We checked what ten compliance platforms actually publish on their own websites on 2026-08-15. Two findings changed how we would advise a founder. First, only one of them publishes a price: Ostendio, at 2,994 US dollars a year for Select, 23,940 for Premium and 119,400 for Enterprise, all written as from figures. The other nine route to a sales conversation. Second, three of the names that keep appearing in these searches are not in the same category at all. Risk Ledger is supplier risk management, Archer is enterprise integrated risk management, and Apptega sells to service providers first. This post is a category map and a shortlist method, not a ranking, because a ranking built on unpublished prices would be fiction.
Key findings
- One of ten publishes numeric pricing. Ostendio. Everyone else routes to sales.
- Three of the commonly searched names are a different product category. Risk Ledger (third-party and supply chain risk), Archer (enterprise integrated risk management), Apptega (service-provider first).
- Framework lists are the only hard published differentiator. They are specific, checkable and they diverge meaningfully between vendors.
- Packaging shape varies more than capability does. Stage tiers, outcome tiers, and modular add-ons produce different budget surprises for the same underlying product.
- None of the ten performs a penetration test. Every one of them gives you a control that expects the report as evidence.
- Neither SOC 2 nor ISO 27001 names a penetration test as a mandatory line item. The test gets done because auditors, enterprise customers and investors ask for it.
Cybersecify is a founder-led penetration testing firm based in Bengaluru. We do not resell, refer or take commission from any platform on this page, and we hold no SOC 2 or ISO 27001 certification ourselves. We deliver audit-prep and the independent test. We wrote this because the shortlist stage is where founders lose the most time, and because we keep arriving at the end of this process with six weeks left on the clock.
What we checked, and what we refused to guess
On 2026-08-15 we opened the pricing page or equivalent product page of each platform below and recorded three things: whether a numeric price appears, what the tiers are called, and which frameworks are named. Every source is listed at the end.
Where a vendor publishes no price, this page says so. It does not substitute a number from a review site, a listicle or a sales blog. That constraint removes most of what usually fills a post like this, which is exactly why it is worth reading.
Finding one: the category is almost entirely price-opaque
| Platform | Numeric price published? | Tiers or plans named |
|---|---|---|
| Ostendio | Yes | Select, Premium, Enterprise |
| Vanta | No | Essentials, Plus, Professional, Enterprise |
| Drata | No | Startup, Growth, Enterprise |
| Secureframe | No | Fundamentals, Complete, Defense |
| Sprinto | No | Foundation, Growth, plus GRC modules |
| Oneleet | No | None published |
| ISMS.online | No | None published, pricing described as bespoke |
| Apptega | No | Essentials, Plus, Premium |
| Archer | No | None published |
| OneTrust Certification Automation | No | None published on the product page |
All rows verified on the vendors’ own pages, 2026-08-15.
Ostendio is the outlier. Its pricing page shows Select from 2,994 US dollars a year, Premium from 23,940 US dollars a year and Enterprise from 119,400 US dollars a year. Note the word from on each: these are floors, and the page presents the same feature list across all three tiers, so the difference between them is not a published feature difference.
We are not recommending Ostendio on the strength of publishing a number. We are pointing out that it is the only data point in the category that lets you calibrate at all, and that a spread from roughly three thousand to roughly one hundred and twenty thousand dollars a year across three tiers of one vendor tells you how wide this market’s range is. If you were assuming these tools cluster around one price, they do not.
Oneleet’s pricing page is explicit that its model depends on factors specific to your needs and asks you to book a demo for accurate pricing. ISMS.online states its pricing is bespoke so you are not paying for things you do not need or seats you will not use. Those are honest positions. They are also unshoppable positions, and you should plan your evaluation accordingly.
The practical consequence: you cannot build a price shortlist from public information. You build a capability shortlist from published information, then run parallel quote requests. Do them in the same week, at the same headcount and framework scope, or the numbers are not comparable.
Finding two: three of these are not the product you are looking for
This is the part that saves the most time.
Risk Ledger describes itself as transforming third-party risk management with continuous, collective supply chain defence. It is a platform for assessing your suppliers and mapping your supply chain, with a network model where suppliers maintain a profile that multiple customers can view. That is a genuinely interesting product and a completely different job from getting your own company certified. If your problem is that enterprise customers keep sending you security questionnaires, Risk Ledger is on the wrong side of that transaction.
Archer positions as enterprise integrated risk management, and its own site cites adoption across Fortune 500 companies and large banks. This is a category that predates the startup compliance automation wave and serves organisations with a risk function, not a founder doing compliance between product releases. If you are under a hundred people, Archer will be a heavy fit.
Apptega publishes tiers named Essentials, Plus and Premium, and its pricing page speaks first to service providers: MSSPs, MSPs, MDRs and consulting firms delivering security and compliance for clients, with in-house teams named second. The feature emphasis on custom branding, sub-accounts and multiple workspaces confirms it. If you are the end company, you are the secondary audience, and you will feel that in the product.
OneTrust Certification Automation names SOC 2, ISO 27001, GDPR, HIPAA and NIS 2 and claims support for more than fifty standards. It sits inside a much larger privacy and data governance suite. That is a strength if you are already standardised on OneTrust and an unnecessary surface area if you are not.
ISMS.online is the ISO specialist of the group. Its framework list leans heavily into the ISO family: ISO 27001, ISO 42001, ISO 27701, ISO 22301, ISO 9001, ISO 14001, ISO 45001, alongside SOC 2, NIS 2, DORA and GDPR. If your destination is an ISO certification rather than a SOC 2 attestation, that concentration is a real advantage worth a demo.
Which leaves the five that genuinely do compete for the same startup buyer: Vanta, Drata, Secureframe, Sprinto and Oneleet.
Finding three: framework lists diverge in ways that decide the purchase
Since price is invisible and core capability is similar, the framework list is the highest-signal published information you have. It is specific, it is checkable, and it is a decent proxy for where each company has spent its engineering effort.
The divergences that actually change a decision, all read off the vendors’ own pages on 2026-08-15:
- Sprinto names DPDPA (India) and RBI SAR. No other platform we checked names either. It also names PDPA Singapore, Australian DPA, PIPEDA Canada and UK-GDPR.
- Vanta names HITRUST, FedRAMP, Cyber Essentials and the NIST AI Risk Management Framework. Sprinto’s select framework list does not name HITRUST or FedRAMP.
- Drata names DORA. Secureframe’s pages do not.
- Secureframe dedicates a whole tier, Defense, to CMMC, with SSP, POA&M, SPRS score tracking and CUI management named on it. Drata names CMMC in its list without a dedicated tier.
- ISO 42001 now appears on Vanta, Drata and Sprinto. The AI management system framework has become table stakes in about a year, which is a useful signal about where enterprise questionnaires are heading.
The rule to apply: if a framework you need is not named on a vendor’s own page, treat it as a custom build project rather than a feature, and make them prove otherwise in the demo. We have gone deeper on the individual matchups in Secureframe vs Vanta, Drata vs Secureframe and Sprinto vs Vanta.
The evidence none of these platforms can collect
Every platform on this page automates the same fundamental thing: reading state out of systems that expose an API. Your cloud configuration. Your identity provider’s access lists. Your code repository’s branch protection and review history. Your HR system’s joiner and leaver records. Your endpoint manager’s disk encryption status.
That is a large share of an audit evidence pack and automating it is worth real money, particularly during a SOC 2 Type 2 observation period where the same evidence has to keep arriving every month for six to twelve months.
Here is what is not in any of those APIs.
Whether a user authenticated to tenant A can read an object belonging to tenant B by changing an identifier in a request. Whether a multi-step workflow that validates correctly at every individual step can be walked out of order to skip an approval or a payment. Whether a password reset flow leaks whether an account exists. Whether an AI feature with tool access can be argued into calling a tool outside its intended scope, or into returning data from a document the current user should not see.
Those are application logic questions. They require a person who forms a hypothesis about your specific system and then tests it. No integration will ever surface them, because there is no API endpoint that reports whether your authorisation model is correct.
This is why the scoping conversation at the start of a pentest looks nothing like a platform onboarding. Platform onboarding asks which systems to connect. We ask which roles exist and which one is interesting, whether tenancy is enforced in the database or in application code, which API paths are undocumented, whether staging shares data with production, and what the most damaging thing a logged-in customer could plausibly do. Those answers determine whether the test finds anything.
We test against OWASP WSTG v4.2 for web applications and the OWASP API Security Top 10 2023 for API surfaces, and map every finding to the relevant Trust Services Criteria so your auditor is not doing the mapping themselves.
On what the frameworks actually say
Be sceptical of anyone, vendor or consultancy, who tells you a specific test format is mandated by a clause. The claim is usually stronger than the source.
The AICPA Trust Services Criteria are organised into five categories: Security, Availability, Processing Integrity, Confidentiality and Privacy. ISO/IEC 27001:2022 is Edition 3, published October 2022, and specifies requirements for an information security management system. PCI DSS is currently at version 4.0.1 per the PCI Security Standards Council’s own document library.
Neither SOC 2 nor ISO 27001 contains an instruction to buy a penetration test. The test is done because auditors ask for evidence of independent technical testing, because enterprise security questionnaires name the report, and because investors ask for it in diligence. Those are commercial reasons, and they are sufficient. You do not need a fabricated regulatory one, and using a fabricated one is how a vendor loses a technically literate buyer.
The shortlist method
- Write the framework list first. Every framework anyone has asked for, including offhand mentions in sales calls. Check each name literally against each vendor’s published list.
- Write the integration list second. Cloud provider, code repository, identity provider, HR system, endpoint management. Require a live demonstration of your specific ones, not a slide.
- Eliminate the wrong category. If you are a startup getting yourself certified, Risk Ledger, Archer and Apptega are probably not your shortlist.
- Note the packaging shape. Stage tiers create upgrade conversations tied to headcount. Modular add-ons create quotes with more lines and harder forecasting. Ask which of your requirements land in the base plan.
- Request quotes in parallel, same week, same scope. Ask each for the first-year number, the number at double your headcount, and the renewal number.
- Name the owner before you sign. The most common failure in this category is a correctly chosen platform that nobody operated.
- Book the penetration test on its own track. It has a lead time, findings need fixing, and the retest needs to land before your audit window closes.
Where we fit
Whichever platform you land on, the independent test is yours to arrange, and it is the one deliverable on your compliance plan that no software produces.
Our pentest plans start at INR 74,999 for the Startup plan: one scope, five business days, six founder-led consulting hours and one free retest. The Growth plan at INR 1,79,999 covers two scopes over ten business days with twelve consulting hours and SOC 2 plus ISO 27001 evidence mapping. Both co-founders are hands-on on every engagement; Rathnakara holds OSCP and leads the testing. Our audit and compliance service covers how readiness work and testing sequence together, and the sample report shows exactly what your auditor receives.
If you want a second opinion on your shortlist before you sign anything, book a call. We have no incentive in which platform you pick, which is the reason the conversation is useful.
Related reading: Vanta vs Drata vs Secureframe vs Sprinto 2026, SOC 2 Pentest Requirements: What Auditors Check, What Is GRC for Startups?, SOC 2 vs ISO 27001 vs DPDP: Which Compliance First?.
Sources
All checked 2026-08-15.
- Ostendio pricing: https://www.ostendio.com/pricing (Select from 2,994 USD/yr, Premium from 23,940 USD/yr, Enterprise from 119,400 USD/yr)
- Vanta pricing: https://www.vanta.com/pricing (tiers and framework list, no published price)
- Drata pricing: https://drata.com/pricing (tiers and framework list, no published price)
- Secureframe pricing: https://secureframe.com/pricing (tiers including Defense, no published price)
- Sprinto pricing: https://sprinto.com/pricing/ (Foundation and Growth plans, GRC modules, select framework list, no numeric price in any currency)
- Oneleet pricing: https://www.oneleet.com/pricing (no published price, demo required for a quote)
- ISMS.online plans: https://www.isms.online/pricing/ (bespoke pricing, ISO-family framework list)
- Apptega pricing: https://www.apptega.com/pricing (tiers, service-provider-first positioning, no published price)
- Archer: https://www.archerirm.com/ (enterprise integrated risk management positioning, no published price)
- OneTrust Certification Automation: https://www.onetrust.com/products/certification-automation/ (framework list, no published price)
- Risk Ledger: https://riskledger.com/ (third-party and supply chain risk management, no published price)
- AICPA Trust Services Criteria categories: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
- ISO/IEC 27001:2022, Edition 3, published 2022-10: https://www.iso.org/standard/27001
- PCI Security Standards Council document library, PCI DSS v4.0.1: https://www.pcisecuritystandards.org/document_library/