Scrutineer.ai

Scrutineer · Vendor risk

Third-party risk management software pricing and cost

Third-party risk management software runs from about $21,000 a year for a mid-market program to well past $150,000 at enterprise vendor counts, and almost nobody publishes a rate card. UpGuard lists $1,750 a month for 50 vendors as of September 2026.

The headline is the least useful number in a TPRM quote. What decides your year-three invoice is the unit you are billed in.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with TPRM software pricing

Almost no TPRM vendor publishes a price, and that silence is itself a pricing model

Work through the category and the pattern is hard to miss. SecurityScorecard, Bitsight, Panorays, Whistic, Venminder and OneTrust all quote per customer with no public list price. UpGuard publishes one tier and sends you to sales for the other three. ProcessUnity, which acquired CyberGRX, announced a VRM Essential Edition starting at $15,000 a year, though that figure comes from a 2021 company announcement and is old enough that you should treat it as a starting point for a conversation rather than a current rate. Quote-only pricing is not an oversight. It lets a vendor price on what your program is worth to you rather than on what the software costs to run, which is why two companies with identical vendor counts routinely pay very different numbers for the same platform. It also means the first number you hear is an anchor, not a price. Reported discounts of 15 to 30 percent on multi-year commitments show up consistently across recorded purchase data in this category, and Bitsight deals closed near its December 31 fiscal year end are frequently reported at the deeper end of that band. Practically, that gives a buyer three levers before signing anything: ask for the rate card rather than a total, ask what happens to the price at double your current vendor count, and get the renewal escalator in writing during the first negotiation rather than the second.

The unit you are billed in decides your year-three invoice

Every quote in this market reduces to one of five units, and they behave completely differently as a program matures. Per monitored vendor is the most common, used by the security-ratings platforms, and it is the one buyers underestimate: a platform that costs a certain amount for 50 vendors can cost several times that at 300, because you are billed for the size of the population you watch. Per assessment charges for the work rather than the watching, which suits a program that reviews a small number of vendors deeply. Per user is rare in TPRM and common in GRC, and it quietly punishes exactly the outcome you want, which is business owners doing their own reviews instead of routing everything through two analysts. Per module is the OneTrust model, where the quote is assembled from parts and the sticker price of the first part tells you almost nothing about the total. Flat is the rarest. The reason this matters more than the headline figure is that a mature third-party risk program monitors more vendors, not fewer. You onboard, you tier, you discover fourth parties, you stop deleting vendors from the inventory because the contract technically lapsed. Under a per-vendor unit, every one of those improvements arrives as an invoice increase. Ask the question directly during the demo: if we do this well, what does the price do?

The line items that are real and are not in the quote you were shown

The gap between a TPRM quote and the money that actually leaves the business is usually made of four things. Implementation and onboarding are quoted separately by most enterprise platforms, and one-time fees from $5,000 to $25,000 are commonly reported for the security-ratings vendors. Add-on modules come next: AI document review, framework mapping, fourth-party monitoring, managed assessment services and questionnaire exchanges are frequently sold on top, so a platform that looks cheap at the base tier can reach or pass a rival once you add the pieces your program actually needs. Third is the annual escalator, a contractual uplift at each renewal that is normal in this category and almost never mentioned in a demo. Fourth, and largest, is the line no vendor bills you for and no comparison article counts: your own team. If the platform still requires an analyst to chase, read and reconcile questionnaire responses by hand, the software fee is the smaller half of the cost of the program. When you build the budget, build it as three-year total cost rather than year-one subscription: license, plus implementation, plus the modules you know you will need by month twelve, plus escalators, plus the headcount the workflow still assumes. That is the number to compare across vendors, and it is the one that reorders the shortlist.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Publishes every plan in full, so you can size the spend before a sales call instead of after three of them
  • Prices on a flat plan rather than per monitored vendor, so widening coverage to the vendors you had been ignoring does not raise the bill
  • Includes unlimited vendor risk scoring and continuous monitoring on the Risk+ tier, rather than selling monitoring as a module on top
  • Runs vendor risk and your own control evidence on one base, which removes the second license most programs buy to cover the half the first one misses
  • Carries no per-questionnaire fee, so the cost of answering a customer security review does not scale with how many customers ask
  • Lets you run a real assessment in the Scrutiny Desk above before paying, so the evaluation does not depend on a scripted demo
TPRM SOFTWARE PRICING readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

TPRM pricing reference

What each third-party risk platform actually bills you for, and what makes the number jump

Most pricing articles in this category list a vendor and a dollar range and stop there. The range is the least portable fact in the table, because it depends entirely on a scope you do not share with the buyer it was recorded from. What transfers between companies is the billing unit and the trigger that moves it. Figures below are reported unless marked verified, and every one of them should be confirmed with the vendor before it enters a budget.

Platform What you are billed for What makes the number jump Publishes a rate card? Reported annual cost
UpGuard Monitored vendors, in fixed tiers Crossing a tier boundary, or adding vendors at $79 a month each Partly. One tier is listed, three say contact sales Vendor Risk Standard listed at $1,750 a month billed annually for 50 vendors, verified September 2026
SecurityScorecard Vendors monitored, with volume tiering Portfolio growth, plus a one-time implementation fee commonly reported at $5,000 to $25,000 No Roughly $25,000 to $50,000 a year for a 50 to 200 vendor portfolio, reported August 2026
Bitsight Companies monitored Portfolio size and enterprise modules No Near $22,000 a year for smaller organizations and near $147,000 at enterprise scale, reported August 2026
Panorays Vendor count, annual assessment volume and modules Running more assessments per year, not just watching more vendors No Median near $21,700 a year, with a reported low near $12,000 and a high near $34,900
Whistic Assessment volume and users Assessment volume at enterprise scale No Median near $20,300 a year across 72 recorded purchases, low near $12,850, high near $42,625
ProcessUnity (acquired CyberGRX) Subscription edition sized to the vendor population Moving off the entry edition Historically. A VRM Essential starting figure was announced, then not maintained VRM Essential announced from $15,000 a year in a 2021 ProcessUnity release, with posted tiers near $2,700 to $6,000 a month
OneTrust Modules taken Each additional module, which is how the same product spans a very wide range No Reported minimum near $10,000, GRC entry near $50,000, mid-market $40,000 to $120,000, multi-module rollouts $150,000 and up
Scrutineer A flat plan. Vendor scoring is unlimited on the Risk+ tier, so the vendor count is not the meter Frameworks and scale, not how many vendors you add Yes, in full and on the public site Published: from $599 a month, Risk+ at $2,500 a month, annual plans quoted at $5,988, $11,988 and $24,996

Reported figures come from recorded purchase data and vendor announcements re-checked between July and September 2026, and they move. Treat them as a starting range for a negotiation, not a quote, and confirm current pricing with each vendor. Scrutineer is readiness and monitoring software; an accredited auditor still issues any attestation.

Good questions

Questions about TPRM software pricing

Most mid-market third-party risk programs land somewhere between $20,000 and $50,000 a year for the platform alone. Recorded purchase data puts medians near $21,700 for Panorays and $20,300 for Whistic, while enterprise deployments with large vendor portfolios or several modules run well past $150,000. Implementation is usually quoted separately.
Per year, expect roughly $12,000 to $35,000 at the entry and mid-market end, $25,000 to $50,000 for a security-ratings platform covering 50 to 200 monitored vendors, and $50,000 to $250,000 or more at enterprise scale. The spread is driven by how many vendors you monitor, how many assessments you run, and how many modules you take.
Because quote-only pricing lets a vendor price on the value of your program rather than the cost of the software. It also removes the anchor a buyer would otherwise negotiate against. The practical effect is that two companies with the same vendor count often pay very different amounts for the same platform, so the first number you are given should be treated as an opening position.
A few. UpGuard lists its Vendor Risk Standard tier at $1,750 a month billed annually for 50 vendors and quotes the rest. Scrutineer publishes every plan in full, from $599 a month, with the Risk+ vendor risk tier at $2,500 a month. Most of the category, including SecurityScorecard, Bitsight, Panorays, Whistic and OneTrust, quotes privately.
Most often per monitored vendor, particularly among the security-ratings platforms. Some vendors price per assessment run, some per module taken, and GRC suites more often price per user. The unit matters more than the headline number, because a per-vendor meter means the price rises every time your program covers more of your supply chain.
Four recur. One-time implementation and onboarding, commonly reported at $5,000 to $25,000. Add-on modules such as fourth-party monitoring, framework mapping and managed assessments. An annual escalator applied at renewal. And the analyst time the workflow still assumes, which is the largest cost in most programs and appears on no invoice.
As of September 2026 UpGuard lists Vendor Risk Standard at $1,750 a month, billed annually, covering 50 vendors, with additional vendors at $79 a month each. Professional (150 vendors), Corporate (500 vendors) and Enterprise+ (unlimited) are quote-based. Earlier published figures of $1,599 and $3,333 a month no longer appear on the page.
Yes, and it is expected in a quote-only market. Discounts of 15 to 30 percent are commonly reported on multi-year commitments and at renewal. Ask for the rate card rather than a total, fix the renewal escalator in the first contract, and get the price at double your current vendor count in writing before you sign the first one.
For a first program covering 50 to 150 vendors, budget the platform at $20,000 to $40,000 a year, add implementation if the vendor charges it separately, and add the modules you will need by month twelve rather than the ones you need in week one. Compare vendors on three-year total cost, not year-one subscription.
For a real program, no. Free tiers in this category cover a handful of vendors and stop at outside-in scanning, which answers what the internet can see about a supplier and nothing about their internal controls. They are useful for a one-off look at a single vendor. Once anyone outside your team relies on the answer, you need dated evidence and an audit trail, and that is where paid platforms start.
Usually a little, because vendor risk management is typically the narrower scope: assessing and monitoring suppliers. Third-party risk management as sold often adds fourth-party discovery, contract and obligation tracking and regulatory reporting. The names are used interchangeably by most vendors, so compare the module list rather than the label on the quote.
Risk+ is $2,500 a month, or $24,996 billed annually, and includes unlimited vendor risk scoring and continuous third-party monitoring alongside the compliance platform. Plans start at $599 a month for a single framework. There is no free tier; the interactive Scrutiny Desk above runs a real assessment before you pay anything.

Keep reading

More on what compliance and vendor risk tooling costs

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification