Skip to content
Organization Pricing

Scale Your Compliance with Confidence

From boutique startups to global enterprises, we provide the technical assurance you need to navigate NIS2, DORA, NIST CSF 2.0, and ISO 27001.

Billing cycle
Tier 1 · Assessment

Assessment

€749/one-time

One-time — no recurring charge

One complete, framework-mapped self-assessment with a full gap analysis — for organizations that need a rigorous baseline, not a subscription.

Select Plan

ForOrganizations that need one thorough, defensible self-assessment ahead of an ISO 27001, NIS2, or DORA review.

Core Benefits
  • One complete self-assessment — Vivid Maturity Index scoring (ENG-01)
  • Full findings report with a prioritized remediation roadmap across NIS2, ISO 27001, DORA & NIST CSF (ENG-04) — not a truncated summary
  • Audit-Readiness Agent (Vigilance-1, AGT-01) — an AI-generated narrative summary of those findings, on request, on top of the full report above
  • PDF export with a tamper-evident HMAC-SHA256 report chain link (ENG-08), plus a standalone Cryptographic Proof Bundle Export (JSON) of that same chain data
The engines behind this plan
Engines2 Core Engines (ENG-01, ENG-04)
Agents1 Domain Agent (AGT-01)
Why choose this

Gain a rigorous, framework-mapped self-assessment with AI-augmented findings and a thorough gap analysis you can act on immediately.

Recommended Core
Tier 2 · Compliance Workspace

Compliance Workspace

€499/month
€499€414/month

or €4,968/yr billed annually (~17% off)

Billed annually at €4,968/yr (~17% off)

Ongoing compliance work: unlimited re-assessments, AI-assisted cross-mapping, an unlimited incident register, and a vendor registry.

Select PlanSelect Plan

ForSMEs and scale-ups with ongoing NIS2, DORA & ISO 27001 compliance work and evolving tech stacks.

Core Benefits
  • Everything in Tier 1
  • Unlimited re-assessments
  • AI-augmented cross-mapping (ENG-04)
  • Incident register — unlimited, on every tier (ENG-06, NIS2 Art. 23 guidance)
  • Vendor registry — capped at 35 records (ENG-07, flat registry, not a 4th-party graph)
8 more capabilities, with their limits
  • FAIR Monte Carlo loss simulation (10,000 iterations) + exact 0/1 knapsack remediation-spend optimizer (ENG-03 + ENG-09)
  • Continuous evidence freshness decay engine (ENG-02) — ~0.1%/hr exponential decay, 28.8-day half-life
  • Tenant-scoped HMAC-SHA256 report & evidence chain (ENG-08) — tamper-evident linear chain, not a Merkle tree
  • Vulnerability Lifecycle Hub — manually logged, CVSS-sorted triage via Sherlock-6 (AGT-06)
  • 3 more AI narrative agents: risk prioritization (Sentinel-2), incidents (Guardian-3), vendors (Ecosystem-5)
  • Continuity of Assurance: a tenant-authenticated webhook endpoint for GCP/Azure/AWS security telemetry — every accepted event is chained into your tamper-evident report/evidence record (ENG-08), and can reset a referenced control’s evidence freshness clock (ENG-02) without a manual re-upload
  • CRA Article 14 reporting register (ENG-11) — a private 24h/72h/final-report clock for actively exploited vulnerabilities and severe incidents in products you place on the EU market. Shown only if you tell us you are a CRA manufacturer. It files nothing: no ENISA connection, no Single Reporting Platform integration, no automated submission
  • DORA Register of Information (ENG-12) — exports 4 of the register’s 15 templates as plain CSV from your vendor registry. A data-preparation aid, not an xBRL-CSV submission, and not filable with the Central Bank of Ireland. Shown only if you select DORA oversight. Column codes follow Annex I as corrected by the 19.9.2025 corrigendum
Engines10 Live Engines (ENG-01, ENG-02, ENG-03, ENG-04, ENG-06, ENG-07, ENG-08, ENG-09, ENG-11, ENG-12)
Agents5 Domain Agents (AGT-01, AGT-02, AGT-03, AGT-05, AGT-06)
Why choose this

Compliance isn't a one-off. This plan adds unlimited re-assessments, AI-assisted cross-mapping, and vendor tracking to your Tier 1 baseline.

Coming Soon — Not Yet Live
  • EU AI Act Governance Engine (ENG-05) — held for the AI Office's official Art. 27 FRIA questionnaire
  • Multi-Cloud Asset & Policy Ingestion (AWS/GCP/Azure)
Tier 3 · Team

Team

€1,099/month
€1,099€879/month

or €10,548/yr billed annually (20% off)

Billed annually at €10,548/yr (20% off)

Everything in Compliance Workspace, with an unlimited vendor registry, priority support, and a dedicated enterprise SLA.

Select PlanSelect Plan

ForLarger teams and organizations with a growing third-party footprint and dedicated compliance staff.

Core Benefits
  • Everything in Tier 2 — Team adds no separate engine or agent of its own
  • Vendor registry — unlimited
  • Priority support (tickets automatically routed High-priority)
  • Dedicated enterprise SLA
  • First access to new capabilities as they're built and verified — never sold as included before they exist
The engines behind this plan
EnginesSame 10 Live Engines as Tier 2
AgentsSame 5 Domain Agents as Tier 2
Why choose this

Unlimited vendor tracking and priority support on top of the same engines every tier runs on — roadmap capabilities are clearly marked and never sold as included before they're built.

Coming Soon — Not Yet Live
  • EU AI Act Governance Engine (ENG-05) — held for the AI Office's official Art. 27 FRIA questionnaire
  • DSA Compliance Agent — Archon-7 (AGT-07)
  • Multi-Agent Coordinator — Synthesizer-8 (AGT-08)
  • WebAssembly High-Density Graph Offload — 2,000-node Barnes-Hut SIMD (ENG-10)
  • Multi-Cloud Asset & Policy Ingestion (AWS/GCP/Azure)

Are you an MSP, MSSP, or Advisory Firm?

Explore multi-tenant portal tooling and 15%–30%+ recurring commission tiers in our dedicated Partner Ecosystem.

Partner Pricing
What You're Actually Buying

Every Engine & Agent, By Tier

No feature here is sold before it's built. Each card below is either live today, at the tier shown, or clearly marked as roadmap — never both.

Tier 1 · Assessment

  • ENG-01Live

    Vivid Maturity Index (VMI) & Severe Gap Penalty Engine

    Computes your maturity score from your questionnaire answers, minus a penalty for the share of severe and moderate controls that came back as gaps — a severe miss costs about three times a moderate one and can’t be diluted by unrelated "Yes" answers. 113 of the 118 questions carry a scored control; the other 5 are profile and history questions that record your situation rather than a control, and are excluded deliberately.

    NIS2 Art. 21(1)-(2): scores the risk-management measures the Article requires
  • ENG-04Live

    Multi-Framework Cross-Mapping Engine

    Gemini-assisted mapping of your evidence against NIS2, ISO 27001, DORA & NIST CSF citations. AI-generated draft output — review before relying on it for an audit.

    No single mandate — maps evidence toward NIS2 & DORA citations (ISO 27001/NIST CSF are voluntary standards, not statutory)
  • AGT-01Live

    Vigilance-1 — Continuous Audit Readiness Agent

    AI-assisted summary of your real assessment findings, on request. Shows nothing before a real assessment exists.

    None independently — narrates ENG-01's NIS2 Art. 21(1)-(2) findings

Tier 2 · Compliance Workspace (Team inherits all of this)

  • ENG-02Live

    Continuous Evidence Freshness Decay Engine

    Evidence confidence decays on a ~28.8-day half-life from upload. A verified cloud webhook event naming the control resets the clock without a re-upload.

    None independently — keeps evidence current for the NIS2 Art. 21(2) controls it's attached to
  • ENG-03Live

    FAIR Monte Carlo Financial Loss Simulator

    A 10,000-iteration Monte Carlo simulation over your own frequency/magnitude estimates, with cited GDPR & NIS2 statutory ceilings shown alongside it.

    GDPR Art. 83 & NIS2 Art. 34: statutory fine ceilings shown as reference, not a compliance requirement itself
  • ENG-06Live

    NIS2 & DORA Incident Register

    Log incidents and track them against NIS2 Article 23's 24h/72h notification guidance. Manual entry — no automated CSIRT filing.

    NIS2 Art. 23 & DORA Arts. 17-19: incident classification and reporting obligations
  • ENG-07Live

    Third-Party Vendor Registry

    A flat registry of the vendors you add, with criticality and compliance status. Not a recursive sub-processor or 4th-party dependency graph.

    NIS2 Art. 21(2)(d) & DORA Arts. 28-30: supply-chain / ICT third-party risk management
  • ENG-08Live

    HMAC-SHA256 Report & Evidence Chain

    A tamper-evident linear chain covering report exports, evidence uploads/reviews, and now authenticated cloud telemetry events — one continuous per-tenant sequence.

    None independently — evidentiary integrity supporting whichever Article a chained record documents
  • ENG-09Live

    Remediation Spend Optimizer

    An exact 0/1 knapsack, solved via bounded dynamic programming (not a greedy approximation), over your open gaps and budget.

    None independently — prioritizes closing gaps against NIS2 Art. 21(2)(f)'s effectiveness-assessment obligation
  • ENG-11Live

    CRA Article 14 Reporting Register

    A private 24h/72h/final-report clock for actively exploited vulnerabilities and severe incidents in products you place on the EU market. Files nothing — no ENISA connection, no Single Reporting Platform integration, no automated submission. Shown only if you declare yourself a CRA manufacturer. All six stage timings are verified against the Official Journal text of 20.11.2024.

    CRA (Regulation (EU) 2024/2847) Art. 14: reporting obligations applicable since 11 September 2026
  • ENG-12Live

    DORA Register of Information Export

    Exports 4 of the register's 15 templates as plain CSV from your vendor registry. A data-preparation aid — not xBRL-CSV, not validated against the EBA taxonomy, not filable with the Central Bank of Ireland. All 45 column codes are verified against Annex I as corrected by the 19.9.2025 corrigendum, and against the EBA XBRL 4.0 taxonomy.

    DORA (Regulation (EU) 2022/2554) Art. 28(3): the register of information on ICT third-party contractual arrangements
  • AGT-02Live

    Sentinel-2 — Risk Prioritization & ROI Agent

    AI-assisted executive narrative over a real, already-solved ENG-09 remediation allocation. Never computes a euro figure or score of its own — it only narrates numbers you already computed. Shows nothing until you solve a real allocation.

    None independently — narrates ENG-09's output
  • AGT-03Live

    Guardian-3 — Incident Reporting Agent

    AI-assisted briefing over your real open incidents (ENG-06), referenced against the notification windows of the regime your own jurisdiction is under — NIS2 Article 23 in Ireland and the EU, the NIS Regulations 2018 in the UK — timing information only, never a compliance verdict. Shows nothing when there are no open incidents.

    NIS2 Art. 23 (EU/Ireland); NIS Regulations 2018 reg. 11 (UK): incident-reporting windows
  • AGT-05Live

    Ecosystem-5 — Supply Chain Concentration Agent

    AI-assisted narrative over your real Third-Party Vendor Registry (ENG-07): category concentration and data-access exposure computed from fields you entered. Never an automated sub-processor discovery — there is no real data source for that. Shows nothing until you have a vendor on file.

    NIS2 Art. 21(2)(d): narrates ENG-07's supply-chain risk data
  • AGT-06Live

    Sherlock-6 — Vulnerability Triage Agent

    AI-assisted patching-priority briefing over your real, manually-logged vulnerabilities, sorted by real CVSS score and affected-asset count. No scan-feed ingestion, no asset-criticality correlation and no financial-exposure figure — none of those data sources exist yet. Shows nothing until you have a vulnerability on file.

    None independently — narrates your logged vulnerability data

Public Roadmap — Not Sold Yet

  • ENG-05

    EU AI Act Governance Engine

    Planned: automate Article 6 risk classification and Fundamental Rights Impact Assessments. We hold the verified primary regulation text — held for the EU AI Office to publish the official Art. 27(5) FRIA questionnaire template, not blocked on sourcing. Not yet built.

    Will cite: EU AI Act Arts. 6 & 27 (not yet built)
  • ENG-10

    WASM High-Density Graph Offload

    Planned: offload large entity-graph rendering to WebAssembly for high-density vendor/asset graphs. Not yet built.

    None — rendering/performance tool, not compliance-mapped
  • AGT-04

    Prometheus-4 — EU AI Act Agent

    Planned: narrate EU AI Act governance findings once ENG-05 exists, which is itself held for the AI Office's official FRIA questionnaire. Not yet built.

    Will cite: EU AI Act, once ENG-05 exists (not yet built)
  • AGT-07

    Archon-7 — DSA Compliance Agent

    Planned: track notice-and-action and transparency-reporting workflows under the EU Digital Services Act. Not yet built.

    Will cite: EU Digital Services Act (not yet built)
  • AGT-08

    Synthesizer-8 — Multi-Agent Coordinator

    Planned: coordinate outputs across the other roadmap agents once they exist. Not yet built.

    None — coordinates other agents' output, no citation of its own
Live Today

Built On What
Actually Works.

Vivid Risk starts with a rigorous, framework-mapped self-assessment that tells you exactly where your gaps are, backed by AI-augmented findings and a full incident and vendor register. Citations follow your jurisdiction: EU NIS 2 for Ireland and the EU, and the NCSC Cyber Assessment Framework plus UK GDPR for the UK, which NIS 2 does not apply to. Evidence freshness decay, a tenant-scoped report chain, an exact remediation-spend optimizer, a FAIR Monte Carlo loss simulation over your own estimates, and a tenant-authenticated cloud webhook endpoint that chains verified telemetry into that same report/evidence record are all live too — with cited GDPR and NIS2 fine ceilings shown alongside the loss simulation. A CRA Article 14 reporting register and a DORA Register of Information CSV export are live as well; both are private working records that file nothing with any authority, and both say so on every screen and in every file they produce. Automated cross-mapping of telemetry against a regulatory framework, autonomous remediation, and the EU AI Act statutory ceiling are on the roadmap — built transparently, in the open, not claimed before they exist.

  • VMI Self-Assessment

    Online

    Framework-Mapped Scoring

    Live • Deterministic, From Your Answers

  • Incident Register

    Online

    NIS2 Art. 23 Guidance

    Live • Per-Tenant Records

  • Vendor Registry

    Online

    Third-Party Risk Tracking

    Live • Per-Tenant Records

  • Report Chain & Evidence Decay

    Online

    HMAC-SHA256 Chain, Tenant-Scoped

    Live • Server-Side, OCC-Safe Append

  • Remediation Spend Optimizer

    Online

    Exact 0/1 Knapsack, VMI Gain

    Live • Bounded DP, Not Greedy

  • Financial Loss Estimator

    Online

    FAIR Monte Carlo, 10,000 Iterations

    Live • Your Own Estimates

  • Cloud Webhook Ingest

    Online

    Per-Tenant Auth, HMAC-Chained, Freshness Recovery

    Live • GCP/Azure/AWS, Compliance Workspace+

  • CRA Art. 14 Register

    Online

    24h / 72h / Final-Report Clock

    Live • Private Record — Files Nothing With ENISA

  • DORA Register of Information

    Online

    4 of 15 Templates, Plain CSV

    Live • Data Prep Only — Not An xBRL Submission

  • Automated Cross-Mapping & Remediation

    Roadmap

    AI Evaluation of Telemetry Against Frameworks

    Roadmap • Not Yet Available

  • Cited to the Source

    Every scored control carries its NIS2, CAF, ISO 27001 or CSF 2.0 citation, with unverified mappings labelled as such.

  • Regional Focus

    Ireland, the UK and the EU. Control citations follow the jurisdiction you select — EU NIS 2 for Ireland and the EU, NCSC CAF and UK GDPR for the UK, which NIS 2 does not bind. Other regions are not supported today.

  • Enterprise Ready

    Role-based access and audit logging. Custom SSO/SAML is roadmap, not yet built.

  • Private & Controlled

    Your assessment data stays strictly within your control.