SOC 2 / multi-framework compliance automation platform Β· verified
Strike Graph
We previously described Strike Graph as the only platform in our set with published pricing and a free tier; the published-numbers part still holds as of 2026-07-24 (Certify $10,000/yr, Scale $21,500/yr, Enterprise $35,000/yr, all confirmed on the live pricing page).
The "free tier" framing needs softening: the free option is a separate, lead-form-gated signup (strikegraph.com/start-for-free) capped at 15 evidence attachments and two integrations (Office 365, Google Drive), not a persistent free plan inside the Certify/Scale/Enterprise comparison table -- it reads more like a limited trial/lead magnet than a standing freemium tier of the actual compliance product. Framework add-on pricing is granular and can add up fast: a Certify customer adding ISO 27001 plus an internal audit and a penetration test could add $20K+/yr on top of the $10,000 base.
Desk research against public sources. Every figure below carries its source and the date we retrieved it.
Strike Graph publishes a price.
You can read the numbers without a sales call, which is uncommon in this category and worth weighing on its own.
- Disclosure model
- Published, $10Kβ$35K/yr
- Observed range
- USD 10,000β35,000 / year
- Basis
- Confirmed, 2026-07-24
Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.
What Strike Graph does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Vendor claims automated evidence collection from 300+ systems and 50,000+ data points, with scheduled refresh and an Evidence API for custom sources. Source |
| Auditor workspace | Yes | Pricing/comparison table lists a dedicated "Auditor Role" permission and full audit-workbook export across all plans; vendor states the platform works with any independent auditor the customer chooses. Source |
| Trust center | Yes | "Trust Center" and "Trust asset library" are listed as plan features; also a dedicated nav item (strikegraph.com/trust-chain area). Source |
| Security questionnaire answering | Yes | "Questionnaires" (AI-assisted response generation from implemented controls) is a paid add-on on the Certify plan and included from Scale up. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | SSO is confirmed (paid add-on on Certify at $3k/yr, included Scale+) and role management/multi-domain users are confirmed on the pricing table. SCIM is not mentioned anywhere on the pricing or integrations pages, so provisioning depth is unconfirmed -> marked partial rather than yes. Source |
| SCIM 2.0 provisioning | Yes | Strike Graph's own changelog records expanding SCIM support to cover deactivation, reactivation and role mapping from the identity provider, so it exists today rather than being newly launched. The tier is the gap: its pricing table is granular enough to price SSO as a $3k add-on on the entry tier and include it above, and never mentions SCIM at all. Source |
| Continuous control testing | Yes | "Control monitoring" and "Automated Collection" are listed as included features across all three plans, and the integrations page describes evidence updating on a defined schedule rather than only at audit time. Source |
| Native multi-framework support | Partial | Vendor's own language: "New frameworks are automatically mapped to your existing controls" and the pricing page sells "Cross-framework mappings" as a named feature -- this is explicitly a crosswalk-mapping model, not independently built native control sets per framework. Source |
8 frameworks, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Listed as a Tier 1 framework on the current pricing page; also has a dedicated SOC 2 solution page (strikegraph.com/soc2). Source |
| ISO 27001 | Vendor-claimed | Tier 2 framework; add-on pricing shown ($5k-$8k/yr depending on plan). Source |
| HIPAA | Vendor-claimed | Tier 1 framework; HIPAA certification add-on priced separately ($4k-$5k/yr). Source |
| GDPR | Vendor-claimed | Tier 1 framework. Source |
| ISO 27701 | Vendor-claimed | Tier 1 framework, pre-seeded alongside SOC 2/HIPAA/GDPR. Source |
| PCI DSS | Vendor-claimed | Tier 2 framework. Source |
| NIST 800-171 | Vendor-claimed | Tier 3 framework. Source |
| CCPA | Vendor-claimed | Tier 1 framework. Source |
Who actually issues the report.
Strike Graph is compliance software, not a CPA firm, and does not issue the SOC 2 report itself. The platform states it is compatible with any independent auditor the customer already uses, and separately offers to connect customers with vetted independent auditors through its own partner network if they don't have one; audit/assessment services through that network are priced separately ($4K-$8K/yr per the pricing FAQ).
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Strike Graph is for, and who it is not.
Good fit
A company that wants to see real dollar figures before a sales call: Strike Graph is one of the few vendors in this set that puts specific starting prices ($10,000 / $21,500 / $35,000 per year) and most framework add-on costs directly on its public pricing page.
Poor fit
A pre-revenue or bootstrapped startup with no live deal forcing SOC 2 right now should not commit to a paid plan yet -- the cheapest published tier (Certify) still starts at $10,000/year, and several core AI/questionnaire features are reserved for the $21,500/year Scale tier and above.
Typical buyer: Growth-stage SaaS/tech companies that need SOC 2 plus one or more adjacent frameworks (HIPAA, ISO 27001, GDPR) and want a single platform with published, plan-based pricing..
Where every figure on this page came from.
7 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Live, current pricing: Certify $10,000/yr, Scale $21,500/yr, Enterprise $35,000/yr; framework tiers and add-on prices; feature comparison table including Auditor Role, SSO, Trust Center, control monitoring. https://www.strikegraph.com/pricing
- Details of the free signup: capped at 15 attachments, risk assessment, Office 365/Google Drive integrations, expert support -- a lead-gated limited account rather than a listed plan tier. https://www.strikegraph.com/start-for-free
- 300+ systems/tools and 50,000+ data points for automated evidence collection; Evidence API option. https://www.strikegraph.com/integrations
- "Strike Graph has been rated 4.7 stars by 193 verified reviews on G2" (per Google/Serper cached snippet; direct G2 page fetch was blocked by DataDome anti-bot protection). https://www.g2.com/sellers/strike-graph
- $3.9M seed round, Oct 2020, led by Madrona Venture Group. https://techcrunch.com/2020/10/05/strike-graph-raises-3-9-million-to-help-automate-security-audits
- 2023 funding round (reported as $7M by GeekWire vs $8.5M in the vendor's own release) and a cumulative total of $18.9M reported at that time. https://www.geekwire.com/2023/compliance-automation-startup-strike-graph-lands-7m-to-expand-certification-offerings
- $8.5M funding round led by BAMCAP with Madrona and Information Venture Partners, Dec 2023; Jim Sheward (BAMCAP) joined the board. https://www.corporatecomplianceinsights.com/strike-graph-funding-2023
β All SOC 2 compliance software Β· How we verify
Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.
Something here out of date?
Every figure above carries a source and the date we read it. If one has moved, send us the current source and we will update the record.
Verification is free and always will be. It does not change where Strike Graph appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.