Skip to main content
20% off — first 20 customers. See the offer →

Pricing

One price list. Every user included

Four plans banded by company size, not seats. ISO 27001 and UK / EU GDPR essentials are in the core of every plan. Prices are annual list prices in pounds sterling, excluding VAT. No per-user fees, no per-control fees, no setup charges and no success invoice when you pass your audit.

See all 29 modulesWhat the platform doesFounding customer rate

Starter

£1,500

per year (£125 a month equivalent)

£1,200 at the founding-customer rate

£139 month to month, cancel any time

Up to 25 employees

Founding teams getting certified for the first time.

Starter is a subscription to the Sentinel42 platform for organisations with up to 25 employees. It includes the ISO 27001 core — risk register, Statement of Applicability, policies, evidence vault, audits and management review — and UK / EU GDPR essentials (records of processing, data subject requests, DPIAs and breach log), with unlimited users, the AI assistant on fair use, standard integrations and email support. Framework modules are £2,000 a year each or any three for £5,000. Billed annually in advance, or month to month at a 10% premium with no minimum term.

  • ISO 27001 core: risks, Statement of Applicability, policies, evidence vault, audits, management review
  • UK / EU GDPR essentials: ROPA, DSAR, DPIA, breach log
  • Unlimited users — every control owner, approver and auditor included
  • AI assistant on fair use
  • Standard integrations
  • Email support

Modules £2,000 each, or any three for £5,000

Business

Most popular

£5,000

per year (£417 a month equivalent)

£4,000 at the founding-customer rate

£459 month to month, cancel any time

Up to 100 employees

Companies running a live ISMS with department heads and auditors.

Business is a subscription for organisations with up to 100 employees. It includes everything in Starter plus executive and board reporting, the Trust Centre, auditor access with the one-click audit pack, all integrations and AI agents, priority support and an onboarding workshop. No framework module is included: modules are £2,000 a year each or any three for £5,000. Billed annually in advance, or month to month at a 10% premium with no minimum term.

  • Everything in Starter
  • Executive and board reporting
  • Trust Centre
  • Auditor access and one-click audit pack
  • All integrations and AI agents
  • Priority support
  • Onboarding workshop

Modules £2,000 each, or any three for £5,000

Scale

£10,000

per year (£833 a month equivalent)

£8,000 at the founding-customer rate

Annual only

Up to 500 employees

Multi-framework organisations with more than one entity.

Scale is an annual subscription for organisations with up to 500 employees. It includes everything in Business plus every framework module, single sign-on, up to three workspaces or entities, API access, a quarterly review with a Sentinel42 consultant and a service-level agreement. There is no module pricing on Scale: every module is included. Billed annually in advance.

  • Everything in Business
  • Every framework module included
  • Single sign-on
  • Up to three workspaces or entities
  • API access
  • Quarterly review with a Sentinel42 consultant
  • Service-level agreement

Every module included — no framework tax

Enterprise

From £18,000

per year, priced per deal

Annual only

500+ employees or groups

Groups, regulated firms and organisations with data-residency requirements.

Enterprise is an annual subscription for organisations with more than 500 employees, or for groups of companies, priced per agreement from £18,000 a year. It includes everything in Scale plus unlimited workspaces, a dedicated success contact, a security review and a custom Data Processing Agreement, an onboarding programme and, by arrangement, a dedicated instance in a chosen region. Every module is included. Enterprise is contracted under a Master Services Agreement and sits outside the founding-customer offer.

  • Everything in Scale
  • Unlimited workspaces
  • Dedicated success contact
  • Security review and custom DPA
  • Onboarding programme
  • Optional data-residency instance in a chosen region, by arrangement

Every module included

Want to see it before you decide? Book a 30-minute demo — or take the free ISO 27001 starter checklist.

Company size bands are up to 25, up to 100, up to 500 and 500-plus employees. The band is declared by you and written into the order. Month-to-month is available on Starter and Business at a 10% premium and cancels any time. 14-day free trial, no card required.

Founding customer rate — 20 places

20% off Starter, Business or Scale, locked for 24 months

The first 20 paying customers on a Starter, Business or Scale annual plan take 20% off the tier price, locked for 24 months. If 20 places are not taken the offer closes on 31 March 2027 regardless.

  • Annual plans only. Month-to-month is at list with a 10% premium and cancels any time.
  • Modules are always at list — the founding rate applies to the tier price only.
  • Enterprise is outside the offer.
  • Not combined with any other discount; if you also qualify for the charity, education or two-year prepaid discount you take whichever is better.
  • From month 25 the list price in force at the time applies, disclosed at signup and in the order, with the CPI + 2% renewal cap from then on.
Apply for a founding place

Framework modules

One ISMS. Every framework your customers ask for

ISO 27001 and GDPR essentials are your foundation. Every module maps back to them, so controls, evidence and policies you have already implemented count automatically. £2,000 a year each, or any three for £5,000 on Starter and Business. Scale and Enterprise include every module. Modules are always at list price — the founding rate applies to the plan price only.

The published launch offer of any three modules for £4,000 is honoured for orders placed up to 31 December 2026, as promised.

SOC 2 (Type I & II)

Module

Trust Services Criteria, system description, audit periods and guest auditor access for US enterprise deals.

~65% inherited from ISO 27001

ISO 27701 (privacy)

Module

Privacy information management as an extension of your ISMS, with controller and processor split.

~85% inherited

ISO 42001 (AI management)

Module

AI management system: clauses, Annex A AI controls, AI system register and impact assessments.

~45% inherited

EU AI Act

Module

Risk classification, Article 9–15 obligations and conformity evidence for AI providers and deployers.

~50% inherited

ISO 9001 (quality)

Module

Quality management system with shared management review and quality records.

~80% inherited

DORA

Module

Five pillars, register of information and 24h / 72h / 1 month reporting clocks for EU financial entities.

~70% inherited

NIS2

Module

Article 21 measures, management accountability records and incident reporting timers.

~70% inherited

NCSC CAF v3.2

Module

Objectives A–D, 39 contributing outcomes and profile-based scoring for UK OES and GovAssure.

~65% inherited

NIST CSF 2.0 / 800-53

Module

CSF functions with an 800-53 Rev 5 crosswalk and evidence reuse.

~75% inherited

NIST 800-171 / CMMC 2.0

Module

Requirement families and CMMC level guidance for US defence supply chains.

~70% inherited

Cyber Essentials

Module

The five technical control areas with a self-assessment scaffold and evidence pack.

~60% inherited

Cyber Essentials Plus

Module

Assessor verification records, sampling and certificate register on top of Cyber Essentials.

Defence Cyber Certification

Module

Def Stan 05-138 Issue 4 controls across Levels 0–3 for MOD suppliers, mapped to your Annex A controls.

PCI DSS v4.0.1

Module

Requirements, SAQ guidance and readiness summaries for card data environments.

TISAX / VDA ISA 6

Module

Information security, prototype protection and data protection assessment groups for automotive.

ISO 22301 (continuity)

Module

Business continuity management using your BIA, continuity plans and restore tests.

HIPAA

Module

Security, Privacy and Breach Notification rules with BAA tracking for health data.

NHS DSPT

Module

Standards, assertions and a submission-ready export for NHS providers and their sub-processors.

~70% inherited

UK Cyber Security and Resilience Bill

Module

Duties tracked against your existing controls so you are ready before it commences.

ISO 27017 / 27018 (cloud)

Module

Cloud security and cloud PII extensions with shared-responsibility guidance.

CSA STAR (CCM v4 / CAIQ)

Module

Cloud Controls Matrix domains, STAR level guidance and a CAIQ-style coverage export.

ISO 27036 (supplier security)

Module

Supplier security across plan, agree, operate and exit, driven by your supplier register.

EU Cyber Resilience Act

Module

Essential product requirements, vulnerability handling duties and reporting deadlines.

FCA / PRA operational resilience

Module

Important business services, impact tolerances, scenario testing and SS2/21 outsourcing duties.

ISO 37002 (whistleblowing)

Module

Confidential reporting channels, impartial investigation, protection from retaliation and trend reporting to the board.

ISO 20000-1 (service management)

Module

Service catalogue, service levels, capacity, availability, change, incident, problem and release management.

~60% inherited

PECR & cookie consent records

Module

Cookie and tracker inventory, consent before non-essential cookies, marketing rules and demonstrable consent records.

~70% inherited

Pharmaceutical wholesale distribution (GDP)

Module

MHRA Good Distribution Practice: responsible person duties, batch and serial traceability, controlled drugs register, temperature excursions, recalls and returns.

Modern Slavery & ESG

Module

Section 54 transparency statement, supply chain due diligence beyond tier one, labour standards and ESG governance.

Full module detail, and what is in the core

Module bundles

Three modules for £5,000, chosen for the deal you are chasing

Most companies do not buy modules one at a time. They buy them because a customer, a regulator or a tender has asked for a particular set. The bundles below are the three-module combinations we are asked for most often, at the standard pack price of £5,000 a year — £1,000 less than the same modules bought separately. Every bundle maps back to your ISO 27001 core, so controls and evidence you have already put in place count towards each new framework automatically. Swap any module for another, add a fourth at £2,000, or simply pick any three of the 29 — and every further three are another £5,000. On Scale and Enterprise every module is included, so the bundles are just a sensible order in which to switch them on.

Any three modules — a bundle below or your own selection — £5,000 a year on Starter and Business. Additional modules £2,000 a year each. Every module included on Scale and Enterprise. On month-to-month plans modules follow the plan's cadence at the same 10% premium: £184 a month for a single module, £459 a month for any three.

Modules are always at list price: the founding-customer rate applies to the plan price only. The published launch offer of any three modules for £4,000 is honoured for orders placed up to 31 December 2026.

US enterprise sales

For UK and EU companies selling to American enterprises.

  • SOC 2 (Type I & II)
  • NIST CSF 2.0 / 800-53
  • CSA STAR (CCM v4 / CAIQ)

The three things a US procurement team asks for: a SOC 2 report, a NIST alignment statement and a completed CAIQ. Around two-thirds of SOC 2 and three-quarters of NIST CSF inherit directly from your ISO 27001 controls, so most of the bundle is evidence you already hold, mapped and presented the way American buyers expect.

Often added: HIPAA, if you handle US health data.

£5,000 a year

NHS and public sector supplier

For suppliers to the NHS, local government and central government.

  • Cyber Essentials
  • Cyber Essentials Plus
  • NHS DSPT

Cyber Essentials is the baseline for any UK public contract, Plus is what the larger frameworks and NHS trusts want to see, and the Data Security and Protection Toolkit is required of every organisation with access to NHS patient data or systems. The bundle runs all three from one evidence set, with a submission-ready DSPT export.

Often added: NCSC CAF v3.2, if you are an operator of essential services or in scope of GovAssure.

£5,000 a year

Defence supply chain

For MOD suppliers and companies in US defence supply chains.

  • Defence Cyber Certification
  • Cyber Essentials Plus
  • NIST 800-171 / CMMC 2.0

Defence Cyber Certification (Def Stan 05-138 Issue 4, Levels 0 to 3) is being introduced into MOD contracts, Cyber Essentials Plus is the entry ticket, and NIST 800-171 with CMMC 2.0 covers the US primes. The DCC module was built and mapped by a qualified DCC auditor, so the control interpretations are the ones an assessor will recognise.

Often added: ISO 27036 (supplier security), for the flow-down to your own sub-contractors.

£5,000 a year

EU regulated entities

For essential and important entities under NIS2 and financial entities under DORA.

  • NIS2
  • DORA
  • ISO 22301 (continuity)

NIS2's Article 21 measures and DORA's five pillars overlap heavily with each other and with ISO 27001 — about seventy per cent of each inherits from the core. ISO 22301 supplies the business continuity discipline both regulations assume, with the business impact analysis, continuity plans and restore tests regulators ask to see. The incident-reporting clocks for both regimes run in the platform.

Often added: EU Cyber Resilience Act, if you place digital products on the EU market.

£5,000 a year

UK financial services and payments

For FCA and PRA regulated firms and anyone handling card data.

  • FCA / PRA operational resilience
  • PCI DSS v4.0.1
  • ISO 27036 (supplier security)

Important business services, impact tolerances and scenario testing under the FCA and PRA operational resilience rules, with SS2/21 outsourcing duties; the PCI DSS requirements and SAQ guidance for your card data environment; and supplier security across plan, agree, operate and exit, which is where the outsourcing rules and PCI's service-provider duties bite hardest.

Often added: DORA, if you serve EU financial entities.

£5,000 a year

AI governance

For companies building or deploying AI systems.

  • ISO 42001 (AI management)
  • EU AI Act
  • ISO 27701 (privacy)

ISO 42001 gives you a certifiable AI management system; the EU AI Act module tracks risk classification and the Article 9 to 15 obligations for providers and deployers; ISO 27701 extends your ISMS to the personal data most AI systems process. Together they answer the AI section now appearing in every enterprise security questionnaire.

Often added: ISO 27017 / 27018 (cloud), if your models run on third-party cloud.

£5,000 a year

Cloud and managed service providers

For hosting, SaaS and managed service providers selling to security-conscious customers.

  • ISO 27017 / 27018 (cloud)
  • CSA STAR (CCM v4 / CAIQ)
  • ISO 20000-1 (service management)

The cloud security and cloud-PII extensions to ISO 27001; the Cloud Controls Matrix with a CAIQ-style export for customer due diligence; and a service management system for the catalogue, service levels, change and incident management your contracts promise. About sixty per cent of ISO 20000-1 inherits from what you already run.

Often added: SOC 2, for US customers.

£5,000 a year

Tender ready

For companies bidding into public sector and large corporate tenders.

  • ISO 9001 (quality)
  • ISO 22301 (continuity)
  • Modern Slavery & ESG

The three questions that sit next to information security on almost every pre-qualification questionnaire: do you have a quality management system, a business continuity plan and a modern slavery statement. ISO 9001 shares your management review and around eighty per cent of its structure with ISO 27001; ISO 22301 uses your existing impact analysis and restore tests; the Modern Slavery & ESG module produces the Section 54 statement and supply-chain due diligence evidence.

Often added: Cyber Essentials, which most UK tenders also require.

£5,000 a year

Sector modules that stand on their own

TISAX / VDA ISA 6 (automotive) · Pharmaceutical wholesale distribution (GDP) · HIPAA · ISO 37002 (whistleblowing) · PECR & cookie consent records · UK Cyber Security and Resilience Bill

£2,000 a year each — or add any two of them to a third module and pay the bundle price of £5,000.

How bundles work

  • A bundle is three modules for £5,000 a year on Starter and Business — the same price as any three modules of your own choosing. Bundles are curated selections, not a separate price.
  • Swap freely: replace any module in a bundle with any other at no change in price.
  • A fourth and fifth module are £2,000 a year each; every further three modules form another pack at £5,000, so six modules are £10,000.
  • Modules run co-terminous with your plan and renew with it. Added part-way through the year, they are charged pro rata to your renewal date. A module you no longer need comes off at renewal.
  • On annual plans, modules are invoiced with the plan. On month-to-month Starter and Business, modules are billed monthly on the same basis as the plan — £184 a month for a single module, £459 a month for any three.
  • Modules are always at list price. The founding-customer rate, and the charity, education and prepaid discounts, apply to the plan price only.
  • Scale and Enterprise include every module; on those plans the bundles are simply a recommended order in which to switch modules on.
  • Inherited-control figures are typical values from the platform's control mappings and vary with your scope and Statement of Applicability.
  • The published launch offer of any three modules for £4,000 is honoured for orders placed up to 31 December 2026.

The honest steer

Business plus a three-module bundle is £10,000 a year — the same as Scale, which includes every module, single sign-on, up to three workspaces, API access and a quarterly consultant review, for organisations of up to 500 employees. If you are on Business and need three or more modules, ask us about Scale before you order. We would rather say so now than at renewal.

How our pricing works

The short version of our commercial terms. The Platform Terms of Service are the full version and take precedence where the two differ.

Company size bands
Plans are banded by your total headcount — permanent and fixed-term employees, workers and contractors — whether or not they use the platform. The bands are up to 25, up to 100, up to 500 and 500-plus. You declare your headcount when you subscribe and again at each renewal, and it is written into your order. If your headcount grows past your band during the year, tell us within 30 days and we move you to the right plan, charging only the difference for the rest of the period.
Users
Every plan includes unlimited users within your organisation, plus guest access for your auditors and advisers. Credentials are personal and must not be shared between individuals.
What every plan includes
The ISO 27001 core, UK / EU GDPR essentials, the AI assistant, standard integrations, the hash-chained audit log and data export at any time. There is no charge for setup, for the number of controls in scope, or for passing your audit.
Billing and payment
Annual plans are invoiced in advance at the start of each subscription year. Month-to-month billing is available on Starter and Business only, invoiced monthly in advance at the annual price plus 10%, and can be cancelled at any time to the end of the current month. Pay by card through our payment provider or by bank transfer within 30 days of the invoice date. All prices are in pounds sterling and exclude VAT.
Term, renewal and cancellation
Annual plans run for 12 months and renew automatically for a further 12 months unless either of us gives at least 30 days' written notice before the renewal date. Month-to-month plans can be cancelled from your account or by email and end at the close of the current monthly period.
Price protection
Your plan price is fixed for 24 months from your start date. After that, any change applies from a renewal date with at least 60 days' notice, and an increase is capped at the change in UK CPI over the previous 12 months plus two percentage points.
Changing plan
Upgrade at any time and pay only the pro-rata difference for the rest of your period. Downgrades take effect at your next renewal.
Framework modules
On Starter and Business, modules are £2,000 a year each or any three for £5,000. Scale and Enterprise include every module. On month-to-month plans modules are billed monthly on the same basis as the plan — £184 a month for a single module, £459 a month for any three. Modules added part-way through the year are charged pro rata to your renewal date so that everything renews together; a module you no longer need comes off at renewal. Modules are always at list price.
Founding-customer rate
The first 20 paying customers on an annual Starter, Business or Scale plan, through any channel, take 20% off the plan price, locked for 24 months from their start date. The offer closes when the places are taken or on 31 March 2027, whichever comes first. Annual plans only; modules at list; Enterprise excluded; not combined with any other discount. From month 25 the published plan price then in force applies, disclosed at signup and in your order, with the CPI + 2% cap from then on.
Other discounts
Registered charities, education providers and customers who prepay two years qualify for a discount on the plan price — ask us. Discounts do not stack: if you qualify for more than one, you take whichever is better. Modules are always at list.
What is not included
Certification-body audit fees, penetration testing and Cyber Essentials assessment fees are paid directly to the provider concerned, as they are with every vendor in this market. Sentinel42 can quote for implementation, internal audit and fractional CISO support alongside the platform, delivered by a UK lead auditor.
Buying through a partner
If a Sentinel42 partner introduced you and you contract with them, the partner invoices you for the platform and remains your commercial contact. Your use of the platform and your data are still covered by our terms, and the partner can exercise your export rights on your written authority.
From trial to paid
Your 14-day trial workspace becomes your live workspace when you choose a plan, so nothing is rebuilt. No card is taken and nothing is charged during the trial. If you decide not to subscribe, trial data is deleted 30 days after the trial ends.
Your data at the end
When a subscription ends you have 30 days to export your data in machine-readable formats. We then delete your instance from live systems within 30 days and confirm in writing if you ask.

What is not included

These are separate with every vendor in this market, and we would rather say so here than in a renewal conversation.

  • Certification-body audit fees — separate with every vendor
  • Penetration testing
  • Cyber Essentials assessment fees

Sentinel42 can quote for implementation, internal audit and fractional CISO support alongside the platform, delivered by a UK lead auditor. Ask us for the services rate card.

Common questions

Are users capped on any plan?
No. Every plan includes unlimited users, because an ISMS only works if every control owner, approver and auditor is in it. Plans are banded by company size instead, plus guest access for your auditors and advisers.
Is GDPR an extra?
No. Records of processing, data subject requests, DPIAs and the breach log are in the core of every plan. ISO 27701, SOC 2, NIS2 and the rest are modules.
Do you charge implementation or setup fees?
No. The list price is the price. Optional advisory days are billed separately only if you ask for them.
What happens after the free trial?
Your workspace stays intact and becomes your live workspace on the plan you choose, so nothing is rebuilt. No card is taken and nothing is charged during the trial. If you decide not to subscribe, trial data is deleted 30 days after the trial ends.
Where is my data hosted?
In the EU region by default — full detail on the security page. Enterprise customers can request a dedicated instance in a chosen region by arrangement; see international data protection.
Can I pick my own three modules?
Yes. The bundles are the combinations we are asked for most often, but any three modules are £5,000 a year, and you can swap any module in a bundle for any other.
What if I only need one module?
A single module is £2,000 a year. You can add a second and third later; once you have three you pay the pack price of £5,000 from your next renewal, or from the date you add the third if you ask us to re-base the order.
Do bundles get the founding-customer rate?
No. The founding rate is 20% off the plan price only. Modules and bundles are always at list.
Can I change the modules in a bundle after I have bought it?
You can add modules at any time, charged pro rata to your renewal date. Swapping or removing a module takes effect at renewal.
I am on Scale or Enterprise — do bundles matter to me?
No. Every module is included in your plan, so switch on whichever you need whenever you need it.
Can we get a DPA?
Yes — our standard Data Processing Agreement is available and covers Article 28 UK GDPR.