COMPLIANCE PRICING
Menu

TRACK: READING A PRICING PAGE · GUIDE 04 OF 10

How to read a compliance plan tier

Short answer

A plan card tells you four things if you read it closely: the limit that ends the tier, what is included, what is sold as an add-on, and what happens next (a price or a quote). Most compliance pricing pages publish the first three for at least one plan and leave the price out.

By The Cost Desk, Compliance Pricing · Published 2025-09-23 · Updated 2026-09-29 · 3 min read

Compliance vendors present plans as cards: a name, a short list of features and a button. Read like a receipt, each card answers four questions. Our pricing census renders every plan this way.

1. What ends the tier?

Look for a limit. It is the most useful line on a card because it tells you when you will be moved up. Examples from our census:

  • Drata Compliance Automation Foundation: up to 50 FTEs and one pre-mapped framework from SOC 2, ISO 27001, Cyber Essentials, HIPAA or GDPR.
  • Vanta: Essentials is one framework; Plus covers 25 questionnaires per year; Professional covers 144.
  • Sprinto Foundation: 20 AI security questionnaires per year and 24x5 support.
  • Secureframe Fundamentals and Scytale Build Starter: one framework.

If a card shows no limit, ask what the limit is. There is always one: a framework count, a headcount, a volume or a support level.

2. What is included?

The inclusion list is where tiers differ most. Sprinto's Foundation lists a long set of items, from audit management to a trust center. Secureframe Fundamentals lists monitoring, evidence collection, personnel, risk and policy management, a Trust Center and audit partner network access. Scytale's bundles are short lists, but two of them include consulting and a pen test.

Be careful with feature names. "Trust Center Standard" (Drata) and "Advanced Trust Center" (Vanta Professional) tell you that lower and higher versions exist; the card does not say what separates them.

3. What is an add-on?

Add-ons are items you can buy without changing tier. Drata names two on Foundation: additional frameworks and user access reviews. Scytale's Build Starter says add-ons are available. Add-ons are rarely priced on the page, so list the ones you need and ask for each price.

4. What happens next?

The button tells you whether the price is public. Secureframe shows "Starting at $7,500/year" on Fundamentals. Everyone else shows a call to action: "Get a demo" (Scytale), "Request a free demo" to get personalized pricing (Vanta), "Get Personalized Pricing" (Drata). Scrut's pricing URL returned Page Not Found, and Thoropass's shows no prices.

Labels are not facts

"Most popular" appears on Scytale's Build DFY and Vanta's Professional. It is the vendor's label, not a measure of anything you can check, so we show it as "Vendor label: Most popular".

Tiers may include more than the card shows

Cards often list only what is new at that tier. We record only what each card lists, and note under every set of receipts that a tier may include more. Ask the vendor for the full inclusion list of the tier you are quoted.

The takeaway

For each vendor, write down the limit, the inclusions you need, the add-ons you need and the call to action. That four-line summary is enough to compare tiers before any price arrives.

Next guide: Framework add-ons and cross-mapping: paying for the second framework