Assess it. Run it. Govern the portfolio.
Three packages on one axis. Compliance Starter assesses and reports on CIS Controls and NIST CSF 2.0. GRC Professional runs the entire program across every framework we support. Enterprise Governance runs it for every company you manage, audit, or own. Everything is self-serve — 7-day trial, then buy in-app on a 12-month agreement, no sales call required.
Compliance Starter
Assess and report across compliance, risk, and governance.
For a single organization getting its bearings on CIS Controls and NIST CSF 2.0 — run the assessments, collect evidence, close the gaps, and hand leadership a defensible report.
- Standard seats
- 3
- Guest seats
- 100
- Frameworks
- CIS Controls + NIST CSF 2.0
- Storage
- 100 GB
- Linked accounts
- None
- CIS Controls and NIST CSF 2.0, with maturity heatmaps
- Compliance, risk, and governance in one place
- Risk assessments with readiness packs
- Evidence library and evidence packages
- Policies, policy templates, and attestations
- Gap analysis, defined targets, and executive reporting
“We need another framework, an add-on module, or to run the program continuously — work items, remediation plans, control testing, incidents — not just assess and report on it.”
GRC Professional
Everything in Starter, plus run the entire program — work items, remediation, control testing, incidents, and audits.
Every management capability in the platform for one organization — the full risk register, work items and remediation, control testing, incidents, audits, board-grade reporting, and defensible evidence.
- Standard seats
- 8
- Guest seats
- 150
- Frameworks
- Unlimited
- Storage
- 250 GB
- Linked accounts
- None
- Everything in Compliance Starter, plus:
- Every framework we support — SOC 2, ISO 27001, HIPAA, PCI DSS, and the rest
- All five add-on modules available to attach
- Full risk register, work items, and remediation plans
- Control testing, incidents, KRIs, and root-cause analysis
- Audit management, workpapers, and PBC requests
- Quantitative risk (FAIR) and continuous control monitoring
- Report builder, the full capstone library, SSO, SIEM forwarding
“We manage, audit, or own more than one company — and we need to govern all of them.”
Enterprise Governance
Everything in GRC Professional, plus govern a portfolio of companies from one command center.
Everything in GRC Professional — plus the one thing it doesn't do: govern a portfolio. Add a linked account for every company you manage, audit, or own, and run their GRC programs from one parent command center.
- Standard seats
- 20
- Guest seats
- 250
- Frameworks
- Unlimited
- Storage
- 1,000 GB
- Linked accounts
- 1 included · $1,000/yr each
- Everything in GRC Professional, plus:
- Linked accounts — one per company you govern
- Portfolio rollup dashboards and command center
- Parent-managed billing across all entities
- Cross-entity data-sharing agreements
- Consolidated audit view across the portfolio
- 20 seats, 250 guests, 1 TB storage
Trials run on GRC Professional — switch to Enterprise Governance in the in-app store when you buy.
Whole product areas, priced per year.
Modules attach to GRC Professional and Enterprise Governance at the same flat price on either, so moving up to govern a portfolio never changes what a module costs. Compliance Starter is the assess-and-report package and does not carry them.
Third-Party Risk Management
Vendor inventory, security questionnaires, tiering, contracts and SLAs, the vendor portal, your trust center, and advanced vendor and supply-chain monitoring. Includes 50 active vendors; buy vendor blocks of 100 for more. Available on GRC Professional and Enterprise Governance.
Workforce Governance
Roster, asset catalog, custodians, training evidence, access reviews, and joiner-mover-leaver. Available on GRC Professional and Enterprise Governance.
Application Security
Early accessRepository and pipeline governance, SDLC control attestation, scanner findings, SBOM/VEX, API security posture, and product advisories. Early access.
Auditor & Advisory
BetaRun client engagements as a firm: engagement case files, technology and cybersecurity due-diligence questionnaires, interview records, evidence requests, findings with costed remediation, and an investment-committee summary. Each client is a linked account on Enterprise Governance. Beta.
AI Insights
AI assistance across drafting, analysis, questionnaire answering, and report narratives. You connect your own AI provider key, so usage runs on your own provider account — there is no usage meter to buy from us.
Every add-on module is $8,000/yr, flat — pick the areas your program needs and they attach to whichever package you run.
Size it to your program.
Pick a package, set your scale, add modules. Email yourself the estimate, or start a trial and buy in-app when you're ready.
8 included. Each additional seat on GRC Professional: $900/yr.
150 included. Additional guests are billed in blocks of 100 at $1,500/yr.
250 GB included. Each additional 100 GB block: $500/yr.
GRC Professional includes every framework we support, at no additional cost.
Govern more than one company — subsidiaries, portfolio companies, franchisees, or clients — each with its own complete GRC program rolling up to you. to price a portfolio.
Every package, module, and linked account here is purchasable in-app — no sales call required.
Annual list pricing for standard configurations, sold on a 12-month agreement. All three packages are purchasable online in-app at list price — no sales call required. Quotes generated here are estimates and are valid for 30 days from the date generated.
Full rate card — seats, guests, storage, vendors, frameworks, linked accounts
| Add-on | Unit | Annual |
|---|---|---|
| Additional standard seat Priced per package. A standard seat is a fully-licensed user who runs the platform day to day. | per seat / yr | $600–$1,200 |
| Guest seat block Guests answer assessments and upload evidence. They never consume a standard seat. | per 100 guests / yr | $1,500 |
| Storage block Evidence, artifacts, and export archives. | per 100 GB / yr | $500 |
| Vendor block Active third parties under management. Requires the Third-Party Risk Management module. | per 100 active vendors / yr | $2,000 |
| Linked account A separately-governed company you manage, audit, or own — subsidiary, portfolio company, franchisee, or client — rolling up to your parent organization. Enterprise Governance only; the first one is included. | per linked account / yr | $1,000 |
The AI add-on runs on your own AI provider key — inference is billed to you by that provider, not resold or marked up by us. Your administrators still set per-user limits and per-feature ceilings inside Talarity, so usage never runs past what you authorise.
Want to see what that spend returns? Project your ROI →
The complete feature list.
Every capability in the platform, and exactly where it lives. Open a section — or expand everything — and jump here from any package card to light up its column. The differences are real capability boundaries, not feature-gating for its own sake.
76 capabilities across 13 areas.
| Capability | Compliance Starter Starting at $10,000/yr | GRC Professional Starting at $24,000/yr | Enterprise Governance Starting at $56,000/yr |
|---|---|---|---|
| Assessment hub, catalog, and custom assessment wizard | Included | Included | Included |
| CIS Controls and NIST CSF 2.0 programs with maturity heatmaps | Included | Included | Included |
| Framework assessments — SOC 2, ISO 27001, HIPAA, PCI DSS v4, CMMC 2.0, FedRAMP, GDPR, SOX, SEC Cyber, NIST AI RMF, CSA AICM | Not included | Included | Included |
| Risk assessment wizard and extended risk assessments (cloud, API, CI/CD, IAM, privacy, regulatory, BCDR, controls) | Included | Included | Included |
| Readiness packs and defined compliance targets | Included | Included | Included |
| Assessment assignment, campaigns, and guest responses | Included | Included | Included |
| Scoring, response viewer, question index, and assessment history | Included | Included | Included |
| Gap analysis | Included | Included | Included |
| Evidence library, collection, and evidence packages | Included | Included | Included |
| Evidence mapping, review, and gap detection | Included | Included | Included |
| Smart evidence and request intake | Included | Included | Included |
| Artifact repository and security artifacts | Included | Included | Included |
| Compliance hub and framework compliance dashboards | Included | Included | Included |
| Evidence automation and external monitoring | Not included | Included | Included |
| Continuous control monitoring | Not included | Included | Included |
| Statistical sampling and management assertions | Not included | Included | Included |
| Regulatory change management and regulatory submissions | Not included | Included | Included |
| BC/DR planning and DR program management | Not included | Included | Included |
| Policy library, policy templates, and attestation campaigns | Included | Included | Included |
| Control library, framework setup, and requirements | Included | Included | Included |
| Control testing and the test methodology library | Not included | Included | Included |
| Control exceptions and exception management | Not included | Included | Included |
| Tasks, task forms, and the workflow builder | Not included | Included | Included |
| Initiatives, strategic roadmap, RACI matrix, and security metrics | Not included | Included | Included |
| Operational procedures and procedure templates | Not included | Included | Included |
| Board & committees, conflict of interest, ESG, whistleblower hotline (early access) | Not included | Included | Included |
| E-signature envelopes and segregation of duties (early access) | Not included | Included | Included |
| Risk overview, security posture, and executive risk dashboards | Included | Included | Included |
| Full risk register, risk scenarios, and treatment plans | Not included | Included | Included |
| Work items, work-item dashboard, and approvals | Not included | Included | Included |
| Remediation planner and remediation verification | Not included | Included | Included |
| Key risk indicators (KRIs) and KRI alerts | Not included | Included | Included |
| Incident management and root-cause analysis | Not included | Included | Included |
| Quantitative risk (FAIR) and custom risk models | Not included | Included | Included |
| Threat & vulnerability management and threat intelligence | Not included | Included | Included |
| RCSA workflows, risk concentration, and threat modeling (early access) | Not included | Included | Included |
| Audit management, workpapers, and formal interviews | Not included | Included | Included |
| PBC requests and the auditor portal | Not included | Included | Included |
| Chain-of-custody evidence sealing | Not included | Included | Included |
| WORM audit-log export and legal holds | Not included | Included | Included |
| Insights home and role dashboards — Area Insights, CISO, CRO, Risk Manager, Security Manager, Assessment Analyst | Included | Included | Included |
| Executive reports, board reporting, and the CISO package | Included | Included | Included |
| Shared reports, report history, and scheduled reports | Included | Included | Included |
| Industry benchmark | Included | Included | Included |
| Custom report builder | Not included | Included | Included |
| Capstone reports — full library | Not included | Included | Included |
| Integrations, connector marketplace, API keys, and webhooks | Included | Included | Included |
| Ticketing integration and ticketing evidence | Included | Included | Included |
| SSO (SAML/OIDC) and SCIM user provisioning | Not included | Included | Included |
| SIEM forwarding | Not included | Included | Included |
| Linked accounts — separately-governed companies you manage, audit, or own | Not included | Not included | 1 included · then per-account pricing |
| Portfolio rollup dashboards and the parent command center | Not included | Not included | Included |
| Parent-managed billing across all entities | Not included | Not included | Included |
| Cross-entity data-sharing agreements | Not included | Not included | Included |
| Consolidated audit view across the portfolio | Not included | Not included | Included |
| Per-entity evidence, controls, and assessments with parent oversight | Not included | Not included | Included |
| Vendor inventory, tiering, and vendor dashboard | Not included | Add-on | Add-on |
| Vendor security questionnaires and assessments | Not included | Add-on | Add-on |
| Contracts, obligations, and SLA tracking | Not included | Add-on | Add-on |
| Vendor portal and trust center | Not included | Add-on | Add-on |
| Advanced vendor and supply-chain monitoring | Not included | With TPRM module | With TPRM module |
| Workforce roster, asset catalog, and custodians | Not included | Add-on | Add-on |
| Assignments, app access profiles, and training evidence | Not included | Add-on | Add-on |
| Access reviews and entitlement certification | Not included | With Workforce module | With Workforce module |
| Joiner-mover-leaver | Not included | With Workforce module | With Workforce module |
| Repository and pipeline governance, SDLC attestation | Not included | Add-on | Add-on |
| Scanner findings, SBOM/VEX, API security posture | Not included | Add-on | Add-on |
| Product security advisories (PSIRT) | Not included | Add-on | Add-on |
| Client engagement case files, scope, milestones, and team | Not included | Add-on | Add-on |
| Technology and cybersecurity due-diligence questionnaires | Not included | Add-on | Add-on |
| Interview records, evidence requests, and findings with costed remediation | Not included | Add-on | Add-on |
| Investment-committee summary and capability benchmarks | Not included | Add-on | Add-on |
| AI drafting assistance, copilot, and questionnaire answering | Not included | Add-on | Add-on |
| AI-enhanced report narratives | Not included | Add-on | Add-on |
| AI agents | Not included | With AI module | With AI module |
| Runs on your own AI provider key | Not included | Add-on | Add-on |
This is the complete feature list — every row is a real product boundary, and expanding a package's column shows everything it includes. Rows marked "Add-on" belong to an add-on module you can attach to GRC Professional or Enterprise Governance.
Which package fits?
One axis, three steps: assess it, run it, then run it for every company you govern. Pick the one that matches the job in front of you this year — the upgrade trigger tells you when you have outgrown it.
Choose Compliance Starter if…
$10,000/yr- You need to know where you stand — across compliance, risk, and governance
- The immediate job is getting assessed, audit-ready, and reported to leadership
- Your evidence lives in shared drives and spreadsheets today
- You want readiness packs, a gap list, and a report you can hand to the board
“We need another framework, an add-on module, or to run the program continuously — work items, remediation plans, control testing, incidents — not just assess and report on it.”
Choose GRC Professional if…
$24,000/yr- Someone owns the findings — work items, remediation plans, and treatment decisions
- You test controls between audits and manage incidents when they happen
- The board and the auditor want reporting built from live program data
- An auditor or regulator will challenge how your evidence was collected and held
“We manage, audit, or own more than one company — and we need to govern all of them.”
Choose Enterprise Governance if…
$56,000/yr- You manage, audit, or own more than one company — subsidiaries, portfolio companies, franchisees, or clients
- Each entity needs its own GRC program, and the parent needs the rollup
- You want one bill, one command center, and per-entity accountability
- Entities must share data with each other under an explicit agreement
License Talarity yourself, start to finish.
All three packages — and every module, linked account, and scale block — are self-serve. You never need to wait on us. Here is the whole path:
Start your trial
Sign up with a work email — 7 days, no credit card. Your workspace is provisioned automatically, no one has to set it up for you.
Build your readiness package
The in-app checklist walks you through it: pick a framework, apply a readiness pack, collect evidence, close the gaps, generate the report.
Buy online when you’re ready
In the app, open Settings → Billing → Store. Pick your package and any add-ons, pay by card, and keep everything you’ve built — on a 12-month agreement, no sales call required.
Already have an account? Sign in and the store is one click away.
Pricing FAQ.
How does the trial work?
Can I buy without talking to sales?
Is a credit card required for the trial?
How do the three packages differ?
What's the difference between GRC Professional and Enterprise Governance?
What is a linked account, and what does it cost?
Can I move up a package later?
What are add-on modules?
What is a standard seat versus a guest seat?
How is AI usage priced?
How long is the agreement?
Do you offer annual prepay or multi-year terms?
Do you support purchase orders and invoicing?
Ready to start?
Seven days to build your first readiness package — pick a framework, collect evidence, close the gaps, generate the report. Then buy online in-app, no sales call required.