Choose the [PERCH] plan that fits your risk program.
Every plan includes the complete NIST CSF 2.0 journey, complete threat intelligence for your sector, and ISA/IEC 62443 exposure self-assessment. What changes between tiers is how many sites and users you cover, and how much collaboration and governance you need.
For a single site starting its risk journey.
- Complete NIST CSF 2.0 journey — all six functions
- Assessment, strategic profiles, prioritized roadmap, Journal and reports
- Complete threat intelligence for your sector (weekly)
- ISA/IEC 62443 exposure self-assessment
- Asset inventory: manual or CSV/XLSX import
- MFA and audit trail
- NIST CSF 2.0 maturity tier estimate and historical trends
- AI assistant — same model as every plan · EN, PT-BR, ES
For growing programs managing multiple sites.
- Everything in Starter — same journey, same intelligence
- Multi-site portfolio
- Site and domain comparison
- Site ranking and portfolio insights
- Market benchmarking
- Risk, confidence, freshness and trend per site
For corporate programs at full scale.
- Everything in Professional
- Action management — owner, deadline, priority and status
- Weighted corporate risk score
- Executive dashboard — critical sites, attention needed, data freshness
- Regional hierarchy — risk aggregated by region or unit
- Follow-up of actions across all sites
For scaling your business with [PERCH] intelligence across your client portfolio
- Everything in Business
- Multi-client portfolio — up to 10 organizations in one account
- Per-client view: plan, status, sites, risk and assessments
- Portfolio overview — highest-risk client, stale clients, upcoming renewals
- Dedicated onboarding and support
- A single pane of glass for all your customers’ risks and priorities
Billing will be processed by Lemon Squeezy at launch.
Annual plan + Strategic Partnership = up to 30% total savings.
Strategic Partners get an extra 15% permanent preferred pricing on top of the annual discount — in exchange for shaping the future of operational cybersecurity with us.
Every feature, side by side.
| Feature | STARTER$299 | PROFESSIONAL$799 | BUSINESS$1,499 | ALLIANCEon request |
|---|---|---|---|---|
| Complete NIST CSF 2.0 journey — assessment, profiles, roadmap, Journal, reports | ✓ | ✓ | ✓ | ✓ |
| Complete threat intelligence (External Threats) | ✓ | ✓ | ✓ | ✓ |
| ISA/IEC 62443 exposure self-assessment | ✓ | ✓ | ✓ | ✓ |
| Organizations | 1 | 1 | 1 | 10 |
| Sites / users | 1 / 3 | 3 / 10 | 10 / 50 | 30 / 100 |
| Additional sites — $259 per site / month (annual and partner discounts apply) | ✓ | ✓ | ✓ | ✓ |
| AI queries per month | 100 | 300 | 1,000 | 3,000 |
| AI assistant — same model and quality in every plan | ✓ | ✓ | ✓ | ✓ |
| NIST CSF 2.0 maturity tier estimate | ✓ | ✓ | ✓ | ✓ |
| Asset inventory: manual or CSV/XLSX import | ✓ | ✓ | ✓ | ✓ |
| Reports PDF/PPTX | ✓ | ✓ | ✓ | ✓ |
| MFA and audit trail | ✓ | ✓ | ✓ | ✓ |
| Historical trends and assessment comparison | ✓ | ✓ | ✓ | ✓ |
| Languages: English · Portuguese · Spanish | ✓ | ✓ | ✓ | ✓ |
| Multi-site, comparison, ranking, benchmark | — | ✓ | ✓ | ✓ |
| Action management, weighted corporate score, executive dashboard, regional hierarchy | — | — | ✓ | ✓ |
| Multi-client portfolio — up to 10 organizations, per-client plan, status, sites and risk | — | — | — | ✓ |
| Portfolio overview — highest-risk client, stale clients, upcoming renewals | — | — | — | ✓ |
The key message: plans scale by size and governance — sites, users, collaboration — never by access to the intelligence or to the journey itself. Threat intelligence is not an upsell.
On the roadmap, but not included at launch: SSO, public API, custom frameworks, and white label.
Upgrade your plan at any time.
You're never locked out of growing. Move up whenever your program needs more — here's how it works:
- You can switch to annual at any time — the new 12-month cycle starts on the date of the change (it is not retroactive).
- If you already paid for the current month, the unused pro-rata value is applied as credit on the annual invoice — never as a refund.
- Moving from annual back to monthly happens only at renewal, never mid-cycle.
- The discount applies to the contracted plan. If you upgrade tiers during an annual term (e.g., Professional → Business), the pro-rata difference is charged and your renewal anniversary stays the same.
- Need more sites? Any plan can add extra sites for $259 per site per month (monthly plans) — annual billing and any other discount you hold, such as Strategic Partner pricing, apply equally to additional sites. Additional sites expand your site count, not your plan tier: each one is a complete, independent journey, while multi-site comparison, ranking, benchmark and portfolio remain Professional and above.
This is what checking out will feel like.
A visual mockup only — no payment is processed here yet. At launch, this step will be handled securely by Lemon Squeezy.
Checkout handled by a payment platform you can verify.
We don't process or store your card details. Every [PERCH] subscription is billed through Lemon Squeezy, a Merchant of Record that handles PCI-compliant payment processing, global tax, invoicing and refunds.
- PCI-DSS compliant processing — card data never touches our servers
- Merchant of Record: global VAT and sales tax handled for you
- Automated invoices, receipts and subscription management
- Major cards, and regional methods where available
Frequently asked questions
Can I change plans later?
Yes — you can upgrade at any time. Mid-term tier upgrades charge only the pro-rata difference and keep your renewal date; annual-to-monthly changes take effect at renewal.
Is my assessment data secure?
[PERCH] is built by a cybersecurity team first. Data is encrypted in transit and at rest, and never shared with third parties.
Where does the threat intelligence come from?
The weekly sector publication draws on CISA KEV, CISA ICS Advisories, NVD/NIST, NIST CSF 2.0, CISA CPG 2.0 and internal MITRE ATT&CK/ICS knowledge, related to your declared environment and reviewed by our specialists. It is included in every plan — never an upsell.
What counts as an AI query?
Each question you ask the assistant — clarifying a questionnaire item, requesting a summary, or querying a result — counts as one query toward your monthly plan allowance. The journey itself is never limited by it.
Who is NIST, and what is the CSF 2.0?
The National Institute of Standards and Technology is a U.S. federal standards agency founded in 1901 — it sells nothing and has no commercial interest in any tool. Its Cybersecurity Framework, revised as CSF 2.0 in 2024, organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond and Recover — and is the common language of risk that regulators, insurers and boards worldwide already recognize. [PERCH] guides your whole journey through those six functions.
What is ISA/IEC 62443?
Where NIST provides governance and maturity, ISA/IEC 62443 is the international standard written specifically for industrial automation and control systems (OT). [PERCH] uses it to measure your exposure by zone through Security Level Targets, always explained in plain language. Note: [PERCH] provides guidance and structured self-assessment aligned with these frameworks — it does not issue certification or attest formal compliance.
What do the Security Level Targets (SL1–SL4) mean?
They describe the strength of attacker each zone should withstand: SL1 — accidental or casual violation; SL2 — intentional attack with simple, openly available tools; SL3 — specialized attack with ICS/OT knowledge; SL4 — advanced persistent attack, typically state-sponsored. In [PERCH] you pick a target per zone and the platform shows the distance between where you are and where you need to be.
How is the [PERCH] AI actually built?
Two layers. The scoring engine is classic AI / machine learning running on rules established by our team of certified cybersecurity specialists — every score and recommendation traces back to expert-defined, explainable logic. On top of it, a conversational assistant supports the whole journey: clarifying questionnaire items, explaining results and suggesting next steps.