Evidence your auditor can trace to a control, not a screenshot of a dashboard.
Decide in three minutes. No call required.
Three self-serve plans, four published prices, no demo gate and no sales call in the way. Assess decides what to do, Operate runs the work, Program proves it.
- (01)AssessDECIDE$4,800/yr$499/month, cancel anytime
- (02)OperateDO$14,400/yr$1,499/month, cancel anytime
- (03)ProgramRecommendedPROVE$36,000/yrAnnual only — no monthly option
- (04)EnterprisePROGRAM, ON YOUR INFRASTRUCTURECustom · from $72K/yrTypically $72–150K/year
Not sure which tier fits?
Every price on this page is the price.
There is no quote, no discovery call, and no "contact us for pricing" step between you and a number. The three self-serve plans check out with a card. Enterprise is the one plan that is quoted, and its range is printed anyway. Renewal is at the then-current published list price, less the published multi-year discounts where they apply — if our list price has not moved, yours does not either.
On this date we opened the pricing pages of Vanta and Drata — two compliance-automation platforms a buyer comparing us is likely to open too. Neither page showed a dollar figure. Vanta listed four plans (Essentials, Plus, Professional, Enterprise) behind a "Get personalized pricing" action; Drata's page routed to a demo request.
That is a record of what two web pages showed on one day. It is not a claim about what either company charges, whether their pricing is fair, or how they choose to sell. Both pages are linked so you can check them yourself and see whether this is still true.
Match the plan to the date on your calendar.
Buyers here are working backwards from a date, not from a job title. Find the date, read the deliverable it needs, and the plan follows.
The questionnaire answered from your real environment, and a read on where the cover falls short.
Exposure in dollars as a two-sided band, with the assumptions named — not a colour-coded heat map.
Every plan boundary above is quoted from the same comparison rows rendered in the matrix below — the deliverable names are the row labels, not marketing paraphrase.
What each plan actually buys.
For the founder staring down a first audit, a board question, or a customer questionnaire.
- · Design a new stack — Lean, Balanced, Advanced, priced
- · Review the architecture you already run
- · Compliance scoring across all 24 frameworks
- · Board-ready PDF + risk register
- · Breach Replay — type a CVE ID, see if it reaches you
- · 1 configuration review a year
For the in-house team that owns security week to week.
- Everything in Assess, plus:
- · Configuration Review — 3 a year, rule by rule
- · Single-vendor attack paths
- · Report shares for your CFO, board, auditor, broker
- · Insurance questionnaire pre-fill
- · Underinsurance gap analysis
- · Identity-export ingestion (Okta / Entra)
- · Evidence ledger (read-only view)
- · Re-run the assessment whenever your environment changes
For the security program that has to prove its posture all year, not assert it.
- Everything in Operate, plus:
- · Configuration Review — unlimited, all 37 vendors, 1,926 checks
- · Multi-vendor attack paths to your crown jewels
- · Proof over time — the evidence ledger, hash-chained and dated
- · NHI Blast Radius · Vendor Breach Simulator · Agent-Reachability Gate
- · Year-in-review report
The jump from Operate buys proof over time: a tamper-evident, dated evidence ledger, a proven-regression trail, and the year-in-review — the difference between asserting your posture to an auditor and handing them a bundle they can re-verify themselves. Your CISO judgment still owns the board meeting; the engine does the analysis underneath.
For organizations that need the engine on their own infrastructure, under their own brand.
- Everything in Program, plus:
- · Single-tenant, on your infrastructure
- · White-label PDFs under your brand
- · Named CSM with quarterly review
- · Custom SLA, MSA, and DPA
We'll handle MSA, DPA, and PO.
These are CyberTwin's subscription prices — a flat fee, published in full. They're separate from the tool-cost estimates inside your reports, which price the recommended security tools (sourced from vendor pages and Vendr benchmarks). We never blur the two. See what those tool costs look like for a company like yours →
Typical Big-4 or Big-4-adjacent engagement — valid the day it’s printed; a refresh re-engagement typically runs $30–80K.
The full comparison →Each re-run is another round of in-house analyst time, with sourcing rigor that varies engagement to engagement.
The full comparison →Live dashboards stop existing the day you stop paying. CyberTwin’s proofs are dated, signed files you keep — re-checkable by anyone, with no subscription attached.
The full comparison →Program is $36,000/yr — and the deliverables are files you keep, re-runnable whenever your environment changes.
The limits, stated as limits.
Caps, exclusions and prerequisites read as caps, exclusions and prerequisites — not as bullets with the word “includes” in front of them. Each one is enforced by a real gate, and each is stated before you pay, not discovered after.
- Limit: 1 configuration review per year on Assess.
Operate raises it to 3 a year, one vendor per review. Program removes the cap.
- Limit: 3 assessment refreshes per year on Assess.
Operate and Program are unlimited. A refresh is a re-run, not a new subscription.
- Program is annual only. There is no monthly option.
Assess and Operate bill monthly or annually; on those two, monthly cancels at the next cycle.
- No free trial. A card is required at signup.
The evaluation path is the sample report (/sample-report) and the free attack-path sandbox (/demo) — both need no account.
- No refunds. You can cancel before any future charge.
After cancellation the account is read-only for 90 days so you can export, and the data is deleted at 180.
- Every PROVEN line needs a file you upload.
We run no scan, deploy no agent, and hold no credential to your systems — so with no export, a control stays MODELED.
- Seats: 5 on Assess and Operate, 10 on Program.
Seats cover people working in the app. The PDFs and share links you produce can go to anyone.
Data handling does not vary by plan: customer data at rest is hosted in Frankfurt (EU), encrypted in transit and at rest, and region-pinned residency is quoted on Enterprise only. That is one answer for all four plans rather than a column in the matrix — the subprocessors and the detail live on /trust.
Grouped by what you came here to ask.
Not by feature area — by buyer concern, with what gets PROVEN from a file you uploaded kept separate from what gets MODELED. Every plan scores all 24 frameworks.
| WHAT YOU GET | Assess $499/mo or $4,800/yr Decide · cancel anytime | Operate $1,499/mo or $14,400/yr Do · cancel anytime | Program $36,000/yr · annual only Prove · Recommended | Enterprise Custom · from $72K/yr Custom contract |
|---|---|---|---|---|
INTAKE & COVERAGE What you can hand it, how much of it, and how often you can come back. | ||||
| Read network diagrams and extract topology | ✓ | ✓ | ✓ | ✓ |
| Upload audit reports and security docs — we surface contradictions | ✓ | ✓ | ✓ | ✓ |
| Configuration Reviews per year | 1 | 3 | Unlimited | Unlimited |
| Vendors covered | Any 1 per review | Any 1 per review | All 37 | All 37 |
| Assessment refreshes | 3 / year | Unlimited | Unlimited | Unlimited |
| Monthly engine refresh + end-of-month digest email | — | ✓ | ✓ | ✓ |
WHAT GETS PROVENPROVEN Read from the bytes of a file you uploaded, and citable back to it. Needs an export to exist. | ||||
| Rule-by-rule security and compliance audit | ✓ | ✓ | ✓ | ✓ |
| What's misconfigured and how to fix it (per-finding remediation) | ✓ | ✓ | ✓ | ✓ |
| Rules Excel export | ✓ | ✓ | ✓ | ✓ |
| Re-upload an export to re-prove your posture | — | ✓ | ✓ | ✓ |
WHAT GETS MODELEDMODELED Inferred, never read from a file — labelled as such everywhere it appears, with dollars as two-sided bands. | ||||
| Recommended stack of security tools | ✓ | ✓ | ✓ | ✓ |
| Three priced options (lean, balanced, advanced) for each recommendation | ✓ | ✓ | ✓ | ✓ |
| Review of your current architecture — gaps and upgrades | ✓ | ✓ | ✓ | ✓ |
| Step-by-step setup guide for every tool you choose | ✓ | ✓ | ✓ | ✓ |
| Compare scenarios side-by-side | ✓ | ✓ | ✓ | ✓ |
ATTACK PATHS & THE CUT How an attacker gets from the edge to what matters, and the single change that severs the most routes. | ||||
| Attack-path mapping from your architecture | In your review | Single-vendor | Multi-vendor | Multi-vendor |
| Specific attacker technique named for each weakness | ✓ | ✓ | ✓ | ✓ |
| Threat-group attribution | ✓ | ✓ | ✓ | ✓ |
| Cross-vendor attack chains, stitched to your crown jewels | — | — | ✓ | ✓ |
| Attack-path simulation report | — | ✓ | ✓ | ✓ |
PROOF & ARTIFACTS The dated, signed files you keep — the part that still verifies after you stop paying us. | ||||
| Evidence ledger — read-only view of your signed entries | — | ✓ | ✓ | ✓ |
| Evidence ledger — tamper-evident proof trail | — | — | ✓ | ✓ |
| Proven-regression trail (a closed gap that reopens) | — | — | ✓ | ✓ |
| Proven-closure copilot (a fix is closed only when re-proven) | — | — | ✓ | ✓ |
| Audit readiness — show-me vs trust-me per control | — | — | ✓ | ✓ |
| Year-in-review report (60 days before your renewal) | — | — | ✓ | ✓ |
COMPLIANCE & REPORTS The documents you hand to a named person: an auditor, a broker, a board. | ||||
| Compliance posture across all 24 frameworks | ✓ | ✓ | ✓ | ✓ |
| Board-ready PDF + risk register | ✓ | ✓ | ✓ | ✓ |
| Compliance-only report for your auditor | ✓ | ✓ | ✓ | ✓ |
| Pack for your board (risk-quantified) | ✓ | ✓ | ✓ | ✓ |
| Pack for your auditor (control evidence + framework mapping) | — | ✓ | ✓ | ✓ |
| Pack for your insurance broker (questionnaire pre-filled) | — | ✓ | ✓ | ✓ |
| All compliance playbooks as Word documents | ✓ | ✓ | ✓ | ✓ |
| Each setup step tagged with which compliance controls it satisfies | — | ✓ | ✓ | ✓ |
| Incident retrospective template | — | ✓ | ✓ | ✓ |
| OSCAL export — machine-readable control evidence for GRC tools (NIST OSCAL: SAR, POA&M, profile, catalog) | — | — | ✓ | ✓ |
SHARING & ADMIN Getting the output to people who do not log in, and into systems that do not read PDFs. | ||||
| Share reports with stakeholders | — | ✓ | ✓ | ✓ |
| Read-only API — pull your posture, findings, and compliance scores into your own tools on a schedule | — | ✓ | ✓ | ✓ |
| Your firm's logo on every PDF (white-label) | — | — | — | ✓ |
| Map your custom internal control sets | — | — | — | ✓ |
| Your own single-tenant instance | — | — | — | ✓ |
SUPPORT & RESPONSE Who answers, and how long you wait. | ||||
| How to reach us | Email + Chat | Email + Chat + Phone | ||
| Reply within (feature / question) | Best-effort | 48 business hours | 24 business hours | 4 hrs critical / 24 hrs standard |
| Service-level agreement (with contractual penalties) | — | — | — | ✓ |
| Named success manager | — | — | — | ✓ |
| Quarterly business review | — | — | — | ✓ |
BILLING & COMMITMENT What you are signing up to, and for how long. These are limits, not features. | ||||
| Monthly billing (cancel anytime) | ✓ | ✓ | — | Custom |
| Annual billing | ✓ (~20% off) | ✓ (~20% off) | ✓ (annual-only) | Standard |
| Minimum commitment | 1 month | 1 month | 1 year | Per quote |
See your year-one ROI.
Five inputs. Live calculation. Same engine math your real assessment uses — calibrated against IBM 2025, Verizon, Sophos, and Coalition breach data.
Calculations are deterministic — the same engine that produces your real assessment. Numbers are illustrative based on declared inputs; your actual environment may produce different results.
When none of these is the right buy.
Four cases where the honest answer is to spend the money somewhere else. Do not buy this if any of them describes you.
You need to know within the hour that something changed.
CyberTwin reads exports you upload. It runs no scan, deploys no agent, and installs nothing, so the clock starts when you hand it a file. If detection speed is the requirement, a cloud-security platform or an endpoint tool with standing scans is the buy — and we will tell you whether you need one and price it in.
Your only need is collecting evidence to pass one audit by a fixed date.
Compliance-evidence platforms automate control attestations, policy distribution, training, and vendor reviews. If your sole need is "pass our audit by a fixed date," start with one of those. We complement, not replace — the two cover different layers and run together.
You want a virtual CISO with regular advisory time.
Virtual-CISO platforms include scheduled advisory time in the package. CyberTwin does not — we sell the engine output, not the relationship. If your motion is "a fractional CISO with software," that is the closer fit. If it is "I need the document," we are.
Procurement requires a named firm on the cover page.
Some engagements are bought for whose name signs them. We do not put a consulting brand on the cover and we do not issue an audit opinion — we produce the analysis underneath, cited and re-runnable. If the brand is the deliverable, hire the firm.
The longer version, with the concessions spelled out per category, is on /compare.
Asked before buying.
More on product, data, or compliance? Search the full FAQ →
Start small. Upgrade when it earns it.
Your reports are PDFs. They're yours — they work after you cancel.