Onyx Blog

Insights on security and compliance

Practical, no-nonsense guidance on PCI, ISO 27001, GDPR, penetration testing, and building an audit-ready security posture.

Cybersecurity Due Diligence: A Buyer's Guide

Cybersecurity due diligence helps the acquirer assess security risk before an M&A deal, investment, partnership, or vendor onboarding. What it covers, when you need it, and how to approach it.

PCI Compliance Cost: What Drives the Price

PCI compliance cost depends on your merchant level and how you handle cardholder data: validation, scanning, penetration testing, remediation, and ongoing effort. How to budget and reduce the cost of PCI compliance.

HIPAA Compliance Cost: What Drives the Price

HIPAA compliance cost: driven by PHI volume, covered entities vs business associates, risk analysis, safeguards, and audit scope. No certificate exists.

ISO 27001 Certification Cost: What Drives the Total

ISO 27001 certification cost has three parts: the certification body fee plus surveillance, ISMS implementation, and internal time. What drives each, how to reduce costs, and how to budget.

SOC 2 Audit Cost: What You Will Actually Pay

SOC 2 audit cost explained: the CPA auditor fee plus readiness work. What drives each, the key factors that move the number for Type 1 and Type 2 audits, and how to keep compliance costs down.