One license. Everything in it.
CISGuard is licensed per deployment, sized by endpoint count. Every capability ships in every tier. The quote is fixed, and nothing is metered afterwards.
- 0Per-asset fees
- 0Module unlocks
- 0Metered scans
- 0Surprise true-ups
- Licensing model
- Per-deployment, sized by endpoint count; no per-endpoint fees, no metered scans, no surprise true-ups
- Tiers
- Starter (up to 50 endpoints), Professional (up to 500 endpoints), Enterprise (unlimited endpoints)
- What is included
- Every capability in every tier; no per-module unlocks or add-on fees
- Deployment and onboarding
- On-premises, air-gapped or private cloud; managed onboarding by CISGuard compliance engineers
- How to get a quote
- Contact consult@cisguard.io; pricing is quoted per deployment
Sized by estate, not by feature.
Three tiers, one product. Pick the scale that matches your endpoints and the support your team wants beside it.
- Starter50endpoints, up to
Small teams beginning continuous compliance.
- Managed onboarding by CISGuard engineers
- Email support
Per-deployment license. Every capability below included.
Talk to sales - Professional500endpoints, up to
Growing organizations with a serious compliance posture.
- Managed onboarding by CISGuard engineers
- Priority support
Per-deployment license. Every capability below included.
Get a quote - EnterpriseUnlimitedendpoints
Large estates, multiple sites, the strictest environments.
- Managed onboarding by CISGuard engineers
- Dedicated compliance engineer with SLA-backed response
Per-deployment license. Every capability below included.
Talk to sales
In every tier.
The whole product, from the first endpoint. There is no edition with the good parts removed.
Assess
- All 22 CIS benchmarks, 3,933 controls
- CIS Level 1 and Level 2 profiles
- Agent-based endpoints, agentless cloud and Kubernetes
- Scheduled scanning with blackout windows
Fix
- 2,032 signed, reversible remediations
- Preview, approve, apply, verify, roll back
- Continuous monitoring and drift detection
- Exception and waiver workflow with expiry
Prove
- NIST 800-53, ISO 27001 and SOC 2 mapping from one scan
- Executive, detailed and gap-analysis reports
- Framework coverage reports
- Immutable audit trail
Run
- On-premises, private cloud or air-gapped deployment
- Dedicated single-tenant installation
- SSO (SAML 2.0, Microsoft Entra ID) and LDAP
- SIEM (syslog, CEF, JSON over HTTPS), email and webhook alerts
Licensing questions, answered.
The questions procurement asks first.
How is CISGuard licensed?
CISGuard is licensed per deployment, sized by the number of endpoints. Every capability is included in every tier, with no per-module or per-scan fees.
Why no public price list?
Enterprise security deployments vary materially by endpoint count, framework scope, deployment topology (on-premises, air-gapped, hybrid) and SLA requirements. We provide a fixed quote within one business day of an initial conversation, with no hidden modules or metered scans afterwards.
Is there a free trial?
We offer a 45-minute Executive Briefing: a live scan against a sample of your own infrastructure with your security engineering team in the room. Contact consult@cisguard.io to schedule.
Can I upgrade my plan later?
Yes. You can move to a larger tier at any time. Our team handles the transition with zero downtime.
What counts as an endpoint?
Any Windows, Linux or container host that runs the CISGuard agent. Cloud-scanned resources (Azure subscriptions, AWS accounts, Microsoft 365 tenants) are counted separately based on your plan.
Do you offer volume discounts?
Yes. Custom pricing is available for large deployments (500+ endpoints) and multi-year agreements. Contact consult@cisguard.io for a quote.
What support is included?
Every tier includes managed onboarding. Professional adds priority support. Enterprise adds a dedicated compliance engineer with SLA-backed response times.
Ready for a tailored quote?
A 45-minute Executive Briefing: a live scan against your environment, a framework mapping walkthrough, and a fixed quote within one business day.