Attack Surface Management Vendors: How to Shortlist EASM Tools and What They Actually Cost
Every roundup of attack surface management vendors names the same twelve products and none of them tells you what any of it costs. Here is the shortlisting method that survives contact with procurement, and the question worth answering before you take a single demo.
- Published
- 8 min read
- Landscape
- Osintpro analyst notes
If you have spent an afternoon reading vendor comparisons for attack surface management, you have met the same list several times: CyCognito, CrowdStrike Falcon Surface, Palo Alto Cortex Xpanse, Microsoft Defender EASM, Tenable, IONIX, Detectify, Bishop Fox Cosmos. The lists are accurate. They are also written by the vendors selling into the category, which is why they compare capability checklists and never once tell you what a year costs.
That omission is the actual problem. A shortlist you cannot price is not a shortlist, it is a demo schedule. So this post does the two things those roundups skip: it sorts the vendors into the three groups they genuinely fall into, and it says plainly what is and is not published about price as of September 2026.
The three groups attack surface management vendors fall into
Almost every product in this category belongs to one of three shapes, and the shape predicts the price and the contract far better than the feature grid does.
- Platform-attached EASM. Microsoft Defender EASM, CrowdStrike Falcon Surface, Palo Alto Cortex Xpanse, Tenable and Qualys. The external discovery is a module hanging off a platform you may already own. Cheapest to add if you are already a customer, effectively unbuyable on its own if you are not, because the commercial conversation is a platform conversation.
- Standalone EASM. CyCognito, IONIX, Detectify, Attaxion, Bishop Fox Cosmos. These live or die on discovery quality and they are the group most likely to win a head-to-head bake-off on asset coverage. They are also the group where asset-count pricing bites, because the thing you are billed for is the thing the product is good at finding more of.
- Search and scan indexes. Shodan, Censys, ZoomEye. Not EASM products, frequently shortlisted as if they were. They index what is listening across the internet and leave the attribution, the triage and the write-up to you.
There is a fourth shape that rarely appears on these lists because it is not continuous monitoring: passive, records-based review, where you take one named subject and derive what is publicly established about it from registration records, DNS, certificate transparency and registries. It answers a different question, and I will come back to why that matters for the buying decision.
What attack surface management vendors actually cost
The short answer: with one exception, they do not tell you. This is not cynicism, it is what the pricing pages say when you read them.
Microsoft Defender EASM
- Is a price published
- No figure on the pricing page
- What the pricing page routes you to
- An Azure pricing calculator or Contact Sales
Censys
- Is a price published
- No tier prices
- What the pricing page routes you to
- Sales, with consumption credit packs from a $100 minimum
Detectify
- Is a price published
- No list price on the vendor site
- What the pricing page routes you to
- A scoping call; third parties report entry pricing near $90 a month
CyCognito, IONIX, Cortex Xpanse, Falcon Surface
- Is a price published
- No
- What the pricing page routes you to
- Contact sales or a partner
Shodan
- Is a price published
- Yes, in the documentation
- What the pricing page routes you to
- Self-serve: $49 one-time, or $69, $359, $1,099 a month
Two things follow from that table. First, budget approval will take longer than the evaluation, so start the procurement conversation in week one rather than after you have picked a favorite. Second, when nobody publishes a number, the only comparable figure you control is your own: the hours your team currently spends producing the output the tool is supposed to replace. Price the tools against that, not against each other.
Ask for the renewal price, not the first-year price, in the first call.
Asset-count pricing in this category is discovery-driven, and a good EASM product finds assets you did not know about. That is the point of buying it, and it is also why year two frequently prices higher than year one on an unchanged estate. Get the growth mechanism written down before you sign, including what happens when a subsidiary is acquired.
The question to answer before you take a demo
Continuous external monitoring solves one specific problem: assets appear and change without anyone telling you. If that is genuinely your problem, you need a product from group one or group two and this post has nothing better to offer you.
It is worth checking honestly whether it is your problem, because a large share of teams that go shopping for EASM are not being asked to watch a moving estate at all. They are being asked to produce an answer about a specific organization, on a specific date, that somebody else will read and act on. Vendor onboarding. Pre-signature diligence. An insurance or audit question. A subsidiary inherited in an acquisition. In those cases the deliverable is a document about one subject, and a continuous monitoring platform is an expensive way to generate the inputs to a document you still have to write yourself.
- How many distinct subjects will you look at this year, and are they mostly yours or mostly somebody else's?
- Does anyone outside the security team read the output, and does it have to hold up if a finding is challenged?
- Is the work continuous, or does it run when a trigger fires, such as a new vendor or a renewal date?
- Who runs it? An analyst who lives in the tool, or a risk reviewer who touches it four times a quarter?
Answer those four before the first demo and the shortlist usually cuts itself in half. Mostly your own estate, continuous, analyst-operated: buy EASM. Mostly other people's organizations, trigger-driven, reviewed by non-specialists: you are shopping in the wrong aisle, and attack surface management built from public records is the closer fit.
Where the search indexes fit, and where they stop
Shodan and Censys keep landing on EASM shortlists, usually because someone on the team already uses one and it is cheap. They are excellent at what they do and they are not the same product. A search index answers "what is listening on the internet that looks like this". An EASM product answers "which of these things is mine, is it new, and should I care". The attribution layer between those two questions is most of what you are paying an EASM vendor for.
If your team is already running one of them and wondering whether to upgrade or move sideways, the trade-offs and the published numbers are laid out on our Shodan alternative comparison, including where Shodan wins outright and why we would not try to replace it for internet-wide device search.
One practical note about scope creep in the other direction. Once discovery hands you a list of hosts that are genuinely yours, the next question is nearly always operational rather than investigative: which of these is actually up, and did that staging box come back online last night. That is a job for ordinary uptime and port monitoring on a short interval, and it is considerably cheaper than paying an EASM license to notice a state change.
A shortlisting sequence that survives procurement
- Write the deliverable down first. A dashboard somebody watches, or a document somebody signs. This single sentence eliminates more vendors than any feature matrix.
- Count the subjects and their ownership. Your own estate points to EASM. Third parties point to a diligence and reporting tool.
- Ask every vendor for the renewal-year figure and the asset-growth mechanism in writing, in the first call.
- Run the same two or three domains through every candidate and compare what came back, not what the deck claims. Include a subsidiary or a recent acquisition, which is where discovery quality actually separates.
- Check who has to operate it in month six. If that person is not a full-time analyst, weight ease of use above coverage, because unused coverage is worth nothing.
- Price all of it against the hours the work costs you today. That is the only number in the process that you can actually verify.
Is EASM the same as vendor risk management?
No, and conflating them is how teams end up owning two overlapping subscriptions. EASM watches infrastructure you own and continuously reports on its exposure. Vendor risk work asks whether a counterparty is who it claims to be, what it has published about itself, and whether that is acceptable enough to sign. The evidence overlaps; the unit of work, the cadence and the reader do not.
If the driver behind your search was a vendor program rather than your own estate, the arithmetic and the workflow for that case are set out under third party risk management software, and the wider field is compared in the OSINT tools comparison.
What to take away
The vendor lists are not wrong, they are just answering a question you have not asked yet. Sort the field into platform-attached, standalone and search-index, decide whether your deliverable is a dashboard or a document, and get the renewal number in writing before you fall in love with a demo. Do that and the shortlist writes itself, and you will be able to defend the choice to whoever signs the purchase order.
See it produce one
Every habit in this post is what the sweep does automatically.
Declare a scope, run a domain, and read findings that already carry the raw record, the source endpoint and the UTC retrieval time. It takes a domain and never a person.