Basic
For organisations resolving issues and managing the rating.
- Security rating and risk vectors
- Asset management
- Issue tracking
- Basic reports and alerts
- Basic threat insights
Bitsight is licensed by edition and, for third-party risk, by the number of vendors you monitor. There is no list price — a quote depends on coverage, workflow, integrations and services. BitScore packages and quotes these editions in INR ₹ or USD $ based on your preference, with onboarding and advisory included in the conversation.
If you have not seen your rating yet, start there instead — the Cyber Risk Rating Report is complimentary and arrives as little as 45 minutes for publicly listed entities, up to 48 hours for all others. Most engagements begin there, not here.
Three editions, each building on the one before it. Every edition includes the 250–900 rating and risk-vector breakdown; the differences are analytics depth, integration breadth, and whether you manage subsidiaries. For what SPM does and how it differs from the scanning and testing you already run, see Security Posture Management.
For organisations resolving issues and managing the rating.
For organisations measuring, improving and demonstrating cyber resilience.
For organisations scaling posture management across subsidiaries.
Two packages. The first gives you continuous, evidence-based visibility; the second adds the workflow layer that replaces questionnaires. Both are banded by portfolio size. For vendor tiering, fourth-party concentration and what regulators now expect, see Third-Party Risk Management.
Continuous, evidence-based visibility across your vendor portfolio.
Adds the workflow layer — intake, assessment and remediation — on top of monitoring.
Two organisations with the same headcount can have vendor portfolios an order of magnitude apart, and the workflow requirements that follow differ just as much. A single published number would be wrong for almost everyone.
Four factors determine a quote. Knowing your position on each before you enquire will get you an accurate number considerably faster.
Figures for Bitsight do circulate on spend-management and software-review sites. They are third-party estimates rather than Bitsight's numbers, and they almost never say which edition or which vendor band they describe — which is to say they quote a price without the two variables that set it.
◆ Edition names and inclusions reflect Bitsight's published packaging as at July 2026 and may change. Packaging is Bitsight's; the quote, onboarding and advisory are BitScore's.
Bitsight does not publish a list price, and no honest single figure exists. Security Posture Management is licensed by edition and Third-Party Risk Management by the number of vendors monitored, so two organisations of the same size can be quoted very differently. Four things move the number: vendor coverage, whether you need monitoring alone or the intake, assessment and remediation workflow with it, the integrations you connect, and the services wrapped around the licence. BitScore quotes against scope in Indian rupees or US dollars.
Because the two things it is licensed on vary by an order of magnitude between customers of the same size. A firm with forty vendors and a firm with four hundred are buying materially different amounts of the same product, and the workflow requirements that follow differ just as much. A single published number would be wrong for almost everyone who read it, which is why the vendor quotes to scope instead.
Figures circulating on spend-management, procurement and software-review sites are third-party estimates, assembled from what some customers reported paying. They are not Bitsight’s numbers and Bitsight does not stand behind them. The more practical problem is that they almost never state which edition or which vendor band they describe, and those are the two variables that actually set the price — so a quoted average has no scope attached to it and cannot be compared with a quote you receive.
No. Security Posture Management is priced by edition — Basic, Standard or Advanced — and Third-Party Risk Management by the number of third parties you monitor, banded at 1–50, 51–100, 101–500 and unlimited. Seat count is not the meter, so adding readers to a dashboard is not what changes the figure. Widening the vendor portfolio is.
The API is an edition question rather than a separate meter. API access and integrations sit in the Standard edition of Security Posture Management, not the Basic one, and are included in both Third-Party Risk Management packages. A programme that intends to push ratings into a GRC, ITSM or SIEM platform should therefore scope Standard or above from the start rather than treating the connection as something to add later.
The platform is licensed, not free. What is free is the baseline: BitScore delivers a complimentary, one-time Cyber Risk Rating Report carrying your current rating, how it compares with your industry average, your likelihood of ransomware and data-breach incidents, and your performance over the last twelve months. It carries no obligation and is a complete report rather than a teaser. Seeing your own rating therefore costs nothing; monitoring it continuously, or monitoring your vendors, is what a licence buys.
Onboarding and advisory. Most ratings programmes stall on adoption rather than licensing — confirming which internet-facing assets are genuinely yours, tiering the vendor base so the alerts are proportionate, and routing findings to someone who acts on them. BitScore includes local onboarding and advisory in the conversation, and scopes Bitsight’s own third-party risk services alongside the licence where a programme has to launch quickly.
Yes. BitScore packages and quotes Bitsight editions in Indian rupees or US dollars, whichever an organisation prefers to contract in, as an authorised Bitsight partner in India. That removes the foreign-exchange and procurement friction that a direct dollar-denominated licence would otherwise add for an Indian entity.
Most programmes stall on adoption, not licensing — asset attribution, tiering the vendor base, getting alerts to an owner who acts on them. BitScore includes local onboarding and advisory, and Bitsight offers dedicated third-party risk services for programmes that need to launch quickly. Tell us where you are and we will scope both.