Scrutineer · Vendor risk
Third-party risk management software pricing and cost
Third-party risk management software runs from about $21,000 a year for a mid-market program to well past $150,000 at enterprise vendor counts, and almost nobody publishes a rate card. UpGuard lists $1,750 a month for 50 vendors as of September 2026.
The headline is the least useful number in a TPRM quote. What decides your year-three invoice is the unit you are billed in.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with TPRM software pricing
Almost no TPRM vendor publishes a price, and that silence is itself a pricing model
Work through the category and the pattern is hard to miss. SecurityScorecard, Bitsight, Panorays, Whistic, Venminder and OneTrust all quote per customer with no public list price. UpGuard publishes one tier and sends you to sales for the other three. ProcessUnity, which acquired CyberGRX, announced a VRM Essential Edition starting at $15,000 a year, though that figure comes from a 2021 company announcement and is old enough that you should treat it as a starting point for a conversation rather than a current rate. Quote-only pricing is not an oversight. It lets a vendor price on what your program is worth to you rather than on what the software costs to run, which is why two companies with identical vendor counts routinely pay very different numbers for the same platform. It also means the first number you hear is an anchor, not a price. Reported discounts of 15 to 30 percent on multi-year commitments show up consistently across recorded purchase data in this category, and Bitsight deals closed near its December 31 fiscal year end are frequently reported at the deeper end of that band. Practically, that gives a buyer three levers before signing anything: ask for the rate card rather than a total, ask what happens to the price at double your current vendor count, and get the renewal escalator in writing during the first negotiation rather than the second.
The unit you are billed in decides your year-three invoice
Every quote in this market reduces to one of five units, and they behave completely differently as a program matures. Per monitored vendor is the most common, used by the security-ratings platforms, and it is the one buyers underestimate: a platform that costs a certain amount for 50 vendors can cost several times that at 300, because you are billed for the size of the population you watch. Per assessment charges for the work rather than the watching, which suits a program that reviews a small number of vendors deeply. Per user is rare in TPRM and common in GRC, and it quietly punishes exactly the outcome you want, which is business owners doing their own reviews instead of routing everything through two analysts. Per module is the OneTrust model, where the quote is assembled from parts and the sticker price of the first part tells you almost nothing about the total. Flat is the rarest. The reason this matters more than the headline figure is that a mature third-party risk program monitors more vendors, not fewer. You onboard, you tier, you discover fourth parties, you stop deleting vendors from the inventory because the contract technically lapsed. Under a per-vendor unit, every one of those improvements arrives as an invoice increase. Ask the question directly during the demo: if we do this well, what does the price do?
The line items that are real and are not in the quote you were shown
The gap between a TPRM quote and the money that actually leaves the business is usually made of four things. Implementation and onboarding are quoted separately by most enterprise platforms, and one-time fees from $5,000 to $25,000 are commonly reported for the security-ratings vendors. Add-on modules come next: AI document review, framework mapping, fourth-party monitoring, managed assessment services and questionnaire exchanges are frequently sold on top, so a platform that looks cheap at the base tier can reach or pass a rival once you add the pieces your program actually needs. Third is the annual escalator, a contractual uplift at each renewal that is normal in this category and almost never mentioned in a demo. Fourth, and largest, is the line no vendor bills you for and no comparison article counts: your own team. If the platform still requires an analyst to chase, read and reconcile questionnaire responses by hand, the software fee is the smaller half of the cost of the program. When you build the budget, build it as three-year total cost rather than year-one subscription: license, plus implementation, plus the modules you know you will need by month twelve, plus escalators, plus the headcount the workflow still assumes. That is the number to compare across vendors, and it is the one that reorders the shortlist.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Publishes every plan in full, so you can size the spend before a sales call instead of after three of them
- Prices on a flat plan rather than per monitored vendor, so widening coverage to the vendors you had been ignoring does not raise the bill
- Includes unlimited vendor risk scoring and continuous monitoring on the Risk+ tier, rather than selling monitoring as a module on top
- Runs vendor risk and your own control evidence on one base, which removes the second license most programs buy to cover the half the first one misses
- Carries no per-questionnaire fee, so the cost of answering a customer security review does not scale with how many customers ask
- Lets you run a real assessment in the Scrutiny Desk above before paying, so the evaluation does not depend on a scripted demo
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
TPRM pricing reference
What each third-party risk platform actually bills you for, and what makes the number jump
Most pricing articles in this category list a vendor and a dollar range and stop there. The range is the least portable fact in the table, because it depends entirely on a scope you do not share with the buyer it was recorded from. What transfers between companies is the billing unit and the trigger that moves it. Figures below are reported unless marked verified, and every one of them should be confirmed with the vendor before it enters a budget.
| Platform | What you are billed for | What makes the number jump | Publishes a rate card? | Reported annual cost |
|---|---|---|---|---|
| UpGuard | Monitored vendors, in fixed tiers | Crossing a tier boundary, or adding vendors at $79 a month each | Partly. One tier is listed, three say contact sales | Vendor Risk Standard listed at $1,750 a month billed annually for 50 vendors, verified September 2026 |
| SecurityScorecard | Vendors monitored, with volume tiering | Portfolio growth, plus a one-time implementation fee commonly reported at $5,000 to $25,000 | No | Roughly $25,000 to $50,000 a year for a 50 to 200 vendor portfolio, reported August 2026 |
| Bitsight | Companies monitored | Portfolio size and enterprise modules | No | Near $22,000 a year for smaller organizations and near $147,000 at enterprise scale, reported August 2026 |
| Panorays | Vendor count, annual assessment volume and modules | Running more assessments per year, not just watching more vendors | No | Median near $21,700 a year, with a reported low near $12,000 and a high near $34,900 |
| Whistic | Assessment volume and users | Assessment volume at enterprise scale | No | Median near $20,300 a year across 72 recorded purchases, low near $12,850, high near $42,625 |
| ProcessUnity (acquired CyberGRX) | Subscription edition sized to the vendor population | Moving off the entry edition | Historically. A VRM Essential starting figure was announced, then not maintained | VRM Essential announced from $15,000 a year in a 2021 ProcessUnity release, with posted tiers near $2,700 to $6,000 a month |
| OneTrust | Modules taken | Each additional module, which is how the same product spans a very wide range | No | Reported minimum near $10,000, GRC entry near $50,000, mid-market $40,000 to $120,000, multi-module rollouts $150,000 and up |
| Scrutineer | A flat plan. Vendor scoring is unlimited on the Risk+ tier, so the vendor count is not the meter | Frameworks and scale, not how many vendors you add | Yes, in full and on the public site | Published: from $599 a month, Risk+ at $2,500 a month, annual plans quoted at $5,988, $11,988 and $24,996 |
Reported figures come from recorded purchase data and vendor announcements re-checked between July and September 2026, and they move. Treat them as a starting range for a negotiation, not a quote, and confirm current pricing with each vendor. Scrutineer is readiness and monitoring software; an accredited auditor still issues any attestation.
Good questions
Questions about TPRM software pricing
Keep reading
More on what compliance and vendor risk tooling costs
Compliance automation software pricing
What twelve compliance platforms charge, and how the annual contract value is actually assembled.
Read the guideTPRM software comparison
Nine vendor risk platforms compared on what they measure, who they suit and where each one stops.
Read the guideBest third-party risk management software
The categories of TPRM tool, what each is genuinely good at, and how to shortlist against your own program.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification