CyberTwin
Pricing

Decide in three minutes. No call required.

Three self-serve plans, four published prices, no demo gate and no sales call in the way. Assess decides what to do, Operate runs the work, Program proves it.

Decide · Do · Prove — four published prices
  • (01)
    Assess
    DECIDE
    $4,800/yr
    $499/month, cancel anytime
  • (02)
    Operate
    DO
    $14,400/yr
    $1,499/month, cancel anytime
  • (03)
    ProgramRecommended
    PROVE
    $36,000/yr
    Annual only — no monthly option
  • (04)
    Enterprise
    PROGRAM, ON YOUR INFRASTRUCTURE
    Custom · from $72K/yr
    Typically $72–150K/year
Assess and Operate bill monthly or annually — cancel anytime; a monthly plan ends at the next cycle, an annual plan runs to its term. Program is annual only.Compare every line →

Not sure which tier fits?

(01)PUBLISHED PRICE

Every price on this page is the price.

There is no quote, no discovery call, and no "contact us for pricing" step between you and a number. The three self-serve plans check out with a card. Enterprise is the one plan that is quoted, and its range is printed anyway. Renewal is at the then-current published list price, less the published multi-year discounts where they apply — if our list price has not moved, yours does not either.

OBSERVATIONCHECKED 2026-08-25

On this date we opened the pricing pages of Vanta and Drata — two compliance-automation platforms a buyer comparing us is likely to open too. Neither page showed a dollar figure. Vanta listed four plans (Essentials, Plus, Professional, Enterprise) behind a "Get personalized pricing" action; Drata's page routed to a demo request.

That is a record of what two web pages showed on one day. It is not a claim about what either company charges, whether their pricing is fair, or how they choose to sell. Both pages are linked so you can check them yourself and see whether this is still true.

(02)START FROM THE DEADLINE

Match the plan to the date on your calendar.

Buyers here are working backwards from a date, not from a job title. Find the date, read the deliverable it needs, and the plan follows.

AN AUDIT DATE

Evidence your auditor can trace to a control, not a screenshot of a dashboard.

The auditor pack — control evidence with framework mapping.
Operate and up. The compliance-only report is on every plan, including Assess.
AN INSURANCE RENEWAL

The questionnaire answered from your real environment, and a read on where the cover falls short.

The broker pack — questionnaire pre-filled, plus the underinsurance gap analysis.
Operate and up.
A BOARD MEETING

Exposure in dollars as a two-sided band, with the assumptions named — not a colour-coded heat map.

The board pack and the risk register, both risk-quantified.
Every plan, starting at Assess.

Every plan boundary above is quoted from the same comparison rows rendered in the matrix below — the deliverable names are the row labels, not marketing paraphrase.

(03)DECIDE · DO · PROVE

What each plan actually buys.

ASSESS · DECIDE
$4,800/yr
$499/month, cancel anytime

For the founder staring down a first audit, a board question, or a customer questionnaire.

  • · Design a new stack — Lean, Balanced, Advanced, priced
  • · Review the architecture you already run
  • · Compliance scoring across all 24 frameworks
  • · Board-ready PDF + risk register
  • · Breach Replay — type a CVE ID, see if it reaches you
  • · 1 configuration review a year
OPERATE · DO
$14,400/yr
$1,499/month, cancel anytime

For the in-house team that owns security week to week.

  • Everything in Assess, plus:
  • · Configuration Review — 3 a year, rule by rule
  • · Single-vendor attack paths
  • · Report shares for your CFO, board, auditor, broker
  • · Insurance questionnaire pre-fill
  • · Underinsurance gap analysis
  • · Identity-export ingestion (Okta / Entra)
  • · Evidence ledger (read-only view)
  • · Re-run the assessment whenever your environment changes
PROGRAM · PROVE · RECOMMENDED
$36,000/yr
Annual only — no monthly option

For the security program that has to prove its posture all year, not assert it.

  • Everything in Operate, plus:
  • · Configuration Review — unlimited, all 37 vendors, 1,926 checks
  • · Multi-vendor attack paths to your crown jewels
  • · Proof over time — the evidence ledger, hash-chained and dated
  • · NHI Blast Radius · Vendor Breach Simulator · Agent-Reachability Gate
  • · Year-in-review report

The jump from Operate buys proof over time: a tamper-evident, dated evidence ledger, a proven-regression trail, and the year-in-review — the difference between asserting your posture to an auditor and handing them a bundle they can re-verify themselves. Your CISO judgment still owns the board meeting; the engine does the analysis underneath.

ENTERPRISE · CUSTOM
From $72K/yr
Typically $72–150K/year

For organizations that need the engine on their own infrastructure, under their own brand.

  • Everything in Program, plus:
  • · Single-tenant, on your infrastructure
  • · White-label PDFs under your brand
  • · Named CSM with quarterly review
  • · Custom SLA, MSA, and DPA

We'll handle MSA, DPA, and PO.

These are CyberTwin's subscription prices — a flat fee, published in full. They're separate from the tool-cost estimates inside your reports, which price the recommended security tools (sourced from vendor pages and Vendr benchmarks). We never blur the two. See what those tool costs look like for a company like yours →

Comparing us to consultants or platforms? →

(05)THE CONSTRAINTS

The limits, stated as limits.

Caps, exclusions and prerequisites read as caps, exclusions and prerequisites — not as bullets with the word “includes” in front of them. Each one is enforced by a real gate, and each is stated before you pay, not discovered after.

  • Limit: 1 configuration review per year on Assess.

    Operate raises it to 3 a year, one vendor per review. Program removes the cap.

  • Limit: 3 assessment refreshes per year on Assess.

    Operate and Program are unlimited. A refresh is a re-run, not a new subscription.

  • Program is annual only. There is no monthly option.

    Assess and Operate bill monthly or annually; on those two, monthly cancels at the next cycle.

  • No free trial. A card is required at signup.

    The evaluation path is the sample report (/sample-report) and the free attack-path sandbox (/demo) — both need no account.

  • No refunds. You can cancel before any future charge.

    After cancellation the account is read-only for 90 days so you can export, and the data is deleted at 180.

  • Every PROVEN line needs a file you upload.

    We run no scan, deploy no agent, and hold no credential to your systems — so with no export, a control stays MODELED.

  • Seats: 5 on Assess and Operate, 10 on Program.

    Seats cover people working in the app. The PDFs and share links you produce can go to anyone.

Data handling does not vary by plan: customer data at rest is hosted in Frankfurt (EU), encrypted in transit and at rest, and region-pinned residency is quoted on Enterprise only. That is one answer for all four plans rather than a column in the matrix — the subprocessors and the detail live on /trust.

(06)LINE BY LINE

Grouped by what you came here to ask.

Not by feature area — by buyer concern, with what gets PROVEN from a file you uploaded kept separate from what gets MODELED. Every plan scores all 24 frameworks.

Plan comparison, grouped by buyer concern. Four plans: Assess, Operate, Program, Enterprise.
WHAT YOU GET
Assess
$499/mo or $4,800/yr
Decide · cancel anytime
Operate
$1,499/mo or $14,400/yr
Do · cancel anytime
Program
$36,000/yr · annual only
Prove · Recommended
Enterprise
Custom · from $72K/yr
Custom contract
INTAKE & COVERAGE

What you can hand it, how much of it, and how often you can come back.

Read network diagrams and extract topology
Upload audit reports and security docs — we surface contradictions
Configuration Reviews per year13UnlimitedUnlimited
Vendors coveredAny 1 per reviewAny 1 per reviewAll 37All 37
Assessment refreshes3 / yearUnlimitedUnlimitedUnlimited
Monthly engine refresh + end-of-month digest email
WHAT GETS PROVENPROVEN

Read from the bytes of a file you uploaded, and citable back to it. Needs an export to exist.

Rule-by-rule security and compliance audit
What's misconfigured and how to fix it (per-finding remediation)
Rules Excel export
Re-upload an export to re-prove your posture
WHAT GETS MODELEDMODELED

Inferred, never read from a file — labelled as such everywhere it appears, with dollars as two-sided bands.

Recommended stack of security tools
Three priced options (lean, balanced, advanced) for each recommendation
Review of your current architecture — gaps and upgrades
Step-by-step setup guide for every tool you choose
Compare scenarios side-by-side
ATTACK PATHS & THE CUT

How an attacker gets from the edge to what matters, and the single change that severs the most routes.

Attack-path mapping from your architectureIn your reviewSingle-vendorMulti-vendorMulti-vendor
Specific attacker technique named for each weakness
Threat-group attribution
Cross-vendor attack chains, stitched to your crown jewels
Attack-path simulation report
PROOF & ARTIFACTS

The dated, signed files you keep — the part that still verifies after you stop paying us.

Evidence ledger — read-only view of your signed entries
Evidence ledger — tamper-evident proof trail
Proven-regression trail (a closed gap that reopens)
Proven-closure copilot (a fix is closed only when re-proven)
Audit readiness — show-me vs trust-me per control
Year-in-review report (60 days before your renewal)
COMPLIANCE & REPORTS

The documents you hand to a named person: an auditor, a broker, a board.

Compliance posture across all 24 frameworks
Board-ready PDF + risk register
Compliance-only report for your auditor
Pack for your board (risk-quantified)
Pack for your auditor (control evidence + framework mapping)
Pack for your insurance broker (questionnaire pre-filled)
All compliance playbooks as Word documents
Each setup step tagged with which compliance controls it satisfies
Incident retrospective template
OSCAL export — machine-readable control evidence for GRC tools (NIST OSCAL: SAR, POA&M, profile, catalog)
SHARING & ADMIN

Getting the output to people who do not log in, and into systems that do not read PDFs.

Share reports with stakeholders
Read-only API — pull your posture, findings, and compliance scores into your own tools on a schedule
Your firm's logo on every PDF (white-label)
Map your custom internal control sets
Your own single-tenant instance
SUPPORT & RESPONSE

Who answers, and how long you wait.

How to reach usEmailEmailEmail + ChatEmail + Chat + Phone
Reply within (feature / question)Best-effort48 business hours24 business hours4 hrs critical / 24 hrs standard
Service-level agreement (with contractual penalties)
Named success manager
Quarterly business review
BILLING & COMMITMENT

What you are signing up to, and for how long. These are limits, not features.

Monthly billing (cancel anytime)Custom
Annual billing✓ (~20% off)✓ (~20% off)✓ (annual-only)Standard
Minimum commitment1 month1 month1 yearPer quote
(07)ROI CALCULATOR · POWERED BY THE ACTUAL ENGINE

See your year-one ROI.

Five inputs. Live calculation. Same engine math your real assessment uses — calibrated against IBM 2025, Verizon, Sophos, and Coalition breach data.

Modeled loss if nothing changes (MODELED)
Source: IBM Cost of a Data Breach 2025 (per-record anchor) + engine FAIR model
Modeled loss if the Operate-cadence fixes are implemented (MODELED)
Source: Engine effectiveness curve calibrated against Balanced reference (posture 78)
Modeled loss if the Program-cadence fixes are implemented (MODELED)
Source: Engine effectiveness curve calibrated against Advanced reference (posture 91)

Calculations are deterministic — the same engine that produces your real assessment. Numbers are illustrative based on declared inputs; your actual environment may produce different results.

(08)WHEN TO WALK AWAY

When none of these is the right buy.

Four cases where the honest answer is to spend the money somewhere else. Do not buy this if any of them describes you.

(01)

You need to know within the hour that something changed.

CyberTwin reads exports you upload. It runs no scan, deploys no agent, and installs nothing, so the clock starts when you hand it a file. If detection speed is the requirement, a cloud-security platform or an endpoint tool with standing scans is the buy — and we will tell you whether you need one and price it in.

(02)

Your only need is collecting evidence to pass one audit by a fixed date.

Compliance-evidence platforms automate control attestations, policy distribution, training, and vendor reviews. If your sole need is "pass our audit by a fixed date," start with one of those. We complement, not replace — the two cover different layers and run together.

(03)

You want a virtual CISO with regular advisory time.

Virtual-CISO platforms include scheduled advisory time in the package. CyberTwin does not — we sell the engine output, not the relationship. If your motion is "a fractional CISO with software," that is the closer fit. If it is "I need the document," we are.

(04)

Procurement requires a named firm on the cover page.

Some engagements are bought for whose name signs them. We do not put a consulting brand on the cover and we do not issue an audit opinion — we produce the analysis underneath, cited and re-runnable. If the brand is the deliverable, hire the firm.

The longer version, with the concessions spelled out per category, is on /compare.

(09)PRICING FAQ

Asked before buying.

Nothing is metered by environment — every paid plan includes unlimited environments. You typically run one per business unit, region, or production-vs-staging boundary. We tier on depth of audit and breadth of tool coverage, not on how much you use us, because charging for "more environments" rewards the wrong thing.
The files you already downloaded stay yours and keep working — a signed proof bundle re-verifies in a browser tab with our servers switched off, so it does not depend on an active subscription. Inside the account: after cancellation it is read-only for 90 days so you can export everything, retained a further 90 days in case you come back, and deleted at 180 days. Nothing is deleted while you still have export access.
No. There is no agent to install, no scan, no connector, and no credential of yours in our hands — the engine reads the exports and documents you upload and nothing else. Secrets are redacted in memory before anything is written to disk. Read-only connectors into your systems (cloud, identity, SIEM) are on the post-launch roadmap and are not live today.
Yes. Upgrade any time and proration is applied automatically — you pay the difference for the remainder of the term, with no upgrade fee. Moving up to Program means moving onto its annual term, since Program has no monthly option. Downgrades take effect at the end of the cycle you have already paid for.
Assess at $499/month or $4,800/year: the decision engine output — architecture design, current-state review, 24-framework compliance scoring, scenario comparison, and the board-ready PDF. No free tier today; the engine output requires actual customer + environment data to be useful.
Operate audits one of your security tools' configuration deeply per review, three reviews a year (you upload the config export), and includes the auditor pack, the insurance broker questionnaire pre-fill, and attack-path reporting. Program runs unlimited reviews across all 37 supported tools — you upload the configs, we run every vendor-specific check — plus cross-vendor attack-path chains stitched to your crown jewels, the evidence ledger, and the year-in-review report. If you've got one critical system to scrutinize, Operate fits. If you're running a full program, Program is the fit.
Assess and Operate monthly billing cancels at the next billing cycle. Annual billing runs to term.
No refunds on paid tiers, but you can cancel before any future charge. After cancellation, your account is read-only for 90 days so you can export your data; we retain the data for another 90 days for re-activation; deleted permanently after 180 days.
You keep your data. You lose access to features the lower tier doesn't include. Your existing PDFs remain downloadable for 90 days. You can re-upgrade anytime.
Credit card (Visa, Mastercard, Amex). ACH for annual purchases over $10,000 — email billing@cybertwin.io to set up. Wire transfer for multi-year contracts. No invoicing on monthly plans.
No free trial — card is required at signup. The sample report at /sample-report is the evaluation path: download it, see exactly what the engine produces, then decide. Assess is the paid entry tier ($4,800/yr or $499/mo).
Monthly billing is charged every 30 days. Annual is one upfront payment and saves the real dollar gap per tier — $1,188/yr on Assess, $3,588/yr on Operate (about 20% off the monthly run-rate). Program is annual-only. Both options support the same feature set on the chosen tier.
Upgrade anytime — proration is applied automatically. Downgrade takes effect at the end of your current billing cycle. No upgrade penalties, no downgrade penalties.
Yes. 10% off year 2 of an annual subscription. 20% off year 3. Three-year prepay available — email billing@cybertwin.io. The discount applies to the published list price; we don't negotiate beyond what's published.
30% off any tier for: registered 501(c)(3) nonprofits, accredited education institutions, pre-seed and seed-stage startups (under $5M raised). Email hello@cybertwin.io with proof before signup. Discount applies for as long as you remain eligible.
When you need any of: white-label PDFs (custom logo + cover branding), single-tenant deployment, multi-entity grouping (parent + subsidiaries under one contract), a dedicated success manager, SLA-backed response time with contractual penalties, custom framework mapping, or custom integrations. Email enterprise@cybertwin.io or use the contact form — pricing typically lands in the $72–150K/yr range depending on scope.

More on product, data, or compliance? Search the full FAQ →

READY TO START

Start small. Upgrade when it earns it.

Your reports are PDFs. They're yours — they work after you cancel.

Pricing — CyberTwin