2-2.5+ million USD depending for a full chain with persistence (lower end of range is for iOS higher end is for Android).
That is probably the lower end of the rough cost to buy that capability which you can use as many times as you want.
https://zerodium.com/images/zerodium_prices_mobiles.png
> Is it sensitive to compromise a phone, now that there is a national law allowing it, passed through a democratic process?
The technology itself is sensitive, when you buy a full chain exploit like the ones that have the public bounty price above, if it gets burnt it's useless for everyone else who bought it after its patched.
Generally exploit brokers don't like it when you burn their exploits.