Complies

COMPETITOR PRICING · VERIFIED AUGUST 2026

OneTrust pricing: what OneTrust costs in 2026, and what each product is metered on

OneTrust publishes something most vendors hide and hides the thing most buyers want. For all nine products it tells you exactly what the meter counts, and for none of them does it tell you the rate. Here is what that means for your budget.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
PRICING

What does OneTrust cost?

OneTrust does not publish a price. Its pricing page lists nine products and attaches a dollar figure to none of them, and every button reads Get Pricing or Get Customized Pricing, with the form asking you to schedule a quick call for a personalized quote based on your team size and business goals. There is no free tier and no free trial on any product. What OneTrust does publish, and this is genuinely more useful than most vendors offer, is the metric each product is priced on. AI Governance is priced on admin users and AI inventory. Both Consent Management tiers are priced on average daily visitors aggregated across channels. Universal Consent and Preference Management is priced on total data subject profiles captured. Both Privacy Automation tiers are priced on users and privacy asset inventory. Tech Risk and Compliance is priced on admin users and asset inventory. Both Third-Party tiers are priced on admin users and third-party inventory. Read that list closely, because it tells you where your bill grows. Three of the nine meters count something other than seats: web traffic, customer profiles, and inventory size. A company whose headcount is flat can still see its OneTrust renewal climb because its website got more visitors or its data map got more complete. For an actual number, the most credible third-party benchmark is Vendr, which publishes anonymized data from contracts it has handled. As of February 2026 Vendr reports a median OneTrust contract of $11,970 a year across 307 purchases, ranging from $1,620 to $48,230, with buyers saving about 20 percent off the opening quote. Treat that as a record of what companies paid, not a rate card, and note how wide the range is: the top of it is nearly thirty times the bottom, because these are nine different products sold in different combinations. Complies takes the opposite approach and publishes the whole range, $79 to $499 a month, with all five frameworks cross-mapped from Growth. It is also a much narrower product, and it does not do consent management, cookie banners, DSAR automation, or data discovery, so for a large slice of what OneTrust sells there is no comparison to make.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated August 2026

WHAT MOVES THE PRICE

Three things that decide what you actually pay OneTrust

1

Three of the nine meters are not headcount

This is the detail that surprises buyers at renewal. Consent Management is priced on average daily visitors, Universal Consent and Preference Management on total data subject profiles captured, and the Privacy Automation and Third-Party products partly on inventory size. A successful marketing quarter, a mailing list that doubles, or a data-mapping exercise that finally finds everything can all raise next year's quote without a single new hire. Ask for the band boundaries in writing, not the current rate.

obligation tracking software
2

You are buying modules, not a platform

OneTrust sells nine products, several of them split into a Base and a Suite version, and each one carries its own meter. The Suite tiers add the expensive parts: CMP Suite adds automated data subject request processing on top of CMP Base, Privacy Automation Suite adds DSR fulfillment and incident management, and Third-Party Management Suite adds Dow Jones sanctions, PEP and adverse media screening. A quote for one module tells you very little about the quote for three, which is why buyers who scope narrowly at first contact tend to end up renegotiating in year two.

control mapping software
3

Implementation and the auditor are separate bills

A OneTrust deployment is a configuration project with an internal owner, and services are quoted apart from licenses. On the compliance side, no platform can issue your SOC 2 or ISO 27001 certificate: a licensed CPA firm or accredited certification body does that, it is a different company, and it invoices you separately. A SOC 2 Type 1 typically runs $5,000 to $20,000 in audit fees. When you compare platforms, compare the software line only.

audit readiness software
COMPARE

What OneTrust meters, product by product

This is the part of OneTrust pricing that is actually published, and almost nobody tabulates it. Every entry in the middle two columns is taken from onetrust.com/pricing as of August 2026. The last column is our own honest answer, and it is no more often than it is yes.

OneTrust product What the price is based on What the product covers Does Complies do this?
AI Governance Admin users and AI inventory Model, agent, dataset and vendor register, EU AI Act, NIST and ISO 42001 alignment, approval gates, drift monitoring, runtime controls No. Complies ships no AI governance module
Consent Management (CMP) Base Average daily visitors across channels Tracker and SDK inventory, a database of over 45 million categorized cookies, consent banners across web, mobile and CTV No. Complies has no cookie banner or consent tooling
Consent Management (CMP) Suite Average daily visitors across channels Everything in Base, plus privacy notice management across sites and languages, and automated data subject request processing No
Universal Consent and Preference Management Total data subject profiles captured Preference centers, consent capture across the customer journey, cross-system consent sync, real-time dashboards No
Privacy Automation Base Users and privacy asset inventory Automated data and activity mapping, privacy impact assessments, vendor privacy risk and DPA management, DataGuidance regulatory intelligence No. Complies does no data discovery or mapping
Privacy Automation Suite Users and privacy asset inventory Everything in Base, plus DSR fulfillment including intake, ID verification, retrieval and deletion, plus privacy incident management No
Tech Risk and Compliance Admin users and asset inventory Requirements broken into tasks across 50+ standards and frameworks, IT risk identification, risk quantification, automated assessments, control management, policy lifecycle Yes, this is the overlap. Complies covers controls, obligations, evidence, risk register and policies for 5 frameworks
Third-Party Risk Management Base Admin users and third-party inventory Third-party inventory and tiering, automated vendor assessments and mitigation workflows, risk intelligence on millions of third parties Partly. Complies tracks vendors, owners and review dates but does not buy external risk intelligence
Third-Party Management Suite Admin users and third-party inventory Everything in Base, plus Dow Jones ethics and compliance databases covering PEP, sanctions and watchlists, and adverse media screening No

One row out of nine is a genuine like-for-like comparison, and half of another. That is the honest shape of this decision: if you are buying OneTrust for consent, DSAR automation, data mapping or sanctions screening, no cheaper compliance platform replaces it, and you should be comparing it to privacy specialists instead. For a feature-level read on the overlap rather than a pricing one, see For the feature comparison rather than the pricing one, read OneTrust alternatives, Vanta alternatives and Drata alternatives.

PRICE TRANSPARENCY

Who publishes a price in this category, and who makes you ask

A OneTrust evaluation rarely stays a OneTrust evaluation. These are the platforms buyers most often put beside it, with one rule applied throughout: published figures only, or a clearly labeled third-party benchmark. Where a vendor publishes nothing, the table says so instead of guessing.

Platform Price published? Reported or published figures Where it fits beside OneTrust
OneTrust No. Nine products, the metric published, no rate Vendr, Feb 2026: median $11,970/yr, range $1,620 to $48,230, 307 purchases The broadest privacy and GRC suite available, built for organizations with a privacy team
TrustArc No figures on its own site No credible benchmark we are willing to publish The closest like-for-like privacy suite, usually shortlisted alongside OneTrust
Osano Yes, published tiers on its own pricing page Read the current figures on osano.com, they change Consent and privacy for smaller teams that found OneTrust oversized
Vanta No. Four tiers named, no figures Vendr, Feb 2026: median $20,000/yr, range $7,500 to $57,236 Chosen when the real requirement was SOC 2 readiness, not privacy operations
Drata No. Three tiers per platform, no figures Vendr, Feb 2026: median $24,868/yr, range $9,649 to $60,000. Publishes a 50 FTE cap on its entry GRC tier Same lane as Vanta, with two structural limits it does publish
AuditBoard (now Optro) No. Quote-only, CTA is schedule a demo Vendr, Feb 2026: median $45,895/yr, range $21,180 to $110,551, 85 purchases Enterprise internal audit and controls, a different buyer entirely
Complies Yes. Every tier and both billing terms $79, $199 and $499 per month billed yearly, or $95, $239 and $599 monthly The compliance half only, for 5 to 200 person companies with no privacy team

Two honest notes. Vendr figures are third-party records of contracts Vendr handled, not vendor rate cards, and your quote can land well outside them. And a median of $11,970 is not evidence that OneTrust is overpriced: it is a nine-product suite with regulatory research, a cookie database and sanctions screening behind it, and buyers who need those get real value. It is evidence that OneTrust and a $199 a month compliance tool are not competing for the same purchase. You will also find confident per-module figures in search results, along with a widely repeated claim that OneTrust now requires a $10,000 minimum annual contract. OneTrust has published neither, so we will not state either as fact. Put the minimum to your rep as a direct question instead, because if it is true it is the single most important thing to know before you scope.

CAPABILITIES

What you get on every Complies plan from Growth

The price is on the page

Starter $79 a month, Growth $199, Scale $499 at the yearly rate, or $95, $239 and $599 billed monthly. No demo gate, no discovery call, and no meter that quietly counts your website traffic.

One meter, and it is not your traffic

Your bill does not move because a campaign worked or because your data map finally found every system. There is no per-visitor band, no data subject profile count and no published headcount cap.

All five frameworks, no re-quote

SOC 2, ISO 27001, GDPR, HIPAA and PCI DSS are cross-mapped from Growth. When a customer asks for a framework you did not plan on, you add it rather than negotiate it. Finishing SOC 2 pre-fills roughly 60 percent of ISO 27001.

Monthly billing exists

You can pay monthly and leave. That is a real constraint on us and it is the point: the product has to earn its seat every cycle instead of coasting on an annual renewal clause.

Evidence that collects itself

Access reviews, change logs and monitoring settings stream in from AWS, GitHub, Google Workspace and Okta on a schedule, attached to the control they prove and the human who owns them.

A readiness score that will not flatter you

One number, plus a ranked gap list naming what is missing and who owns it. It never reads 100, because no tool can promise an audit outcome, and a score that always shows green is decoration.

BUYING

How to run a OneTrust evaluation without losing a quarter

01

Split the requirement in two before you take a call

Write down which of the nine products you actually need. Privacy operations (consent, DSAR, data mapping, preference management) and compliance operations (controls, obligations, evidence, policies) are separate purchases that happen to share a vendor. Teams that scope them together buy more than they use.

02

Ask what the meter counts, then ask where the bands are

OneTrust publishes the metric but not the thresholds. Get the band boundaries for visitors, profiles or inventory in writing, along with what happens when you cross one mid-term. This is the single highest-value question in the whole evaluation.

03

Price the modules you will need in year two, now

A Base tier quote is not a Suite tier quote, and DSR fulfillment, incident management and sanctions screening all sit in the Suite versions. Get indicative pricing for the upgrade path while you still have leverage, which is before you sign, not at renewal.

04

Price implementation and the auditor separately

Services are quoted apart from licenses, and no platform issues your SOC 2 report. Budget the CPA firm as its own line, typically $5,000 to $20,000 for a Type 1, and compare software against software.

05

Or skip the sales cycle for the compliance half

If what you needed was controls, obligations, evidence and policies across SOC 2, ISO 27001, GDPR, HIPAA and PCI DSS, Complies publishes the number. Sign up, connect AWS, GitHub, Google Workspace and Okta, and see a readiness score today.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You want to know what OneTrust costs before you sit through a discovery call.
  • You got a OneTrust quote and want an honest read on what you are being metered on.
  • You use one or two OneTrust modules and suspect you are paying suite money for them.
  • You are 5 to 200 people and a five-figure annual contract is a real budget decision.
  • You need the compliance half (controls, obligations, evidence, policies) and none of the privacy half.

LOOK ELSEWHERE WHEN

  • You need consent management, cookie banners, DSAR automation, data discovery or data mapping. Complies does none of those, and OneTrust is genuinely good at them.
  • You run a multi-jurisdiction privacy program with a dedicated privacy or legal team behind it.
  • You need Dow Jones sanctions, PEP or adverse media screening on third parties.
  • You need AI governance tooling aligned to the EU AI Act or ISO 42001.
  • Your procurement requires an annual contract, a named account team and a signed implementation plan.
QUESTIONS

Common questions about OneTrust pricing

OneTrust does not publish prices, so there is no official answer. The most credible third-party benchmark is Vendr, which reported a median OneTrust contract of $11,970 a year as of February 2026, across 307 purchases, ranging from $1,620 to $48,230. That range is very wide because OneTrust is nine products sold in different combinations, so where you land depends almost entirely on which modules you scope.

Not in dollars. As of August 2026 onetrust.com/pricing lists nine products and, for each one, the metric the price is based on, but attaches no figures to any of them. Every call to action reads Get Pricing or Get Customized Pricing, and the form asks you to schedule a quick call for a personalized quote based on your team size and business goals.

It varies by product, and OneTrust publishes each metric. AI Governance is priced on admin users and AI inventory. Consent Management is priced on average daily visitors across channels. Universal Consent and Preference Management is priced on total data subject profiles captured. Privacy Automation is priced on users and privacy asset inventory. Tech Risk and Compliance and both Third-Party products are priced on admin users plus asset or third-party inventory.

No. As of August 2026 the pricing page offers no free tier and no free trial on any of the nine products. Every path to the product runs through a sales conversation, which is normal for enterprise privacy software but does mean you cannot evaluate it the way you would evaluate a self-serve tool.

OneTrust does not publish one. A claim that OneTrust requires a $10,000 minimum annual contract from 2026 renewals circulates widely on competitor pricing blogs, and OneTrust has not confirmed it publicly, so we will not repeat it as fact. If you are a small buyer it is the first question to ask your rep, because a published minimum would decide your shortlist before any feature discussion.

Because most of what you pay for is research and data rather than software. The cookie database covers over 45 million categorized cookies, the third-party suite licenses Dow Jones sanctions, PEP and adverse media data, and the privacy modules carry DataGuidance regulatory intelligence. Maintaining those across jurisdictions is expensive, and if you need them, no cheaper tool has them. If you do not need them, you are paying for a library you never open.

It depends which half you use. For consent, cookie banners and DSAR automation the honest alternatives are privacy specialists such as Osano, Ketch, TrustArc or BigID, not us, because Complies does not ship any of those. For the compliance half, controls, obligations, evidence, policies and audit readiness across SOC 2, ISO 27001, GDPR, HIPAA and PCI DSS, Complies publishes its prices at $79 to $499 a month with monthly billing.

Usually not, and the price is only part of why. OneTrust expects a configuration project and an internal owner, and its value comes from breadth across jurisdictions that a 40-person company rarely has. If you are buying it because one enterprise customer asked for a cookie banner and a security questionnaire answer, you are buying a suite to solve two problems. Price the two problems separately first.

Scope narrowly, ask for the meter bands in writing, and get indicative pricing for the modules you expect to need in year two before you sign the first one. Vendr reports buyers saving about 20 percent off the opening quote across 307 purchases, which suggests there is real room, but the leverage is in scope and term rather than in asking for a discount on a number you cannot check.

No. Services are quoted separately from licenses, and a OneTrust deployment is a configuration project rather than a signup. Budget an internal owner for it as well as the services line, because the modules that deliver the most value, data mapping and third-party inventory in particular, are the ones that need the most internal input to populate.

Neither publishes a price, so the only comparison available is third-party. Vendr's February 2026 data puts the OneTrust median at $11,970 a year and Vanta at $20,000, but they are not substitutes: Vanta is a SOC 2 and ISO 27001 readiness platform and OneTrust is a privacy suite with a compliance module attached. Buyers who genuinely need to choose between them usually have not yet decided whether their problem is privacy or audit readiness.

Only for parts of it. If you need a cookie consent banner and automated DSAR handling at volume, you need a privacy tool and OneTrust is a strong one. If what you need is Article 30 records, DPAs, lawful basis documentation, a 72-hour breach process and Article 32 security controls tracked with owners and evidence, that is compliance work, and Complies cross-maps those controls into SOC 2 and ISO 27001 so you do it once.

GO DEEPER

Frameworks and guides

Compliance software with the price on the page

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.