One offer: signed cryptographic evidence your assessor accepts, at a fixed price, in five business days. A manual 12.3.3 inventory is 3–5 days of QSA time at roughly $2,500 a day — unguaranteed, unsigned, and stale on delivery. This is faster, signed, and comes with a revision round if your assessor pushes back. The free scanner and public registry are the on-ramp, not the product. No quote-only games.
For teams · the core offer
↓ Preview a sample Evidence Report
PCI DSS Level 1 service providers · banks · regulated SaaS · QSA firms
multi-repo estates · federal contractors · gov-facing ISVs · FedRAMP vendors
teams assessed annually who want the drift caught before the assessor finds it
For practitioners · the on-ramp
The free scanner and public registry are how teams discover CipherM — not the revenue. The Team tier is on early-access waitlist: an expansion path for champions who bring CipherM to their whole engineering org, not the focus. Assessors and air-gapped environments should look at CipherM Desktop. The Rapid Assessment is still the core offer.
OSS maintainers · students · solo developers
engineering teams · security champions
Is cipherm-scan really Apache-2.0?
The CLI scanner is Apache-2.0 and stays that way. The detection ruleset is proprietary — signed bundles, licensed for the term of your Desktop licence, and the reason the licence is annual. CipherM Desktop, the evidence pack, the registry and the hosted dashboard are proprietary too.
What's a Rapid Assessment, exactly?
A 2-week fixed-scope engagement. We run the scanner across your code and configs and manually review your TLS, cert, and cloud KMS posture. We deliver a CycloneDX 1.6 CBOM, executive summary PDF, compliance matrix per standard, and a prioritized migration playbook. One founder call per week during the engagement.
Who is the Federal PQC Readiness Assessment for?
Federal contractors and systems integrators facing agency data calls (agency PQC migration plans are due to OMB from ~Oct 22, 2026 under M-26-15), gov-facing ISVs and FedRAMP vendors who need FIPS 140-3 evidence after the Sept 22, 2026 Historical sweep, and MSPs/MSSPs who deliver compliance work to those clients. It is not for National Security Systems (the CNSA 2.0 lane) and it is evidence, not legal advice — the FAR contractor rule is a proposed rule, and this engagement is how you get ahead of it.
When is Enterprise actually available?
Year 2 (2027). Pre-traction we don't run a 6-12 month enterprise sales cycle. The Rapid Assessment is the bridge — if it goes well it converts to a multi-year Enterprise contract.
Is there a Team tier?
Yes — it's now in early access via waitlist, sitting between Open and the Rapid Assessment. Open captures distribution, and Team lets internal champions roll CipherM out to their whole engineering org (SSO, dashboards, drift, API, Slack/Teams). It's an expansion path, not the focus: the Rapid Assessment is still the core offer, and Team graduates from waitlist as champions pull it through procurement.
Do I need a domain to use the CLI?
No. cipherm-scan runs locally and emits CycloneDX JSON. The registry is one upload destination among many — your CBOM is yours.
What about students and OSS maintainers?
Open tier covers you forever. If you're maintaining a popular OSS project and want a verified CipherM-scanned badge for your README, email founder@cipherm.io.