Technical evaluation

vCISO Lite versus Panorays

Adjacent categories. Panorays runs a continuous cyber-rating engine at scale — Forrester Wave TPCRM Leader Q2’26. vCISO Lite scans externally inside engagements (red-team, QCD, DC-TPIR), not as an always-on rating engine. We lead on DC-TPIR, Evidence Graph, and APRI callable from your own agent stack, from $299/mo.

Prepared
Method
Capability walk against Panorays’s published product surface (panorays.com, panorays.com/about-us, panorays.com/platform, panorays.com/blog) and vCISO Lite’s live platform.
Sources
panorays.com, panorays.com/about-us, Panorays Q2’26 Forrester Wave TPCRM Leader announcement, Panorays ISO/IEC 42001 certification announcement, vcisolite.com/pricing, vcisolite.com/services, vcisolite.com/briefs-and-specs. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where Panorays leads

  • Continuous cyber-rating engine at scale. Panorays runs continuous scans on each vendor — DNS, TLS, exposed management interfaces, credential-leak monitoring, threat-intel feed correlation — always-on across the whole vendor tail, feeding Risk DNA (99.8% claimed accuracy). Same category as BitSight and SecurityScorecard. vCISO Lite ships external scanning inside three engagement-driven surfaces (red-team, QCD diligence, DC-TPIR) but not as an always-on cyber-rating engine at 200+ vendor scale — different shape.[1]
  • Q2’26 Forrester Wave TPCRM Leader. Dated, specific analyst placement in the exact category they operate in. Reduces sales-cycle friction for procurement.
  • ISO/IEC 42001 certified AI-governance management system. First TPCRM vendor with the cert — a management-system cert on how they operate their AI, not on whether the AI’s answers are correct. For buyers whose procurement filter includes “is your AI operated responsibly,” this is a real procurement signal.[6]
  • Nth-party (4th, 5th) supply-chain discovery. Crawls each vendor’s own vendor list from public sub-processor pages, DPAs, trust-center pages. Real capability with a real coverage boundary (only sees what vendors publish). vCISO Lite doesn’t ship an equivalent.[5]
  • Named enterprise customer roster at scale. Real references we don’t match today.
  • Incident Response Portal. Alert-routing + task-tracking + communications workflow. Real but generic workflow, not codified per-incident-type playbooks.[2]

Where vCISO Lite leads

  • DC-TPIR — codified vendor-incident-response product. Dependency-Centric Third-Party Incident Response, under the Allotrope umbrella; source methodology is Yolonda’s 2026 book Someone Else’s Breach.[2] Per-incident-type playbooks with MSA contractual mapping and comms templates for internal execs / affected customers / regulators. Panorays ships an Incident Response Portal — real, but generic workflow, not codified per-incident-type playbooks.
  • Evidence Graph — externally-anchored, SDK-licensable. Every vendor artifact Ed25519-signed and anchored to an external RFC-3161 timestamp authority, so a SOC 2 auditor or cyber-insurance carrier can prove the chain wasn’t tampered with, without trusting vCISO Lite.[3] Panorays’s audit-trail is platform-internal; no external-anchor mechanism disclosed on the product surface.
  • QCD Pillar 2 — portfolio-level HHI concentration. Tells your CFO — as a dollar figure — how much you’re on the hook for if your most-concentrated vendor exposure turns bad. Panorays’s Risk DNA scores individual vendors; the portfolio-concentration answer isn’t in it.[4]
  • Vendor operations run in the tools your team already uses. Your Claude, your Cursor, your internal LLM, your partner’s agent stack — any MCP-speaking client — can call APRI directly to compute vendor exposure, draft a CAIQ / SIG response with cited evidence, pull the vendor inventory, or submit an assessment. Every LLM-driven action still writes to the Evidence Graph so the audit chain survives. Panorays’s Native AI and Agentic AI stay inside their platform login.[7]
  • Starts at $299/mo. 5 vendors + 5 vendor questionnaires answered per month; every tier on /pricing. Panorays does not publish tier pricing without a scoping call.[9]
  • Platform + services on the same SKU. vCISO Lite ships the platform and productized TPRM services (managed CAIQ / SIG completion, analyst-driven vendor assessments) on /services. Panorays ships the platform only.
  • Broader compliance program on the same SKU. Panorays is TPCRM only; the buyer pairs it with a separate GRC platform for SOC 2 / ISO 27001 / HIPAA / PCI DSS / DORA broader coverage. vCISO Lite bundles all of those on the Enterprise tier alongside vendor-risk.
  • Trustworthy Autonomy. Public beta since 2026-07-07; Level 1 agent governance proven prod 2026-08-17; published evaluation harness grades the agent by task category before purchase.
  • Founder-direct. [email protected] reaches the founder, not an SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
Security teams weighing whether to run their vendor-risk work inside an external cyber-ratings engine (Panorays) or inside a broader vCISO + GRC + services program (vCISO Lite). Also useful for buyers already committed to Panorays who want to see what codified vendor-incident-response and portfolio-concentration analysis look like on a separate SKU.
Evaluation frame
Ten capability categories the TPRM / TPCRM buyer typically weighs. Not: everything each vendor does.
Comparison basis
Both vendors’ published product surfaces (product pages, platform pages, about pages, analyst-award announcements). Not: NDA material, unreleased roadmap, or third-party analyst reports behind paywalls.

Out of scope

Continuous cyber-rating engine at scale
If the buyer’s primary need is always-on cyber posture scoring across 200+ vendors with per-vendor rating rollup, Panorays / BitSight / SecurityScorecard is the honest answer. vCISO Lite does external scanning inside engagements (red-team, QCD diligence, DC-TPIR) but does not ship a continuous rating engine priced per vendor tail.
Israeli / EMEA regional depth
Panorays is New York + Israel headquartered with real EU (DORA-specific compliance monitoring) and UK enterprise adoption. This page compares capability substance, not regional buyer preference.
Attack-surface-management overlap with BitSight / SecurityScorecard
Panorays overlaps with BitSight and SecurityScorecard on the cyber-ratings engine. Whether Panorays or BitSight or SecurityScorecard is the right pick within that category is a separate evaluation the buyer should run directly against those three.

Capability coverage

Ten capabilities§3

Amber = Panorays ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

Regulatory Compliance Monitoring · DORAframework mapping · reporting dashboards · portfolio-level compliance viewAgentic AIautomated remediation · Nth-party discovery agentsISO/IEC 42001 certifiedNative AI QuestionnairesAI reads evidence → completes cybersecurity questionnairesSmart Inventory · Supply Chain DiscoveryNth-party (4th, 5th) discovery · hidden relationship mappingCybersecurity Questionnairesstructured questionnaire data model · response trackingRisk DNA — per-vendor cybersecurity composite score99.8% claimed accuracy · continuous refresh · portfolio-rollupExternal Attack Surface Management · scanningDNS · TLS · exposed services · cred-leak · threat-intel feeds
Panorays stack, bottom-up.The dashed base — external attack-surface scanning — is the primary technical asset. Risk DNA composites it into the per-vendor score; everything above is questionnaire layer, agentic remediation, and compliance rollup. vCISO Lite doesn’t compete on the scanner base.
§4.1

External attack-surface scanning

Different shape, not different presence. Panorays runs continuous cyber-rating at scale; vCISO Lite runs external scanning inside engagements — deep and episodic, not continuous and broad.

Panorays

Continuous scans on each vendor: DNS records, TLS certificate posture, exposed management interfaces, credential-leak monitoring (HIBP-style), threat-intel feed correlation. Always-on across the whole vendor tail. Feeds Risk DNA composite score (99.8% claimed accuracy — retrospective breach-outcome correlation, not real-time precision/recall).

Inputs
Vendor domain lists; distributed scanner infrastructure; threat-intel feeds (sources not publicly named).
Outputs
Per-vendor Risk DNA score, continuous refresh; portfolio rollup.
Evidence
Public product page and Forrester Wave Q2'26 recognition.
Fails when
Buyer's need isn't cyber posture on the vendor tail but rather codified vendor-incident response, portfolio-concentration analysis, or an audit trail an untrusting auditor can re-derive.
vCISO Lite

External scanning ships inside three surfaces. (1) The red-team service applies it as part of engagement-driven adversarial testing. (2) The QCD (Quantitative Cyber Diligence) service applies it to an M&A target's external footprint as part of the five-pillar CCOD analysis. (3) DC-TPIR uses it to determine whether a vendor has been exploited or is currently vulnerable during incident response. Deep + episodic, not always-on cyber rating.

Inputs
Engagement scope (red-team), M&A target (QCD), or vendor under active incident review (DC-TPIR).
Outputs
Engagement findings signed to the Evidence Graph; QCD pillar-1 attack-surface loss estimate; DC-TPIR exploitation-status determination inside the incident playbook.
Evidence
External scanning capability exists across three shipped surfaces. The packaging is engagement-driven, not a continuous rating engine priced per vendor tail.
Fails when
Buyer needs continuous cyber ratings on 200+ vendors as a monitored, always-on service with per-vendor score rollup — that's a different shape than what vCISO Lite ships. Panorays / BitSight / SecurityScorecard is the honest answer for that specific need.
§4.2

Vendor-incident-response as codified product

Panorays ships an Incident Response Portal — real, but generic workflow. DC-TPIR is codified per-incident-type playbooks.

Panorays

Incident Response Portal — 'go from alert to action in seconds, assign tasks, and track progress from one dedicated Incident Response Portal.' Generic workflow: alert triggers task, task gets assigned and tracked, comms happen through the portal.

Inputs
Risk DNA drop below threshold, external scan alert, vendor questionnaire response gap.
Outputs
Tracked task list, communication log.
Evidence
Panorays homepage names the Incident Response Portal specifically.
Fails when
Buyer needs a codified, named playbook per third-party incident type (vendor breach, ransomware at vendor, business-continuity failure, regulatory disclosure obligation) with contractual mapping and communication templates. The Panorays portal is workflow, not codified per-incident-type playbook.
vCISO Lite DC-TPIR

DC-TPIR ships codified per-incident-type playbooks with MSA contractual mapping and comms templates, every step Ed25519-signed to the Evidence Graph so a regulator, insurance carrier, or M&A diligence reviewer can prove after the fact that response happened per playbook — without trusting vCISO Lite.

Inputs
Third-party incident signal · vendor tier data · contractual exposure · business dependency graph.
Outputs
Per-incident-type response playbook · MSA contractual-obligation mapping · communication templates · executive briefing PDF · Evidence Graph record of every action.
Evidence
Source methodology is Yolonda's 2026 book Someone Else's Breach; executive brief on /briefs-and-specs.
Fails when
N/A — Panorays's Incident Response Portal is generic workflow, not codified per-incident-type playbook.
§4.3

Evidence integrity substrate

Panorays records land in a platform-internal store. vCISO Lite writes to a re-derivable, externally-anchored chain.

Panorays

Vendor records, Risk DNA scores, Nth-party discovery findings, agentic remediation actions land in the platform's internal store. No external-anchor mechanism, no per-event cryptographic signing, no transparency log surfaced on the product page. The ISO/IEC 42001 cert is on their AI-governance management system, not on the audit-trail substrate.

Inputs
Every vendor action, scan result, questionnaire response, agent output.
Outputs
Internal audit records readable through the platform UI + export.
Evidence
Public product surface has no reference to RFC-3161, Ed25519, or transparency-log mechanisms.
Fails when
Adversarial auditor asks to verify a specific vendor assessment independently against an external record; the audit-trail requires trusting Panorays to trust the record.
vCISO Lite Evidence Graph

Every vendor artifact — questionnaire responses, risk decisions, APRI answers, autonomous actions — is Ed25519-signed and anchored to an external RFC-3161 timestamp authority, so a SOC 2 auditor or cyber-insurance carrier can prove the chain wasn't tampered with, without trusting vCISO Lite.

Inputs
Every agent action, evidence artifact, policy decision, framework mapping, vendor-incident response step.
Outputs
Sealed evidence chain · external timestamp attestation · re-derivable proof.
Evidence
SDK-licensable since 2026-08-15 — partners and insurance carriers can embed the same integrity properties.
Fails when
Buyer's existing audit tooling has not been briefed on RFC-3161 verification; onboarding the audit firm to the chain takes one call.
§4.4

Where the AI actually runs — inside the vendor's UI vs callable from the buyer's stack

Panorays's Native AI and Agentic AI live inside their platform. vCISO Lite exposes vendor operations as callable tools any MCP-speaking client can invoke.

Panorays

Native AI Questionnaires (autofill from vendor-uploaded evidence) + Agentic AI (automated remediation + Nth-party discovery agents) — both live inside the Panorays UI. The buyer accesses the AI through Panorays's screens; no public API or agent-facing surface for external LLMs.

Inputs
Uploaded vendor evidence, questionnaire templates, external scan data — all provided through the Panorays UI.
Outputs
Auto-populated questionnaire responses; agentic remediation workflows; discovered Nth-party relationships.
Evidence
Panorays product page describes Native AI and Agentic AI as platform capabilities. Nothing on the public surface describes an external-agent-callable interface.
Fails when
Buyer's security team lives in Claude / Cursor / their own LLM and wants vendor-risk work to happen there. Or a partner (insurance carrier, M&A diligence firm) wants to wire vendor answers into their own agent stack. Or an autonomous agent needs to invoke vendor operations continuously.
vCISO Lite APRI

APRI exposes vendor operations (compute_vendor_exposure, create_vendor_assessment, get_vendor_inventory, submit_vendor_assessment_for_review) as callable tools any MCP-speaking client — Claude, Cursor, custom LLM, autonomous loop — can invoke, so vendor-risk work happens where your team already sits.

Inputs
Whatever context the invoking agent has — a question, a document reference, a vendor alert, a workflow step from another MCP server (Jira, GitHub, Slack).
Outputs
Cited answers grounded in the customer's evidence chain · questionnaire responses with per-question citations · vendor tier changes · exposure computations. Every output signed to the Evidence Graph regardless of which agent invoked it.
Evidence
Three architectural guarantees make the composability safe: caller-entitlement scoped (uses the invoking user's entitlements, not a service account), complete tool-call audit trail (Ed25519-signed on the Evidence Graph), observe-first (writes go through a confirmation gate).
Fails when
Buyer's primary constraint is 'continuous external cyber ratings' rather than 'my team's agents need to reach vendor operations' — Panorays's scanner is not something APRI substitutes for.
§4.5

Portfolio-concentration risk

Panorays Risk DNA scores individual vendors. QCD Pillar 2 applies portfolio-level HHI concentration analysis.

Panorays

Risk DNA — per-vendor cybersecurity composite score. Individual-vendor continuous rating. Portfolio-level concentration analysis is not surfaced.

Inputs
External scan data + questionnaire responses + threat feeds.
Outputs
Continuous per-vendor risk score, tunable weights.
Evidence
Public product page describes the score as continuous and per-vendor.
Fails when
Buyer needs portfolio-level concentration analysis — 'we depend too heavily on one vendor category or one vendor.' Individual-vendor scoring does not surface this.
vCISO Lite QCD Pillar 2

QCD Pillar 2 tells your CFO — as a dollar figure — how much you're on the hook for if your most-concentrated vendor exposure turns bad. Panorays's Risk DNA scores vendors one at a time; the portfolio-concentration answer isn't in it.

Inputs
Vendor inventory + per-vendor Max Single-Vendor Loss estimate + portfolio-level HHI computation.
Outputs
Expected Annual Cost from concentration · P90 tail figure · portfolio-level risk narrative for board reporting.
Evidence
Codified from Yolonda's 2026 book Someone Else's Debt.
Fails when
Buyer needs continuous refresh on individual vendor cyber ratings (Panorays's Risk DNA is designed for that) rather than portfolio concentration.

Framework & control coverage

Framework depth§5

Panorays surfaces DORA as a first-class framework in its Regulatory Compliance Monitoring layer and covers broader compliance through general framework mapping. vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls)— every SCF-mapped control unlocks the frameworks that share it.

Panorays[6]

DORA
SOC 2
ISO 27001
NIST CSF
HIPAA
PCI DSS
GDPR
NYDFS 500

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

Direct-buy floor vs enterprise implementation§6

Panorays is sales-led with no dollar figure surfaced without a scoping call (free-trial entry available on some tiers). vCISO Lite starts at $299/mo Starter (5 vendors + 5 vendor questionnaires answered), with additional tiers on /pricing. And vCISO Lite ships productized TPRM services on top of the platform — Panorays ships the platform only.

Panorays

Enterprise SaaS

Contact-sales · free-trial entry on some tiers · no public dollar figure[9]

Sold to
Security-team buyers at mid-market to enterprise scale — fintechs, retailers with big vendor tails, security-conscious SaaS
Published tiers
None — contact-sales for pricing
Free-trial entry
“Start Free Trial” / “Get Started Free” on entry tiers
Delivery model
Sales-led · demo-gated · enterprise implementation
Sales cycle
Request-a-demo → scoping call → contract
vCISO Lite

From $299/mo

Direct-buy from Starter · every tier on /pricing

Starter
$299/mo — 5 vendors + 5 vendor questionnaires answered per month. Additional tiers on /pricing.
Platform + services
vCISO Lite ships the platform and productized TPRM services (managed CAIQ / SIG completion, analyst-driven vendor assessments) on /services. Panorays ships the platform only.
Sales cycle
Direct-buy end-customer · Enterprise: one call, flat MSRP on file · no scoping-call gate to see a price

Integration surface

Native connectors§7

Panorays lists integrations on the platform surface but does not enumerate a public catalog. vCISO Lite’s full catalog is on /features/integrations.

IntegrationPanoraysvCISO Lite
AWSNative
AzureNative
GCPNative
SnowflakeNative
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365Native
OktaNative
JiraNative
SlackNative
ServiceNowNative
MCP (Model Context Protocol)Native
External scanner (attack-surface)Native
Threat-intelligence feedsNative
Integration catalog published?Referenced, not enumeratedFull catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributePanoraysvCISO Lite
Service modelSaaS multi-tenant · TPCRM specialist · attack-surface scanner + AI questionnaire layerSaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request
Public APINot enumerated on public product surfaceREST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0
SSO / SCIMNot publicly disclosed on product pageSAML 2.0 · OIDC · SCIM 2.0
Audit-trail modelPlatform-internal store · no external anchor / per-event signing / transparency log disclosedEvidence Graph · hash-chained per-event · Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Vendor-incident-response productIncident Response Portal — alert routing + task tracking + comms (generic workflow)DC-TPIR (Dependency-Centric Third-Party Incident Response) — codified per-incident-type playbooks with MSA contractual mapping and comms templates; methodology from Yolonda’s Someone Else’s Breach
Where the AI actually runsInside the Panorays UI · buyer’s Claude / Cursor / partner agents cannot invoke vendor operations directlyCallable from any MCP-speaking client (Claude, Cursor, custom LLMs, partner stacks, autonomous loops) · every invocation Ed25519-signed to Evidence Graph
Autonomous execution layerAgentic AI drives automated remediation inside the platform; not separately productized with published evaluation harnessTrustworthy Autonomy (public beta 2026-07-07) · Level 1 agent governance proven prod 2026-08-17 · published evaluation harness
External attack-surface scanningPrimary technical asset · continuous scans on the whole vendor tail · Risk DNA composite scoreInside the red-team service, QCD diligence, and DC-TPIR · engagement-driven, not a continuous cyber-rating engine at 200+ vendor scale
ISO/IEC 42001 AI-governance certFirst TPCRM vendor with the cert (management-system cert on how the AI is operated, not on whether the AI’s answers are correct)Not certified today
Portfolio-concentration risk primitiveIndividual-vendor Risk DNA onlyQCD Pillar 2 (HHI concentration) codified from Yolonda’s Someone Else’s Debt
Own complianceISO/IEC 42001 certified AI-governance management system; broader own-compliance not publicly disclosedSOC 2 Type II · ISO 27001 (in progress) · runs on itself

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside Panorays

A PDF business case, personalized to your company, that lays out the three options — no vendor-risk platform, Panorays, or direct-buy vCISO Lite — with the cost math and honest tradeoffs. Written to be credible with a buyer who's already seen Panorays's Forrester Wave TPCRM Leader positioning and needs to see what the integrated vCISO + GRC + services + DC-TPIR alternative actually delivers on a separate axis.

View pricing

Notes & sources

Provenance§10
  1. [1] Panorays External Attack Surface Management (continuous scans on each vendor: DNS, TLS, exposed management interfaces, credential leak monitoring, threat-intelligence feed correlation) and Risk DNA per-vendor cybersecurity composite score (99.8% claimed accuracy) from panorays.com (accessed 2026-09-15). Same technical category as BitSight and SecurityScorecard.
  2. [2] Panorays Incident Response Portal (“go from alert to action in seconds, assign tasks, and track progress from one dedicated Incident Response Portal”) from panorays.com. vCISO Lite DC-TPIR (Dependency-Centric Third-Party Incident Response) — codified per-incident-type playbooks with contractual mapping and communication templates. Executive brief on vcisolite.com/briefs-and-specs; sits under the Allotrope umbrella. Source methodology is Yolonda’s 2026 book Someone Else’s Breach, named on vcisolite.com/about.
  3. [3] vCISO Lite Evidence Graph (hash-chained records + per-event Ed25519 signing shipped 2026-08-16 + RFC-3161 external timestamp anchor + transparency log live in production 2026-08-20; SDK-licensable since 2026-08-15) verified against live platform state. Panorays audit-trail characteristics from panorays.com (no external-anchor / per-event signing / transparency-log mechanism disclosed on the product surface; ISO/IEC 42001 cert is on the AI-governance management system, not on the audit-trail substrate).
  4. [4] QCD Pillar 2 (Third-Party & Vendor Concentration) Herfindahl-Hirschman Index concentration penalty at portfolio level, combined with Max Single-Vendor Loss for Expected Annual Cost + P90, codified from Yolonda’s 2026 book Someone Else’s Debt. Panorays Risk DNA (individual-vendor continuous scoring) from panorays.com.
  5. [5] Panorays Smart Inventory + Supply Chain Discovery (Nth-party discovery via public sub-processor pages, DPAs, trust-center pages; discovers 4th and 5th-party dependencies) from panorays.com. Real capability with a real coverage boundary (only sees what vendors publish).
  6. [6] Panorays ISO/IEC 42001 certified AI-governance management system (first TPCRM vendor with the cert). Q2’26 Forrester Wave TPCRM Leader positioning from Panorays announcement. Framework coverage (250+ SCF-cross-mapped frameworks + 1,468 universal controls) for vCISO Lite verified against live vcisolite.com/features/compliance.
  7. [7] vCISO Lite APRI (MCP tool graph + evidence-backed answer surface; live MCP endpoint at mcp.vcisolite.com; three architectural guarantees: caller-entitlement scoped, complete tool-call audit trail, observe-first with confirmation gates on writes) verified against vcisolite.com/titanium. Panorays Native AI Questionnaires + Agentic AI (inside the Panorays UI; no public MCP endpoint or external-agent-callable interface) from panorays.com.
  8. [8] Trustworthy Autonomy (public beta 2026-07-07, Level 1 agent governance proven in production 2026-08-17, published evaluation harness) from vcisolite.com/trustworthy-autonomy.
  9. [9] Panorays pricing (contact-sales; no dollar figure surfaced without scoping conversation; free-trial entry on some tiers) from panorays.com (accessed 2026-09-15). vCISO Lite platform tiers from vcisolite.com/pricing; productized TPRM services from vcisolite.com/services.
  10. [10] vCISO Lite Enterprise SKU bundling (SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, DORA, NYDFS Part 500, HITRUST, CJIS, CMMC, ISO 42001, NIST AI RMF, TPRM, plus Trustworthy Autonomy + Evidence Graph + APRI + productized services on one contract) from vcisolite.com/pricing. Panorays as TPCRM specialist (broader compliance not on the same SKU) from panorays.com.
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. If Panorays ships a codified per-incident-type response playbook or an externally-anchored evidence chain since publication, corrections at /contact.
  12. This page does not compare against other TPCRM vendors (BitSight, SecurityScorecard) on their own merits — the buyer evaluating the attack-surface-based cyber-ratings category should run that comparison directly. See also /vs/processunityfor the workflow-plus-shared-vendor-exchange TPRM comparison. Riskonnect is not compared here (it’s a Salesforce-native multi-domain enterprise RMIS where TPRM is one SKU of 20+; the vCISO Lite comparison against Riskonnect lives on the Risk / CRQ / Risk-Intelligence axis and belongs in a separate batch).