Three Tiers for the SOC 2 / NIST CSF Readiness Journey.
Free → Assessment → Audit-Ready.
Whether you’re at the start of your SOC 2 conversation, mid-readiness with a framework gap report, or already engaging an auditor, CyberStackHub has a tier built for that exact step. The same Stripe Connect checkout as our per-report tools — no separate billing system, no enterprise sales calls.
Free → Assessment → Audit-Ready
Each tier feeds the next: the Free self-assessment gives you a maturity score, the $99 Assessment produces the framework gap PDF the auditor will ask for, and the $599/mo Audit-Ready subscription gives you the evidence-automation + cyber-insurance partner pre-qualification that closes the loop on a real SOC 2 program.
- 5-minute SOC 2 / NIST CSF maturity score
- Top 5 prioritized CC1–CC9 gap list
- SOC 2 / NIST CSF framework reference
- Breach detection lookup + email funnel
- CyberStackHub Cyber Pulse weekly brief signup
- Full framework gap PDF
- CC-by-CC detailed mapping
- Audit-ready evidence automation
- Full Compliance Gap Analysis with maturity score
- CC1–CC9 + Availability detailed control mapping
- NIST CSF 6-Function crosswalk
- Prioritized remediation roadmap
- Board-ready PDF (yours to keep)
- Shareable interactive view for leadership / auditor
- Single Stripe Connect checkout — same path as Compliance Gap
- Continuous evidence automation
- Everything in the Starter tier ($299/mo)
- 200 AI credits / month
- SOC 2 Type I/II dashboard
- Compliance drift detection
- Automated evidence collection (CC6-CC9 coverage)
- Unlimited domain monitoring
- Email + Slack support
- Corgi cyber-insurance partner CTA post-audit
Free vs Assessment vs Audit-Ready — Side by Side
If you’re not sure which tier you need, the table below maps each tier to what it actually produces. Most SMBs start with the Free self-assessment, pay $99 for the Assessment PDF before engaging an auditor, and graduate to Audit-Ready for the post-engagement evidence automation.
| Feature | Free | Assessment — $99 | Audit-Ready — $599/mo |
|---|---|---|---|
| SOC 2 / NIST CSF maturity score | Yes — top-5 gaps | Yes — full CC1–CC9 | Yes — continuous |
| Framework control mapping (CC1–CC9 detail) | – | Full | Full |
| PDF deliverable (yours to keep) | – | Board-ready PDF | All reports |
| NIST CSF 6-Function crosswalk | – | Yes | Yes |
| HIPAA / PCI-DSS gap analysis | – | Add-on available | Included |
| Domain monitoring | 1 domain / week | – | Unlimited |
| Cyber Pulse weekly intelligence brief | Signup | – | Included |
| Email support | – | Receipt + post-purchase | Priority + Slack |
| SOC 2 Type I/II dashboard | – | – | Yes |
| Compliance drift detection | – | – | Yes |
| Automated evidence collection (CC6–CC9) | – | – | Yes |
| Corgi cyber-insurance partner CTA | – | Optional handoff | Built-in |
| AI credits / month | 3 credits | – | 200 credits |
| Billing model | Forever free | One-time Stripe Connect | Recurring Stripe subscription |
Compliance Gap Add-on (HIPAA / PCI-DSS) can be added to any $99 Assessment purchase — see /tools/compliance-gap-analysis for the tool page.
Pricing FAQ
Free gives you a 5-minute SOC 2 / NIST CSF self-assessment with a maturity score and high-level gap list — email-only, no payment. Assessment is the $99 framework gap analysis (one-time, Stripe Connect checkout): full CC1–CC9 / NIST CSF mapping, prioritized remediation roadmap, and a downloadable PDF. Audit-Ready is the $599/mo subscription tier that combines the Professional stack (SOC 2 Type I/II dashboard, evidence automation, unlimited domains) with the cyber-insurance partner CTA via Corgi so the post-audit insurance conversation runs on the same controls.
No — the tiers are independent. Most SMBs run the Free self-assessment first to find their maturity score, jump straight to Assessment ($99) if they want a one-shot framework gap report with PDF, and graduate to Audit-Ready ($599/mo) when they’re ready to engage an auditor and need continuous evidence collection. Each tier works on its own.
The $99 Assessment is the full Compliance Gap Analysis framework report — you answer ~10 minutes of structured questions across CC1–CC9 + Availability (SOC 2), the 6 NIST CSF Functions, or HIPAA Security Rule, and we produce a maturity score (0–100), a prioritized gap list, a control-to-CC mapping matrix, and a remediation roadmap. The deliverable is a board-ready PDF + on-screen interactive view you can share with leadership or your auditor.
The Audit-Ready tier is the CyberStackHub Professional subscription: everything in Starter ($299/mo) plus the SOC 2 Type I/II dashboard, 200 AI credits/month, unlimited domain monitoring, compliance drift detection, evidence-collection automation, and Slack support. It also unlocks the cyber-insurance partner CTA (Corgi) so you can pre-qualify for a policy using the same controls an insurer would audit.
Sprinto, Drata, and Vanta price in the $7K–$12K/year band for evidence automation, with an additional $25K–$60K CPA-firm audit fee on top — most SMBs’ first-year SOC 2 program runs $50K–$100K+. Defendify’s all-in-one stack is in the $4K–$8K/year band. CyberStackHub’s 3-tier model splits the journey so SMBs only pay for what they actually need: Free for the readiness score, $99 for the framework gap PDF, $599/mo for the Audit-Ready evidence-automation subscription.
CyberStackHub integrates with Corgi (a specialist SMB-focused insurance broker) for the post-assessment insurance conversation. After you complete the Assessment or Audit-Ready tier, the platform hands you off to a Corgi advisor who already has your maturity score + framework gap report. This means the insurance pre-qualification conversation runs on the same SOC 2 / NIST CSF controls you just produced — no redundant questionnaire, no second audit.
Yes — the $599/mo Professional plan is per-account with unlimited seats for the customer’s domain. If you manage security for multiple clients (an MSP/MSSP), contact hello@cyberstackhub.ai for MSP partner rates and volume pricing across 5+ client accounts.
Start With the Free SOC 2 / NIST CSF Self-Assessment
The Free tier routes to our existing free SMB security assessment page (no signup required) and our Cyber Pulse weekly intelligence newsletter. Enter your work email to score your maturity against CC1–CC9 + NIST CSF Functions in under 5 minutes, then receive the prioritized gap list by email — the same funnel the SOC 2 Checklist, NIST CSF Guide, and NIST vs SOC 2 pages now feed.
Get Your Free SOC 2 / NIST CSF Maturity Score
Email-only signup. No credit card. The maturity score is the same one the $99 Assessment PDF builds on — see whether you’re closer to “framework owner” or “framework-starter” before paying for a deeper gap analysis.
You can also skip directly to /assess for the full free self-assessment — same funnel, same maturity score.
Map the Tier to Your Buyer Stage
If you’re new to SOC 2 / NIST CSF, start with the Free self-assessment. If you already have a maturity score but need the framework gap PDF for an enterprise buyer, take the $99 Assessment. If you’re engaging an auditor, graduate to the $599/mo Audit-Ready subscription for the evidence automation + cyber-insurance partner CTA. The same three tools the SOC 2 Checklist, NIST CSF Guide, and NIST vs SOC 2 pages now feed through — pinned to the matching buyer stage.
Three Tiers. One Buyer Journey.
Start free. Pay once. Subscribe when you’re ready to engage an auditor.
Read the SOC 2 framework deep-dive at /soc-2-checklist · the NIST CSF framework deep-dive at /nist-csf-guide · the SOC 2 vs NIST CSF comparison at /nist-vs-soc2.