OneTrust Pricing: GRC and TPRM Costs
How OneTrust prices GRC and third-party risk: the usage meters behind each package, the marketplace median, and what to count before you ask for a quote.
By the Scrutineer team
September 2026 · 8 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
OneTrust does not publish prices. Every package is quoted by sales and metered on usage: for GRC and third-party risk, the meters are the number of admin users and the size of the inventory you manage, meaning assets for Tech Risk & Compliance and third parties for vendor risk. Vendr's marketplace data across 309 OneTrust purchases puts the median contract at about $12,000 a year, with recorded deals from $1,620 to $48,215 as of February 2026.
That median is honest data, but it is not your number. A marketplace sample mixes every kind of OneTrust purchase, from a single consent package to multi-package programs, and a median sits where the smaller deals cluster. A security or compliance team buying GRC and vendor risk together, with a few hundred vendors in scope, is pricing a different product. This guide shows how OneTrust meters each package, what actually moves a GRC or TPRM quote, and what to count before your first sales call so the quote does not surprise you at renewal.
How much does OneTrust cost?
OneTrust costs whatever your quote says, because the company lists no public prices for any package. The best public benchmark is Vendr's transaction data: a median of about $12,000 a year across 309 recorded purchases, with a range of $1,620 to $48,215, last updated February 2026. Vendr itself describes mid-market and enterprise deployments as running into six figures a year, so treat the median as a single-package figure, with implementation as a separate line.
We do not repeat the per-module dollar figures that circulate in comparison posts. Almost all of them come from vendors selling a competing product, several contradict each other, and none cite a contract. If you need a number for a budget request, use the marketplace median as a floor for a single package and get a written quote for anything larger.
How does OneTrust pricing work?
OneTrust sells solution packages, each with one or more usage meters. Its own pricing FAQ says that solutions for privacy, technology, third-party or AI risk and compliance programs "are metered on admin users and the size of inventory managed by the solution," while consent and data collection products are metered on visitors, data profiles or data volume. The table below is taken from OneTrust's pricing page.
| Package | What it covers | How OneTrust meters it |
|---|---|---|
| Tech Risk & Compliance | GRC: framework templates across 50+ standards, IT risk, control management, policy lifecycle | Admin users and asset inventory |
| Third-Party Risk Management Base | Vendor inventory, automated assessments and workflows, third-party risk intelligence data | Admin users and third-party inventory |
| Third-Party Management Suite | Everything in Base, plus Dow Jones PEP, sanctions and watchlist data, ethics and compliance screening, adverse media monitoring | Admin users and third-party inventory |
| Privacy Automation Base and Suite | Privacy program management, data mapping, assessments | Users and privacy asset inventory |
| Consent Management Platform Base and Suite | Cookie and consent banners across web and apps | Average daily visitors across all properties |
| Universal Consent & Preference Management | Consent and preference records across channels | Total data subject profiles |
| AI Governance | AI inventory, assessments and oversight | Admin users and AI inventory |
Customers still on the older module-based contracts are told to ask their account executive for a proposal under the new packages. That matters at renewal: the old line items and the new meters do not map one to one, so ask for the new quote in writing before you agree to migrate.
OneTrust GRC pricing
OneTrust's GRC product is the Tech Risk & Compliance package, which grew partly out of its 2021 acquisition of Tugboat Logic, a compliance automation startup built for SOC 2, ISO 27001 and similar frameworks. It is metered on admin users and asset inventory. The admin user count is usually small and predictable: your compliance and security team. The asset inventory is the part to model carefully, because it is whatever you load into the platform to track risk against, and in a cloud-heavy company that list grows every quarter.
Before you ask for a quote, decide what counts as an asset for your program. An inventory of 40 business applications and an inventory of 4,000 cloud resources describe the same company, and they will not produce the same price.
OneTrust TPRM pricing
Vendor risk comes in two packages, and the difference between them is the most useful thing to know before a sales call. Third-Party Risk Management Base covers the security and privacy side: the vendor inventory, assessments, workflows and third-party risk intelligence, the lineage of the Vendorpedia exchange OneTrust launched for pre-completed vendor profiles. Third-Party Management Suite adds the ethics and compliance side: Dow Jones politically exposed person, sanctions and watchlist data, ethics screening and adverse media monitoring.
If your third-party risk program is run by security and IT and exists to answer "is this vendor safe to hold our data," Base is the package to price. The Suite earns its cost when compliance or legal also screens suppliers for sanctions, corruption and reputation, which is common in regulated financial services and manufacturing and rare in a SaaS company.
Both packages are metered on third-party inventory, which leads to the pricing mechanic that surprises buyers most.
The meter that grows is your vendor list, not your team
OneTrust's FAQ says that if usage "consistently exceeds the current tier's limits, your Account Executive will help you transition to the next tier." With admin users, that rarely happens. With third-party inventory, it happens to almost everyone, because a vendor inventory only grows. Procurement adds SaaS tools every month, acquisitions bring whole supplier lists, and a new regulation like the DOJ bulk data rule suddenly pulls vendors into scope that nobody assessed before.
So the practical cost of a OneTrust TPRM contract is set less by your first quote than by how many vendors you decide to put in the inventory. Two decisions keep that under control:
- Tier before you load. Not every vendor needs to sit in the risk platform. A tiering pass that separates critical, high, moderate and low-risk vendors usually shows that a minority of vendors need full assessment. Our guide to vendor tiering walks through the criteria.
- Write the tier headroom into the contract. Ask for the next tier's price at signing, and ask how "consistently exceeds" is measured: a month, a quarter, the contract year.
What drives a OneTrust quote up
- Packages, not users. Each solution package is priced on its own meters. GRC plus TPRM Base plus Privacy Automation is three quotes rolled into one.
- Suite versus Base. The Suite adds licensed third-party data, such as the Dow Jones screening content, which carries its own cost.
- Inventory size. Assets for GRC, third parties for TPRM, privacy assets for privacy. This is the meter that moves.
- Implementation. OneTrust is highly configurable, and large rollouts often run through professional services or an implementation partner. Budget the project separately from the subscription.
- Term and renewal terms. Multi-year terms usually buy a lower annual rate. Renewal uplifts and tier changes are where totals drift, so track the notice date and any uplift clause in your contract management system rather than in someone's calendar.
Is OneTrust worth the price?
For the buyer it was built for, often yes. OneTrust was founded in Atlanta in 2016 to help companies comply with GDPR and the new wave of privacy laws, and privacy operations, consent and data mapping remain its strongest ground. If a large enterprise wants privacy, consent, GRC, vendor risk and ethics screening from one vendor, administered by a dedicated team, the price buys genuine breadth.
It is a harder case for a security and compliance team whose actual job is SOC 2, ISO 27001 or HIPAA readiness plus vendor security reviews. That team pays for a platform designed to be configured, and it needs someone to configure it. Our OneTrust alternative comparison covers where OneTrust wins and where a narrower tool fits better, feature by feature.
OneTrust pricing vs Scrutineer pricing
Scrutineer publishes its prices and does not meter the vendor list. That is a real difference for a team whose third-party inventory is growing, and it comes with a real limit: Scrutineer is not a privacy operations or consent platform, and it does not include sanctions or adverse media screening data.
| Question | OneTrust | Scrutineer |
|---|---|---|
| Are prices public? | No, every package is quoted | Yes, on the pricing page |
| What sets the price? | Admin users plus inventory size, per package | A flat plan price |
| GRC and multi-framework compliance | Tech Risk & Compliance package | Growth: $1,200 a month, or $11,988 a year billed annually |
| Compliance plus third-party risk | Tech Risk & Compliance plus a TPRM package | Risk+ (TPRM): $2,500 a month, or $24,996 a year, with unlimited vendor risk scoring |
| Privacy, consent and data mapping | Strong, separate packages | GDPR control mapping only, no consent platform |
| Sanctions, PEP and adverse media data | Third-Party Management Suite | Not included |
For the full field, including Vanta, Drata, Hyperproof and the TPRM specialists, see our compliance automation software pricing comparison, and if vendor risk is the main purchase, the third-party risk management software pricing page breaks down how each pricing model behaves as the vendor list grows.
Does OneTrust publish its pricing?
No. OneTrust's pricing page names every package and explains the usage meter behind each one, but lists no dollar amounts. Prices come from a sales quote. Third-party marketplaces such as Vendr publish aggregated purchase data, which is the most reliable public benchmark, though it reflects the mix of deals that went through that marketplace.
Is OneTrust expensive?
For a single package at a mid-size company, not unusually: Vendr's recorded median is about $12,000 a year. It becomes expensive when you combine several packages, load a large asset or vendor inventory, add Suite-level screening data and pay for implementation. The same platform can be a five-figure line item or a large enterprise program, depending entirely on scope.
How to get an accurate OneTrust quote
- Count admin users per package: the people who configure and run each program, not everyone who answers an assessment.
- Count and tier your third parties, and decide which tiers go into the platform.
- Define your asset inventory for GRC at the level you will actually manage risk.
- Decide whether you need Base or Suite for vendor risk, based on who screens suppliers for sanctions and ethics.
- Ask for next-tier pricing, the renewal uplift cap and the implementation estimate in writing before signing.
If you would rather see a flat-priced alternative working on your own framework first, run a scrutiny in the demo at the top of this page. It maps controls to SOC 2, ISO 27001, HIPAA, GDPR or PCI DSS and scores a vendor the same way, with no sales call needed.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.