Everything we get asked, answered honestly. Most of these came from real customers.
| Framework | Lite | Standard | Pro |
|---|---|---|---|
| NIST CSF 2.0 | $49 | $79 | $129 |
| PCI DSS v4.0 | $59 | $89 | $149 |
| HIPAA | $59 | $99 | $159 |
| All 3 Bundle | $129 | — | $249 |
Pro tier is the most popular for organizations actually implementing — it's the tier that includes the full policy set, risk matrix, and implementation roadmap.
Yes. 30-day, no-questions-asked money-back guarantee. Email support@dorseyreports.com from the address you used for purchase, and we'll process the refund within 5 business days. No forms, no friction.
You permanently own the version you purchased. When that version is updated for major regulatory changes (NIST CSF revisions, new PCI DSS minor versions, HHS guidance updates), you receive the update for free as long as the underlying framework is the same major version. A move to a new major version (e.g., a hypothetical NIST CSF 3.0) is treated as a new product with a discounted upgrade path for existing customers.
The standard license covers one organization. For multi-client use, contact us about MSP / volume licensing — pricing is structured per-client at a fraction of typical consultant rates and includes:
Volume packages start at 10 clients.
No — direct resale, repackaging as your own product, or distributing the unmodified files is prohibited. However: consultants and MSPs may customize the documents for individual client engagements, deliver tailored versions as part of their services, and charge for that work. The license you're buying is to use the documents as the foundation of your work, not to substitute them for our work.
Every package includes:
.md) — easy to edit, diff, version-controlOpen and edit in any tool you like. The Markdown source is the canonical format; PDF and Word are generated from it.
Yes. They're written to be edited. Bracketed placeholders ([Company Name], [Effective Date]) make obvious where your details go. Section structure, terminology, and specific control values (password length, retention periods, review cadences) can all be adjusted to fit your environment as long as you don't drop below regulatory minimums.
Typical experience:
The package replaces drafting time, not review time. Internal review is on you.
The artifacts are designed to be audit-ready. But: passing an audit depends on:
The package gives you (1) a head start on documentation and (2) a clear list of evidence to collect. Operational reality is on you.
Pro tier includes email support for 30–60 days depending on the framework — useful for "how should I handle X" questions while you're customizing. Hands-on audit support, sitting next to you while a QSA or OCR investigator is in the room, is a separate service. Contact us if you need it.
| Generic templates ($20–40) | Consulting firm ($25K–$200K) | Us | |
|---|---|---|---|
| Audit-ready depth | No | Yes | Yes |
| All artifacts | No | Yes | Yes |
| Editable Markdown source | No | No | Yes |
| Mapped to specific citations | No | Yes | Yes |
| Worked risk-matrix scenarios | No | Yes | Yes |
| Cost | $20–40 | $25K–$200K | $49–$159 |
| Customization speed | Days | Months | Days |
We sit between "cheap and generic" and "expensive and bespoke." For most organizations, that's the right place.
Email notification to the address you purchased with. Also visible from your Gumroad library — the file timestamp updates when we ship a new version.
Yes — aligned with the 2024 update, including the new Govern function as the sixth top-level domain.
Yes — current with v4.0 and tracked for v4.0.x bulletins. Includes all the v4.0 expansions: MFA across all CDE access, payment-page script integrity (Req 6.4.3), anti-phishing technical controls (Req 5.4.1), Targeted Risk Analyses, customized vs. defined approach.
Yes. Business Associates and their subcontractors are treated as directly liable per HITECH/Omnibus, breach-notification timelines are included, and BAA terms reflect post-2013 requirements.
The package gives you the methodology, the matrix, and 10 worked examples. Operating the analysis — identifying your specific assets/threats and getting leadership signoff — is your work, as OCR expects. The package shaves weeks off that effort.
NIST CSF maps naturally to NIST SP 800-53 (which underpins FedRAMP) and CMMC, and overlaps significantly with ISO 27001 Annex A. The package is a strong starting point for those programs but isn't a one-to-one replacement — those frameworks have specific deliverables (FedRAMP SSP, CMMC SSP+POAM, ISO Statement of Applicability) that you'll need to layer on top.
Depends on your level. ASV scans are required quarterly for almost everyone with internet-facing CDE — those are external. QSA-attested Reports on Compliance are required for Level 1 merchants and most service providers; smaller merchants typically self-assess via SAQ. The package supports both paths and includes guidance on selecting both.
No — they're complementary. The downloads are the artifacts (policies, checklists, roadmap). The SaaS dashboard is the operating layer (track progress, generate reports, manage evidence over time). Many customers buy the download to start, then add the dashboard once they're past initial implementation.
Yes — engagements include:
Contact sales@dorseyreports.com with your scope and we'll scope and quote.
Browse frameworks, compare tiers, or jump straight to the dashboard.
View Pricing Start Assessment