PREVIEWCISO360AI is offered as-is while in preview. Features and data may change. Learn more.

Plans for every stage of GRC

Start free, get audit-ready on Essentials, run a full programme on Complete. Yearly billing saves roughly 17%.

Free
Try the platform
$0/mo

$0/yr billed yearly

Evaluate — or very small teams & solo operators

Essentials
Get audit-ready on one framework
$25/mo

$250/yr billed yearly

SMB starter — one framework, light cadence

Most popular
Complete
Multi-framework GRC + AI vCISO
$250/mo

$2,500/yr billed yearly

Full SMB GRC programme

Coming soon
Enterprise / Custom
Enterprise GRC with SSO, workflows & on-premise
Contact sales

Mid-market & regulated enterprise

Compare every feature

FeatureFreeEssentialsCompleteEnterprise
AI Sidekick — your built-in AI vCISO
AI vCISO assistant (chat, guidance, drafting)5-credit trial
AI personas2 (Compliance, Analyst)5 (CISO, Compliance, Analyst, IR, Pentester)5
Hosted AI credits / month5 (signup trial)25250Unlimited
Top-up credits
AI propose / approve loop on evidence & controlsBasic
AI risk derivation from compliance gapsPreview
Scheduled AI workflows (gap review, assessment cadence)Monthly only
Bring your own agent (your model & key) — all tiers
Native MCP server — connect Claude, Copilot or Cursor
MCP tools (read + human-approved actions)34343434
Agentic API keys (OAuth 2.1 or scoped)
Safe actions — human-approved, scope-gated tools
Compliance & Standards
Standards available1 — NIST CSF 2.0 (read-only)2 active baselinesAll 17All 17 + unlimited custom
Control ↔ requirement mapping (bidirectional)
Cross-framework derivation (NIST CSF hub)
Custom framework builder (template, from scratch, CSV import)
Assessments & evidence
Onboarding wizard
Assessment runs1 (read-only)UnlimitedUnlimitedUnlimited
Control state machine (claimed → validated → gap → managed)View only
Coverage / maturity / gap analyticsBasic snapshot
Manual evidence uploadUp to 1 GBUp to 25 GBUnlimited
Evidence expiry tracking + reminders
Risk management
Org-level risk appetitePreview
Risk registerPreview
5×5 inherent / residual scoringPreview
SCF threat catalogue (41 threats / 39 risk statements)Preview
Risk heatmapPreview
Risk treatment plans linked to controlsPreview
Materiality flagPreview
Remediation actions inbox (gap → action, auto-close on fix)Preview
CTEM — Continuous Threat Exposure Management
Attack-surface scansPassive onlyPassive + light activeDeep, active, passive & customAll + custom modules
Manual scans / month525UnlimitedUnlimited
Scheduled scansDaily / weekly / monthlyDaily / weekly / monthlyContinuous + SLA
Monitored domains31025Unlimited
Tracked assets50200500Unlimited
Asset types (domain, host, IP, cert, identity, data, app, device…)9999 + custom
Live scan feed
Vulnerability triage with audit eventsRead-only
CVE enrichment
EPSS / KEV vulnerability enrichment
Exposure scoring & CTEM prioritisationPreview
Identity exposure & dark-web monitoring
Dark-web & breach monitoring cadenceOn-demandMonthlyWeeklyDaily
Leaked / breached credential findings
Breach timelines & first-seen history
Domain-ownership verification (DNS-TXT)
Reveal leaked credential (audited)
Cloud & SaaS connectors — Configuration Posture (CSPM)
Cloud & SaaS connectorsPreview1 connector (Microsoft 365)Up to 3 connectorsUnlimited connectors + custom
Scheduled connector sync (identities, devices, vulnerabilities)
Native configuration-posture checks (MFA, admin governance, device compliance…)Preview
Posture mapped to NIST CSF → auto-evidencePreview
Failing checks become tracked remediation actions (auto-close on fix)
Policies & governance
Starter catalogue of policy, procedure & playbook templates
Author, version & restore (full change history)
Generate polished documents & reports
Dashboards & analytics
Real-data dashboards (assets, scans, findings)Preview
GRC dashboard (compliance + risk posture)Preview
Attack-surface graph viewPreview
Time-bucketed trend analyticsPreview
Reporting & exports
Compliance report (executive summary, coverage, gaps, risk)Preview
Findings report (evidence, screenshots, editable draft)Preview
HTML reports (browser print)Preview
Data exportPreviewCSV onlyCSV + JSONCSV + JSON + bulk
Collaboration
Collaboration & project sharing (internal + third-party)
Email notifications (scan events, digests, alerts)Basic
Activity feed
Shared AI Sidekick team memory
Gamification & engagement
Maturity achievement badgesPreview
Maturity progress & path-to-baselinePreview
Risk-treated-over-time streaksPreview
Identity, access & audit
OIDC single sign-on (Microsoft 365 & email)
Built-in roles (Main Admin / Admin / User / Reader)
MFA (via identity provider)
Audit log (typed events)Last 7 daysRead by adminRead + exportRead + export
Platform & support
Projects12UnlimitedUnlimited
Users1310Unlimited
Data retention7 days30 days90 days365 days (configurable)
Public REST API access
SupportCommunityEmail (business hours)Priority email + chatDedicated CSM, 24×7
OnboardingSelf-serveSelf-serve + docsOnboarding callTailored training

17 standards seeded and ready

NIST CSF 2.0 is the core spine every account runs; Complete unlocks all of the below.

NIST CSF 2.0ISO/IEC 27001:2022SOC 2 (TSC 2017/2022)SMB1001:2026CIS Controls 8.1GDPRHIPAA Security RuleNIST Privacy Framework 1.0OWASP Top 10:2025NZ Privacy Act 2020NZ HISF 2025NCSC MCSS 2025 (NZ)UK Cyber Essentials 2025UK NCSC CAF 4.0ACSC Essential Eight 2023BSI 200-1 (ISMS)SMB Minimum Baseline

View standards, coverage & licensing →

All prices in USD. During preview, capabilities marked “Preview” are available on all plans, including Free — plan limits for these are being introduced as the platform exits preview. Enterprise plans add unlimited scale, public API access and dedicated support — talk to sales for design-partner pricing. Yearly billing saves roughly 17% versus monthly. Registered users can preview what we are building next on our roadmap.

See what we are building next →