Pricing strategy
Living document · v1.1.0 · 2026-07-12. Every signed Customer Contract and Scope of Work inherits its commercial terms from this page. Update here first, then reference the new version in the SOW.
1. Core value metrics
NSO does not charge per seat — collaboration between engineering and security teams should never be gated. Pricing scales on two value metrics that grow with the customer:
- Monitored assets / domains — verified endpoints, root domains, and active webhook targets under continuous audit.
- Scan & assessment volume — cadence of the scanning engine (weekly, on-demand, or continuous post-deploy diffs).
2. Tiered packaging
- 10 monitored assets
- on demand scanning
Estimate only. The signed Scope of Work is authoritative.
| Line item | Qty / Rate | Amount |
|---|---|---|
| Base subscription | $299 – $599 / mo | $599/mo |
| Included assets | 25 | — |
| Overage assets | 0 | — |
| Overage packs (5 assets/pack) | 0 | $0/mo |
| Total monthly | — | $599/mo |
| Annual total | — | $7,188 |
CUSTOMER CONTRACT — SERVICE SCHEDULE (DRAFT) Customer: Customer, Inc. Generated: 2026-08-28 Source: NSO Pricing Estimator (living document) 1. Selected Tier Growth / Professional — $299 – $599 / mo 2. Scope of Monitoring • Monitored assets: 10 • Scan cadence: On-demand and post-deploy scans • Compliance framework exports are NOT included in this engagement. 3. Pricing Breakdown | Line item | Qty / Rate | Amount | | --- | --- | --- | | Base subscription | $299 – $599 / mo | $599/mo | | Included assets | 25 | — | | Overage assets | 0 | — | | Overage packs (5 assets/pack) | 0 | $0/mo | | **Total monthly** | — | **$599/mo** | | **Annual total** | — | **$7,188** | 4. Commercial Terms • Base subscription: $299 – $599 / mo • Billing cadence: Monthly, in advance. Net 15. • Term: 12 months, auto-renewing unless cancelled with 30 days' notice. 5. Deliverables • Access to the NSO platform for the 10 in-scope asset(s). • on-demand and post-deploy scans with findings triaged in the dashboard. • Verification audit log and platform audit log retention per Rules of Engagement. 6. Authoritative Documents This schedule is generated from the Pricing Strategy living document. The signed Scope of Work and Rules of Engagement remain authoritative in the event of any conflict.
Tier 1 — Starter / Developer
- Target: solo developers, early startups, asset-visibility trials.
- Price: $49 – $99 / month (restricted free tier available).
- Up to 3 verified assets/domains.
- Weekly automated network & vulnerability scans.
- Basic public API / healthcheck access.
- Standard webhook notifications (Slack / Discord).
Tier 2 — Growth / Professional
- Target: scaling teams, mid-market B2B platforms.
- Price: $299 – $599 / month.
- 25 – 50 verified assets/domains.
- Continuous / on-demand scanning with post-deploy scan diffs.
- Advanced webhook engine with mandatory HMAC signatures and
x-nso-timestampreplay protection. - Custom scan scheduling.
- Remediation workflow: assign findings, track status.
Tier 3 — Enterprise / Compliance
- Target: regulated companies, enterprise engineering, MSP/agencies.
- Price: from $1,200 / month, custom annual contracts.
- High-volume or unlimited asset brackets.
- Compliance module: NIST, CIS, SOC 2 mappings + audit-ready CSV/JSON exports.
- Multi-tenant workspaces for auditing external clients.
- Priority API rate limits, long-term vulnerability retention.
- SAML / SSO account security.
3. Strategic add-ons (expansion revenue)
- Overage asset packs — bundles of +5 domains for $30 / month on top of the tier limit.
- Dedicated webhook targets — high-throughput event-streaming pipelines billed per target.
- Verification-retry fees — itemized per Customer Contract §4 and surfaced in /settings/verification-audit.
- Compliance framework add-ons — additional frameworks beyond the tier baseline (HIPAA, PCI-DSS, ISO 27001).
4. Contract mapping
Every signed Customer Contract selects one tier and lists the chosen add-ons on its Scope of Work. Because both are living documents, mid-term upgrades (extra assets, added frameworks) are handled by amending the SOW and bumping its version in the changelog — no full re-signature required for non-material changes.
5. Pros, cons, and counter-strategy
Pros
- Expansion built in. As customers launch new microservices or client portals, their asset count naturally pushes them into higher-revenue brackets.
- Aligned with maturity. Startups pay a fair entry price; enterprises pay premium rates only when SOC 2 / NIST compliance becomes existential.
Cons
- Perceived stagnation risk. A green dashboard for months can feel like no value.
- Counter-strategy. Continuous telemetry digests (“perimeter remains secure”) and monthly posture summaries reinforce ongoing value even when zero new findings surface.
6. Change control (living document)
Price-point changes, tier renames, or new add-ons are versioned in the changelog. Existing contracts retain the pricing version referenced on their SOW until renewal.