Pricing

Fixed price. In the open.

One offer: signed cryptographic evidence your assessor accepts, at a fixed price, in five business days. A manual 12.3.3 inventory is 3–5 days of QSA time at roughly $2,500 a day — unguaranteed, unsigned, and stale on delivery. This is faster, signed, and comes with a revision round if your assessor pushes back. The free scanner and public registry are the on-ramp, not the product. No quote-only games.

For teams · the core offer

For teams with a deadline — PCI 12.3.3 or federal.

↓ Preview a sample Evidence Report

PCI DSS Level 1 service providers · banks · regulated SaaS · QSA firms

Cryptographic Evidence Engagement

$15,000fixed price · 5 business days
  • Signed cryptographic inventory attestation — the artefact your assessor actually needs, not a scan result
  • CycloneDX 1.6 CBOM + confidence-scored negative statements (what we looked for and did not find, and how sure we are)
  • PCI DSS 4.0.1 Req 12.3.3 control mapping with QSA-ready language you can paste into the ROC
  • Every page stamped with engine version, rule-bundle version and bundle date — provenance is the point
  • One revision round included if your assessor pushes back
  • Priced against the alternative: 3–5 days of QSA time at ~$2,500/day, unguaranteed and unsigned

multi-repo estates · federal contractors · gov-facing ISVs · FedRAMP vendors

Complex / Federal Engagement

$22,000fixed price · 7–10 business days
  • Everything in the standard engagement, across multiple repositories and mixed language stacks
  • FIPS 140-2 → 140-3 module exposure map — what sweeps to the Historical List Sept 22, 2026, and the validated path per module
  • OMB M-23-02 nine-element cryptographic inventory export (CyberScope-shaped CSV)
  • OMB M-26-15 migration-plan skeleton, auto-filled from your scan — for agency data calls due from ~Oct 22, 2026
  • EO 14412 deadline mapping: PQC key establishment by Dec 31, 2030 · signatures by Dec 31, 2031
  • Get-ahead evidence for the proposed FAR contractor rule (proposed, Dec 19, 2026)

teams assessed annually who want the drift caught before the assessor finds it

Quarterly Evidence Retainer

$30,000per year · four engagements
  • Four engagements a year with guaranteed capacity during assessment season
  • Year-over-year diff: exactly what cryptography changed since your last submission
  • Priority scheduling — you are not queued behind spot work when your ROC date moves
  • Rush delivery available on any engagement (+$5,000 for 48-hour turnaround)
  • The cheapest way to stop treating 12.3.3 as an annual fire drill

For practitioners · the on-ramp

Free to start.

The free scanner and public registry are how teams discover CipherM — not the revenue. The Team tier is on early-access waitlist: an expansion path for champions who bring CipherM to their whole engineering org, not the focus. Assessors and air-gapped environments should look at CipherM Desktop. The Rapid Assessment is still the core offer.

OSS maintainers · students · solo developers

Open

$0forever
  • cipherm-scan CLI · 169 rules (classical + post-quantum)
  • cipherm-tls handshake validator
  • Public CBOM registry — upload, browse, diff
  • Threat Clock + Q-CBOM extension
  • CycloneDX 1.6 output, freely interoperable

engineering teams · security champions

Team

Early accesswaitlist · pricing at general availability
  • SSO (SAML / OIDC) for the whole team
  • Team dashboards across every repo
  • Historical scanning + drift detection
  • API access for CI/CD pipelines
  • Slack / Teams integration
  • Shared private CBOM workspace
or email founder@cipherm.io

FAQ

Is cipherm-scan really Apache-2.0?

The CLI scanner is Apache-2.0 and stays that way. The detection ruleset is proprietary — signed bundles, licensed for the term of your Desktop licence, and the reason the licence is annual. CipherM Desktop, the evidence pack, the registry and the hosted dashboard are proprietary too.

What's a Rapid Assessment, exactly?

A 2-week fixed-scope engagement. We run the scanner across your code and configs and manually review your TLS, cert, and cloud KMS posture. We deliver a CycloneDX 1.6 CBOM, executive summary PDF, compliance matrix per standard, and a prioritized migration playbook. One founder call per week during the engagement.

Who is the Federal PQC Readiness Assessment for?

Federal contractors and systems integrators facing agency data calls (agency PQC migration plans are due to OMB from ~Oct 22, 2026 under M-26-15), gov-facing ISVs and FedRAMP vendors who need FIPS 140-3 evidence after the Sept 22, 2026 Historical sweep, and MSPs/MSSPs who deliver compliance work to those clients. It is not for National Security Systems (the CNSA 2.0 lane) and it is evidence, not legal advice — the FAR contractor rule is a proposed rule, and this engagement is how you get ahead of it.

When is Enterprise actually available?

Year 2 (2027). Pre-traction we don't run a 6-12 month enterprise sales cycle. The Rapid Assessment is the bridge — if it goes well it converts to a multi-year Enterprise contract.

Is there a Team tier?

Yes — it's now in early access via waitlist, sitting between Open and the Rapid Assessment. Open captures distribution, and Team lets internal champions roll CipherM out to their whole engineering org (SSO, dashboards, drift, API, Slack/Teams). It's an expansion path, not the focus: the Rapid Assessment is still the core offer, and Team graduates from waitlist as champions pull it through procurement.

Do I need a domain to use the CLI?

No. cipherm-scan runs locally and emits CycloneDX JSON. The registry is one upload destination among many — your CBOM is yours.

What about students and OSS maintainers?

Open tier covers you forever. If you're maintaining a popular OSS project and want a verified CipherM-scanned badge for your README, email founder@cipherm.io.