We use strictly necessary cookies to keep you signed in and to protect your Zero-Knowledge encryption session. With your consent we also count anonymous page views to improve the product. We do not sell data, we do not track you across the web, and we never use cookies to advertise.
Details in our cookie policy and privacy notice.
Zero-knowledge encryption
Every piece of evidence is encrypted in your browser before it reaches our servers. If we are subpoenaed or breached, attackers receive mathematical static. Only you hold the keys.
Choose a platform tier, then add the framework modules you need. Modules are annual licences, additive to any tier. Three or more modules: 15% bundle discount.
Your first framework. AI evidence engine, public Trust Center, modular framework licences.
The mid-market default. Auditor View, advanced AI controls, dual-framework cross-mapping.
Enterprise SME. SAML SSO, customer-managed KMS, white-label, dedicated CSM, contractual SLA.
Multi-entity, multi-jurisdiction GRC. Named executive sponsor, bespoke contract.
Tier names follow the GRC maturity curve every auditor recognises: attest, certify, assure, govern.
CertiFlow PLUS is compliance software. We are not an auditor and not a certification body, and we cannot certify you β nobody selling software can. Certificates are issued by accredited bodies precisely so that vendors like us cannot issue them. That independence is what makes your certificate worth anything.
Our fee is one line on a larger bill, and we would rather you knew that now than found out later. A typical first ISO 27001 certification for a small company:
| CertiFlow PLUS platform + one framework | from $7,200/yr |
| Certification audit, paid to an accredited body | $6,000β$15,000 |
| Penetration test, if your framework requires one | $4,000β$15,000 |
| Your own teamβs time | 15β20 hours |
That last line is the one that matters. Without a platform, a first-time SOC 2 or ISO 27001 typically costs a company around 120 hours of internal work. We take it to roughly 15 to 20. We do not claim to take it to zero, because no honest vendor can.
If you would rather someone did the whole thing for you, that is a consultancy engagement rather than a software licence, and we are glad to introduce you to a partner who does exactly that. Just ask us.
Pick only the frameworks your customers ask for. Add more as you grow. All prices annual, billed up-front. 15% off when you attach three or more.
Click any framework for a plain-English description of what it does and what CertiFlow PLUS ships in the box.
| Module | Annual | Primary buyer | Availability | |
|---|---|---|---|---|
| SOC 2 Type 1 (Trust Services Criteria) | $3,600 | SaaS / tech / B2B | Available now | |
| ISO/IEC 27001:2022 | $3,600 | Global B2B | Available now | |
| GDPR / UK-GDPR | $1,200 | Universal EU / UK | Available now | |
| HIPAA Security Rule | $2,400 | US healthcare | Available now | |
| PCI DSS v4 | $3,000 | Payments / retail | Available now | |
| NIS2 Directive | $2,400 | EU critical infra | Available now | |
| Swiss FADP / nLPD | $1,200 | Swiss + CH-facing firms | Available now | |
| CCPA / CPRA | $900 | US consumer data | Available now | |
| ISO 27701 (Privacy) | $1,800 | Privacy-mature firms | Q4 2026 | |
| ISO 42001 (AI Mgmt) | $2,400 | AI-using firms | Q4 2026 | |
| ISO 22301 (BCM) | $2,400 | Regulated services | Q4 2026 | |
| Cyber Essentials (UK) | $600 | UK SMEs | Available now | |
| EU AI Act (transparency + AI literacy) | $1,800 | Anyone using AI in the EU | Available now | |
| DORA (EU Financial) | $4,800 | EU financial services | Q1 2027 |
Need TISAX, ISO 13485, ISO 22000, ISO 50001 or ISO/IEC 17025? These are unlocked at Assurance tier and above on customer request β talk to sales.
Full feature access on one framework. No card required. AI evidence engine, Trust Center, the lot. If itβs not for you, walk away. If it is, choose a tier and your work continues.
Start 14-day trial