Compliance pricing you can actually budget for
Most platforms in this category will not publish a number. Here is ours, what it includes, and what it does not, so there are no surprises at signature.
Plans
Priced on scope and framework, never on headcount.
Early Stage
10-100 employees, Seed to Series A
- One framework (SOC 2 or ISO 27001)
- Named compliance lead, weekly check-ins
- Pre-built control library and policies
- Automated evidence collection
- Trust center
- Audit-ready in 8-12 weeks
Growth
100-500 employees, multi-framework
- Multiple frameworks on one shared control library
- No per-framework licence fee
- Vendor risk and questionnaire automation
- Risk register and policy lifecycle
- Priority support
Enterprise
500+ employees, regulated or multi-entity
- All frameworks including ISO 42001 and EU AI Act
- AI governance module
- Multi-entity and regional scoping
- SSO / SCIM
- Dedicated compliance team
Pay at signoff
The platform fee falls due when your audit is signed off, not on the day you sign the contract. It keeps the incentive where it belongs: on getting you certified, not on renewing software you never managed to roll out.
What compliance actually costs
The platform is one line item. Here is the honest full picture for a first SOC 2.
| Line item | Typical range | With Certifyi |
|---|---|---|
| Compliance platform | $8,000 - $50,000/yr | From Minimal inital cost |
| Additional framework | $3,000 - $15,000 each | Included, shared control library |
| Implementation / onboarding | $2,000 - $10,000 | Included |
| External auditor | $8,000 - $20,000 | Paid directly to auditor |
| Penetration test | $4,000 - $12,000 | Separate, scoped only if required |
| Internal headcount | 0.5 - 1 FTE | Replaced by your named lead |
FAQ
Pricing questions, answered
How is Certifyi priced?
By scope and framework, never by headcount. The plan depends on how many frameworks you need, the size of your environment and whether you want a dedicated deployment. There is no per-framework licence fee and no charge for auditor or supplier seats.
When is the platform fee due?
At audit sign-off. Half is invoiced upfront to start the engagement and the balance when your auditor signs, so the incentive sits where it belongs: on getting you certified.
What is included in every plan?
The shared control library, policies written with your team, the risk register, automated evidence collection with hashing, the Trust Center, the Auditor and Supplier Workspaces, and a named compliance lead with weekly check-ins.
What is billed separately?
The audit firm’s own fee and any penetration test you commission. Certifyi introduces independent auditors and coordinates the engagement but never issues the opinion, so those costs stay separate and transparent.
Do we pay more when we add a second framework?
Scope changes are priced, headcount is not. Because frameworks share one control library, adding ISO 27001 to a SOC 2 programme reuses most of the existing controls and evidence, so the increment is small compared with starting again.
Is there a free trial or a demo?
A readiness call is the fastest way to see it: twenty minutes with a compliance lead, working through your scope in the platform. You leave with a scope, a gap list and a realistic date.