
Choose a Shomar plan without starting from a blank form.
Compare tiers, check your plan fit, see what drives the quote, and send a pre-scoped buying brief when your team is ready.
Pick a plan before talking to sales.
Clear starting points, with room for custom scope.
Each tier is a buying starting point. The final quote adjusts only for usage, deployment, evidence, VAPT, support, and implementation scope.
Entry package for teams that need basic scans, an industry-applicable baseline framework, basic reports, and Shomar-managed evidence.
- 3 users including org admin
- 2 projects
- Industry-applicable baseline framework
- MFA/SSO
- Basic scans/month
- light VAPT scan/quarter
- Basic reports
- Shomar-managed evidence
Growth adds more scan volume, industry baseline mapping, evidence workflows, CI/CD readiness, and a basic VAPT allowance.
- 10 users including admin and auditor
- 5 projects
- Industry-applicable baseline framework
- MFA/SSO
- Scans/month
- Basic VAPT allowance
- Evidence workflows
- CI/CD, SCA, IaC, and SARIF import
Business adds API/webhooks, customer-owned or external evidence storage, advanced reports, and larger VAPT allowance.
- 15 users including admin, auditor, and executive
- 10 projects
- Industry-applicable baseline framework
- Scans /month
- Larger VAPT allowance
- API/webhooks
- Customer-owned or external evidence
- Advanced reports
- CodeQL-compatible evidence import
Enterprise is custom scoped for large regulated organisations that need controlled workers, tenant isolation, sovereign deployment, and premium assurance.
- Custom users/projects
- Customer-controlled workers
- Dedicated tenant
- Sovereign/on-prem option
- SLA + customer success manager
- Custom frameworks, SARIF evidence, and premium VAPT
Use these rules to choose the right tier.
The goal is to help the buyer decide before speaking with sales, then use the conversation only to confirm commercial and delivery scope.
Early team that needs basic scans, an industry-applicable baseline framework, MFA/SSO, basic reports, and Shomar-managed evidence.
3 users including org admin, 2 projects, industry-applicable baseline framework, MFA/SSO, basic scans, light quarterly VAPT.
Choose Growth when CI/CD, fintech compliance mapping, or repeatable evidence workflows matter.
Scaling fintech or payments team that needs more scan volume, CI/CD, industry baseline mapping, and repeatable evidence workflows.
10 users including admin and auditor, 5 projects, industry-applicable baseline framework, MFA/SSO, evidence workflows, CI/CD, SARIF import, basic VAPT allowance.
Choose Business when APIs, advanced reports, or customer-owned evidence are required.
MFB, finance house, or regulated fintech with stronger admin governance and audit reporting needs.
15 users including admin, auditor, and executive, 10 projects, industry-applicable baseline framework, API/webhooks, CodeQL-compatible evidence import, advanced reports, larger VAPT allowance.
Choose Enterprise when private workers, dedicated tenancy, sovereign deployment, or custom frameworks are required.
Bank, government, or large regulated organisation with custom deployment, SLA, or private execution requirements.
Custom users/projects, controlled workers, dedicated tenant, SLA, CSM, custom frameworks, BYO CodeQL/SARIF evidence, premium VAPT.
Stay here when procurement, regulator, or infrastructure constraints need a custom commercial path.
What changes the final commercial number.
Shomar avoids public fixed prices because regulated deployments differ. These are the variables that affect the quote, so prospects know what matters before a call.
Licence tier and included users/projects
Expected scan volume and scan types
External evidence imports: SARIF, CodeQL, GitHub Advanced Security, or CI-generated findings
Compliance bundle: NDPR/NDPA, PCI DSS, CBN, NPS, VASP, MFB, finance-house, or custom frameworks
VAPT allowance: light, basic, larger, dedicated, or premium
Evidence storage: Shomar-managed, customer-owned, or external-link evidence
Deployment: SaaS, customer-controlled worker, dedicated tenant, sovereign/on-prem option
Onboarding, support, SLA, and customer success expectations
Product access
The selected Shomar licence tier, enabled modules, and feature flags.
Implementation path
Onboarding, bundle setup, evidence workflow, integrations, and handover scope.
Operational delivery
Support level, VAPT allowance, scan volume, worker model, and service commitments.
Expansion logic
How the organisation can add projects, frameworks, regions, or private execution later.
Start simple, expand by real usage.
Best for teams that know their sector: banking, fintech, MFB, finance house, or VASP.
Add PCI, CBN, NPS, ISO 27001, regional bundles, or custom frameworks when needed.
Use private workers, dedicated tenancy, premium VAPT, SLA, and sovereign options for sensitive organisations.
Send a scoped brief instead of filling another long form.
Include your selected plan, organisation type, users/projects, compliance scope, evidence or deployment requirements, and buying timeline. The account manager can respond with the right commercial path.