UpGuard Pricing: Vendor Risk Plan Costs
UpGuard pricing: Vendor Risk Standard is $1,750 a month billed annually for 50 vendors. Every tier, the $79 per-vendor math, and what sits outside the price.
By the Scrutineer team
September 2026 · 8 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
UpGuard publishes exactly one price. Vendor Risk Standard costs $1,750 a month, billed annually, which is $21,000 a year for 50 monitored vendors and six admin users, with extra vendors at $79 a month each. Professional (150 vendors), Corporate (500), Enterprise and Enterprise+ (both unlimited) are quote only, and Breach Risk, Trust Exchange and User Risk are priced separately. We read these figures on UpGuard's own pricing page in September 2026.
That makes UpGuard unusually open for a third-party risk vendor. Most of the market, from OneTrust to Prevalent, publishes no number at all. But one published tier is not a full price list, and the number that decides your contract is not the $1,750. It is how many vendors you put into the platform. This guide lays out every tier, does the vendor-slot math you will need before a sales call, and flags where UpGuard's own documents disagree with each other.
How much does UpGuard cost?
UpGuard Vendor Risk starts at $1,750 per month on the Standard plan, billed annually, so the entry contract is $21,000 a year. It covers 50 monitored vendors and six admin or general users. Each vendor beyond 50 adds $79 a month. Every higher tier, and every other UpGuard product, is priced through sales, so a program with a few hundred vendors has no public list price.
For budgeting, the useful reading is this: $21,000 a year is the floor for a paid Vendor Risk contract, not the typical deal. Teams that monitor more than 50 vendors either pay per extra vendor on Standard or move to a quoted tier, and both routes cost more.
UpGuard pricing plans compared
The table below is taken from the Vendor Risk section of upguard.com/pricing. The vendor slots and user counts come from UpGuard's own comparison table. Where UpGuard lists no price, we list none.
| Plan | Price | Monitored vendors | Admin or general users | What the tier adds |
|---|---|---|---|---|
| Standard | $1,750 a month, billed annually | 50, extra vendors $79 a month each | 6 | Vendor security ratings, assessment and remediation workflows |
| Professional | Contact sales | 150 | 6 | Role-based accounts, custom co-branding |
| Corporate | Contact sales | 500 | 10 | Fourth-party monitoring, audit log |
| Enterprise | Contact sales | Unlimited | 30 | Premium enterprise support, data residency at extra cost |
| Enterprise+ | Contact sales | Unlimited | Unlimited | Multi-org accounts, enterprise support, data residency at extra cost |
Two things in that table matter more than they look. Fourth-party monitoring and the audit log only appear from Corporate up. If a regulator or a customer expects you to show who changed a vendor's risk rating and when, or to see the subcontractors behind your critical vendors, the plan that does it is a quoted one. And the user count stays at six through Professional, so a program run jointly by security, procurement and legal can hit the seat limit before it hits the vendor limit.
UpGuard TPRM pricing: the vendor-slot math
UpGuard meters Vendor Risk on monitored vendors. That is the number to model, because a vendor inventory only grows. Here is what the published list price implies on Standard, before any discount:
| Vendors monitored | Monthly at list | Yearly at list |
|---|---|---|
| 50 | $1,750 | $21,000 |
| 75 | $1,750 + 25 x $79 = $3,725 | $44,700 |
| 100 | $1,750 + 50 x $79 = $5,700 | $68,400 |
| 150 | $1,750 + 100 x $79 = $9,650 | $115,800 |
Every 22 extra vendors adds roughly as much as the whole Standard base price (22 x $79 is $1,738). Nobody should pay the 150-vendor figure in that table, because Professional exists to cover 150 vendors at a quoted price, and that quote will almost certainly land below the add-on arithmetic. The point of the table is the direction. Past about 70 vendors, the add-on route stops making sense and you should be negotiating a tier.
The better lever is the vendor count itself. Not every supplier needs continuous external monitoring. A tiering pass that separates critical and high-risk vendors from the long tail usually shows that a minority of the list drives almost all the risk. Our guide to vendor tiering covers the criteria. For banks, the 2026 interagency proposal pushes the same way: it says lower-risk relationships such as clerical and office support vendors do not need extensive inventories, which is covered on our interagency guidance on third-party relationships software page.
Does UpGuard have a free plan?
UpGuard's own documents disagree. Its help center describes a self-service Vendor Risk plan that comes with 5 vendors at no charge, with more vendors at $79 a month each, and it quotes a Starter plan at $1,599 a month and Professional at $3,333 a month billed annually. The current pricing page lists neither: it shows Standard at $1,750 and Professional as contact sales. The pricing page is the newer document, so treat the help center figures as out of date and ask sales which plans you can actually buy.
The same help article is useful for one thing: it says Breach Risk is not included in the self-service Vendor Risk plan and was offered as an add-on from $250 a month. Whatever the current figure, the structure holds. Vendor Risk watches other companies. Breach Risk watches your own attack surface. They are separate line items.
What the Vendor Risk price does not include
- Breach Risk. External attack surface monitoring of your own domains and IPs, priced separately.
- Trust Exchange and User Risk. Listed as separate products on the pricing page, each with its own plans.
- Fourth parties. Only from the Corporate tier.
- Data residency. Available on Enterprise and Enterprise+ at additional cost.
- Your own compliance program. UpGuard scores vendors from the outside and runs questionnaires. It does not map your own controls to SOC 2 or ISO 27001 or collect the evidence your auditor will ask you for.
That last line is where total cost surprises people. A team that buys UpGuard for vendor risk usually still needs a compliance platform for its own audit, and the two budgets add up. Our compliance automation software pricing comparison puts both kinds of tool in one table.
Is UpGuard worth the price?
For the job it was built for, often yes. UpGuard started in 2012 in Australia as a configuration monitoring tool and grew into outside-in security ratings, so its strength is watching a large vendor portfolio from the internet without waiting for anyone to answer a questionnaire. If you have hundreds of suppliers, many of them unresponsive, and you need a daily signal on each, published per-vendor pricing is a real advantage: you can model the cost before you talk to anyone.
It is a weaker fit when your actual problem is proving your own controls. An external rating says how a vendor looks from outside. It does not tell an auditor that your access reviews happened or that your change management works. Our UpGuard alternative page covers where UpGuard wins and where a combined compliance and vendor risk tool fits better.
UpGuard pricing vs Scrutineer pricing
Scrutineer also publishes its prices, and it does not meter the vendor list. That is the real difference for a growing inventory, and it comes with a real limit: Scrutineer is not an internet-wide external scanner.
| Question | UpGuard | Scrutineer |
|---|---|---|
| Are prices public? | One tier: Standard at $1,750 a month, billed annually | All three plans, on the pricing page |
| What sets the price? | Monitored vendors, $79 a month per vendor over 50 | A flat plan price |
| Vendor risk | Vendor Risk, 50 vendors on the published tier | Risk+ (TPRM): $2,500 a month, or $24,996 a year, unlimited vendor risk scoring |
| Your own SOC 2, ISO 27001, HIPAA readiness | Not included | Included in every plan, with automated evidence collection |
| Outside-in security ratings of any company | Core strength | Not offered; vendors are assessed from evidence and questionnaires |
At 50 vendors, UpGuard Standard is cheaper per year than Risk+. At 75 vendors on list add-ons it is not, and Risk+ also covers your own audit readiness. Which one fits depends on whether external ratings or evidence of controls is the thing you are being asked to produce.
How to get an accurate UpGuard quote
- Count and tier your vendors, and decide which tiers need continuous monitoring rather than an annual review.
- Count the people who will administer the program. Six seats runs out quickly across security, procurement and legal.
- Decide whether you need fourth-party monitoring or an audit log. Both push you to Corporate.
- List any other UpGuard products you want, Breach Risk in particular, and ask for them on one quote.
- Ask for next-tier pricing and the renewal uplift cap in writing. Vendor pricing pages change without notice, and UpGuard's already has once, so if you want to know when a supplier's list price moves before your renewal, point a website change monitoring tool at the page.
For the rest of the market, including the vendors that publish nothing, our third-party risk management software pricing page compares what each TPRM platform bills on. If you would rather see a flat-priced option work first, run a vendor assessment in the demo at the top of this page. It scores a sample vendor the same way it would score yours, with no sales call.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.