Transparent, predictable pricing
No hidden fees. Start with a free trial, upgrade when you're ready.
Always Free
- 30-question cross-framework readiness assessment
- Maps to CE, ISO 27001, CAF, and DORA simultaneously
- Prioritised gap analysis and roadmap
- Cross-Framework Mapping
- Cyber Essentials, CAF, DORA, ISO 27001, AI Governance, CRMA, NIST CSF 2.0, CIS Controls v8, NIS2 Directive
- One Phronesis AI analysis run per assessment
- Sector benchmarking
- PDF, JSON, and share export restricted during trial
Assessment Products
- 9 compliance frameworks — CE, CAF, DORA, ISO 27001, AI Governance, CRMA, NIST CSF 2.0, CIS Controls v8, NIS2 Directive
- Phronesis AI analysis (3 runs/month, shared across all your assessments) + generous daily chat allowance
- Evidence Vault, Audit Pack & AI Policy Generator (8 templates)
- Remediation Tracker & Risk Scenarios
- Trust Centre, Compliance Passport & Peer Benchmarking
- Full PDF, JSON, share & Cross-Framework Mapping
- Everything in Solo
- Shared scores across all 9 frameworks
- Collaborative drafts with cross-device sync
- Team Remediation Tracker with shared assignments
- Activity log & team admin controls
- Cyber Essentials v3.3 assessment
- Single Phronesis AI analysis
- CE Plus readiness preview via M365 signals
- 30-day read access + PDF export
Assessment Hub + Supply Chain Risk Manager
All 9 compliance frameworks combined with supplier questionnaire distribution, Risk Purview external scanning, and portfolio risk tracking. Pricing tailored to supplier volume and team size.
Specialist Assessments
Claim-gated assessments for PE firms, SOC teams, defence contractors, cloud service providers, and US healthcare entities. Invoiced per engagement.
- 14-theme IASME-aligned assessment (70 questions)
- IASME tier badge and RAG deal risk rating
- 100-day remediation plan with cost band
- Phronesis AI deal analysis
- Repeatable analysis runs, capped per engagement
- 7-domain capability assessment (70 questions)
- SOC type filtering (Enterprise, SMB, MSSP)
- Practitioner evidence capture
- Phronesis AI analysis
- Repeatable analysis runs, capped per engagement
- All 110 NIST SP 800-171 Rev 2 practices (14 families)
- Real DoD SPRS score, computed to the official methodology
- Plain-English guidance alongside official NIST wording
- Phronesis AI analysis
- Repeatable analysis runs, capped per engagement
- All 323 NIST SP 800-53 Rev 5 Moderate baseline controls (18 families)
- Plain-English guidance alongside official NIST wording
- Suggested answers from a finalised CMMC run (shared controls)
- Phronesis AI analysis
- Repeatable analysis runs, capped per engagement
- 47 questions across Administrative, Physical & Technical Safeguards
- Required vs. Addressable specifications scored correctly
- Suggested answers from a finalised NIST CSF 2.0 run
- Phronesis AI analysis
- Repeatable analysis runs, capped per engagement
Supply Chain Risk Manager
Supplier questionnaire distribution, Risk Purview external verification, and portfolio risk tracking.
- Up to 200 suppliers
- Questionnaire distribution with email delivery
- Risk Purview passive scans (attack surface, breach intel, SSL/DNS hygiene, corporate register)
- Monthly automated re-scans with drift alerts
- Custom questions — author up to 100 bespoke scorable questions, append up to 100 per send
- Phronesis Portfolio Risk Analysis — AI-generated narrative report across your full supplier portfolio, covering aggregate risk posture, critical gaps, and prioritised remediation guidance
- Trend sparklines and contradiction detection
- Unlimited suppliers
- Everything in Tier 2
- Daily automated rescans across your full supplier estate
- Priority CVE triage & SOC alerting — critical findings surfaced to your security team in real time, not just monthly re-scan summaries
- Higher frequency breach intelligence — more frequent credential and data breach monitoring with SOC alerting
- Dedicated Cloud Function infrastructure
- SLA-backed response times
| Feature | Supply Chain | Enterprise |
|---|---|---|
| Suppliers managed | Up to 200 | Unlimited |
| Questionnaire distribution & email delivery | ✓ | ✓ |
| Risk Purview passive scans (breach intel, SSL/DNS, attack surface, Companies House) | ✓ | ✓ |
| Automated rescans & drift alerts | Monthly | Daily |
| Trend sparklines & contradiction detection | ✓ | ✓ |
| Phronesis Portfolio Risk Analysis Report | ✓ | ✓ |
| Custom scorable questions (up to 100 authored, 100 per send) | ✓ | ✓ |
| Priority CVE triage & real-time SOC alerting | — | ✓ |
| Higher frequency breach intelligence & SOC alerting | — | ✓ |
| Dedicated infrastructure & SLA | — | ✓ |
Feature Comparison
| Feature | Free Trial | CE One-Shot | Solo | Team |
|---|---|---|---|---|
| Compliance Readiness Assessment | ✓ | ✓ | ✓ | ✓ |
| Cyber Essentials Assessment | ✓ | ✓ | ✓ | ✓ |
| CAF, DORA, ISO 27001, AI Governance, CRMA, NIST CSF 2.0, CIS Controls v8, NIS2 Directive | ✓ | — | ✓ | ✓ |
| Phronesis AI Analysis | 1 run per assessment | 1 run | 3 / month | 3 / month |
| PDF / JSON Export | — | ✓ | ✓ | ✓ |
| Share Results | — | ✓ | ✓ | ✓ |
| Sector Benchmarking | ✓ | ✓ | ✓ | ✓ |
| Cross-Framework Mapping | ✓ | ✓ | ✓ | ✓ |
| AI Policy Generator | — | — | ✓ | ✓ |
| Evidence Vault | — | — | ✓ | ✓ |
| Audit Pack | — | — | ✓ | ✓ |
| Trust Centre | — | — | ✓ | ✓ |
| Remediation Tracker | — | — | ✓ | ✓ |
| Risk Scenarios | ✓ | ✓ | ✓ | ✓ |
| Multi-user team access | — | — | — | ✓ |
| Result Access Duration | 7 days | 30 days | Unlimited | Unlimited |
Frequently Asked Questions
How does Team pricing work?
The Team plan starts at £249 per month, which covers the account owner (one seat). Each additional team member costs £69 per month. A three-person team pays £387 per month; a five-person team pays £525 per month. All team members share the same assessment portfolio and there is no minimum beyond the included base seat.
Can I upgrade from a free trial to a paid plan?
Yes. Your assessment data is preserved when you upgrade. Contact us and we'll activate your subscription immediately.
How many Phronesis AI analysis runs do I get on the free trial?
One run per assessment — so you can sample Phronesis across all seven frameworks (Cyber Essentials, CAF, DORA, ISO 27001, AI Governance, CRMA, NIST CSF 2.0). This matches the CE One-Shot product (one run per purchase). Subscribe to the Assessment Bundle for 3 analysis runs per month, shared across all your assessments — re-run whichever framework you need, whenever you need it, up to your monthly allowance.
What happens when my CE One-Shot expires?
After the 30-day read-only window, your results are no longer accessible. You can purchase another one-shot or upgrade to the Assessment Bundle for ongoing access.
Is there a contract or commitment period?
Monthly subscriptions (Assessment Bundle, Supply Chain) can be cancelled at any time. CE One-Shot is a single payment with no recurring commitment. PE Due Diligence and SOC Maturity are invoiced per engagement, scoped and agreed with our team before work begins.
Do you offer discounts for multiple products?
Yes. Contact us to discuss bundled pricing if you need both assessments and Supply Chain Risk Manager access.
Questions? Talk to us.
Our team can help you choose the right plan and get set up.
Contact Us