Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

XRENN Labs s.r.o.

Services & pricing

A clear scope. A clear price.

Start with an audit, choose an implementation package or bring in a specialist. Every option has a clear scope and concrete deliverables.

Recommended Starting Step

Entry audit. Your starting point.

Independent evaluation of NIS2 / Act 264/2025 Coll. applicability, ISO/IEC 27001:2023 Annex A check and risk profile.

Delivery: 10–15 business days

9 900 Kčone-time delivery · excl. VAT
Order Entry Audit
  • Formal NIS2 applicability evaluation
  • ISO 27001 Annex A controls review
  • Risk profile & remediation roadmap
The right level of support

Choose your next step.

One-time implementation builds your security foundation. Monthly support keeps your documentation, processes and priorities up to date.

Core Documentation

START

49 000 Kč

one-time implementation · excl. VAT

Included deliverables:

  • Security Policy compliant with NIS2 Articles 13-15
  • Risk Management Plan (methodology, risk register, treatment plan)
  • Business Continuity & Disaster Recovery Plan (BCP/DR baseline)
  • Incident Reporting Process setup (NÚKIB/CSIRT templates & deadlines)
  • Executive Leadership (4h) and IT Technical Team (8h) training
Select START
Recommended for SMB

BUSINESS

129 000 Kč

one-time implementation · excl. VAT

Everything in START, plus:

  • Detailed SOPs: Patch management, Privileged Access Management (PAM), Change Mgmt
  • Quarterly internal compliance audits and review checks
  • NÚKIB Regulatory Audit readiness (simulation and evidence dossier)
  • Security event monitoring (SIEM integration with Wazuh / Elastic)
  • Annual employee awareness cycle with simulated phishing campaigns
Select BUSINESS
Maximum Protection

COMPLETE

249 000 Kč

one-time implementation · excl. VAT

Everything in BUSINESS, plus:

  • Hardware XRENN™ EdgeGuardian NIS2 appliance (offline AI)
  • Continuous network anomaly monitoring and automated audit logs
  • Security KPI evaluations (MTTR, incident resolution rates, risk trends)
  • Monthly executive dashboard and board risk management reporting
  • Technical administration workshops for EdgeGuardian appliance
Select COMPLETE
SLA 1 business day

BASIC Retainer

2 900 Kč

monthly subscription · excl. VAT

What is included:

  • Legislative and methodological updates (NIS2, ZKB, ISO 27001)
  • Email support with guaranteed 1-business-day SLA
  • Quarterly priority summary & actionable recommendations
  • Discounted hourly consulting rate for ad-hoc tasks
Select BASIC Retainer
Recommended

PRO Retainer

7 900 Kč

monthly subscription · excl. VAT

Everything in BASIC, plus:

  • Monthly 1-on-1 auditor consultations (1 hour / month)
  • Continuous compliance checks and policy revisions
  • Risk prioritization & adaptation to emerging cyber threats
  • Continuous automated OSINT domain scanning (up to 10 domains included)
Select PRO Retainer
SLA 4 hours

ELITE Retainer

19 900 Kč

monthly subscription · excl. VAT

Everything in PRO, plus:

  • Weekly executive steering meetings with leadership (30 min / week)
  • Priority support with guaranteed 4-hour SLA
  • Fully outsourced compliance agenda & audit documentation management
  • Direct representation and communication with regulators (NÚKIB)
  • Strategic cybersecurity risk planning & board reporting
Select ELITE Retainer

All prices exclude VAT. The final scope and schedule are agreed before work begins.

Compare package deliverables
Individual services

Expert help. For your specific needs.

Choose a standalone service or extend your package. Rates and billing periods match the inquiry form.

Scan finding remediation

DNS & Email Domain Hardening

Configure SPF, DKIM and DMARC to reduce domain spoofing. We verify legitimate senders and mail delivery after changes.

  • One domain, one mail platform and up to 3 sending services
  • DNS backup and legitimate sender inventory before changes
  • SPF remediation and DKIM setup supported by the mail provider
  • DMARC reporting and staged enforcement after delivery checks
  • Verification scan, delivery checks and handover report

4 900 Kč

excl. VAT · one-time delivery

Start within 5 business days after access is provided; completion after verification

Scan finding remediation

HTTP Security Headers

Add CSP, Permissions-Policy and other security headers. Policies are tailored to your website and checked against its key functions.

  • One website on one domain and up to 3 key user journeys
  • Configuration backup and rollback plan
  • CSP in report-only mode first, enforcement after validation
  • Permissions-Policy, nosniff and Referrer-Policy tailored to the site; HSTS after HTTPS checks
  • Form and integration checks, verification scan and handover report

6 900 Kč

excl. VAT · one-time delivery

Start within 5 business days after access is provided; completion after verification

01

Penetration testing

Vulnerability testing of networks, web applications, APIs and cloud environments based on OSSTMM & OWASP standards.

Network + Web Baseline Package
From 25 000 Kč
LLM & AI Security Testing Module
+15 % to base scope
Deliverable
Technical report & management briefing

excl. VAT

02

Training & workshops

Hands-on workshops for leadership, developers and employees delivered on-site or via secure online platforms.

Awareness Training & Phishing (2h)
4 900 Kč
Leadership & Governance (NIS2/ISO) (4h)
8 900 Kč
Workshop – EdgeGuardian NIS2 Appliance (6h)
16 900 Kč
Secure Coding SSDP & Network Security (8h)
19 900 Kč

excl. VAT

03

ISO 27001 & ISMS

Preparation for accredited certification, ISMS documentation, internal audits and pre-certification simulation.

Entry ISMS Gap Analysis
From 9 900 Kč
Ad-hoc ISMS Consulting
2 500 Kč / hour
Pre-certification Simulation Audit
19 000 Kč

excl. VAT

04

OSINT reporting & monitoring

Keep track of domain exposure, certificates and public leak indicators. Receive reports with priorities for remediation.

Up to 10 domains
500 Kč / mo
PRO & ELITE
Included in the retainer
Expanded OSINT monitoring up to 100 assets
2 500 Kč / moPlanned feature — not available to order

excl. VAT

Side-by-side comparison

What each package includes.

Compare documentation, operational controls and technical protection. Choose the scope that fits your organization.

On smaller screens, scroll the table horizontally to see all packages.

Service / Deliverable START49 000 Kč BUSINESS129 000 Kč COMPLETE249 000 Kč
Security Policy (NIS2 Art. 13-15 compliant) ✓ ✓ ✓
Risk management plan & formal Risk Register ✓ ✓ ✓
Incident reporting workflow (NÚKIB / CSIRT templates) ✓ ✓ ✓
Leadership (4h) & IT Team (8h) training ✓ ✓ ✓
Detailed SOPs: Patch management, PAM, Change Mgmt — ✓ ✓
Quarterly internal compliance audits & checks — ✓ ✓
Simulated NÚKIB regulatory audit & evidence dossier — ✓ ✓
SIEM event monitoring integration (Wazuh / Elastic) — ✓ ✓
Annual employee awareness cycle & phishing simulations — ✓ ✓
Hardware XRENN™ EdgeGuardian NIS2 offline AI appliance — — ✓
Continuous network anomaly detection & automated audit logs — — ✓
Monthly executive dashboard & risk management reporting — — ✓

excl. VAT · one-time implementation

Before you decide

Answers to your questions.

Scope, delivery, billing and the next step. Everything you need to choose your service.

Where should we start, and does NIS2 apply to us?

An entry audit assesses your situation, reviews your ISMS and identifies the next priorities. You receive a risk profile, a remediation roadmap and a management briefing. Price: 9 900 Kč excl. VAT. Delivery: 10–15 business days.

What is the difference between the implementation packages?

START covers documentation, risk management and training. BUSINESS adds operational procedures, quarterly audits, monitoring and employee awareness. COMPLETE extends this with EdgeGuardian, audit logs, management reporting and technical workshops.

How do monthly support plans differ?

BASIC provides updates and email support within one business day. PRO adds a monthly consultation hour, document reviews and OSINT reporting for up to 10 domains. ELITE adds weekly 30-minute consultations, priority support within four hours and management of your compliance agenda.

How is the scope of a penetration test agreed?

We agree on the systems, permitted techniques, schedule and written authorization before testing. The output includes a technical report, prioritized remediation and a management briefing. LLM and AI testing can be added to the agreed scope.

Can we add ongoing OSINT reporting?

Monitoring for up to 10 domains is available with an entry audit or BASIC and is already included in PRO and ELITE. Select the add-on in the inquiry form. Expansion to 100 assets is planned and cannot yet be ordered.

Do prices include VAT, and what happens after an inquiry?

Prices exclude VAT. The inquiry form shows the calculation and separates one-time, monthly and hourly charges. We review your requirements and confirm the scope, final price and schedule with you before work begins.

Can you fix missing SPF, DMARC or security headers from my scan?

Yes. DNS & Email Domain Hardening costs 4 900 Kč and HTTP Security Headers costs 6 900 Kč, excluding VAT, as one-time services. Each covers one domain or website within the listed scope, includes verification and requires administrator access. Follow the recommendation in your dashboard or scan email to select the matching service.

Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.

newsletter-shape newsletter-top-glow-shape newsletter-bottom-glow-shape

Secure Your Organization with XRENN™

From NIS2 and ZKB compliance to penetration testing and offline EdgeAI appliances, protect your critical infrastructure today.