PRICING

Pay for the standards you actually run.

Per user, per month — with a small step-up for each additional standard. Priced so you see value from day one, and far below the enterprise GRC tools built for someone else's standards.

ESSENTIALS

Get audit-ready.

For teams getting their first framework over the line — Essential Eight, ISO 27001 or APRA.

$indicative
Includes 1 standard · min 3 users
A small step-up per additional standard (up to 3 total)
  • Maturity radar & ML-ladder
  • Evidence library, no per-evidence fees
  • Board-ready PDF + live link reports
  • Email support · 1 business day
  • Single business unit
Talk to us 30-min walkthrough
ENTERPRISE

Built around your shape.

For groups, MSPs, and any org with 5+ business units, regulator scrutiny, or specific SLAs.

Let's talk
Custom · unlimited everything
Volume pricing kicks in at 25+ users or 5+ business units. Talk to us early — we'll quote, not surprise.
  • Everything in Standard, plus →
  • Unlimited business units / tenants
  • White-label option
  • SSO + custom auth
  • Dedicated success manager
  • 1-hour SLA · 24/7 P1 cover
  • Custom DPA + jurisdiction
Contact sales → Same-week response
HOW WE COMPARE ON COST

Built for value, not enterprise sticker shock.

The US-centric GRC platforms quote big and quote slow. Spreadsheets look free until an audit eats a fortnight. Cybereen sits where it should — talk to us for a tailored quote.

Cybereen
$
Per user, per standard. A clear quote up front — no enterprise sales-call pricing.
Vanta
$$$
Enterprise SOC 2 tooling, contact-sales pricing, built for someone else's standards.
Drata
$$$
US-enterprise pricing and feature depth — overkill for the messy middle.
Spreadsheets
Free*
*Until an audit eats a fortnight and one evidence gap costs you the deal.
Honest

No surprises on the invoice.

A clear, tailored quote up front — no hidden minimums, no per-evidence fees, and far below enterprise GRC pricing.

10%

Annual discount.

Pay yearly, save 10%. Mid-year upgrade? We pro-rate cleanly — no awkward back-bills.

60-day

Refund. No questions.

Doesn't fit your practice in the first 60 days? Email refund@ and we'll process it within five business days.

Free

White-glove migration.

Coming off spreadsheets? Our team imports your evidence, maps your controls, and runs your first assessment alongside you. Included on Standard + Enterprise.

COMPARE PLANS

What's in each.

Everything we sell, on one page. Standard is most teams; Enterprise is when you outgrow Standard.

Essentials Standard Enterprise
Pricing
Relative cost $ $$$
Standards included 1 Unlimited
Each extra standard Small step-up Bundled
Minimum users 3 From 25
Platform
Maturity radar & reports
Evidence library
Risk register + matrix
Cross-framework reuse
Auditor read-only access
Business units / tenants1Unlimited
White-label
SSO / custom auth
API access
Onboarding & support
Onboarding call30-min walkthroughCustom pilot
Migration assistanceSelf-serve docsDedicated team
Support SLAEmail · 1 BD1 hr · 24/7 P1
Success managerDedicated
Refund window60 daysCustom MSA
PRICING FAQ

Questions before you commit.

If yours isn't here, ask on the call — answers go in the next page revision.

Why per-user-per-standard, not flat?
Because a 5-person ops team running just Essential Eight shouldn't subsidise a 50-person enterprise running ISO 42001 across three subsidiaries. You pay for the standards you actually run, and the cost scales with your team — not your luck.
What counts as a "user"?
Anyone with a Cybereen login who can edit, approve, or assign. Auditor read-only access is free on Standard and Enterprise — they don't count toward your seat count, ever.
Can I change standards mid-cycle?
Yes. Adding a standard pro-rates the addition to the rest of your cycle. Dropping a standard takes effect at next renewal so you don't lose evidence mid-audit. No back-bills, no rude surprises.
What if I'm under 3 users?
Email hello@cybereen.com. Solo consultants and very small teams routinely get a starter rate or a partner-network referral. The min-3 is a sticker price, not a wall — we're not in the business of locking small orgs out of basic compliance hygiene.
How fast can I be live?
Your instance is provisioned in under an hour after sign-off. Most teams run their first maturity assessment in week one; audit-ready in 3 days to 3 weeks depending on starting maturity and number of standards in scope. The white-glove migration handles the heavy import if you're coming off spreadsheets.
GST / VAT?
Your quote is exclusive of GST/VAT. AU customers are issued tax invoices including 10% GST; international B2B customers handle reverse charge in their own jurisdiction. No surprises on the invoice.
Do you offer NFP / education / charity pricing?
Yes — 35% off list for registered AU charities (ACNC) and not-for-profits, and similar for UK-registered charities. Higher-ed gets the same. Ask on the call and we apply it before your first invoice.
What about partners?
If you're an MSP, vCISO firm, audit firm, reseller or implementer — see the Partners programme. Different commercials: margin on subscriptions, deal registration, no joining fee.

Live in an hour. Refund window for 60 days.

A clear quote up front. White-glove migration if you're coming off spreadsheets. No-questions refund within 60 days of your first invoice if it doesn't fit.