Guidance
Consider any middleware or security services this application consumes and consider the share of costs, like IAM, SIEM.
Also consider services provided by InfoSec like Penetration testing, Vulnerability scanning, Security monitoring, SOC.
Consider any costs relating to 3rd party Certificates or Compliance audits