for your business, and working alongside you through the foundational controls (Days 1-30). The specifics of how the hours are scoped and used are worked out on the kickoff call, including whether any time can be banked for later questions. If you'd like to know more before buying, talk to us first.

When I buy Onboarding, how does the scoping call get scheduled?

After purchase, a Foxtrot consultant reaches out to schedule the one-hour call. You don't need to book anything at checkout; we'll find a time that works.

Can I buy now and start later?

Yes. Your license key and kit arrive at purchase; you can start whenever your calendar allows. CPAs typically implement outside tax season, retail outside Q4, schools during summer. The 12 months of included updates run from your purchase date, so buying months before you start means a portion of your update window passes before you begin. If you'd rather time the purchase to your start date, that's reasonable too.

Read the full FAQ

When you're ready.

Pick the tier that fits, or read more first. No rush.