Skip to content
complianceofficer

Blog · 23 Aug 2026 · 9 min read

Multi-entity compliance software pricing: what it costs per subsidiary, and how vendors actually count an entity

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The short answer: for a group with multiple legal entities, compliance software typically lands between $30,000 and $120,000 a year, against a single-entity median of roughly $20,000 to $54,000. The spread is not driven by headcount. It is driven by how your vendor defines an entity, and there are four common definitions that produce four very different numbers for the same corporate group. Get the definition written into the order form before you negotiate the rate.

No vendor in this category publishes a multi-entity price. On 23 August 2026 we opened the public pricing pages of seven of the most-shortlisted platforms, Vanta, Drata, Secureframe, Sprinto, Hyperproof, Onspring and LogicGate. All seven describe tiers or a licensing model. None of the seven shows a dollar figure. So the useful information is not a rate card. It is knowing which lever the salesperson is pulling.

How do vendors count an entity?

This is the question that decides your price, and almost nobody asks it during the demo. Four counting models are in common use. Ask which one you are being quoted on, then apply it to your own group before the first number arrives, because the same holding company can score 3 or 47 depending on the answer.

Counting model What counts as one unit Who it favors
Legal entity Every registered company in the group, including dormant and holding vehicles Nobody with a private-equity or real-estate style structure. This is the model that turns 40 dormant LLCs into 40 line items
Operating unit or business unit Each unit that runs its own processes and controls, regardless of legal wrapper Groups with many legal entities but one shared back office. Usually the cheapest honest model
Workspace or instance Each separated tenant with its own users, data and framework set Groups that genuinely need data separation between subsidiaries, usually for regulatory or deal reasons. Expensive but predictable
Framework instance Each combination of entity and framework, so one subsidiary on SOC 2 and ISO 27001 counts twice Almost nobody. This model compounds fastest and is the one most likely to surprise you at renewal

The framework-instance model is worth flagging because it is the one where growth is multiplicative rather than additive. Add a second framework across six subsidiaries and you have added twelve billable units, not one. If a quote is built that way, the renewal after your next certification push will be a different conversation than the one you are planning for.

What is the cost of enterprise privacy compliance software with multi-entity support?

For a privacy program specifically, expect the entity dimension to matter more than it does for security compliance, because privacy obligations attach to the legal person that controls the data. A group operating in several US states through separate entities may have genuinely different obligations per entity, and that is real work rather than a licensing artifact. Recorded contract data puts OneTrust, the most commonly shortlisted privacy platform, at a median of $11,970 a year with a recorded range from $1,620 to $48,230 and an average 20 percent discount off first quote. Multi-entity deployments sit in the upper half of that range.

The distinction that saves money here: separate legal entities do not automatically need separate privacy programs. If several subsidiaries share one privacy notice, one data map and one DSAR intake, you are running one program with several controllers named on it, and you should be quoted for one. If each entity genuinely has its own notice, its own retention schedule and its own regulator relationship, that is several programs and the price should reflect it. Decide which is true before the vendor decides for you. Our CCPA compliance software page covers the thresholds that determine which of your entities are even in scope, and the answer is often fewer than the whole group.

Why a holding company with 40 dormant LLCs gets quoted like an enterprise

This is the single most common multi-entity pricing failure, and it is avoidable. Real estate groups, private equity portfolios and franchise operators routinely hold dozens of registered entities that have no employees, no systems and no independent processes. Under a legal-entity counting model, every one of them is a billable unit. Under an operating-unit model, they are one.

The fix is to walk in with your own entity classification already done, split three ways: entities with their own systems and staff, entities that are legal wrappers over a shared back office, and entities that are dormant. Bring the list. A vendor that cannot price the second and third categories at or near zero is telling you something useful about how the renewal will go.

Producing that list is harder than it sounds in a group that has grown by acquisition, because the authoritative entity register usually lives in the consolidation system while the systems inventory lives somewhere else entirely. If getting a straight count means waiting three weeks for a controller's spreadsheet, a layer that lets you ask your own systems a question in plain English will get you a defensible number faster than the procurement cycle will.

Do subsidiaries need separate control frameworks?

Usually not, and assuming they do is expensive twice: once in license and once in testing hours. Where subsidiaries share systems, share a control owner and share a process, they share controls. You test the control once and rely on it across the entities it serves. The scoping question is whether the control actually operates the same way everywhere, not whether the entities are legally distinct.

Where they genuinely diverge is worth knowing in advance. A subsidiary running its own ERP instance needs its own IT general controls, because the access and change populations are separate. A subsidiary in a different regulatory regime, say a broker-dealer sitting inside a group that is otherwise unregulated, carries obligations nobody else in the group has. Our financial services compliance software page covers that case, where one entity in the group answers to FINRA and the rest do not, and our ITGC controls software page covers how a second ERP instance changes the IT scope.

What does a subsidiary actually add to the quote?

Rough working figures, based on how these deals are structured rather than on any published rate: an additional operating entity that shares systems and staff typically adds a small percentage to the platform fee, often in the range of 5 to 15 percent per entity, and tapers as the count rises. An additional entity with its own systems, its own framework set and its own users behaves more like a second deployment, commonly 40 to 70 percent of a standalone contract. A dormant entity should add nothing.

Then there is the line that surprises nearly everyone: implementation. Across this category it commonly runs 30 to 100 percent of first-year license, and multi-entity rollouts sit at the top of that band because each entity brings its own systems to integrate and its own owners to onboard. A quote that shows a modest per-entity license uplift and a flat implementation fee is either underscoping the rollout or planning to bill it later as professional services.

What to ask before you sign

  1. Which of the four counting models is this quote built on, and is the definition written into the order form rather than the proposal deck?
  2. What happens when we acquire a company mid-term, and what happens when we divest one? Acquisition pricing is usually addressed and divestiture almost never is.
  3. Are dormant and holding entities billable, and can we get them named as excluded?
  4. If we add a framework, does the entity count multiply against it?
  5. What is the uplift cap at renewal, per entity and overall? Multi-year deals in this category commonly step up in years two and three.
  6. Is implementation quoted per entity or for the group, and what is the trigger that turns a rollout into a change order?

Question two is the one most worth pushing on. Groups buy multi-entity platforms precisely because they expect the group to change shape, and a contract that prices acquisitions generously while treating divestitures as your problem quietly ratchets the fee upward through the term.

Is there a compliance platform with transparent multi-entity pricing?

Not among the major GRC vendors, based on the seven pricing pages checked on 23 August 2026. The closest thing to transparency in this market is aggregated buyer data from recorded contracts, which tells you what firms actually paid rather than what vendors ask. Medians there run from $11,970 for OneTrust and $20,000 for Vanta up to $49,420 for Workiva and $53,783 for LogicGate, with the full recorded range spanning roughly $1,620 to $153,365.

The average discount off first quote varies far more than most procurement teams assume, from about 11 percent on Workiva to about 30 percent on Vanta. A flat negotiating assumption is wrong at both ends of that spread. The full table, with sample sizes and the cost lines that never appear in a headline quote, is on our compliance software pricing comparison, and the SOX-specific version of this analysis is in SOX compliance software pricing. We publish our own pricing as a number rather than a form, which in this category is unusual enough to be worth saying out loud.

Pricing figures are from recorded buyer contracts on the Vendr marketplace, verified 22 and 23 August 2026. Vendor pricing pages checked 23 August 2026. These numbers move; treat any undated version of them as stale. Last updated August 2026.

General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.