Skip to content
Partner Programme

Build a governance practice on rules that keep moving.

MSPs, MSSPs, vCISOs and audit firms use Vivid Risk to run NIS2, DORA and ISO 27001 engagements across a fleet of clients. You keep the advisory relationship and the remediation fees; we are the assessment, quantification and reporting layer underneath.

What you actually get

Every item below is something you can open on the day you are approved.

A multi-tenant client console

Each client workspace is isolated from every other by database security rules, not by a filter in the interface. Onboard them one at a time or by CSV import.

Vivid Discovery

A 66-node pre-sales framework for scoping an engagement before you quote it, with your answers saved per client.

The cross-mapper

Retrieval-grounded: it finds the matching text in a client’s own evidence and drafts the coverage argument across NIS2, ISO 27001, DORA and NIST CSF 2.0 for your review.

A real FAIR Monte Carlo

Ten thousand iterations over a loss distribution, not a five-by-five colour grid. Tying it directly to remediation spend is on the roadmap.

Your logo on the report

Assessment reports your clients receive carry your branding. The engagement is yours; we are the tooling underneath it.

Commission accrual you can audit

Computed from your referred clients’ actual subscription payments, itemised per client, rather than a figure we assert at the end of the month.

What is not built

You are going to resell this. You should know where it stops before you promise anything to a client, not after.

  • Connectors to Microsoft 365, Entra, AWS or anything else — evidence is recorded, never harvested
  • Automated evidence collection of any kind
  • Evidence file storage — the vault holds metadata, and you keep the documents
  • Cryptographic tamper-evidence on vault artifacts
  • No practitioner certification, accreditation course, or demonstration tenant
  • No pitch decks, battlecards or downloadable sales-enablement pack
  • A public API for syncing clients with your PSA or GRC tooling
  • Single sign-on, SCIM, or wholesale partner billing

Commercial tiers

Four relationships, by depth rather than by size. Every figure on this page is read out of the same constants the billing and the client caps use.

Entry • Referral Access

Registered Partner

Independent auditors, solo consultants, and advisory firms testing the channel before committing capital.

€0/month15%
Earns
15% recurring commission on every referred client's subscription, paid monthly for the lifetime of that client.
Clients
Unlimited referrals
Billing
Vivid Risk direct to client
Branding
None (Direct Vivid Risk client relationship)
Support
Standard partner email support
Commitment
Month-to-month (No minimum commitment)
  • €0 Tooling Fee — Zero capital outlay
  • 15% Recurring Commission for life of referred clients
  • Vivid Risk handles 100% of client invoicing & collections
  • Unique partner referral tracking link & promo codes
  • Live commission accrual & payout dashboard
  • Unlimited client referrals
  • Standard partner onboarding & documentation
Growth • Practice Builder

Certified Partner

Growing MSPs and boutique consultancies building a repeatable, high-margin cybersecurity and compliance practice.

€199/month20%
Earns
20% recurring commission, paid monthly as long as clients remain active on Vivid Risk plans.
Clients
Up to 15 active managed clients
Billing
Vivid Risk direct to client
Branding
Co-Branded (Partner logo alongside Vivid Risk on PDF reports & client exports)
Support
Standard Partner Portal priority queue
Commitment
Month-to-month flexible
  • €199/mo Fixed Tooling Fee for portal & fleet infrastructure
  • 20% Recurring Commission on all managed client subscriptions
  • Vivid Risk bills client directly — zero billing receivables risk
  • Full Multi-Tenant Partner Console & client workspace switching
  • Co-branded audit exports (Your logo + Vivid Risk)
  • Up to 15 active managed client entities
  • Bulk client onboarding & intake automation
  • Client compliance progress & evidence decay tracking
Scale • High-Volume Practice

Strategic Partner

Established MSSPs, vCISO advisory firms, and audit practices running continuous, multi-client compliance programs.

€699/month25%
Earns
25% recurring commission on every managed client's subscription (Vivid Risk bills the client directly at standard retail -- wholesale/partner-set client pricing is not yet built).
Clients
Up to 75 active managed clients
Billing
Vivid Risk direct to client
Branding
Partner-Primary ("Powered by Vivid Risk" reduced to a small, discreet footer credit -- your logo and name lead everywhere a client sees the product)
Support
A named contact who answers you directly, not a shared queue
Commitment
12-Month commitment
  • €699/mo Tooling Fee for high-throughput fleet management
  • 25% Recurring Commission on all managed client subscriptions
  • Vivid Risk bills client directly — zero billing receivables risk
  • Up to 75 active managed client entities
  • Partner-Primary Branding ("Powered by Vivid Risk" discreet footer credit)
  • Dedicated Partner Success Manager & quarterly cadence
  • Early Roadmap & Pre-Release Engine Beta access
  • Multi-cloud telemetry & automated compliance cross-mapping
Enterprise • Global Fleet

Alliance Partner

National/global MSSP networks, Big 4-adjacent advisory arms, and national audit alliances.

Custom/month30%
Earns
30%+ negotiated recurring commission, scaling dynamically with committed client volume (Vivid Risk bills the client directly at standard retail -- wholesale/partner-set client pricing is not yet built).
Clients
Unlimited (subject to commitment terms)
Billing
Vivid Risk direct to client
Branding
Full White-Label (100% partner-branded; the "Powered by Vivid Risk" credit is omitted entirely from every export)
Support
A named contact who answers you directly, plus a scheduled review
Commitment
Custom annual volume agreement
  • Custom Tooling Fee with minimum annual volume commitment
  • 30%+ Negotiated Recurring Commission scaling with portfolio size
  • 100% White-Label: the "Powered by Vivid Risk" credit is omitted entirely from every export
  • Unlimited managed client workspaces & fleets
  • Custom SSO, SAML 2.0, & a general Enterprise API (roadmap -- not yet built)
  • Dedicated Customer Success Manager (CSM) & Engineering Pod
  • Board-level strategic governance sync & executive briefings
  • Co-marketing funds, joint PR, and featured Marketplace placement

The managed-client caps are enforced by database security rules, not shown as a number and ignored: onboarding past your cap is refused row by row on import. A tier is a real limit rather than a line on a page.

The questions partners actually ask

What direct co-selling and technical enablement support do partners receive?

Support is by email at support@vividrisk.ai, answered by the team that builds the product. We will join a client call with you where it helps, and we would rather you ask than not. What we do not have is a staffed partner-enablement function: there is no assigned Partner Alliance Manager, no Solution Engineering bench, and no standing commitment to attend a set number of your client presentations. We would rather tell you the size of the company you are partnering with than have you discover it on your second deal.

How long does partner onboarding and practitioner certification take?

Applications are reviewed by a person, not by an automated check, so we will not quote you a turnaround we cannot hold to — we aim to come back within two working days. Once your practice is approved you have the full partner console immediately and can onboard your first client straight away; the product is the training, and there is no course to sit first. To be plain about one thing: there is no Vivid Risk Practitioner certification. A self-paced practitioner assessment is a commercial proposal we have written down and not yet decided on, and until it exists the Certified tier is a commercial tier rather than a statement that anyone has passed anything.

How does cross-framework evidence mapping reduce duplicate audit preparation?

The cross-mapper covers NIS 2, ISO/IEC 27001:2022, DORA and NIST CSF 2.0 today. For each control it finds the real matching text in your client’s own evidence and hands that to the model to judge, so one artifact can suggest coverage across several frameworks at once. Every suggested match is a draft for your review, not an automatic satisfaction of the control.

Is the evidence vault usable for official audits?

For organising and presenting evidence, yes — the vault gives auditors structured, exportable documentation with real upload timestamps and audit tags. Cryptographic hashing and a tamper-evident chain of custody are on the roadmap and not built, so we do not claim cryptographic non-repudiation today. Evidence file content is not stored at all: the vault records metadata, and you keep your own copy of every document.

Can we use Vivid Risk to provide EU AI Act advisory services?

Not yet, and we removed those claims from every live surface rather than leave partners selling them. AI system inventories, high-risk classification and conformity-assessment workflows are specified and not built. We hold the verified primary regulation text, so this is no longer blocked on sourcing; we are holding until the EU AI Office publishes the Fundamental Rights Impact Assessment template Article 27(5) requires, rather than shipping our own version that could diverge from it.

Does the platform connect to my clients’ systems?

No. There are no OAuth connectors, no agents and no automated evidence collection — a claim you will see on most tools in this category and will not see here. Evidence is what you and your client record. That is the honest limit of the product, and it is why we sell it as a decision and reporting engine rather than as compliance automation.

Start with one client.

Run an assessment against your own practice first, then a pilot client. If it does not earn its place in your engagement, you will know inside a week.