PREVIEWCISO360AI is offered as-is while in preview. Features and data may change. Learn more.

Plans for every stage of GRC

Start free, get audit-ready on Essentials, run a full programme on Complete. Yearly billing saves roughly 17%.

Free
Try the platform
$0/mo

$0/yr billed yearly

Evaluate — or very small teams & solo operators

Essentials
Get audit-ready on one framework
$25/mo

$250/yr billed yearly

SMB starter — one framework, light cadence

Most popular
Complete
Multi-framework GRC + AI vCISO
$250/mo

$2,500/yr billed yearly

Full SMB GRC programme

Coming soon
Enterprise / Custom
Enterprise GRC with SSO, workflows & on-premise
Contact sales

Mid-market & regulated enterprise

Compare every feature

FeatureFreeEssentialsCompleteEnterprise
AI Sidekick — your built-in AI vCISO
AI vCISO assistant (chat, guidance, drafting)5-credit trial
AI personas2 (Compliance, Analyst)5 (CISO, Compliance, Analyst, IR, Pentester)5
Hosted AI credits / month5 (signup trial)25250Unlimited
Top-up credits
AI propose / approve loop on evidence & controlsBasic
AI risk derivation from compliance gaps
Scheduled AI workflows (gap review, assessment cadence)Monthly only
Bring your own AI (your model & key) — all tiers
MCP server access (connect your own AI agent)
Agentic API keys (user-managed, scoped)
Safe actions — human-approved, scope-gated tools
Compliance & Standards
Standards available1 — NIST CSF 2.0 (read-only)2 active baselinesAll 16All 16 + unlimited custom
Control ↔ requirement mapping (bidirectional)
Cross-framework derivation (NIST CSF hub)
Assessments & evidence
Onboarding wizard
Assessment runs1 (read-only)UnlimitedUnlimitedUnlimited
Control state machine (claimed → validated → gap → managed)View only
Coverage / maturity / gap analyticsBasic snapshot
Manual evidence uploadUp to 1 GBUp to 25 GBUnlimited
Evidence expiry tracking + reminders
Risk management
Org-level risk appetiteView only
Risk registerManual, basic
5×5 inherent / residual scoring
SCF threat catalogue (41 threats / 39 risk statements)
Risk heatmap
Risk treatment plans linked to controls
Materiality flag
Threat-Informed Attack Surface Management
Attack-surface scansPassive onlyPassive + light activeDeep, active & passiveAll + custom modules
Manual scans / month525UnlimitedUnlimited
Scheduled scansWeeklyDaily / on-demandContinuous + SLA
Monitored domains31025Unlimited
Tracked assets50200500Unlimited
Asset types (domain, host, IP, cert, identity, data, app, device…)9999 + custom
Live scan feed
Vulnerability triage with audit eventsRead-only
CVE enrichment
Dashboards & analytics
Real-data dashboards (assets, scans, findings)Basic
GRC dashboard (compliance + risk posture)
Attack-surface graph view
Time-bucketed trend analytics
Reporting & exports
Compliance report (executive summary, coverage, gaps, risk)Watermarked
HTML reports (browser print)Watermarked
Data exportCSV onlyCSV + JSONCSV + JSON + bulk
Collaboration
Collaboration & project sharing (internal + third-party)
Email notifications (scan events, digests, alerts)Basic
Activity feed
Shared AI Sidekick team memory
Gamification & engagement
Maturity achievement badges
Maturity progress & path-to-baseline
Risk-treated-over-time streaks
Identity, access & audit
OIDC single sign-on (Microsoft 365 & email)
Built-in roles (Main Admin / Admin / User / Reader)
MFA (via identity provider)
Audit log (typed events)Last 7 daysRead by adminRead + exportRead + export
Platform & support
Projects12UnlimitedUnlimited
Users1310Unlimited
Data retention7 days30 days90 days365 days (configurable)
Public REST API access
SupportCommunityEmail (business hours)Priority email + chatDedicated CSM, 24×7
OnboardingSelf-serveSelf-serve + docsOnboarding callTailored training

16 standards seeded and ready

NIST CSF 2.0 is the core spine every account runs; Complete unlocks all of the below.

NIST CSF 2.0ISO/IEC 27001:2022SOC 2 (TSC 2017/2022)CIS Controls 8.1GDPRHIPAA Security RuleNIST Privacy Framework 1.0OWASP Top 10:2025NZ Privacy Act 2020NZ HISF 2025NCSC MCSS 2025 (NZ)UK Cyber Essentials 2025UK NCSC CAF 4.0ACSC Essential Eight 2023BSI 200-1 (ISMS)SMB Minimum Baseline

View standards, coverage & licensing →

All prices in USD. Enterprise plans add unlimited scale, public API access and dedicated support — talk to sales for design-partner pricing. Yearly billing saves roughly 17% versus monthly. Registered users can preview what we are building next on our roadmap.

See what we are building next →