Pricing & Scoping
Security Retainer vs One-Time Audit: Which Model Fits Your Team?
Two different ways to buy security work, and the situations each one actually fits.
LOZULA Senior Security Research Team
2026-04-28
6 min read
Key Takeaways for Security Teams
- A one-time audit is a snapshot, useful but it ages the moment new code ships.
- A retainer trades a lower per-engagement cost for continuous coverage as the codebase evolves.
- Many teams use both: an initial audit before launch, then a retainer for ongoing changes.
A one-time audit gives point-in-time assurance for a specific release; a security retainer provides ongoing access to a security team as your codebase keeps shipping. Neither replaces the other, they answer different needs.
When a One-Time Audit Makes Sense
A point-in-time engagement fits a defined, bounded scope with a clear deadline.
- •Pre-launch or pre-mainnet review of a specific, largely-frozen codebase
- •Compliance requirements that specifically call for an independent point-in-time assessment
- •Fundraising or listing requirements where a published audit report is the deliverable
When a Retainer Makes More Sense
Codebases that ship continuously outgrow the value of a single snapshot review fairly quickly.
- •Teams shipping weekly or biweekly, where a point-in-time audit is stale within a month
- •Organizations that want ongoing access to a security team for design reviews, not just a report
- •Startups scaling fast, where new attack surface is added faster than a single audit can cover