Pricing
One price list. Every user included
Four plans banded by company size, not seats. ISO 27001 and UK / EU GDPR essentials are in the core of every plan. Prices are annual list prices in pounds sterling, excluding VAT. No per-user fees, no per-control fees, no setup charges and no success invoice when you pass your audit.
See all 29 modulesWhat the platform doesFounding customer rate
Starter
£1,500
per year (£125 a month equivalent)
£1,200 at the founding-customer rate
£139 month to month, cancel any time
Up to 25 employees
Founding teams getting certified for the first time.
Starter is a subscription to the Sentinel42 platform for organisations with up to 25 employees. It includes the ISO 27001 core — risk register, Statement of Applicability, policies, evidence vault, audits and management review — and UK / EU GDPR essentials (records of processing, data subject requests, DPIAs and breach log), with unlimited users, the AI assistant on fair use, standard integrations and email support. Framework modules are £2,000 a year each or any three for £5,000. Billed annually in advance, or month to month at a 10% premium with no minimum term.
- ISO 27001 core: risks, Statement of Applicability, policies, evidence vault, audits, management review
- UK / EU GDPR essentials: ROPA, DSAR, DPIA, breach log
- Unlimited users — every control owner, approver and auditor included
- AI assistant on fair use
- Standard integrations
- Email support
Modules £2,000 each, or any three for £5,000
Business
Most popular£5,000
per year (£417 a month equivalent)
£4,000 at the founding-customer rate
£459 month to month, cancel any time
Up to 100 employees
Companies running a live ISMS with department heads and auditors.
Business is a subscription for organisations with up to 100 employees. It includes everything in Starter plus executive and board reporting, the Trust Centre, auditor access with the one-click audit pack, all integrations and AI agents, priority support and an onboarding workshop. No framework module is included: modules are £2,000 a year each or any three for £5,000. Billed annually in advance, or month to month at a 10% premium with no minimum term.
- Everything in Starter
- Executive and board reporting
- Trust Centre
- Auditor access and one-click audit pack
- All integrations and AI agents
- Priority support
- Onboarding workshop
Modules £2,000 each, or any three for £5,000
Scale
£10,000
per year (£833 a month equivalent)
£8,000 at the founding-customer rate
Annual only
Up to 500 employees
Multi-framework organisations with more than one entity.
Scale is an annual subscription for organisations with up to 500 employees. It includes everything in Business plus every framework module, single sign-on, up to three workspaces or entities, API access, a quarterly review with a Sentinel42 consultant and a service-level agreement. There is no module pricing on Scale: every module is included. Billed annually in advance.
- Everything in Business
- Every framework module included
- Single sign-on
- Up to three workspaces or entities
- API access
- Quarterly review with a Sentinel42 consultant
- Service-level agreement
Every module included — no framework tax
Enterprise
From £18,000
per year, priced per deal
Annual only
500+ employees or groups
Groups, regulated firms and organisations with data-residency requirements.
Enterprise is an annual subscription for organisations with more than 500 employees, or for groups of companies, priced per agreement from £18,000 a year. It includes everything in Scale plus unlimited workspaces, a dedicated success contact, a security review and a custom Data Processing Agreement, an onboarding programme and, by arrangement, a dedicated instance in a chosen region. Every module is included. Enterprise is contracted under a Master Services Agreement and sits outside the founding-customer offer.
- Everything in Scale
- Unlimited workspaces
- Dedicated success contact
- Security review and custom DPA
- Onboarding programme
- Optional data-residency instance in a chosen region, by arrangement
Every module included
Want to see it before you decide? Book a 30-minute demo — or take the free ISO 27001 starter checklist.
Company size bands are up to 25, up to 100, up to 500 and 500-plus employees. The band is declared by you and written into the order. Month-to-month is available on Starter and Business at a 10% premium and cancels any time. 14-day free trial, no card required.
Founding customer rate — 20 places
20% off Starter, Business or Scale, locked for 24 months
The first 20 paying customers on a Starter, Business or Scale annual plan take 20% off the tier price, locked for 24 months. If 20 places are not taken the offer closes on 31 March 2027 regardless.
- Annual plans only. Month-to-month is at list with a 10% premium and cancels any time.
- Modules are always at list — the founding rate applies to the tier price only.
- Enterprise is outside the offer.
- Not combined with any other discount; if you also qualify for the charity, education or two-year prepaid discount you take whichever is better.
- From month 25 the list price in force at the time applies, disclosed at signup and in the order, with the CPI + 2% renewal cap from then on.
Framework modules
One ISMS. Every framework your customers ask for
ISO 27001 and GDPR essentials are your foundation. Every module maps back to them, so controls, evidence and policies you have already implemented count automatically. £2,000 a year each, or any three for £5,000 on Starter and Business. Scale and Enterprise include every module. Modules are always at list price — the founding rate applies to the plan price only.
The published launch offer of any three modules for £4,000 is honoured for orders placed up to 31 December 2026, as promised.
SOC 2 (Type I & II)
ModuleTrust Services Criteria, system description, audit periods and guest auditor access for US enterprise deals.
~65% inherited from ISO 27001
ISO 27701 (privacy)
ModulePrivacy information management as an extension of your ISMS, with controller and processor split.
~85% inherited
ISO 42001 (AI management)
ModuleAI management system: clauses, Annex A AI controls, AI system register and impact assessments.
~45% inherited
EU AI Act
ModuleRisk classification, Article 9–15 obligations and conformity evidence for AI providers and deployers.
~50% inherited
ISO 9001 (quality)
ModuleQuality management system with shared management review and quality records.
~80% inherited
DORA
ModuleFive pillars, register of information and 24h / 72h / 1 month reporting clocks for EU financial entities.
~70% inherited
NIS2
ModuleArticle 21 measures, management accountability records and incident reporting timers.
~70% inherited
NCSC CAF v3.2
ModuleObjectives A–D, 39 contributing outcomes and profile-based scoring for UK OES and GovAssure.
~65% inherited
NIST CSF 2.0 / 800-53
ModuleCSF functions with an 800-53 Rev 5 crosswalk and evidence reuse.
~75% inherited
NIST 800-171 / CMMC 2.0
ModuleRequirement families and CMMC level guidance for US defence supply chains.
~70% inherited
Cyber Essentials
ModuleThe five technical control areas with a self-assessment scaffold and evidence pack.
~60% inherited
Cyber Essentials Plus
ModuleAssessor verification records, sampling and certificate register on top of Cyber Essentials.
Defence Cyber Certification
ModuleDef Stan 05-138 Issue 4 controls across Levels 0–3 for MOD suppliers, mapped to your Annex A controls.
PCI DSS v4.0.1
ModuleRequirements, SAQ guidance and readiness summaries for card data environments.
TISAX / VDA ISA 6
ModuleInformation security, prototype protection and data protection assessment groups for automotive.
ISO 22301 (continuity)
ModuleBusiness continuity management using your BIA, continuity plans and restore tests.
HIPAA
ModuleSecurity, Privacy and Breach Notification rules with BAA tracking for health data.
NHS DSPT
ModuleStandards, assertions and a submission-ready export for NHS providers and their sub-processors.
~70% inherited
UK Cyber Security and Resilience Bill
ModuleDuties tracked against your existing controls so you are ready before it commences.
ISO 27017 / 27018 (cloud)
ModuleCloud security and cloud PII extensions with shared-responsibility guidance.
CSA STAR (CCM v4 / CAIQ)
ModuleCloud Controls Matrix domains, STAR level guidance and a CAIQ-style coverage export.
ISO 27036 (supplier security)
ModuleSupplier security across plan, agree, operate and exit, driven by your supplier register.
EU Cyber Resilience Act
ModuleEssential product requirements, vulnerability handling duties and reporting deadlines.
FCA / PRA operational resilience
ModuleImportant business services, impact tolerances, scenario testing and SS2/21 outsourcing duties.
ISO 37002 (whistleblowing)
ModuleConfidential reporting channels, impartial investigation, protection from retaliation and trend reporting to the board.
ISO 20000-1 (service management)
ModuleService catalogue, service levels, capacity, availability, change, incident, problem and release management.
~60% inherited
PECR & cookie consent records
ModuleCookie and tracker inventory, consent before non-essential cookies, marketing rules and demonstrable consent records.
~70% inherited
Pharmaceutical wholesale distribution (GDP)
ModuleMHRA Good Distribution Practice: responsible person duties, batch and serial traceability, controlled drugs register, temperature excursions, recalls and returns.
Modern Slavery & ESG
ModuleSection 54 transparency statement, supply chain due diligence beyond tier one, labour standards and ESG governance.
Module bundles
Three modules for £5,000, chosen for the deal you are chasing
Most companies do not buy modules one at a time. They buy them because a customer, a regulator or a tender has asked for a particular set. The bundles below are the three-module combinations we are asked for most often, at the standard pack price of £5,000 a year — £1,000 less than the same modules bought separately. Every bundle maps back to your ISO 27001 core, so controls and evidence you have already put in place count towards each new framework automatically. Swap any module for another, add a fourth at £2,000, or simply pick any three of the 29 — and every further three are another £5,000. On Scale and Enterprise every module is included, so the bundles are just a sensible order in which to switch them on.
Any three modules — a bundle below or your own selection — £5,000 a year on Starter and Business. Additional modules £2,000 a year each. Every module included on Scale and Enterprise. On month-to-month plans modules follow the plan's cadence at the same 10% premium: £184 a month for a single module, £459 a month for any three.
Modules are always at list price: the founding-customer rate applies to the plan price only. The published launch offer of any three modules for £4,000 is honoured for orders placed up to 31 December 2026.
US enterprise sales
For UK and EU companies selling to American enterprises.
- SOC 2 (Type I & II)
- NIST CSF 2.0 / 800-53
- CSA STAR (CCM v4 / CAIQ)
The three things a US procurement team asks for: a SOC 2 report, a NIST alignment statement and a completed CAIQ. Around two-thirds of SOC 2 and three-quarters of NIST CSF inherit directly from your ISO 27001 controls, so most of the bundle is evidence you already hold, mapped and presented the way American buyers expect.
Often added: HIPAA, if you handle US health data.
£5,000 a year
NHS and public sector supplier
For suppliers to the NHS, local government and central government.
- Cyber Essentials
- Cyber Essentials Plus
- NHS DSPT
Cyber Essentials is the baseline for any UK public contract, Plus is what the larger frameworks and NHS trusts want to see, and the Data Security and Protection Toolkit is required of every organisation with access to NHS patient data or systems. The bundle runs all three from one evidence set, with a submission-ready DSPT export.
Often added: NCSC CAF v3.2, if you are an operator of essential services or in scope of GovAssure.
£5,000 a year
Defence supply chain
For MOD suppliers and companies in US defence supply chains.
- Defence Cyber Certification
- Cyber Essentials Plus
- NIST 800-171 / CMMC 2.0
Defence Cyber Certification (Def Stan 05-138 Issue 4, Levels 0 to 3) is being introduced into MOD contracts, Cyber Essentials Plus is the entry ticket, and NIST 800-171 with CMMC 2.0 covers the US primes. The DCC module was built and mapped by a qualified DCC auditor, so the control interpretations are the ones an assessor will recognise.
Often added: ISO 27036 (supplier security), for the flow-down to your own sub-contractors.
£5,000 a year
EU regulated entities
For essential and important entities under NIS2 and financial entities under DORA.
- NIS2
- DORA
- ISO 22301 (continuity)
NIS2's Article 21 measures and DORA's five pillars overlap heavily with each other and with ISO 27001 — about seventy per cent of each inherits from the core. ISO 22301 supplies the business continuity discipline both regulations assume, with the business impact analysis, continuity plans and restore tests regulators ask to see. The incident-reporting clocks for both regimes run in the platform.
Often added: EU Cyber Resilience Act, if you place digital products on the EU market.
£5,000 a year
UK financial services and payments
For FCA and PRA regulated firms and anyone handling card data.
- FCA / PRA operational resilience
- PCI DSS v4.0.1
- ISO 27036 (supplier security)
Important business services, impact tolerances and scenario testing under the FCA and PRA operational resilience rules, with SS2/21 outsourcing duties; the PCI DSS requirements and SAQ guidance for your card data environment; and supplier security across plan, agree, operate and exit, which is where the outsourcing rules and PCI's service-provider duties bite hardest.
Often added: DORA, if you serve EU financial entities.
£5,000 a year
AI governance
For companies building or deploying AI systems.
- ISO 42001 (AI management)
- EU AI Act
- ISO 27701 (privacy)
ISO 42001 gives you a certifiable AI management system; the EU AI Act module tracks risk classification and the Article 9 to 15 obligations for providers and deployers; ISO 27701 extends your ISMS to the personal data most AI systems process. Together they answer the AI section now appearing in every enterprise security questionnaire.
Often added: ISO 27017 / 27018 (cloud), if your models run on third-party cloud.
£5,000 a year
Cloud and managed service providers
For hosting, SaaS and managed service providers selling to security-conscious customers.
- ISO 27017 / 27018 (cloud)
- CSA STAR (CCM v4 / CAIQ)
- ISO 20000-1 (service management)
The cloud security and cloud-PII extensions to ISO 27001; the Cloud Controls Matrix with a CAIQ-style export for customer due diligence; and a service management system for the catalogue, service levels, change and incident management your contracts promise. About sixty per cent of ISO 20000-1 inherits from what you already run.
Often added: SOC 2, for US customers.
£5,000 a year
Tender ready
For companies bidding into public sector and large corporate tenders.
- ISO 9001 (quality)
- ISO 22301 (continuity)
- Modern Slavery & ESG
The three questions that sit next to information security on almost every pre-qualification questionnaire: do you have a quality management system, a business continuity plan and a modern slavery statement. ISO 9001 shares your management review and around eighty per cent of its structure with ISO 27001; ISO 22301 uses your existing impact analysis and restore tests; the Modern Slavery & ESG module produces the Section 54 statement and supply-chain due diligence evidence.
Often added: Cyber Essentials, which most UK tenders also require.
£5,000 a year
Sector modules that stand on their own
TISAX / VDA ISA 6 (automotive) · Pharmaceutical wholesale distribution (GDP) · HIPAA · ISO 37002 (whistleblowing) · PECR & cookie consent records · UK Cyber Security and Resilience Bill
£2,000 a year each — or add any two of them to a third module and pay the bundle price of £5,000.
How bundles work
- A bundle is three modules for £5,000 a year on Starter and Business — the same price as any three modules of your own choosing. Bundles are curated selections, not a separate price.
- Swap freely: replace any module in a bundle with any other at no change in price.
- A fourth and fifth module are £2,000 a year each; every further three modules form another pack at £5,000, so six modules are £10,000.
- Modules run co-terminous with your plan and renew with it. Added part-way through the year, they are charged pro rata to your renewal date. A module you no longer need comes off at renewal.
- On annual plans, modules are invoiced with the plan. On month-to-month Starter and Business, modules are billed monthly on the same basis as the plan — £184 a month for a single module, £459 a month for any three.
- Modules are always at list price. The founding-customer rate, and the charity, education and prepaid discounts, apply to the plan price only.
- Scale and Enterprise include every module; on those plans the bundles are simply a recommended order in which to switch modules on.
- Inherited-control figures are typical values from the platform's control mappings and vary with your scope and Statement of Applicability.
- The published launch offer of any three modules for £4,000 is honoured for orders placed up to 31 December 2026.
The honest steer
Business plus a three-module bundle is £10,000 a year — the same as Scale, which includes every module, single sign-on, up to three workspaces, API access and a quarterly consultant review, for organisations of up to 500 employees. If you are on Business and need three or more modules, ask us about Scale before you order. We would rather say so now than at renewal.
How our pricing works
The short version of our commercial terms. The Platform Terms of Service are the full version and take precedence where the two differ.
- Company size bands
- Plans are banded by your total headcount — permanent and fixed-term employees, workers and contractors — whether or not they use the platform. The bands are up to 25, up to 100, up to 500 and 500-plus. You declare your headcount when you subscribe and again at each renewal, and it is written into your order. If your headcount grows past your band during the year, tell us within 30 days and we move you to the right plan, charging only the difference for the rest of the period.
- Users
- Every plan includes unlimited users within your organisation, plus guest access for your auditors and advisers. Credentials are personal and must not be shared between individuals.
- What every plan includes
- The ISO 27001 core, UK / EU GDPR essentials, the AI assistant, standard integrations, the hash-chained audit log and data export at any time. There is no charge for setup, for the number of controls in scope, or for passing your audit.
- Billing and payment
- Annual plans are invoiced in advance at the start of each subscription year. Month-to-month billing is available on Starter and Business only, invoiced monthly in advance at the annual price plus 10%, and can be cancelled at any time to the end of the current month. Pay by card through our payment provider or by bank transfer within 30 days of the invoice date. All prices are in pounds sterling and exclude VAT.
- Term, renewal and cancellation
- Annual plans run for 12 months and renew automatically for a further 12 months unless either of us gives at least 30 days' written notice before the renewal date. Month-to-month plans can be cancelled from your account or by email and end at the close of the current monthly period.
- Price protection
- Your plan price is fixed for 24 months from your start date. After that, any change applies from a renewal date with at least 60 days' notice, and an increase is capped at the change in UK CPI over the previous 12 months plus two percentage points.
- Changing plan
- Upgrade at any time and pay only the pro-rata difference for the rest of your period. Downgrades take effect at your next renewal.
- Framework modules
- On Starter and Business, modules are £2,000 a year each or any three for £5,000. Scale and Enterprise include every module. On month-to-month plans modules are billed monthly on the same basis as the plan — £184 a month for a single module, £459 a month for any three. Modules added part-way through the year are charged pro rata to your renewal date so that everything renews together; a module you no longer need comes off at renewal. Modules are always at list price.
- Founding-customer rate
- The first 20 paying customers on an annual Starter, Business or Scale plan, through any channel, take 20% off the plan price, locked for 24 months from their start date. The offer closes when the places are taken or on 31 March 2027, whichever comes first. Annual plans only; modules at list; Enterprise excluded; not combined with any other discount. From month 25 the published plan price then in force applies, disclosed at signup and in your order, with the CPI + 2% cap from then on.
- Other discounts
- Registered charities, education providers and customers who prepay two years qualify for a discount on the plan price — ask us. Discounts do not stack: if you qualify for more than one, you take whichever is better. Modules are always at list.
- What is not included
- Certification-body audit fees, penetration testing and Cyber Essentials assessment fees are paid directly to the provider concerned, as they are with every vendor in this market. Sentinel42 can quote for implementation, internal audit and fractional CISO support alongside the platform, delivered by a UK lead auditor.
- Buying through a partner
- If a Sentinel42 partner introduced you and you contract with them, the partner invoices you for the platform and remains your commercial contact. Your use of the platform and your data are still covered by our terms, and the partner can exercise your export rights on your written authority.
- From trial to paid
- Your 14-day trial workspace becomes your live workspace when you choose a plan, so nothing is rebuilt. No card is taken and nothing is charged during the trial. If you decide not to subscribe, trial data is deleted 30 days after the trial ends.
- Your data at the end
- When a subscription ends you have 30 days to export your data in machine-readable formats. We then delete your instance from live systems within 30 days and confirm in writing if you ask.
What is not included
These are separate with every vendor in this market, and we would rather say so here than in a renewal conversation.
- Certification-body audit fees — separate with every vendor
- Penetration testing
- Cyber Essentials assessment fees
Sentinel42 can quote for implementation, internal audit and fractional CISO support alongside the platform, delivered by a UK lead auditor. Ask us for the services rate card.
Common questions
- Are users capped on any plan?
- No. Every plan includes unlimited users, because an ISMS only works if every control owner, approver and auditor is in it. Plans are banded by company size instead, plus guest access for your auditors and advisers.
- Is GDPR an extra?
- No. Records of processing, data subject requests, DPIAs and the breach log are in the core of every plan. ISO 27701, SOC 2, NIS2 and the rest are modules.
- Do you charge implementation or setup fees?
- No. The list price is the price. Optional advisory days are billed separately only if you ask for them.
- What happens after the free trial?
- Your workspace stays intact and becomes your live workspace on the plan you choose, so nothing is rebuilt. No card is taken and nothing is charged during the trial. If you decide not to subscribe, trial data is deleted 30 days after the trial ends.
- Where is my data hosted?
- In the EU region by default — full detail on the security page. Enterprise customers can request a dedicated instance in a chosen region by arrangement; see international data protection.
- Can I pick my own three modules?
- Yes. The bundles are the combinations we are asked for most often, but any three modules are £5,000 a year, and you can swap any module in a bundle for any other.
- What if I only need one module?
- A single module is £2,000 a year. You can add a second and third later; once you have three you pay the pack price of £5,000 from your next renewal, or from the date you add the third if you ask us to re-base the order.
- Do bundles get the founding-customer rate?
- No. The founding rate is 20% off the plan price only. Modules and bundles are always at list.
- Can I change the modules in a bundle after I have bought it?
- You can add modules at any time, charged pro rata to your renewal date. Swapping or removing a module takes effect at renewal.
- I am on Scale or Enterprise — do bundles matter to me?
- No. Every module is included in your plan, so switch on whichever you need whenever you need it.
- Can we get a DPA?
- Yes — our standard Data Processing Agreement is available and covers Article 28 UK GDPR.