Market audit · 17 May 2026

We audited 136 commercial GRC/ISMS platforms. 103 won't tell you what they cost.

We captured every vendor's pricing page verbatim. Where pricing is hidden behind a demo form we record 'Demo call required'. No estimates, no third-party sources. Nine open-source alternatives (verinice, CISO Assistant, Deming, ISMS Builder, Unicis CE, ourselves and others) are excluded from this list because they don't sell you a subscription.

136

Vendors audited

20

Public pricing

12

Starting price only

103

Demo call required

79

NIS2 as framework

29

Countries

As of: 2026-05-17

Why this market is ripe for disruption

76% of these 136 commercial GRC/ISMS vendors hide their prices. The products are forms, templates and checklists on top of a database. The marginal cost of one more customer is near zero. The price is not. Here are the receipts.

Five-figure annual contracts for a form

Vanta, Drata, Secureframe, OneTrust, MetricStream, IBM OpenPages, ServiceNow GRC, Archer, Diligent — every enterprise GRC suite hides pricing and charges €30,000+/year for a workflow tool with templates.

Eastern EU vendors are 10x cheaper and transparent

Copla (LT) sells NIS2 for €3,500/year as a dedicated SKU. NIS2 Manager (CZ) at ~€980/month. Conformio (HR) at €145/month. Same product category, different pricing decision.

OSS competition is growing from Germany and France

ISMS Builder (DE, AGPL), CISO Assistant (FR, AGPLv3, 130+ frameworks), Little-ISMS-Helper (DACH), Deming (FR) — all free self-hosted, all NIS2 explicit.

Market consolidation is accelerating

AuditBoard → Optro. CONTECHNET → i-doit. DocSetMinder → Allgeier. 3rdRisk → Diligent. RISMA + Wired Relations + ComplyCloud → Cerivo. StandardFusion → Wolters Kluwer. Galvanize → Diligent. Tugboat → OneTrust. Archer → Cinven.

VendorCountryPricingData exportNIS2FreeSourceEntry
3rdRisk (Diligent)NLDemo callYesOpen pricing pageDemo call required; acquired by Diligent Jan 2026
6clicksAUDemo callNoOpen pricing pageDemo call required; Hub-and-Spoke MSP GRC, 1,000+ frameworks
AdaptiveGRC (C&F)PLDemo callYesOpen pricing pageDemo call required
AkitraUSDemo callNoOpen pricing pageDemo call required; agentic-AI compliance
AnecdotesILDemo callYesOpen pricing pageDemo call required; 'One Platform, Simple Pricing' but no €
AnitianUSDemo callNoOpen pricing pageDemo call required; FedRAMP focus
ApptegaUSDemo callNoTrialOpen pricing pageDemo call required; 14-day trial on Essentials
AptienCZDemo callNoFreeOpen pricing pageVendor displays '$-' placeholder; per-user model but no number
Archer (Cinven PE)USDemo callNoOpen pricing pageDemo call required; category-defining form/workflow IRM
Atena GovernanceITDemo callYesTrialOpen pricing pageDemo call required; 30-day trial, no CC
Athereon GRCDEDemo callYesOpen pricing pageDemo call required; 4 size classes S/M/L/XL
AuditBoard (now Optro)USDemo callNoOpen pricing pageDemo call required; rebranded March 2026 AuditBoard → Optro
Auditool (June Factory)FRDemo callYesTrialOpen pricing pageDemo call for full version; 7-day sandbox free with 50+ NIS2 actions
BitSightUSDemo callNoOpen pricing pageDemo call required; cyber ratings + TPRM + ASM
Black KiteUSDemo callNoOpen pricing pageDemo call required; cyber ratings/TPRM
CentraleyesUSDemo callNoOpen pricing pageDemo call required; 180+ frameworks
CerrixNLDemo callYesOpen pricing pageDemo call required; enterprise GRC
CibgestPTDemo callYesTrialOpen pricing pageDemo call required; 14-day trial, no CC
Complidoo (Asystel-BDF)ITDemo callYesOpen pricing pageDemo call required; low-code GRC
ComplyanceUSDemo callYesOpen pricing pageDemo call required; $20M Series A Feb 2026 (GV, EU VCs Creandum/HV/Speedinvest)
ComplyCloud (Cerivo)DKDemo callYesTrialOpen pricing pageDemo call required; part of Cerivo merger 2025/2026
ComplyDoDEDemo callNothing documentedYesOpen pricing pageDemo call required; YC F25, Berlin
CompylUSDemo callNoOpen pricing pageDemo call required; 20+ frameworks
CONTECHNET (i-doit)DEDemo callYesTrialOpen pricing pageDemo call required; CONTECHNET 301-redirects to i-doit
CyberArrowAEDemo callNoOpen pricing pageDemo call required; /pricing returns 403
CyberSaint CyberStrongUSDemo callNoOpen pricing pageDemo call required; annual or multi-year only
CypagoILDemo callNoOpen pricing pageDemo call required; AWS Marketplace from $60k/yr
DataGuardDEDemo callNothing documentedYesOpen pricing pageDemo call required; Base/Pro/Enterprise — all 'Get a quote'
Datalog (Zucchetti)ITDemo callYesOpen pricing pageDemo call required; Zucchetti group
Delve (collapsed)USDemo callNoOpen pricing pageApril 2026: YC dropped them for fake SOC 2 audits + code theft
Diligent (incl. Galvanize, 3rdRisk)USDemo callNoOpen pricing pageDemo call required; ~23,000 clients post-mergers
DocSetMinderDEDemo callNoOpen pricing pageDemo call required; acquired by Allgeier CyRis
DrataUSDemo callPartialNoOpen pricing pageDemo call required; NIS2 not listed on pricing page
EnactiaCYDemo callNoTrialOpen pricing pageDemo call required; 14-day free trial
FormalizeDKDemo callYesTrialOpen pricing pageDemo call required; 14-day limited trial
fuentisDEDemo callYesOpen pricing pageDemo call required; 'Free start' CTAs route to contact form
G DATA BusinessDEDemo callYesTrialOpen pricing pageDemo call for business products; consumer line public
GBTEC (BIC GRC)DEDemo callYesOpen pricing pageDemo call required; product page 404
GlobalSuite SolutionsESDemo callYesOpen pricing pageDemo call required; no /pricing page
GovernXRODemo callYesTrialOpen pricing pageDemo call required (prices behind login); 'Made in Romania, for Europe'
GRCTools (ESG Innova)ESDemo callYesOpen pricing pageDemo call required
HeimdalDKDemo callYesOpen pricing pageDemo call required; /pricing 404
HiScoutDEDemo callReports onlyYesOpen pricing pageDemo call required; no public pricing page
Holm SecuritySEDemo callYesTrialOpen pricing pageDemo call required; 1-3 year minimum contract
Hybridity (Hy5)SEDemo callYesOpen pricing pageDemo call required; €2M raise Feb 2026
HyperComplyCADemo callNoOpen pricing pageDemo call required; TPRM/questionnaire automation
HyperproofUSDemo callYesOpen pricing pageDemo call required; 'AI-powered GRC' marketing
IBM OpenPagesUSDemo callNoOpen pricing pageDemo call required; enterprise GRC + AI
INFODAS (SAVe)DEDemo callNoOpen pricing pageDemo call required; explicitly bundled with consulting
ISMS.onlineUKDemo callYesOpen pricing pageDemo call required; 'Bespoke, customized pricing'; NIS2 as 'optional extra'
KertosDEDemo callYesOpen pricing pageDemo call required
KiteworksUSDemo callYesOpen pricing pageDemo call required; 'CALL FOR PRICING' Enterprise
KymatioESDemo callYesOpen pricing pageDemo call required; no /pricing page
LegiscopeFRDemo callYesOpen pricing pageDemo call required; /pricing 404
LexCyberAIPLDemo callYesFreeOpen pricing pageDemo call required; free NIS 2 bootcamp
LogicGate Risk CloudUSDemo callNoOpen pricing pageDemo call required; no-code workflow builder for GRC
LogicManagerUSDemo callNoOpen pricing pageDemo call required; 'Job-to-be-Done pricing'
Make IT SafeFRDemo callYesOpen pricing pageDemo call required; via ReCyF referential
MetricStreamUSDemo callNoOpen pricing pageDemo call required; IRM mega-suite, AppStudio = form builder
NIS2 Control (Virtual IT)SIDemo callYesOpen pricing pageDemo call required; ZInfV-1 Slovenia
Norm AiUSDemo callNoOpen pricing pageDemo call required; $87M total funding (Coatue, Bain, Blackstone)
NorthGRCNODemo callYesOpen pricing pageDemo call required; no /pricing page
OMNITRACKERDEDemo callReports onlyYesOpen pricing pageDemo call required; 'KOSTENFREI TESTEN' is demo request
OneleetUSDemo callNoOpen pricing pageDemo call required; $33M Series A, GRC + pentest
OneTrustUSDemo callNoOpen pricing pageDemo call required; 6 separate solution suites, all modular
OnspringUSDemo callNoOpen pricing pageDemo call required; Bronze/Silver/Gold/Platinum without prices
otrisDEDemo callNoTrialOpen pricing pageDemo call required; phone-first sales
PeriumNLDemo callYesTrialOpen pricing pageDemo call required; 30-min setup claim
ProcessUnityUSDemo callNoOpen pricing pageDemo call required; pure questionnaire platform
QSEC (Nexis)DEDemo callYesOpen pricing pageDemo call required; claims 'transparent', shows no €
Resolver (Kroll)CADemo callNoOpen pricing pageDemo call required; 3-factor quote (modules + customization + active users)
RIG NIS (Wolters Kluwer PL)PLDemo callYesOpen pricing pageDemo call required
RiskonnectUSDemo callNoOpen pricing pageDemo call required; IRM on Salesforce
RISMA Systems (Cerivo)DKDemo callYesOpen pricing pageDemo call required; only /price-request, no /pricing
Robin DataDEDemo callYesTrialOpen pricing pageDemo call required; /preise page returns 404
SAI360USDemo callNoOpen pricing pageDemo call required; Compliance + Risk bundles, all 'Request Quote'
Schleupen GRCDEDemo callYesOpen pricing pageDemo call required; concurrent user / enterprise license
ScytaleILDemo callNoOpen pricing pageDemo call required; 5 tier names without prices
SecfixDEDemo callYesOpen pricing pageDemo call required; no /pricing page
SECJURDEDemo callYesOpen pricing pageDemo call required; no /pricing page
SecratoBEDemo callYesOpen pricing pagePlan names public, prices not; launched March 2026
secunetDEDemo callYesOpen pricing pageProject-based custom quote; government/defense vendor
SecureframeUSDemo callPartialNoOpen pricing pageDemo call required; 'Get a quote' on every tier
SecurityScorecardUSDemo callNoFreeOpen pricing pageFree Forever tier (limited); Core/Premium/Elite/TITAN MAX all demo-gated
ServiceNow GRCUSDemo callNoOpen pricing pageDemo call required; GRC on Now Platform = forms + workflows
ShieldIQIEDemo callYesFreeOpen pricing pageFreemium, 'no card no setup calls'; tier prices demo-gated
SoSafeDEDemo callYesOpen pricing pageDemo call required; tier names only, no prices
SprintoINDemo callPartialNoOpen pricing pageDemo call required; pricing page is JS SPA, no prices visible
StandardFusion (Wolters Kluwer TeamMate)NLDemo callNoOpen pricing pageDemo call required; 308-redirects to Wolters Kluwer TeamMate
SteryonESDemo callYesOpen pricing pageDemo call required; €1M seed, OT/industrial, NIS2 explicit
SureCloudUKDemo callYesOpen pricing pageDemo call required; 'Talk to us about pricing'
SwissGRCCHDemo callYesOpen pricing pageDemo call required; no /pricing page
Syteca (ex-Ekran)USDemo callYesTrialOpen pricing pageDemo call required; SaaS / On-prem / AWS / Azure SKUs all gated
TenacyFRDemo callYesOpen pricing pageDemo call required; 'sovereign' France-hosted
Teseo NIS2 GRCITDemo callYesOpen pricing pageDemo call required; 'demo di 20 minuti'
Thoropass (was Laika)USDemo callNoOpen pricing pageDemo call required; audit + platform bundle
TrustCloudUSDemo callNoOpen pricing pageDemo call required; 'Every GRC journey is different'
TrusteroUSDemo callNoOpen pricing pageDemo call required; AI GRC
VantaUSDemo callReports onlyNoTrialOpen pricing pageDemo call required (4 tiers: Essentials, Plus, Professional, Enterprise — no prices shown)
WhisticUSDemo callNoFreeOpen pricing pageDemo call required; free profile, paid all gated
WizUSDemo callNoOpen pricing pageDemo call required; cloud-security CNAPP, not pure GRC
WorkivaUSDemo callNoOpen pricing pageDemo call required; ESG/CSRD focus
ZenGRC/RiskOpticsUSDemo callNoOpen pricing pageDemo call required; ECONNREFUSED on direct fetch
Compliance AspekteDEUnverifiableReports onlyNoOpen pricing pageWebsite was unreachable (HTTP 522) at audit time
heyDataDEPartialYesOpen pricing pageStarter from €59/mo, Pro from €99/mo, Enterprise from €169/mo; 2-year minimum contract
ProlianceDEPartialYesOpen pricing pageData Protection from €125-€233/mo; ISMS Light from €500/mo; ISMS Core from €1,000/mo; NIS2 Executive Training €600
kronsoft (opus i)DEPartialNoFreeOpen pricing pageFrom €259/year (entry: 2 modules + support + updates); full price list as downloadable PDF
ConnectSecureUSPartialYesTrialOpen pricing pageFrom $300/mo (MSP only, usage-based); tier prices gated
DocusnapDEPartialYesTrialOpen pricing pageFrom €465/year (on-prem or SaaS); scales by inventory size
BOC Group ADOGRCATPartialYesOpen pricing pageFocus Editions from €520/mo (5 seats); Core from €1,195/mo (3 scenarios); Extended from €2,100/mo (7 scenarios); detailed quotes password-protected
Wired RelationsDKPartialYesFreeOpen pricing pageFree (150 elements); Pro €670/mo (annual billing only); Enterprise quote
VComplyUSPartialNoOpen pricing pagePro GRC Suite from $1,000/mo per module; annual only, 12-mo minimum; 20% nonprofit discount
UpGuardUSPartialNoOpen pricing pageStandard $1,750/mo (annual, 50 vendors); higher tiers gated; extra vendors $79/mo
CybervizeDEPartialYesTrialOpen pricing pagevCISO Basic €3,600/mo (≤20h); Standard €4,900/mo (≤40h); Interim CISO €8,000-€15,000/mo; platform license modular, undisclosed
Strike GraphUSPartialYesFreeOpen pricing pageLaunch free; Certify from $10,000/yr; Scale from $21,500/yr; Enterprise from $35,000/yr; framework add-ons $2K-$8K
Mitratech AlyneDEPartialNoOpen pricing pageEnterprise plan from €25,000/year (publicly stated); 1,500+ control library
OrbiqDETransparentYesFreeOpen pricing pageFree €0; Team €85/mo (€850/yr); Business €190/mo (€1,900/yr); Enterprise custom; 17% annual discount
NIS2CompassDETransparentYesOpen pricing pageFrom €29/month (NIS2-only, 'no consultants')
ISOPlannerNLTransparentYesTrialOpen pricing pageNIS2 €39/mo standalone; ISO €59-€118 per management user/mo (yearly)
EDIRA (ETES)DETransparentYesOpen pricing page€49/month + €150 setup (NIS-2 add-on on existing framework)
Conformio (Advisera)HRTransparentNoTrialOpen pricing pageStarter €145/mo, Pro €245/mo, Advanced €299/mo (annual)
GRASP German GRCDETransparentReports onlyYesTrialOpen pricing page€159–€179/month NIS2 module (3-yr lock 159; 1-yr 179); 1 user incl.
OutlexPTTransparentNoOpen pricing pageCore from €249/mo, Growth from €549/mo + per-credit lawyer consultations
CompleyeNLTransparentYesOpen pricing pagePlatform €275/mo; NIS2 Verification (2-day) €1,600; Training (4-day) per request
activeMind.cloudDETransparentYesOpen pricing page€290/month per module + €49 per additional norm; Whistleblowing €99-€390/mo; extra users €20/mo
DefendsphereEUTransparentYesOpen pricing pageBasic €299/mo (5 infra licenses); Standard €499/mo; Premium custom
VenveraNLTransparentYesTrialOpen pricing pageBasic €399/mo (4 frameworks: DORA, NIS2, GDPR, Cyber Essentials); Pro €899/mo (6 incl. ISO 27001, EU AI Act); 11% annual discount
MatproofNLTransparentYesTrialOpen pricing pageStarter €480/mo (1 framework, 10 members); Professional €1,200/mo (3 frameworks); 20% annual discount
Privado.aiUSTransparentNoOpen pricing pageWeb Auditor from $600/website/mo; App Auditor from $800/app/mo; Wren AI Privacy Agent from $4,200/mo (annual)
NIS2 Portugal (Isofficer)PTTransparentYesFreeOpen pricing pageService catalog: gap analysis from €1,500; training €990/participant; doc kit from €2,500/yr; external CISO from €750/mo
Ratisbona ComplianceDETransparentNothing documentedYesOpen pricing pageRC_NIS2 €799/month (workshops + ISMS); GF-Schulung €999 one-off
NIS2 Manager / CYBER ManagerCZTransparentYesTrialOpen pricing page24,900 CZK/month (~€980) excl. VAT, single tier, 12-mo commitment, 30+ modules
CyberdayFITransparentYesTrialOpen pricing pageEmployee band: <20 €2,500/yr; 20-49 €3,200; 50-99 €4,500; 100-199 €6,800; 200-499 €9,900; up to 2,999 €19,900
ErambaCHTransparentNoFreeOpen pricing pageCommunity free (non-OSI license); self-host Enterprise €2,500/yr; SaaS Enterprise €5,000/yr
Copla (ex-CyberUpgrade)LTTransparentYesOpen pricing pageNIS2 €3,500/year + €499 onboarding (own SKU); ISO 27001 €2,999/yr; DORA €4,500/yr; 20% off each additional framework
NIS2VisionEUTransparentNothing documentedYesOpen pricing pageBasic €4,999 yr 1 (setup €2,599 + €200/mo, 5 users); Important €8,800 yr 1; Essential €17,600 yr 1

Methodology

Verified on 2026-05-17

  • We visited each pricing page manually.
  • Prices are quoted verbatim from the vendor's website.
  • No extrapolation from G2, Capterra, third-party blogs or LinkedIn.
  • Where prices are hidden behind a demo form: 'Demo call required'.
  • Where prices are only quoted as 'from €X': 'Partial transparency'.
  • Quarterly re-audit. Vendors can submit corrections.
Submit a correction

Is our data about your product wrong? Email simon@nisd2.eu with your pricing page URL. We update within 48 hours and keep a change log.

Free + Open Source + no lock-in

We don't sell NIS2 compliance. We make it accessible. Free, open source, no sales team calling you.

Launch platform