Six tiers. One standard. Find the level that fits your organisation today — and grow into the next when you’re ready. Every paid tier includes everything in the tiers below it.
| COMMONS Free, always |
CORE €9 / user / year |
ESSENTIAL €99 / user / year |
PROFESSIONAL €999 / user / year |
ENTERPRISE €9,999 / org / year |
CONGLOMERATE From €99,999 / year |
|
|---|---|---|---|---|---|---|
| Best for | Any organisation exploring compliance for the first time | Start-ups & micro-businesses (1–10 people) needing immediate credibility | SMEs (10–100 people) building a structured governance foundation | Mid-sized organisations (100–1,000 people) with active compliance programmes | Large enterprises (1,000–10,000 people) managing multi-framework governance | Very large enterprises, holding groups & conglomerates (10,000+ people) |
| Policies included | — | 3 enterprise-grade policies (classified PUBLIC) | 10 policies covering full information assurance baseline (classified PUBLIC) | 30 policies covering all major information assurance domains (classified PUBLIC) | Full policy suite — all tiers (classified SHARED CONFIDENTIAL under NDA) | Full policy suite + bespoke extensions built around your architecture |
| Frameworks mapped | GOV Seed Table: ISO 27001, NIST CSF, GDPR, POPIA, SOC 2 (GOV-001 to GOV-015) | Framework Mapping Starter Pack (full GOV-001 to GOV-015 detail) | Full GOV taxonomy GOV-001 to GOV-050, top 5 frameworks | Cross-framework evidence mapping workbooks, 15 international standards | All frameworks + sector-specific overlays (Financial, Health, Public Sector) | Custom framework mapping across all your specific regulatory regimes |
| Governance system | — | — | IMS Lite Manual — functioning Information Management System | OPF Lite + ECF Lite + IMS Core Manual | OPF Core + ECF Core (all 8 domains) + IMS Heavy Manual | Customised IMS deployment built for your organisational architecture |
| CIAO Standard v1.0 | ✓ Full access | ✓ | ✓ | ✓ | ✓ | ✓ |
| Self-Assessment tool | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Open Principles | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Users | Single user | Per-user pricing (any number) | Per-user pricing | Multi-user access across departments | Unlimited users | Unlimited users across all entities |
| Dedicated environment | — | — | — | — | ✓ Dedicated secure environment | ✓ White-label portal, custom logo, multi-entity architecture |
| NDA protection | — | — | — | — | ✓ All content under NDA | ✓ |
| Partner-delivered | — | — | — | — | — | ✓ Fully managed compliance partnership |
| Minimum term | No commitment | Annual | Annual | Annual | Annual | Minimum 3-year cycle |
| Get started | Register Free | Register → | Register → | Register → | Register → | Enquire → |
COMMONS — Free
Free, always. No credit card.
- CIAO Standard v1.0 full access
- GOV Seed Table (GOV-001 to GOV-015)
- Compliance Readiness Self-Assessment
- Full Membership Guidelines
CORE — €9 / user / year
For start-ups and micro-businesses (1–10 people)
- Everything in Commons
- 3 enterprise-grade policies (PUBLIC)
- Framework Mapping Starter Pack
ESSENTIAL — €99 / user / year
For SMEs (10–100 people)
- Everything in Core + Commons
- 10 policies covering full baseline (PUBLIC)
- Full GOV taxonomy GOV-001 to GOV-050
- IMS Lite Manual
PROFESSIONAL — €999 / user / year
For mid-sized organisations (100–1,000 people)
- Everything in Essential, Core + Commons
- 30 policies (PUBLIC)
- OPF Lite + ECF Lite + IMS Core Manual
- Cross-framework evidence mapping workbooks
- Multi-user access
ENTERPRISE — €9,999 / organisation / year
For large enterprises (1,000–10,000 people)
- Everything in all tiers below
- Full OPF Core + ECF Core (all 8 domains)
- IMS Heavy Manual
- Unlimited users
- Dedicated secure environment
- All content under NDA (SHARED CONFIDENTIAL)
CONGLOMERATE — From €99,999 / year
For enterprises 10,000+ people, holding groups & conglomerates
- Everything in all tiers
- Fully managed compliance partnership
- Bespoke framework mapping
- Custom IMS deployment
- White-label subdomain portal
- Minimum 3-year cycle
Not sure which tier is right for you? Take the Compliance Readiness Self-Assessment — it takes under 3 minutes and recommends your tier based on your organisation’s size, compliance maturity, and regulatory exposure.
Every paid tier includes everything from all tiers below it. Your compliance infrastructure grows with your organisation — without losing what you’ve already built. View full membership guidelines →
● LIVE CONTENT
· Verified 15 April 2026 at 17:42 UTC
· Always current at
c-ao.com
· © CIAO Standard 2026