← Help

Billing Guide

Free vs. Pro, how billing actually works, and how to add GRC, Vendor Security, or Training.

Free vs. Pro

FreePro
Up to 2 domainsUnlimited domains
Up to 2 public IPv4 addresses; 1 scan per IP every 24 hours, schedulableUp to 25 public IPv4 addresses; on-demand scans, daily schedule, branded CSV/PDF export, CISA.gov KEV correlation
1 projectUp to 10 projects
Manual "Scan now" only, 1 scan per domain per dayAutomatic daily scanning
TLS valid / invalid on each domainCertificate inventory: issuer, expiry, days remaining
Score and critical-count tiles onlyDashboard analysis: Critical / High / Medium counts and production risk ratings
Overdue-finding emails onlyDaily or weekly digest: new findings, score change, TLS/WHOIS expiry, new subdomains
Latest scan only90-day scan history and last-vs-now score
Core DNS, SPF, DMARC, and TLS checksExtra checks: CAA, DKIM, MTA-STS, DNSSEC, HTTPS redirect, and more
No webhooks or API keysSlack / Teams / generic webhooks and read-only API keys
Due dates on findings, no reminder emailsOverdue reminder emails and unassigned overdue digest
Subdomains are always free and unlimited on both plans, and don't count against the domain limit.

How billing actually works

Plans aren't billed through a self-serve checkout. A CyberEnforced staff member sets your organization's plan directly after you've been invoiced outside the app. There's no card entry or subscription page inside the product itself.

Published list prices

Working quote prices: Pro $29/mo (or $290/yr), GRC $49 / $99 / $179/mo by framework count, Vendor Security $19/mo, Training $19/mo for up to 10 seats then $2/seat, or the Compliance Suite at $229/mo. See pricing for the full breakdown.

Adding GRC, Vendor Security, or Training

These are add-on products, sold and enabled by your account manager, not self-serve. If you don't see one you need in your sidebar, reach out via Contact us and they'll get it set up.

Billing Guide | CyberEnforced