COMPLIANCE PRICING
Menu

TRACK: BUYING AND BUDGETING · GUIDE 08 OF 10

How to request comparable compliance quotes

Short answer

Quotes are only comparable when every vendor prices the same scope. Send each vendor the same one-page scope (frameworks, headcount, audit, pen test, expert help, questionnaires, term) and ask for each line itemized. Six of the seven vendors in our census require a quote, so this step decides most comparisons.

By The Cost Desk, Compliance Pricing · Published 2026-02-17 · Updated 2026-09-29 · 3 min read

Six of the seven vendors in our census publish no price. That makes the quote the real pricing page, and quotes are easy to make incomparable: one includes the audit, another a pen test, a third a two-year term. The fix is to send the same scope to everyone.

The one-page scope

Send this, filled in, before the first demo.

  • Frameworks now: for example SOC 2 Type II.
  • Frameworks in the next 24 months: for example ISO 27001.
  • Headcount today and expected at the end of the term, and how contractors are counted.
  • Audit: arranged by the vendor, by us with our own CPA firm, or undecided.
  • Penetration test: needed or not, and its scope (web app, black box, gray box).
  • Expert help: none, occasional support, or a named expert who runs readiness.
  • Security questionnaires per year.
  • Term: one year or multi-year, and preferred billing.
  • Must-have integrations: your cloud, identity provider, code host and HR system.

Ask for itemized lines

Ask each vendor to price every line separately: platform, each additional framework, audit (if bundled), pen test (if bundled), services, questionnaire allowance and any add-ons. A single bundled figure cannot be compared with anything.

Map the scope to published plans first

Before the calls, check which published plan each vendor should quote. The calculator does this from the same inputs. If a vendor quotes a different tier, ask why.

Examples of what to check:

  • Drata: are you under 50 FTEs and using one of the five Foundation frameworks?
  • Vanta: which tier covers your questionnaire count (25 on Plus, 144 on Professional)?
  • Secureframe: does your scope fit Fundamentals, published as starting at $7,500/year, or does it need Complete?
  • Scytale: do you need Build DFY or Build Stronger for consulting and a pen test, or is Build Starter enough?
  • Sprinto: will 20 questionnaires a year on Foundation cover you?

Compare like with like

Put the quotes in one table with the same rows. Where one vendor bundles the audit and another does not, add an audit firm's quote to the second. Where one bundles a pen test, add a pen test quote to the others. Only then compare totals.

Also compare what is not priced: who does the work (you, a partner or the vendor's expert), how the audit is arranged, and what happens at the limits.

Ask for it in writing

A price mentioned on a call is not a quote. Ask for a written quote that names the tier, the limits and each line, valid for a stated period.

The takeaway

Same scope, itemized lines, one table. Use the multi-compare to line up what each vendor publishes before the quotes arrive.

Next guide: Auditor independence and your budget