Choose your pricing plan
Professional
20,000$Every yearThe Professional plan provides expanded tools for control tracking, evidence management, remediation, reporting, diagrams, and assessment preparation.- CMMC Level 1 and Level 2 support
- Full control assessment workspace
- Assessment objective tracking
- Advanced gap assessment
- SPRS score tracking support
- Expanded evidence mapping
- Advanced POA&M management
- Milestone and remediation tracking
- Network diagram generator
- Information flow diagram generator
- Artifact quality review
- Expanded policy and procedure templates
- Assessment readiness dashboard
- Executive summary reporting
- Assessment package builder
- Evidence request tracking
- Client deliverables center
- Multiple user roles
- Expanded project workspace
Starter
5,000$Every yearThe Starter plan gives organizations the core tools needed to understand where they stand, organize initial evidence, and begin tracking CMMC readiness without overwhelming the team.- CMMC Level 1 readiness tracking
- Basic CMMC dashboard
- Control status tracking
- Gap assessment
- Training and Awareness
- Evidence mapping to controls
- Level 1 policy and procedure templates
- Level 1 POA&M tracking
- Executive reports
- Project workspace
- Artifact review
- Diagram support
Evidence Vault
179$Every monthThe Evidence Vault plan is designed for companies that mainly need evidence storage, organization, and basic compliance recordkeeping.Valid for 12 months- Evidence upload and storage
- Evidence organization by project, folder, or control area
- Evidence download and retention
- Basic evidence search and filtering
- File preview where supported
- Evidence activity history
- Basic evidence inventory export
- Limited user access
- Continuous evidence retention support
Enterprise
70,000$Every yearThe Enterprise plan is built for organizations that need broader visibility, more users, deeper workflow management, and ongoing compliance operations.- Multiple customer or project workspaces
- Advanced readiness command center
- Advanced reporting and exports
- Advanced assessment package management
- Expanded evidence storage
- Expanded user and role limits
- Client handoff workspace
- Client-facing deliverable views
- Release and approval workflows
- Advanced evidence request management
- Continuous monitoring support
- Priority support
- Custom onboarding support
- Enhanced audit activity tracking
- Consultant/client workflow support
- Optional custom feature configuration
Package 1 includes:
-
Initial Gap Analysis
-
Review of audit findings and prioritization of issues.
-
Development of a remediation action plan.
-
-
Policy and Procedure Updates
-
Assistance with creating or updating up to 5 key policies (e.g., Access Control, Data Classification, Incident Response).
-
-
Technical Fixes
-
Basic remediation support for up to 3 critical IT systems.
-
-
Training and Awareness
-
One virtual session for staff covering audit findings and key security updates.
-
-
Progress Reporting
-
Bi-weekly status updates with a final report on completed remediations.
-
Package 2 includes:
-
Detailed Gap Analysis
-
In-depth review of findings, with risk ratings and tailored recommendations.
-
-
Policy and Procedure Updates
-
Assistance with creating or updating up to 10 policies.
-
Implementation guidance for basic compliance frameworks (e.g., NIST 800-171 or ISO 27001 controls).
-
-
Technical Fixes
-
Support for remediation of up to 5 critical IT systems.
-
Assistance with basic configuration of security tools (e.g., firewalls, endpoint protection).
-
-
Training and Awareness
-
Two virtual training sessions: one for general staff and one for technical teams.
-
-
Third-Party Vendor Review
-
Assessment of up to 3 key vendors to ensure compliance with security requirements.
-
-
Progress Reporting
-
Weekly updates and a detailed final report with actionable next steps.
-
Package 3 includes:
-
Comprehensive Gap Analysis and Roadmap
-
Full review of findings, with a roadmap to address high, medium, and low risks.
-
Alignment with compliance frameworks (CMMC, NIST 800-171, SOC 2, ISO 27001).
-
-
Policy and Procedure Development
-
Creation or enhancement of up to 15 policies.
-
Full guidance on policy implementation and staff adoption.
-
-
Technical Fixes and System Hardening
-
Remediation of up to 10 critical IT systems.
-
Advanced configuration support for security tools (e.g., SIEM, IAM solutions).
-
Vulnerability scanning and basic penetration testing to validate fixes.
-
-
Training and Awareness
-
Three training sessions: general staff, technical teams, and executive leadership.
-
-
Third-Party Vendor and Supply Chain Review
-
Assessment of up to 5 vendors, including contract reviews for compliance.
-
-
Audit Preparation
-
Mock audit to prepare for upcoming external assessments.
-
Guidance on documentation and evidence collection.
-
-
Progress Reporting
-
Weekly updates, detailed mid-project review, and a comprehensive final report.
-
