SOC 2 & NIST CSF READINESS · UPDATED JULY 2026

Three Tiers for the SOC 2 / NIST CSF Readiness Journey.
Free → Assessment → Audit-Ready.

Whether you’re at the start of your SOC 2 conversation, mid-readiness with a framework gap report, or already engaging an auditor, CyberStackHub has a tier built for that exact step. The same Stripe Connect checkout as our per-report tools — no separate billing system, no enterprise sales calls.

📅 July 31, 2026 📊 3 tiers · Free / $99 one-time / $599/mo 👥 SMBs 5–500 employees entering the SOC 2 conversation
Free
SOC 2 / NIST CSF self-assessment + maturity score
No email signup required
$99
Framework Gap Analysis — one-time Stripe Connect checkout
Same path as Compliance Gap, Security Audit
$599/mo
Audit-Ready subscription — Professional stack + cyber-insurance CTA
Corgi insurance partner integration
80%
Less than Sprinto / Drata / Vanta SOC 2 first-year cost
AICPA SMB benchmarks
Tiers

Free → Assessment → Audit-Ready

Each tier feeds the next: the Free self-assessment gives you a maturity score, the $99 Assessment produces the framework gap PDF the auditor will ask for, and the $599/mo Audit-Ready subscription gives you the evidence-automation + cyber-insurance partner pre-qualification that closes the loop on a real SOC 2 program.

Free
SOC 2 / NIST CSF self-assessment teaser + email capture into the existing funnel.
$0 forever free
No credit card · No signup
  • 5-minute SOC 2 / NIST CSF maturity score
  • Top 5 prioritized CC1–CC9 gap list
  • SOC 2 / NIST CSF framework reference
  • Breach detection lookup + email funnel
  • CyberStackHub Cyber Pulse weekly brief signup
  • Full framework gap PDF
  • CC-by-CC detailed mapping
  • Audit-ready evidence automation
Start Free Assessment →
Routes to /assess self-assessment & email capture
Audit-Ready
Premium subscription tier with Corgi CTA for live audit prep + post-audit insurance handoff.
$599 / month
Professional subscription · Stripe recurring
  • Everything in the Starter tier ($299/mo)
  • 200 AI credits / month
  • SOC 2 Type I/II dashboard
  • Compliance drift detection
  • Automated evidence collection (CC6-CC9 coverage)
  • Unlimited domain monitoring
  • Email + Slack support
  • Corgi cyber-insurance partner CTA post-audit
Get Audit-Ready — $599/mo →
Compare Tiers

Free vs Assessment vs Audit-Ready — Side by Side

If you’re not sure which tier you need, the table below maps each tier to what it actually produces. Most SMBs start with the Free self-assessment, pay $99 for the Assessment PDF before engaging an auditor, and graduate to Audit-Ready for the post-engagement evidence automation.

Feature Free Assessment — $99 Audit-Ready — $599/mo
SOC 2 / NIST CSF maturity score Yes — top-5 gaps Yes — full CC1–CC9 Yes — continuous
Framework control mapping (CC1–CC9 detail) Full Full
PDF deliverable (yours to keep) Board-ready PDF All reports
NIST CSF 6-Function crosswalk Yes Yes
HIPAA / PCI-DSS gap analysis Add-on available Included
Domain monitoring 1 domain / week Unlimited
Cyber Pulse weekly intelligence brief Signup Included
Email support Receipt + post-purchase Priority + Slack
SOC 2 Type I/II dashboard Yes
Compliance drift detection Yes
Automated evidence collection (CC6–CC9) Yes
Corgi cyber-insurance partner CTA Optional handoff Built-in
AI credits / month 3 credits 200 credits
Billing model Forever free One-time Stripe Connect Recurring Stripe subscription

Compliance Gap Add-on (HIPAA / PCI-DSS) can be added to any $99 Assessment purchase — see /tools/compliance-gap-analysis for the tool page.

FAQ

Pricing FAQ

Free gives you a 5-minute SOC 2 / NIST CSF self-assessment with a maturity score and high-level gap list — email-only, no payment. Assessment is the $99 framework gap analysis (one-time, Stripe Connect checkout): full CC1–CC9 / NIST CSF mapping, prioritized remediation roadmap, and a downloadable PDF. Audit-Ready is the $599/mo subscription tier that combines the Professional stack (SOC 2 Type I/II dashboard, evidence automation, unlimited domains) with the cyber-insurance partner CTA via Corgi so the post-audit insurance conversation runs on the same controls.

No — the tiers are independent. Most SMBs run the Free self-assessment first to find their maturity score, jump straight to Assessment ($99) if they want a one-shot framework gap report with PDF, and graduate to Audit-Ready ($599/mo) when they’re ready to engage an auditor and need continuous evidence collection. Each tier works on its own.

The $99 Assessment is the full Compliance Gap Analysis framework report — you answer ~10 minutes of structured questions across CC1–CC9 + Availability (SOC 2), the 6 NIST CSF Functions, or HIPAA Security Rule, and we produce a maturity score (0–100), a prioritized gap list, a control-to-CC mapping matrix, and a remediation roadmap. The deliverable is a board-ready PDF + on-screen interactive view you can share with leadership or your auditor.

The Audit-Ready tier is the CyberStackHub Professional subscription: everything in Starter ($299/mo) plus the SOC 2 Type I/II dashboard, 200 AI credits/month, unlimited domain monitoring, compliance drift detection, evidence-collection automation, and Slack support. It also unlocks the cyber-insurance partner CTA (Corgi) so you can pre-qualify for a policy using the same controls an insurer would audit.

Sprinto, Drata, and Vanta price in the $7K–$12K/year band for evidence automation, with an additional $25K–$60K CPA-firm audit fee on top — most SMBs’ first-year SOC 2 program runs $50K–$100K+. Defendify’s all-in-one stack is in the $4K–$8K/year band. CyberStackHub’s 3-tier model splits the journey so SMBs only pay for what they actually need: Free for the readiness score, $99 for the framework gap PDF, $599/mo for the Audit-Ready evidence-automation subscription.

CyberStackHub integrates with Corgi (a specialist SMB-focused insurance broker) for the post-assessment insurance conversation. After you complete the Assessment or Audit-Ready tier, the platform hands you off to a Corgi advisor who already has your maturity score + framework gap report. This means the insurance pre-qualification conversation runs on the same SOC 2 / NIST CSF controls you just produced — no redundant questionnaire, no second audit.

Yes — the $599/mo Professional plan is per-account with unlimited seats for the customer’s domain. If you manage security for multiple clients (an MSP/MSSP), contact hello@cyberstackhub.ai for MSP partner rates and volume pricing across 5+ client accounts.

Free Tier Funnel

Start With the Free SOC 2 / NIST CSF Self-Assessment

The Free tier routes to our existing free SMB security assessment page (no signup required) and our Cyber Pulse weekly intelligence newsletter. Enter your work email to score your maturity against CC1–CC9 + NIST CSF Functions in under 5 minutes, then receive the prioritized gap list by email — the same funnel the SOC 2 Checklist, NIST CSF Guide, and NIST vs SOC 2 pages now feed.

Get Your Free SOC 2 / NIST CSF Maturity Score

Email-only signup. No credit card. The maturity score is the same one the $99 Assessment PDF builds on — see whether you’re closer to “framework owner” or “framework-starter” before paying for a deeper gap analysis.

You can also skip directly to /assess for the full free self-assessment — same funnel, same maturity score.

Next Steps

Map the Tier to Your Buyer Stage

If you’re new to SOC 2 / NIST CSF, start with the Free self-assessment. If you already have a maturity score but need the framework gap PDF for an enterprise buyer, take the $99 Assessment. If you’re engaging an auditor, graduate to the $599/mo Audit-Ready subscription for the evidence automation + cyber-insurance partner CTA. The same three tools the SOC 2 Checklist, NIST CSF Guide, and NIST vs SOC 2 pages now feed through — pinned to the matching buyer stage.

Three Tiers. One Buyer Journey.

Start free. Pay once. Subscribe when you’re ready to engage an auditor.

Read the SOC 2 framework deep-dive at /soc-2-checklist · the NIST CSF framework deep-dive at /nist-csf-guide · the SOC 2 vs NIST CSF comparison at /nist-vs-soc2.