Compliance cost glossary: pricing and audit terms explained
Short answer
Thirty-six terms that appear on compliance pricing pages and in SOC 2 and ISO 27001 quotes, each defined in one to three sentences. Where a term comes from a standard or a vendor page, the source is linked.
Add-on
An item you can buy on top of a plan without changing tier. Drata lists additional frameworks and user access reviews as add-ons on Compliance Automation Foundation.
Source: Drata plans page · read 2026-09-29
AICPA peer review
A review program in which CPA firms' accounting and auditing work is reviewed by other practitioners. Asking whether your SOC auditor is enrolled is a basic check on the firm.
Source: AICPA SOC suite of services page · read 2026-09-29
ASV scan
A vulnerability scan by an Approved Scanning Vendor, used for PCI DSS. Thoropass lists certified ASV scans in its PCI DSS offering.
Source: Thoropass home page · read 2026-09-29
Audit partner network
A group of audit firms a compliance vendor introduces to customers. Secureframe Fundamentals lists access to the Secureframe Audit Partner Network; access is not the same as an included audit fee.
Source: Secureframe pricing page · read 2026-09-29
Black-box test
A penetration test where testers start with no inside knowledge of the system. Scytale's Build DFY bundle lists a web app black-box pen test.
Source: Scytale pricing page · read 2026-09-29
Bring your own auditor (BYOA)
Using a CPA firm you choose rather than one introduced by the platform vendor. Sprinto Foundation lists BYOA.
Source: Sprinto pricing page · read 2026-09-29
CMMC
The Cybersecurity Maturity Model Certification used for US defense contractors. Secureframe's Defense plan is built for it.
Common control framework
A single set of controls mapped to several frameworks, so one control can satisfy matching requirements in each. Sprinto describes setting up controls once and reusing them across frameworks.
Source: Sprinto frameworks page · read 2026-09-29
Continuous monitoring
Automated checks that run on connected systems and flag controls that drift out of compliance between audits.
CPA firm
A licensed accounting firm. SOC examinations are services CPAs provide, so a SOC 2 report is issued by a CPA firm, not by a software vendor.
Source: AICPA SOC suite of services page · read 2026-09-29
Cross-mapping
Linking one implemented control to the matching requirements in several frameworks. Scytale describes 80+ frameworks with control cross-mapping, according to Scytale's pricing page; its framework library lists 35.
Source: Scytale frameworks page · read 2026-09-29
CUI enclave
A segregated environment for handling Controlled Unclassified Information. Secureframe's Defense plan lists a managed CUI enclave.
Source: Secureframe pricing page · read 2026-09-29
Done for you (DFY)
Scytale's name for its Build DFY bundle, which pairs the platform with LaunchReady Consulting and a pen test.
Source: Scytale pricing page · read 2026-09-29
Entry plan
The lowest published tier. On this site it is the plan we use for like-for-like comparisons, such as Vanta Essentials or Drata Compliance Automation Foundation.
Evidence collection
Gathering the records an auditor tests, such as access lists, configuration screenshots and training logs. Platforms automate much of it through integrations.
Framework
A set of requirements a company is assessed against, such as SOC 2, ISO 27001, HIPAA or PCI DSS. Entry plans are often priced for one framework.
FTE
Full-time equivalent, a way of counting staff that adds part-time work together. Drata's Foundation plan covers up to 50 FTEs.
Source: Drata plans page · read 2026-09-29
Gray-box test
A penetration test where testers get partial knowledge or access, such as a user account. Scytale's Build Stronger bundle lists a gray-box pen test.
Source: Scytale pricing page · read 2026-09-29
Headcount cap
A published limit on company size for a plan. In our census, Drata is the one vendor that publishes one.
Source: Drata plans page · read 2026-09-29
Integration
A connection between the compliance platform and a system you use, such as a cloud provider, identity provider or HR tool, used to pull evidence automatically. Vendors state counts differently, from 100+ to 400+.
ISMS
Information security management system: the policies, processes and controls an organization uses to manage information security. ISO/IEC 27001 sets the requirements for one.
Source: ISO/IEC 27001:2022 page, iso.org · read 2026-09-29
ISO/IEC 27001:2022
The international standard for information security management systems. Edition 3 was published in 2022-10 and ISO sells it for CHF 155.
Source: ISO/IEC 27001:2022 page, iso.org · read 2026-09-29
Observation period
The span of time a SOC 2 Type II report covers, during which controls must operate and evidence is collected. It is agreed with the auditor.
Penetration test
A controlled attack on your systems by testers who report what they could exploit. Two vendors in our census tie one to their offer: Scytale and Thoropass.
Personalized pricing
A price set per customer after a sales conversation rather than published. Vanta's pricing page asks buyers to request a demo to get personalized pricing.
Source: Vanta pricing page · read 2026-09-29
POA&M
Plan of Action and Milestones: a document tracking security weaknesses and the steps to fix them, used in CMMC and federal work. Listed on Secureframe's Defense plan.
Source: Secureframe pricing page · read 2026-09-29
Pre-mapped framework
A framework whose controls come already mapped in the platform. Drata's Foundation includes one pre-mapped framework from a list of five.
Source: Drata plans page · read 2026-09-29
Questionnaire allowance
The number of security questionnaires a plan's automation covers per year. Vanta publishes 25 on Plus and 144 on Professional; Sprinto publishes 20 on Foundation.
Source: Vanta pricing page · read 2026-09-29
Quote required
Our label for any plan without a published price. Six of the seven vendors in our census require a quote for every plan.
Security questionnaire
A customer's list of questions about your security practices, sent during procurement. Platforms automate answers from your policies and evidence.
SOC 2
An examination by a CPA firm of a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy.
Source: AICPA SOC suite of services page · read 2026-09-29
SOC 2 Type I
A SOC 2 report on whether controls are suitably designed at a specific date.
SOC 2 Type II
A SOC 2 report on whether controls operated effectively over an observation period.
Starting price
The lowest published price for a plan, before scope is known. Secureframe Fundamentals is published as "Starting at $7,500/year"; the price for a given scope can be higher.
Source: Secureframe pricing page · read 2026-09-29
Trust center
A public page where a company shares its security posture and documents with customers, which can reduce questionnaire volume. Vanta, Drata, Secureframe and Sprinto list one on a published plan.
User access review (UAR)
A periodic check that each person's system access is still appropriate. Drata lists UAR as a Foundation add-on and Secureframe lists it on Complete.
Source: Drata plans page · read 2026-09-29