Rapid7

Command Platform Packages

Three ways to take command of exposure — from attack surface visibility to full-platform risk reduction. Choose the tier that fits your environment and scale as you grow.

Surface Command

See and understand your attack surface inside and out.

Core capabilities:

  • Asset discovery & unified inventory (CAASM)
  • Internal + external attack surface visibility (EASM)
  • Asset context, enrichment & relationships (asset graph)
  • Blast radius analysis
  • Exposure Management dashboard & remediation hub
  • Built-in automation & integrations (SOAR-ready)

Exposure Command Essentials

Find and fix vulnerabilities across your environment.

Everything in Surface Command, plus:

  • Vulnerability management: agent-based and network scanning across hybrid environments
  • Risk-based prioritization with threat-aware scoring
  • Policy & configuration assessment
  • Remediation workflows, SLAs & reporting
  • Dynamic asset tagging & criticality
  • Integrations with security & IT tools

Exposure Command Ultimate

Unify risk across cloud, applications, and infrastructure.

Everything in Essentials, plus:

  • Multi-cloud & container security (AWS, Azure, GCP, K8s)
  • Cloud posture & compliance (CIS + frameworks)
  • Attack path analysis & contextual risk prioritization
  • Real-time cloud visibility & threat detection
  • Identity & access risk analysis (least privilege)
  • Infrastructure-as-code (IaC) security
  • Application & API security testing (DAST, API, LLM)
  • Automated cloud remediation

Pricing built for how your environment actually changes

Simple, flexible pricing that helps you expand coverage, adopt new capabilities, and understand what you’re paying for, without added complexity.

Pay for what you use

Pay for what you use

Get access to the platform without paying for capabilities you’re not using. Pricing reflects the asset types and use cases actually in scope.

Grow without re-buying

Grow without re-buying

Add cloud, app sec, or new exposure use cases without re-licensing your full environment or moving to a rigid new pricing model.

See usage clearly

See usage clearly

Track billable asset usage against your entitlement over time, so you understand consumption now and avoid surprises at renewal.

Command pricing

Exposure Command FAQs

Exposure Command pricing is based on the number of billable assets being monitored.

Pricing is not publicly listed and is typically provided via a custom quote based on your environment and requirements.

A billable asset generally includes devices, software, identities, cloud compute instances and applications that are discovered and monitored within your environment. An asset ratio is used to map use cases to asset type to ensure that the pricing reflects the value delivered.

Onboarding support is typically included, but specifics may vary depending on the agreement.

Pricing may vary depending on region and other factors.

Yes, pricing is typically structured as annual subscriptions.

Volume discounts are commonly available for larger asset counts.