Capabilities
100,000+ companies on the exchange.
2,000,000+ organizations scanned daily.
170,000 supported organizations
1,000,000+ companies rated.
RiskRecon distills its assessment criteria into a single score from 0-10.
Usability and the learning curve
Risks detailed on point-in-time vendor assessment coupled with continuous monitoring of inherent risk, threat intelligence, and risk scoring. The exchange model forces more frequent point in time assessments, as many as 2-3 times each year.
High-level summation of risk with the ability to drill down into precise technical details.
Provides high-level summation of vendor risk allowing easy comparison of vendors.
Simple interface for quick grade reports and charts.
Provides risk prioritization based on your configured policy.
Community support
Company and product blog.
UpGuard Summit brings together a community of security leaders from leading companies, explores the future of security and helps businesses stay secure. The UpGuard cybersecurity and risk management blog is updated four times a week and our breach research blog has uncovered and secured some of the largest data breaches.
Company and product blog.
Company and product blog.
Company and product blog.
Release rate
Agile release methodology for both the SaaS platform and content.
UpGuard has adopted DevOps principles internally to develop, test, and release software continuously, ensuring fast, consistent, and safe releases.
Pricing and support
There is no public pricing available for CyberGRX, making it hard to know how much you would pay without talking to them.
UpGuard has a transparent pricing model which you can view here. UpGuard pricing starts at $5k/year and scales with your company.
Public pricing information is not available. Pricing is reported to start at $20,000 plus $2,000-$2,500 per vendor per year.
Public pricing information is not available. Reports say pricing starts at $16,500 for self-assessment plus five vendors, and additional vendors cost $1,500-$2,000 per vendor per year.
Public pricing information is not available. Pricing is reported to start at $10,000 and increases based on the number of vendors monitored.
API and extensibility
Fully functional bidirectional API.
UpGuard offers a standard API to pull data into other enterprise applications.
Third-party integrations
Integrates with multiple GRC platforms (using connectors), visualization tools, ticketing systems, and SOC tools.
Integrates with GRC platforms, ticketing systems like ServiceNow, and more.
Offers integrations with RSA Archer GRC, CyberGRX, OneTrust Vendorpedia, ProcessUnity, MetricStream, and more.
Offers integrations with GRC platforms such as RSA Archer.
Offers integrations with GRC platforms such as RSA Archer, Sigma Ratings, Whistic, and more.
Customers
Fortune 500 companies across several sectors (including Financial Services, Healthcare, Retail, and Technology), and across geographies including North America, Europe, and APAC markets.
NASA, the New York Stock Exchange (ICE), Morningstar, Akamai, Bill.com, IAG, and ADP. Read our customer stories.
Customers include The University of North Florida, Snam, EPAM, and PROSA.
Customers include Symantec, Pepsico, Two Sigma, and Stony Brook University.
Customers include Informatica, Tufts Health Plan, University of San Francisco, and Sentara.
Predictive capabilities
Checks for misconfigurations across Internet footprint and covers breach vectors such as phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data breach incidents are captured, and notice is provided.
As UpGuard checks for misconfigurations across your Internet footprint, many important breach vectors are covered, including phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data leaks are automatically surfaced by the platform for your team to assess and close before they become breaches.
The IP reputation methodology helps catch active malware installations, but that’s only one possible way a data breach can occur.
The IP reputation methodology helps catch active malware installations, but that's only one possible way a data breach can occur. Yes, they use additional data but lack the transparency to prove the efficacy of their scores
Focuses on third-party assessment across 11 security domains and 41 security criteria.
Security rating
Capabilities
100,000+ companies on the exchange.
Usability and the learning curve
Risks detailed on point-in-time vendor assessment coupled with continuous monitoring of inherent risk, threat intelligence, and risk scoring. The exchange model forces more frequent point in time assessments, as many as 2-3 times each year.
Community support
Company and product blog.
Release rate
Agile release methodology for both the SaaS platform and content.
Pricing and support
There is no public pricing available for CyberGRX, making it hard to know how much you would pay without talking to them.
API and extensibility
Fully functional bidirectional API.
Third-party integrations
Integrates with multiple GRC platforms (using connectors), visualization tools, ticketing systems, and SOC tools.
Customers
Fortune 500 companies across several sectors (including Financial Services, Healthcare, Retail, and Technology), and across geographies including North America, Europe, and APAC markets.
Predictive capabilities
Checks for misconfigurations across Internet footprint and covers breach vectors such as phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data breach incidents are captured, and notice is provided.
Security rating
Capabilities
2,000,000+ organizations scanned daily.
Usability and the learning curve
High-level summation of risk with the ability to drill down into precise technical details.
Community support
UpGuard Summit brings together a community of security leaders from leading companies, explores the future of security and helps businesses stay secure. The UpGuard cybersecurity and risk management blog is updated four times a week and our breach research blog has uncovered and secured some of the largest data breaches.
Release rate
UpGuard has adopted DevOps principles internally to develop, test, and release software continuously, ensuring fast, consistent, and safe releases.
Pricing and support
UpGuard has a transparent pricing model which you can view here. UpGuard pricing starts at $5k/year and scales with your company.
API and extensibility
UpGuard offers a standard API to pull data into other enterprise applications.
Third-party integrations
Integrates with GRC platforms, ticketing systems like ServiceNow, and more.
Customers
NASA, the New York Stock Exchange (ICE), Morningstar, Akamai, Bill.com, IAG, and ADP. Read our customer stories.
Predictive capabilities
As UpGuard checks for misconfigurations across your Internet footprint, many important breach vectors are covered, including phishing, ransomware susceptibility (like WannaCry), man-in-the-middle attacks, DNSSEC, vulnerabilities, email spoofing, domain hijacking, and DNS issues. Data leaks are automatically surfaced by the platform for your team to assess and close before they become breaches.
Capabilities
170,000 supported organizations
Usability and the learning curve
Provides high-level summation of vendor risk allowing easy comparison of vendors.
Community support
Company and product blog.
Release rate
Pricing and support
Public pricing information is not available. Pricing is reported to start at $20,000 plus $2,000-$2,500 per vendor per year.
API and extensibility
Third-party integrations
Offers integrations with RSA Archer GRC, CyberGRX, OneTrust Vendorpedia, ProcessUnity, MetricStream, and more.
Customers
Customers include The University of North Florida, Snam, EPAM, and PROSA.
Predictive capabilities
The IP reputation methodology helps catch active malware installations, but that’s only one possible way a data breach can occur.
Security rating
Capabilities
1,000,000+ companies rated.
Usability and the learning curve
Simple interface for quick grade reports and charts.
Community support
Company and product blog.
Release rate
Pricing and support
Public pricing information is not available. Reports say pricing starts at $16,500 for self-assessment plus five vendors, and additional vendors cost $1,500-$2,000 per vendor per year.
API and extensibility
Third-party integrations
Offers integrations with GRC platforms such as RSA Archer.
Customers
Customers include Symantec, Pepsico, Two Sigma, and Stony Brook University.
Predictive capabilities
The IP reputation methodology helps catch active malware installations, but that's only one possible way a data breach can occur. Yes, they use additional data but lack the transparency to prove the efficacy of their scores
Security rating
Capabilities
RiskRecon distills its assessment criteria into a single score from 0-10.
Usability and the learning curve
Provides risk prioritization based on your configured policy.
Community support
Company and product blog.
Release rate
Pricing and support
Public pricing information is not available. Pricing is reported to start at $10,000 and increases based on the number of vendors monitored.
API and extensibility
Third-party integrations
Offers integrations with GRC platforms such as RSA Archer, Sigma Ratings, Whistic, and more.
Customers
Customers include Informatica, Tufts Health Plan, University of San Francisco, and Sentara.
Predictive capabilities
Focuses on third-party assessment across 11 security domains and 41 security criteria.
Security rating
All comparisons
We want you to choose the best platform for you, even if it’s not us.
Sign up to our newsletter
Get the latest curated cybersecurity news, breaches, events and updates in your inbox every week.


Free instant security score
How secure is your organization?
Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
- Instant insights you can act on immediately
- Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

Book a free demo
Book a free, personalized onboarding call with one of our cybersecurity experts.