Pricing

Straightforward pricing for both products

No per-asset surprises and no seat counting. OsintR is priced per root domain with unlimited subdomains underneath; OscalIQ is priced per system with unlimited users.

Verify to see pricing

One quick check and every figure on this page fills in. No email, no form.

OsintR

External attack surface discovery

Priced per root domain. Every subdomain we find underneath it is included - because charging you more for finding more is a strange way to sell a discovery tool.

Recon

1 root domain

••• / month

For a single product or brand you need watched continuously.

Request access
Most popular

Professional

5 root domains

••• / month

For a portfolio: multiple brands, acquisitions, or regional domains.

Request access

Agency

20 root domains

••• / month

For consultancies and MSSPs monitoring a book of clients.

Request access

Included in every OsintR plan

  • Unlimited subdomains · discovered under each root domain
  • Continuous discovery · with alerts when something new appears
  • Exposed paths · admin, debug, backup and version-control directories
  • Leaked secrets · credentials and API keys in JavaScript bundles and inline HTML
  • Technology fingerprinting · cross-referenced against CVE data
  • Host clustering · so mirrors collapse to the systems actually behind them
  • Shareable reports · read-only links you can hand to a stakeholder

Monitoring more than 20 domains, or need an on-premises deployment? Talk to us about Enterprise.

OscalIQ

FedRAMP, OSCAL and compliance-as-code

Priced per system - one authorization boundary, the same unit FedRAMP uses. Users are never metered, so your team, your consultants and your 3PAO all work in it at no extra cost.

Platform

FedRAMP core

••• / system / year

Billed annually · unlimited users

  • SSP conversion · legacy Word and Excel plans become machine-readable NIST OSCAL
  • FedRAMP 20x · Key Security Indicators with live readiness
  • POA&M management · track findings through to closure
  • Control authoring · NIST 800-53 Rev5 catalog, edited in place
  • OSCAL export and REST API · plus bring-your-own-AI assistance
  • Unlimited users · your team, your consultants and your 3PAO
Request access

Add-on modules

Add only what you need

CMMC 2.0 / NIST 800-171 · ••• / system / year

Assess Level 1 and Level 2 against all 110 NIST 800-171 requirements, with DoD SPRS scoring, POA&M eligibility, and a machine-readable export.

DISA STIG · ••• / system / year

Import XCCDF and CKL checklists or pull straight from the STIG library, migrate answers onto new releases, map CCIs to 800-53, and export .ckl or .cklb.

Scan parsing · ••• / system / year

Import Nessus and Qualys exports and keep every scan. Each finding carries host, port, service, CVSS and CVE detail. Severity analytics roll up across systems, and any finding becomes a POA&M item or a Jira issue in one click.

Modules are enabled per workspace and can be added or removed at renewal.

Not pursuing FedRAMP?

Both modules are sold on their own, without the FedRAMP platform, for the organizations that only need one of them.

CMMC only

••• per company / year

For defense contractors pursuing CMMC without a FedRAMP authorization. Unlimited users.

Request access

DISA STIG only

••• per system / year

For government programs assessing an enclave against STIGs, with no FedRAMP baseline required.

Request access

FAQ

Pricing questions, answered

Why does OsintR charge per domain instead of per asset?

Because per-asset billing punishes you for good discovery. Most attack surface tools count every subdomain they find as a billable asset, so the better the tool works, the more you pay - and you end up quietly hoping it finds less. We charge for the root domain and discover as much as exists underneath it.

What counts as a root domain?

A registrable domain such as example.com. Every subdomain found beneath it - however many - is included. If you own example.com, example.co.uk and examplecorp.com, that is three root domains.

What is a "system" in OscalIQ pricing?

One authorization boundary, the same unit FedRAMP itself uses. Most cloud providers have one to three. Users are not metered, so your whole compliance team, your consultants and your 3PAO can all work in it without changing the price.

Can I buy a module without the FedRAMP base?

Yes. CMMC and DISA STIG are both sold standalone for organizations that are not pursuing a FedRAMP authorization - a defense contractor working to 800-171, or a government program assessing an enclave against STIGs.

Is there a free trial or self-service signup?

No. Every engagement starts with a conversation and a scoped pilot, because both products need to be pointed at your real environment to be worth anything. We will run a one-off external exposure report on your domain at no cost so you can see what OsintR finds before you commit.

How is it billed?

By invoice, not by card. OsintR is billed at the listed monthly rate; OscalIQ is billed annually per system. Longer terms and multi-year agreements are worked out as part of the conversation.

See what we find before you decide

We will run a one-off external exposure report on your domain at no cost - the same discovery OsintR does continuously. If it shows you nothing you did not already know, we will say so.

Book a free exposure report