PREVIEWCISO360AI is offered as-is while in preview. Features and data may change. Learn more.

Plans for every stage of GRC

Start free, pick any two modules on Starter, get audit-ready on Essentials, run a full programme on Complete. Yearly billing saves roughly 17%.

SPECIAL: 50% off annual plans for Start-up, Health, EDU and NFPs.

All prices in USD, excluding taxes such as GST. Terms apply.

Free
Try the platform
$0/mo

$0/yr billed yearly

Evaluate — or very small teams & solo operators

Starter
Any 2 of 4 modules — à la carte
$99/mo

$990/yr billed yearly

Small teams that need just one or two capabilities

Essentials
Get audit-ready on one framework
$360/mo

$3,600/yr billed yearly

SMB starter — one framework, light cadence

Most popular
Complete
Multi-framework GRC + AI vCISO
$999/mo

$9,990/yr billed yearly

Full SMB GRC programme

Enterprise / Custom
Enterprise GRC with SSO, workflows & on-premise scan workers
Contact sales

Mid-market & regulated enterprise

What the Free plan includes

Free is a real working account, not a demo — you can run your governance programme end to end on it. Here is what you get, and what a paid plan adds.

  • Governance and compliance, and the starter policy library — no unlock needed
  • A NIST CSF 2.0 self-assessment with coverage, maturity and gap analytics
  • Compliance reports, the activity feed and the typed audit log
  • Your own AI agent over our MCP server, plus a 10-credit AI Sidekick trial
  • Attack-surface and identity-exposure scanning need a DNS ownership check, an invitation code or a paid plan
  • Lists show the 20 highest-risk rows; a paid plan shows all of them
  • The attack-surface graph, raw scan-event history, findings and configuration reports, and data export are paid

Compare every feature

FeatureFreeStarterEssentialsCompleteEnterprise
AI Sidekick — your built-in AI vCISO
AI vCISO assistant (chat, guidance, drafting)10-credit trial
AI personas — all five (CISO, Compliance, Analyst, IR, Pentester)
Hosted AI credits / month10 (signup trial)1003601,000Unlimited
Top-up credits
AI propose / approve loop on evidence & controlsBasicBasic
AI risk derivation from compliance gapsPreview
Scheduled AI workflows (gap review, assessment cadence)Monthly onlyMonthly only
Bring your own agent (your model & key) — all tiers
Native MCP server — connect Claude, Copilot or Cursor
MCP tools (reads + scope-gated actions)Full setFull setFull setFull setFull set
Listed in the Claude connector directory (sign in, no key to copy)
Agentic API keys (OAuth 2.1 or scoped)
Safe actions — scope-gated, higher-risk ones human-approved
Content modules
Modules includedAny 2 of 4Any 2 of 4All 4All 4All 4
GRC / complianceSelectableSelectable
Attack surface (CTEM)SelectableSelectable
Identity exposure & dark-web monitoringSelectableSelectable
Cloud posture (CSPM)SelectableSelectable
Compliance & Standards
Standards available1 — NIST CSF 2.0 (read-only)2 active baselines2 active baselines5 active baselines (any of 17)Unlimited active + custom
Control ↔ requirement mapping (bidirectional)
Cross-framework derivation (NIST CSF hub)
Bring your own standard — custom framework import + builder
Assessments & evidence
Onboarding wizard
Assessment runs1 (read-only)UnlimitedUnlimitedUnlimitedUnlimited
Control state machine (claimed → validated → gap → managed)View only
Coverage / maturity / gap analyticsBasic snapshot
Manual evidence uploadUp to 0.5 GBUp to 1 GBUp to 2 GBUnlimited
Evidence expiry tracking + reminders
Risk management
Org-level risk appetitePreview
Risk registerPreview
5×5 inherent / residual scoringPreview
Threat-informed risk statementsPreview
Risk heatmapPreview
Risk treatment plans linked to controlsPreview
Threat-informed minimum baselinePreview
Remediation actions inbox (gap → action, auto-close on fix)Preview
CTEM — Continuous Threat Exposure Management
Switch on scanningDNS proof, invitation code or paid plan
Attack-surface scansPassive onlyPassive + light activePassive + light activeDeep, active, passive & customAll + custom modules
Manual scans / month51025UnlimitedUnlimited
Scheduled scansMonthlyWeekly / monthlyDaily / weekly / monthlyContinuous; SLA by agreement
Monitored domains131025Unlimited
Tracked assets502005001,000Unlimited
Asset types (domain, host, IP, cert, identity, data, app, device…)99999 + custom
Rows visible per list (assets, findings, vulnerabilities, exposures)Top 20 by risk
Live scan feed
Raw scan-event history (forensic view)
Vulnerability triage with audit eventsRead-only
CVE enrichment
EPSS / KEV vulnerability enrichment
Exposure scoring & CTEM prioritisationPreview
Pentest as a Service
Engagements — scope, testing window, team and lifecycle
Shared library of reusable vulnerability write-ups
Assessment report (scope table, severity matrix, findings index, OWASP annex)
Findings index with stable references across remediation and retest
Retest lineage — a follow-up assessment links back to the report it re-tests
Positive observations and test accounts recorded on the engagement
Testing delivered by our assessorsContact salesContact salesContact salesContact salesContact sales
Identity exposure & dark-web monitoring
Dark-web & breach monitoring cadenceOn-demandMonthlyMonthlyWeeklyDaily
Leaked / breached credential findings
Breach timelines & first-seen history
Domain-ownership verification (DNS-TXT)
Reveal leaked credential (audited)
Triage exposures (resolved / false positive) with audit events
Cloud & SaaS connectors — Configuration Posture (CSPM)
Cloud & SaaS connectorsPreview1 connector (Microsoft 365)1 connector (Microsoft 365)Up to 3 connectorsUnlimited connectors + custom
Scheduled connector sync (identities, devices, vulnerabilities)
Native configuration-posture checks (MFA, admin governance, device compliance…)Preview
Posture mapped to NIST CSF → auto-evidencePreview
Failing checks become tracked remediation actions (auto-close on fix)
Posture insights — capabilities you pay for but have not switched on, effort-ranked
Policies & governance
Starter catalogue of policy, procedure & playbook templates
Author, version & restore (full change history)
Generate polished documents & reports
Dashboards & analytics
Real-data dashboards (assets, scans, findings)Preview
GRC dashboard (compliance + risk posture)Preview
Attack-surface graph view
Time-bucketed trend analyticsPreview
Reporting & exports
Compliance report (executive summary, coverage, gaps, risk)Preview
Findings report (evidence, screenshots, editable draft)
Executive overview report (board summary, AI narrative, prioritised recommendations)
Configuration assessment report (cloud & SaaS posture)
PDF and Word export (assessment reports, policies)Policies only
Your own logo, colour, footer and cover note on exported documents
Other reports in the browser, ready to printCompliance reports only
Data exportCSVCSVCSV + JSONCSV + JSON + bulk
Collaboration
Collaboration & project sharing (internal + third-party)
Email notifications (scan events, digests, alerts)Basic
Activity feed
Shared AI Sidekick team memory
Gamification & engagement
Maturity achievement badgesPreview
Maturity progress & path-to-baselinePreview
Risk-treated-over-time streaksPreview
Identity, access & audit
OIDC single sign-on (Microsoft 365 & email)
Built-in roles (Main Admin / Admin / User / Reader)
MFA (via identity provider)
Audit log (typed events) — read + export
Platform & support
Projects124UnlimitedUnlimited
Users12310Unlimited
Data retention7 days14 days30 days90 days365 days (configurable)
Public REST API access
SupportCommunityEmail (business hours)Email (business hours)Priority email + chatDedicated CSM; 24×7 by agreement
OnboardingSelf-serveSelf-serve + docsSelf-serve + docsOnboarding callTailored training

17 standards seeded and ready

NIST CSF 2.0 is the core spine every account runs; Complete runs up to five at once, chosen from all of the below, and Enterprise is unlimited.

NIST CSF 2.0ISO/IEC 27001:2022SOC 2 (TSC 2017/2022)SMB1001:2026CIS Controls 8.1GDPRHIPAA Security RuleNIST Privacy Framework 1.1OWASP Top 10:2025NZ Privacy Act 2020NZ HISF 2025NCSC MCSS 2025 (NZ)UK Cyber Essentials 2025UK NCSC CAF 4.0ACSC Essential Eight 2023BSI 200-1 (ISMS)SMB Minimum Baseline

View standards, coverage & licensing →

Starter is à la carte — a flat price for any 2 of the 4 content modules; enabling a third moves you to Essentials. On Free, the asset, finding, vulnerability and identity-exposure lists show the 20 highest-risk rows, and switching on either scanning module needs a DNS ownership check, an invitation code or a paid plan — governance and policies need no unlock. During preview, capabilities marked “Preview” are available on all plans, including Free — plan limits for these are being introduced as the platform exits preview. Enterprise plans add unlimited scale and dedicated support — talk to sales for design-partner pricing. Yearly billing saves roughly 17% versus monthly. Registered users can preview what we are building next on our roadmap.

See what we are building next →