Complete Product.
Pay for Scale, Not Features.
Choose the product that fits your requirement. Each CipherQuest product is sold as a complete application. Pricing reflects the scale and operating requirements relevant to that product — not feature tiers.
Focused products. One clear commercial model.
Each published starting price is tied to a defined baseline scope. We confirm the appropriate commercial scale after discussing your operating requirements.
For organizations that need a governed third-party risk lifecycle across due diligence, evidence, treatment, remediation, oversight, and decision history.
Explore CQ Vendor Risk →For organizations that need one current operating view across risk assessment, treatment, ownership, monitoring, and reporting.
Explore CQ IT Risk →For organizations that need security and business significance added to the asset inventory they already maintain.
Explore CQ IT Asset Classification →Pay for the operating scope you use.
The commercial model stays simple: product capability remains complete while the commercial scope scales with the product-specific usage metrics shown for each product.
The number of users who actively operate the product contributes to the commercial scope.
The relevant operating volume depends on the product you are using.
Materially different infrastructure, integration, or bespoke requirements are discussed separately.
Full product capability comes standard.
No Basic / Pro / Enterprise functionality tiers. Standard product capability is included within the agreed commercial scope.
Designed for self-implementation. A mandatory consulting engagement is not required to use CipherQuest SaaS products.
Products and expert services are separate commercial decisions.
Professional services can be purchased independently or alongside a CipherQuest product. They are never required to unlock product features.
Start independently. Review progress with CipherQuest.
CipherQuest products are designed for self-implementation. Eligible customers may request a 30-minute advisory review after approximately 90 days of use to discuss adoption, progress, practical questions, and opportunities to strengthen how the product is being used.
The review is a structured conversation with CipherQuest about product adoption and progress. It is separate from routine helpdesk support and is not a security audit, implementation engagement, or open-ended consulting session.
Use the 30 minutes to review adoption, workflow use, lessons learned, and the practical questions that emerged during the first months.
Identify where configuration, operating discipline, or broader adoption could strengthen the value already being created.
Cybersecurity capability should be accessible beyond large enterprises.
CipherQuest can consider tailored commercial arrangements for eligible nonprofit organizations, academic institutions, and research organizations where standard commercial scale may not reflect the organization’s operating context.
Eligibility, scope, product fit, and commercial terms are assessed individually. These programs do not change the standard product capability or create a separate reduced-feature edition.
Check Program EligibilityClear before you buy.
The appropriate commercial scope is confirmed after requirements discovery and reflected in the proposal and contract.
Published monthly pricing is invoiced under the applicable annual subscription terms.
Bespoke functionality, unusual workflows, integrations, or customer-specific infrastructure are scoped separately.
Prices exclude applicable taxes, where required.
Operate with Control.
Govern with Confidence.
Tell us which product or product combination you need. We will confirm the appropriate commercial scope and subscription terms.
Discuss Your Requirements