- Device identity + built-in CA
- Endpoint agent + NAC visibility
- Threat & malware feeds
- Full community driver pack
- Single site · community support
Editions
Priced per site — by what you protect, not who you are.
One Skans appliance secures one site on one license. You're metered by managed endpoints — every device Skans gives an identity to: cameras, controllers, PLCs, switches, the server itself — not by seats, sockets, or agents. Community is free and runs in production; step a site up as it grows.
- Everything in Community, plus
- Patch management + enforcement
- Backup & disaster recovery
- Alerting & notifications
- Password & lockout baseline
- Email support
- Everything in Essential, plus
- NIST 800-171 / CMMC / ISO 27001 evidence
- 802.1X NAC, dynamic VLAN, segmentation
- Vulnerability management
- Log & topology fusion
- Business-hours support
- Everything in Professional, plus
- OT/ICS driver depth — S7-1500, Desigo, BACnet
- Industrial cert lanes (OPC UA GDS Push)
- Priority support
- Everything in Business, plus
- Distributed Core + Edge (per-site)
- High availability
- Air-gap Update Service + offline licensing
- SSO, advanced RBAC, full audit
- Dedicated support + SLA
Compare every edition.
Every capability, and exactly where it lands. Each edition includes everything in the one before it.
| Capability | CommunityFree | Essential$499 / yr | Professional$999 / yr | Business$2,999 / yr | EnterpriseContact |
|---|---|---|---|---|---|
| Identity & root of trust | |||||
| Enclave root of trust (on-prem CA) | ✓ | ✓ | ✓ | ✓ | ✓ |
| X.509 identity for every device | ✓ | ✓ | ✓ | ✓ | ✓ |
| Full per-vendor cert-push driver pack | ✓ | ✓ | ✓ | ✓ | ✓ |
| Credential vault | ✓ | ✓ | ✓ | ✓ | ✓ |
| Hardware-backed operator login (PIV / FIDO2) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Devices | |||||
| Managed endpoints per site | 25 | 100 | 500 | 1,000 | 1,000+ |
| Device discovery & inventory | ✓ | ✓ | ✓ | ✓ | ✓ |
| Multi-protocol discovery (ONVIF · scan · industrial) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Capability-tier classification (A / B / C) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Endpoint agent — Windows · Linux · macOS | ✓ | ✓ | ✓ | ✓ | ✓ |
| Network access control | |||||
| NAC visibility | ✓ | ✓ | ✓ | ✓ | ✓ |
| 802.1X EAP-TLS admission | — | — | ✓ | ✓ | ✓ |
| Dynamic VLANs + MAB for limited gear | — | — | ✓ | ✓ | ✓ |
| Legacy segmentation + security gateway | — | — | ✓ | ✓ | ✓ |
| Patch, firmware & backup | |||||
| Patch management + enforcement | — | ✓ | ✓ | ✓ | ✓ |
| Vetted, hash-verified firmware repository | — | ✓ | ✓ | ✓ | ✓ |
| Off-source encrypted backup + DR restore | — | ✓ | ✓ | ✓ | ✓ |
| Configuration & secret vaulting | — | ✓ | ✓ | ✓ | ✓ |
| Monitoring & threat intel | |||||
| Continuous monitoring (correlated findings) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Offline CVE + MITRE ATT&CK feeds | ✓ | ✓ | ✓ | ✓ | ✓ |
| Alerting rules, routing & notifications | — | ✓ | ✓ | ✓ | ✓ |
| Vulnerability management (matching + prioritisation) | — | — | ✓ | ✓ | ✓ |
| Log & topology fusion | — | — | ✓ | ✓ | ✓ |
| Compliance | |||||
| NIST 800-171 / CMMC control mapping | — | — | ✓ | ✓ | ✓ |
| ISO 27001 crosswalk (93 Annex A controls) | — | — | ✓ | ✓ | ✓ |
| Signed evidence-pack export | — | — | ✓ | ✓ | ✓ |
| Audit log & change approvals | — | — | ✓ | ✓ | ✓ |
| OT / ICS depth | |||||
| OT/ICS driver depth (S7-1500 · Desigo · BACnet/SC) | — | — | — | ✓ | ✓ |
| OPC UA GDS Push certificate management | — | — | — | ✓ | ✓ |
| Industrial protocol gateways | — | — | — | ✓ | ✓ |
| Scale, availability & governance | |||||
| Distributed Core + Edge (per-site) | — | — | — | — | ✓ |
| High availability | — | — | — | — | ✓ |
| Air-gap Update Service + offline licensing | — | — | — | — | ✓ |
| SSO / OIDC single sign-on | — | — | — | — | ✓ |
| Advanced RBAC & full audit | — | — | — | — | ✓ |
| Support | |||||
| Support | Community | Business-hours | Priority | Dedicated | |
| Uptime SLA | — | — | — | — | ✓ |
Prices are annual, in USD, per site. Multi-site estates license each site — distributed Core + Edge deployments license each Edge. Talk to us about site packs and volume.
Managed endpoints counts devices under active Skans management — identity, certificates, policy, or monitoring. The endpoint agents running on those devices are never metered separately.