Pricing strategy

Living document · v1.1.0 · 2026-07-12. Every signed Customer Contract and Scope of Work inherits its commercial terms from this page. Update here first, then reference the new version in the SOW.

1. Core value metrics

NSO does not charge per seat — collaboration between engineering and security teams should never be gated. Pricing scales on two value metrics that grow with the customer:

  • Monitored assets / domains — verified endpoints, root domains, and active webhook targets under continuous audit.
  • Scan & assessment volume — cadence of the scanning engine (weekly, on-demand, or continuous post-deploy diffs).

2. Tiered packaging

Suggested tier
Growth / Professional
$299 – $599 / mo
  • 10 monitored assets
  • on demand scanning

Estimate only. The signed Scope of Work is authoritative.

Draft Customer Contract section
Generated from your inputs. Paste into the Customer Contract living doc.
Line itemQty / RateAmount
Base subscription$299 – $599 / mo$599/mo
Included assets25
Overage assets0
Overage packs (5 assets/pack)0$0/mo
Total monthly$599/mo
Annual total$7,188
CUSTOMER CONTRACT — SERVICE SCHEDULE (DRAFT)
Customer: Customer, Inc.
Generated: 2026-08-28
Source: NSO Pricing Estimator (living document)

1. Selected Tier
   Growth / Professional — $299 – $599 / mo

2. Scope of Monitoring
   • Monitored assets: 10
   • Scan cadence: On-demand and post-deploy scans
   • Compliance framework exports are NOT included in this engagement.

3. Pricing Breakdown
   | Line item | Qty / Rate | Amount |
   | --- | --- | --- |
   | Base subscription | $299 – $599 / mo | $599/mo |
   | Included assets | 25 | — |
   | Overage assets | 0 | — |
   | Overage packs (5 assets/pack) | 0 | $0/mo |
   | **Total monthly** | — | **$599/mo** |
   | **Annual total** | — | **$7,188** |

4. Commercial Terms
   • Base subscription: $299 – $599 / mo
   • Billing cadence: Monthly, in advance. Net 15.
   • Term: 12 months, auto-renewing unless cancelled with 30 days' notice.

5. Deliverables
   • Access to the NSO platform for the 10 in-scope asset(s).
   • on-demand and post-deploy scans with findings triaged in the dashboard.
   • Verification audit log and platform audit log retention per Rules of Engagement.

6. Authoritative Documents
   This schedule is generated from the Pricing Strategy living document. The
   signed Scope of Work and Rules of Engagement remain authoritative in the
   event of any conflict.

Tier 1 — Starter / Developer

  • Target: solo developers, early startups, asset-visibility trials.
  • Price: $49 – $99 / month (restricted free tier available).
  • Up to 3 verified assets/domains.
  • Weekly automated network & vulnerability scans.
  • Basic public API / healthcheck access.
  • Standard webhook notifications (Slack / Discord).

Tier 2 — Growth / Professional

  • Target: scaling teams, mid-market B2B platforms.
  • Price: $299 – $599 / month.
  • 25 – 50 verified assets/domains.
  • Continuous / on-demand scanning with post-deploy scan diffs.
  • Advanced webhook engine with mandatory HMAC signatures and x-nso-timestamp replay protection.
  • Custom scan scheduling.
  • Remediation workflow: assign findings, track status.

Tier 3 — Enterprise / Compliance

  • Target: regulated companies, enterprise engineering, MSP/agencies.
  • Price: from $1,200 / month, custom annual contracts.
  • High-volume or unlimited asset brackets.
  • Compliance module: NIST, CIS, SOC 2 mappings + audit-ready CSV/JSON exports.
  • Multi-tenant workspaces for auditing external clients.
  • Priority API rate limits, long-term vulnerability retention.
  • SAML / SSO account security.

3. Strategic add-ons (expansion revenue)

  • Overage asset packs — bundles of +5 domains for $30 / month on top of the tier limit.
  • Dedicated webhook targets — high-throughput event-streaming pipelines billed per target.
  • Verification-retry fees — itemized per Customer Contract §4 and surfaced in /settings/verification-audit.
  • Compliance framework add-ons — additional frameworks beyond the tier baseline (HIPAA, PCI-DSS, ISO 27001).

4. Contract mapping

Every signed Customer Contract selects one tier and lists the chosen add-ons on its Scope of Work. Because both are living documents, mid-term upgrades (extra assets, added frameworks) are handled by amending the SOW and bumping its version in the changelog — no full re-signature required for non-material changes.

5. Pros, cons, and counter-strategy

Pros

  • Expansion built in. As customers launch new microservices or client portals, their asset count naturally pushes them into higher-revenue brackets.
  • Aligned with maturity. Startups pay a fair entry price; enterprises pay premium rates only when SOC 2 / NIST compliance becomes existential.

Cons

  • Perceived stagnation risk. A green dashboard for months can feel like no value.
  • Counter-strategy. Continuous telemetry digests (“perimeter remains secure”) and monthly posture summaries reinforce ongoing value even when zero new findings surface.

6. Change control (living document)

Price-point changes, tier renames, or new add-ons are versioned in the changelog. Existing contracts retain the pricing version referenced on their SOW until renewal.