How the model works
The SaaS line takes the year-one subscription you select (medians from Vendr’s observed contracts, February 2026, or your own quote), scales it for the number of people who need access and the number of frameworks, then applies the chosen uplift and 10% seat growth in years two and three. The SECORA line is a one-time deployment equal to 1.2× that first-year subscription, with an optional 15% maintenance renewal from year two, the same assumptions as the SECORA executive brochure. Audit fees, penetration tests and remediation are excluded from both lines because you pay them regardless of platform.
The costs a subscription quote leaves out
- Renewal uplift: 5 to 10% a year is common across Vanta, Drata and Secureframe contracts; Hyperproof and AuditBoard report 3 to 7%.
- Seat and headcount growth: employee-count pricing rises as you hire; questionnaire caps and add-ons force tier jumps.
- Mid-contract frameworks: adding ISO 27001 to a SOC 2 subscription is reported to cost 15 to 30% more than at signing.
- First-year extras: CostBench estimates Drata customers spend 44 to 81% on top of the subscription in year one once pentest and audit are counted.
- Vendor risk work: a SaaS GRC tool holding your evidence needs its own assessment, contract review and monitoring, every year.
- Exit: export the data, lose the history and the audit trail.
What the SECORA deployment fee covers
Installation of the signed package in your tenant, framework configuration with controls, objectives and scoring, the policy and procedure library with client-branded PDF output, dashboard layout and department structure to your preferences, continuous checks for your Microsoft estate, and twelve months of maintenance, updates and support by ITSECOPS. Optional: gap assessment and remediation support, evidence collectors for AWS, Azure and Google Cloud, the multi-client edition, maintenance renewal from year two and vCISO coaching.


Sources: Vendr: Vanta · Vendr: Drata · Vendr: Secureframe · Vendr: Hyperproof · CostBench: Drata hidden costs. Competitor figures are observed contract data or published estimates, not list prices; verify with the vendor.
Frequently asked
Observed 2026 medians: Vanta $20,000, Drata $25,000, Secureframe $20,000, Hyperproof $41,400, AuditBoard $45,947, with ranges from $7,500 to over $100,000 depending on headcount, frameworks and modules. SECORA is a one-time deployment fee per organisation with twelve months of maintenance included.
No. SOC 2, ISO 27001 and CMMC assessments are performed by independent auditors or C3PAOs and cost the same whichever platform you use, so they are excluded from both lines.
It is the illustrative assumption used in the SECORA executive brochure so the two curves can be compared. Your actual quote depends on frameworks, estate size and optional services; request it and we send the real number within one business day.
Yes. The tool detects your locale and converts at approximate rates; quotes are issued in USD, EUR or NOK.
In your own Microsoft 365 tenant or SharePoint Server: SharePoint lists for controls, policies, risks, tasks, inventory and the audit trail, and a versioned document library for evidence. SECORA has no cloud of its own and no vendor database.
No. SECORA is licensed per organisation with a one-time deployment fee and twelve months of maintenance included. Invite every control owner, department head and external auditor without changing the bill.
See SECORA running in your own tenant
Walkthrough slots, deployment scope and a written quote within 1 business day.