Pricing
Priced for founders, not procurement
Annual list prices, ex VAT. No per-control fees, no setup charges, no surprise "success" invoices when you pass your audit.
Light
£4,000
or £360 / month
3 seats
Founding team preparing for Stage 1.
- Full policy set & Annex A controls
- Risk register with owners
- Hash-chained audit log
- Incident & DSAR log
- MCP agent access (ChatGPT, Claude, Cursor)
- Email support
Business
Popular£8,000
or £720 / month
10 seats
Startups running a live ISMS with department heads.
- Everything in Light
- Role separation: Head of InfoSec / Head of Dept / Auditor
- Supplier register & third-party reviews
- Assets & information classification
- MCP agent access (ChatGPT, Claude, Cursor)
- Priority email support
Enterprise
£16,000
or £1,440 / month
Unlimited seats (fair-use)
Certified organisations with multiple departments and auditors.
- Everything in Business
- Multiple auditors & external reviewer access
- SSO on request
- Custom sub-processor & DPA reviews
- MCP agent access (ChatGPT, Claude, Cursor)
- Named contact for support
- Dedicated environment option on request (separate backend, scoping call)
Framework bolt-ons
One ISMS. Every certification your customers ask for
ISO 27001 is your foundation. Each bolt-on maps back to it, so controls, evidence and policies you've already implemented count automatically — no duplicated work. Every module below is £2,000 / year.
SOC 2
Add-on£2,000 / year
~65% inherited from ISO 27001
US enterprise contracts and vendor security reviews.
- Trust Services Criteria mapped to Annex A
- Audit-ready System Description
- Evidence inherits from your SoA
ISO 42001 (AI)
Add-on£2,000 / year
~45% inherited from ISO 27001
AI-first products proving responsible AI governance.
- Clauses 4–10 + Annex A AI controls
- AI impact assessment scaffolding
- Auditable AI management system
ISO 9001 (Quality)
Add-on£2,000 / year
~80% inherited from ISO 27001
Regulated markets, tenders and quality-conscious buyers.
- Clauses 4–10 + quality-specific mappings
- Management review consolidation
- Printable QMS description
DORA
Add-on£2,000 / year
~70% inherited from ISO 27001
EU financial entities and their critical ICT providers under Regulation (EU) 2022/2554.
- Five-pillar coverage: risk, incidents, testing, third-party, intel-sharing
- Register of Information & 24h/72h/1mo reporting timers
- Dashboard readiness card
NCSC CAF v3.2
Add-on£2,000 / year
~65% inherited from ISO 27001
UK NIS Operators of Essential Services and central-government GovAssure.
- Objectives A–D and 39 Contributing Outcomes
- Enhanced, Basic and custom CA profiles
- Per-Objective scoring on the dashboard
NIS2
Add-on£2,000 / year
~70% inherited from ISO 27001
EU essential and important entities under Directive (EU) 2022/2555.
- Article 21 measures mapped to Annex A
- Management-body accountability records
- Incident reporting timers (24h/72h/1mo)
NIST CSF / 800-53
Add-on£2,000 / year
~75% inherited from ISO 27001
US federal supply chain and enterprise buyers using NIST frameworks.
- CSF 2.0 functions + 800-53 Rev 5 crosswalk
- Control inheritance and evidence reuse
- Profile-based scoring
ISO 27701 (Privacy)
Add-on£2,000 / year
~85% inherited from ISO 27001
Privacy-conscious buyers and GDPR-heavy sectors.
- PIMS extension of your ISMS
- Controller / processor role split
- GDPR Article mapping
Cyber Essentials
Add-on£2,000 / year
~60% inherited from ISO 27001
UK public-sector tenders and MOD supply chain baseline.
- Five technical control areas
- Self-assessment questionnaire scaffold
- Assessor-ready evidence pack
NHS DSPT
Add-on£2,000 / year
~70% inherited from ISO 27001
NHS providers and their sub-processors.
- Standards and evidence items mapped
- Assertion authoring workflow
- Submission-ready export
EU AI Act
Add-on£2,000 / year
~50% inherited from ISO 27001
Providers and deployers of AI systems in the EU market.
- Risk-tier classification (prohibited / high / limited / minimal)
- Article 9–15 obligations tracker
- Conformity assessment evidence
GDPR
Add-on£2,000 / year
~85% inherited from ISO 27001
Any organisation processing UK / EU personal data.
- Article 30 records (ROPA)
- DSAR & Article 34 breach registers
- DPIA & sub-processor workflows
Launch offer — available until 31 December 2026
Take any 3 modules for £4,000
Mix and match from the full bolt-on catalogue. One flat annual price, no surprises.
Prefer to pay monthly?
Monthly plans available on request
Email us and we'll issue a licence tailored to your billing cycle.
Common questions
- Do you charge implementation or setup fees?
- No. The list price is the price. Optional advisory days are billed separately at £399/day (ex VAT) only if you ask for them.
- What happens after the free trial?
- Your workspace stays intact and moves to the tier you choose. Nothing is auto-charged during the trial.
- Is my data hosted in the UK/EU?
- Yes. Managed Postgres and storage sit in the EU region. Full detail on the security page.
- Can we get a dedicated environment?
- Yes — Enterprise customers can request a physically separated backend environment by arrangement. Contact us for scoping and pricing.
- Can we get a DPA?
- Yes — our standard Data Processing Agreement is available and covers Article 28 UK GDPR.