COMPETITOR PRICING · VERIFIED AUGUST 2026
OneTrust pricing: what OneTrust costs in 2026, and what each product is metered on
OneTrust publishes something most vendors hide and hides the thing most buyers want. For all nine products it tells you exactly what the meter counts, and for none of them does it tell you the rate. Here is what that means for your budget.
From $79/mo · Prices published · No sales call · Monthly billing
Audit readiness
0 %
Built for teams of 5 to 200
What does OneTrust cost?
OneTrust does not publish a price. Its pricing page lists nine products and attaches a dollar figure to none of them, and every button reads Get Pricing or Get Customized Pricing, with the form asking you to schedule a quick call for a personalized quote based on your team size and business goals. There is no free tier and no free trial on any product. What OneTrust does publish, and this is genuinely more useful than most vendors offer, is the metric each product is priced on. AI Governance is priced on admin users and AI inventory. Both Consent Management tiers are priced on average daily visitors aggregated across channels. Universal Consent and Preference Management is priced on total data subject profiles captured. Both Privacy Automation tiers are priced on users and privacy asset inventory. Tech Risk and Compliance is priced on admin users and asset inventory. Both Third-Party tiers are priced on admin users and third-party inventory. Read that list closely, because it tells you where your bill grows. Three of the nine meters count something other than seats: web traffic, customer profiles, and inventory size. A company whose headcount is flat can still see its OneTrust renewal climb because its website got more visitors or its data map got more complete. For an actual number, the most credible third-party benchmark is Vendr, which publishes anonymized data from contracts it has handled. As of February 2026 Vendr reports a median OneTrust contract of $11,970 a year across 307 purchases, ranging from $1,620 to $48,230, with buyers saving about 20 percent off the opening quote. Treat that as a record of what companies paid, not a rate card, and note how wide the range is: the top of it is nearly thirty times the bottom, because these are nine different products sold in different combinations. Complies takes the opposite approach and publishes the whole range, $79 to $499 a month, with all five frameworks cross-mapped from Growth. It is also a much narrower product, and it does not do consent management, cookie banners, DSAR automation, or data discovery, so for a large slice of what OneTrust sells there is no comparison to make.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
Last updated August 2026
Three things that decide what you actually pay OneTrust
Three of the nine meters are not headcount
This is the detail that surprises buyers at renewal. Consent Management is priced on average daily visitors, Universal Consent and Preference Management on total data subject profiles captured, and the Privacy Automation and Third-Party products partly on inventory size. A successful marketing quarter, a mailing list that doubles, or a data-mapping exercise that finally finds everything can all raise next year's quote without a single new hire. Ask for the band boundaries in writing, not the current rate.
obligation tracking softwareYou are buying modules, not a platform
OneTrust sells nine products, several of them split into a Base and a Suite version, and each one carries its own meter. The Suite tiers add the expensive parts: CMP Suite adds automated data subject request processing on top of CMP Base, Privacy Automation Suite adds DSR fulfillment and incident management, and Third-Party Management Suite adds Dow Jones sanctions, PEP and adverse media screening. A quote for one module tells you very little about the quote for three, which is why buyers who scope narrowly at first contact tend to end up renegotiating in year two.
control mapping softwareImplementation and the auditor are separate bills
A OneTrust deployment is a configuration project with an internal owner, and services are quoted apart from licenses. On the compliance side, no platform can issue your SOC 2 or ISO 27001 certificate: a licensed CPA firm or accredited certification body does that, it is a different company, and it invoices you separately. A SOC 2 Type 1 typically runs $5,000 to $20,000 in audit fees. When you compare platforms, compare the software line only.
audit readiness softwareWhat OneTrust meters, product by product
This is the part of OneTrust pricing that is actually published, and almost nobody tabulates it. Every entry in the middle two columns is taken from onetrust.com/pricing as of August 2026. The last column is our own honest answer, and it is no more often than it is yes.
| OneTrust product | What the price is based on | What the product covers | Does Complies do this? |
|---|---|---|---|
| AI Governance | Admin users and AI inventory | Model, agent, dataset and vendor register, EU AI Act, NIST and ISO 42001 alignment, approval gates, drift monitoring, runtime controls | No. Complies ships no AI governance module |
| Consent Management (CMP) Base | Average daily visitors across channels | Tracker and SDK inventory, a database of over 45 million categorized cookies, consent banners across web, mobile and CTV | No. Complies has no cookie banner or consent tooling |
| Consent Management (CMP) Suite | Average daily visitors across channels | Everything in Base, plus privacy notice management across sites and languages, and automated data subject request processing | No |
| Universal Consent and Preference Management | Total data subject profiles captured | Preference centers, consent capture across the customer journey, cross-system consent sync, real-time dashboards | No |
| Privacy Automation Base | Users and privacy asset inventory | Automated data and activity mapping, privacy impact assessments, vendor privacy risk and DPA management, DataGuidance regulatory intelligence | No. Complies does no data discovery or mapping |
| Privacy Automation Suite | Users and privacy asset inventory | Everything in Base, plus DSR fulfillment including intake, ID verification, retrieval and deletion, plus privacy incident management | No |
| Tech Risk and Compliance | Admin users and asset inventory | Requirements broken into tasks across 50+ standards and frameworks, IT risk identification, risk quantification, automated assessments, control management, policy lifecycle | Yes, this is the overlap. Complies covers controls, obligations, evidence, risk register and policies for 5 frameworks |
| Third-Party Risk Management Base | Admin users and third-party inventory | Third-party inventory and tiering, automated vendor assessments and mitigation workflows, risk intelligence on millions of third parties | Partly. Complies tracks vendors, owners and review dates but does not buy external risk intelligence |
| Third-Party Management Suite | Admin users and third-party inventory | Everything in Base, plus Dow Jones ethics and compliance databases covering PEP, sanctions and watchlists, and adverse media screening | No |
One row out of nine is a genuine like-for-like comparison, and half of another. That is the honest shape of this decision: if you are buying OneTrust for consent, DSAR automation, data mapping or sanctions screening, no cheaper compliance platform replaces it, and you should be comparing it to privacy specialists instead. For a feature-level read on the overlap rather than a pricing one, see For the feature comparison rather than the pricing one, read OneTrust alternatives, Vanta alternatives and Drata alternatives.
Who publishes a price in this category, and who makes you ask
A OneTrust evaluation rarely stays a OneTrust evaluation. These are the platforms buyers most often put beside it, with one rule applied throughout: published figures only, or a clearly labeled third-party benchmark. Where a vendor publishes nothing, the table says so instead of guessing.
| Platform | Price published? | Reported or published figures | Where it fits beside OneTrust |
|---|---|---|---|
| OneTrust | No. Nine products, the metric published, no rate | Vendr, Feb 2026: median $11,970/yr, range $1,620 to $48,230, 307 purchases | The broadest privacy and GRC suite available, built for organizations with a privacy team |
| TrustArc | No figures on its own site | No credible benchmark we are willing to publish | The closest like-for-like privacy suite, usually shortlisted alongside OneTrust |
| Osano | Yes, published tiers on its own pricing page | Read the current figures on osano.com, they change | Consent and privacy for smaller teams that found OneTrust oversized |
| Vanta | No. Four tiers named, no figures | Vendr, Feb 2026: median $20,000/yr, range $7,500 to $57,236 | Chosen when the real requirement was SOC 2 readiness, not privacy operations |
| Drata | No. Three tiers per platform, no figures | Vendr, Feb 2026: median $24,868/yr, range $9,649 to $60,000. Publishes a 50 FTE cap on its entry GRC tier | Same lane as Vanta, with two structural limits it does publish |
| AuditBoard (now Optro) | No. Quote-only, CTA is schedule a demo | Vendr, Feb 2026: median $45,895/yr, range $21,180 to $110,551, 85 purchases | Enterprise internal audit and controls, a different buyer entirely |
| Complies | Yes. Every tier and both billing terms | $79, $199 and $499 per month billed yearly, or $95, $239 and $599 monthly | The compliance half only, for 5 to 200 person companies with no privacy team |
Two honest notes. Vendr figures are third-party records of contracts Vendr handled, not vendor rate cards, and your quote can land well outside them. And a median of $11,970 is not evidence that OneTrust is overpriced: it is a nine-product suite with regulatory research, a cookie database and sanctions screening behind it, and buyers who need those get real value. It is evidence that OneTrust and a $199 a month compliance tool are not competing for the same purchase. You will also find confident per-module figures in search results, along with a widely repeated claim that OneTrust now requires a $10,000 minimum annual contract. OneTrust has published neither, so we will not state either as fact. Put the minimum to your rep as a direct question instead, because if it is true it is the single most important thing to know before you scope.
What you get on every Complies plan from Growth
The price is on the page
Starter $79 a month, Growth $199, Scale $499 at the yearly rate, or $95, $239 and $599 billed monthly. No demo gate, no discovery call, and no meter that quietly counts your website traffic.
One meter, and it is not your traffic
Your bill does not move because a campaign worked or because your data map finally found every system. There is no per-visitor band, no data subject profile count and no published headcount cap.
All five frameworks, no re-quote
SOC 2, ISO 27001, GDPR, HIPAA and PCI DSS are cross-mapped from Growth. When a customer asks for a framework you did not plan on, you add it rather than negotiate it. Finishing SOC 2 pre-fills roughly 60 percent of ISO 27001.
Monthly billing exists
You can pay monthly and leave. That is a real constraint on us and it is the point: the product has to earn its seat every cycle instead of coasting on an annual renewal clause.
Evidence that collects itself
Access reviews, change logs and monitoring settings stream in from AWS, GitHub, Google Workspace and Okta on a schedule, attached to the control they prove and the human who owns them.
A readiness score that will not flatter you
One number, plus a ranked gap list naming what is missing and who owns it. It never reads 100, because no tool can promise an audit outcome, and a score that always shows green is decoration.
How to run a OneTrust evaluation without losing a quarter
Split the requirement in two before you take a call
Write down which of the nine products you actually need. Privacy operations (consent, DSAR, data mapping, preference management) and compliance operations (controls, obligations, evidence, policies) are separate purchases that happen to share a vendor. Teams that scope them together buy more than they use.
Ask what the meter counts, then ask where the bands are
OneTrust publishes the metric but not the thresholds. Get the band boundaries for visitors, profiles or inventory in writing, along with what happens when you cross one mid-term. This is the single highest-value question in the whole evaluation.
Price the modules you will need in year two, now
A Base tier quote is not a Suite tier quote, and DSR fulfillment, incident management and sanctions screening all sit in the Suite versions. Get indicative pricing for the upgrade path while you still have leverage, which is before you sign, not at renewal.
Price implementation and the auditor separately
Services are quoted apart from licenses, and no platform issues your SOC 2 report. Budget the CPA firm as its own line, typically $5,000 to $20,000 for a Type 1, and compare software against software.
Or skip the sales cycle for the compliance half
If what you needed was controls, obligations, evidence and policies across SOC 2, ISO 27001, GDPR, HIPAA and PCI DSS, Complies publishes the number. Sign up, connect AWS, GitHub, Google Workspace and Okta, and see a readiness score today.
Who this is for, and who it is not
A GOOD FIT WHEN
- You want to know what OneTrust costs before you sit through a discovery call.
- You got a OneTrust quote and want an honest read on what you are being metered on.
- You use one or two OneTrust modules and suspect you are paying suite money for them.
- You are 5 to 200 people and a five-figure annual contract is a real budget decision.
- You need the compliance half (controls, obligations, evidence, policies) and none of the privacy half.
LOOK ELSEWHERE WHEN
- You need consent management, cookie banners, DSAR automation, data discovery or data mapping. Complies does none of those, and OneTrust is genuinely good at them.
- You run a multi-jurisdiction privacy program with a dedicated privacy or legal team behind it.
- You need Dow Jones sanctions, PEP or adverse media screening on third parties.
- You need AI governance tooling aligned to the EU AI Act or ISO 42001.
- Your procurement requires an annual contract, a named account team and a signed implementation plan.
Common questions about OneTrust pricing
OneTrust does not publish prices, so there is no official answer. The most credible third-party benchmark is Vendr, which reported a median OneTrust contract of $11,970 a year as of February 2026, across 307 purchases, ranging from $1,620 to $48,230. That range is very wide because OneTrust is nine products sold in different combinations, so where you land depends almost entirely on which modules you scope.
Not in dollars. As of August 2026 onetrust.com/pricing lists nine products and, for each one, the metric the price is based on, but attaches no figures to any of them. Every call to action reads Get Pricing or Get Customized Pricing, and the form asks you to schedule a quick call for a personalized quote based on your team size and business goals.
It varies by product, and OneTrust publishes each metric. AI Governance is priced on admin users and AI inventory. Consent Management is priced on average daily visitors across channels. Universal Consent and Preference Management is priced on total data subject profiles captured. Privacy Automation is priced on users and privacy asset inventory. Tech Risk and Compliance and both Third-Party products are priced on admin users plus asset or third-party inventory.
No. As of August 2026 the pricing page offers no free tier and no free trial on any of the nine products. Every path to the product runs through a sales conversation, which is normal for enterprise privacy software but does mean you cannot evaluate it the way you would evaluate a self-serve tool.
OneTrust does not publish one. A claim that OneTrust requires a $10,000 minimum annual contract from 2026 renewals circulates widely on competitor pricing blogs, and OneTrust has not confirmed it publicly, so we will not repeat it as fact. If you are a small buyer it is the first question to ask your rep, because a published minimum would decide your shortlist before any feature discussion.
Because most of what you pay for is research and data rather than software. The cookie database covers over 45 million categorized cookies, the third-party suite licenses Dow Jones sanctions, PEP and adverse media data, and the privacy modules carry DataGuidance regulatory intelligence. Maintaining those across jurisdictions is expensive, and if you need them, no cheaper tool has them. If you do not need them, you are paying for a library you never open.
It depends which half you use. For consent, cookie banners and DSAR automation the honest alternatives are privacy specialists such as Osano, Ketch, TrustArc or BigID, not us, because Complies does not ship any of those. For the compliance half, controls, obligations, evidence, policies and audit readiness across SOC 2, ISO 27001, GDPR, HIPAA and PCI DSS, Complies publishes its prices at $79 to $499 a month with monthly billing.
Usually not, and the price is only part of why. OneTrust expects a configuration project and an internal owner, and its value comes from breadth across jurisdictions that a 40-person company rarely has. If you are buying it because one enterprise customer asked for a cookie banner and a security questionnaire answer, you are buying a suite to solve two problems. Price the two problems separately first.
Scope narrowly, ask for the meter bands in writing, and get indicative pricing for the modules you expect to need in year two before you sign the first one. Vendr reports buyers saving about 20 percent off the opening quote across 307 purchases, which suggests there is real room, but the leverage is in scope and term rather than in asking for a discount on a number you cannot check.
No. Services are quoted separately from licenses, and a OneTrust deployment is a configuration project rather than a signup. Budget an internal owner for it as well as the services line, because the modules that deliver the most value, data mapping and third-party inventory in particular, are the ones that need the most internal input to populate.
Neither publishes a price, so the only comparison available is third-party. Vendr's February 2026 data puts the OneTrust median at $11,970 a year and Vanta at $20,000, but they are not substitutes: Vanta is a SOC 2 and ISO 27001 readiness platform and OneTrust is a privacy suite with a compliance module attached. Buyers who genuinely need to choose between them usually have not yet decided whether their problem is privacy or audit readiness.
Only for parts of it. If you need a cookie consent banner and automated DSAR handling at volume, you need a privacy tool and OneTrust is a strong one. If what you need is Article 30 records, DPAs, lawful basis documentation, a 72-hour breach process and Article 32 security controls tracked with owners and evidence, that is compliance work, and Complies cross-maps those controls into SOC 2 and ISO 27001 so you do it once.
Frameworks and guides
GDPR compliance software
SOC 2SOC 2 compliance software
GDPRBest GDPR Compliance Software: 8 Tools Compared
TPRMThird-Party Risk Management Software: Do You Need TPRM?
Compliance software with the price on the page
Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.