An IriusRisk Alternative for Teams That Want Published Pricing

IriusRisk is one of the most established threat modeling platforms, and for large organisations that want threats generated automatically across hundreds of applications it's a strong choice. Teams usually look for an alternative for one of four reasons: they've hit the free Community Edition's limit of three threat models and one user, they can't get budget approved for a quote-only enterprise contract, they find rules-generated threat lists harder to act on than they expected, or they want to understand what the January 2026 acquisition by ThreatModeler means for them.

ThreatTree takes a different approach to the same problem. This page sets out the differences honestly, including where IriusRisk is the better choice.

The short version: IriusRisk generates threats and countermeasures from component rules, and is built and priced for large programmes. ThreatTree has your team identify threats and break the important ones down into attack trees, scores them into a risk register, and publishes its price: free for three systems, then $29 per user per month.

Side by side

IriusRiskThreatTree
PriceEnterprise: on requestPro: $29/user/month, published; Enterprise: on request
Free optionCommunity Edition: 3 active threat models, 1 userFree plan: 3 forests, each with up to 3 DFDs and 5 attack trees per DFD
DeploymentSaaS or on-premiseSaaS; dedicated deployment on Enterprise
Diagramdraw.io-based canvas with component librariesPurpose-built DFD editor with cloud-provider trust boundaries and infrastructure elements
Finding threatsGenerated from rules attached to components; AI assistantIdentified by your team, tagged with STRIDE, LINDDUN, OWASP Top 10, CAPEC and MITRE ATT&CK
Attack treesNoYes, with AND/OR gates, linked to the DFD
Risk registerThreats and countermeasures per model, with risk ratingsForest-wide register built from every scored attack-tree step, with treatment plans and owners
Standards mappingExtensive standards librariesISO 27001:2022, NIST SP 800-53, NIST CSF 2.0, CIS v8, ASVS, PCI DSS v4.0, SOC 2 (Pro)
Issue trackersYes, on paid plansTwo-way Jira, ServiceNow, Linear and Azure DevOps sync (Enterprise)
Importing architectureImport from other diagramming tools (Enterprise)Terraform, CloudFormation and OpenAPI to DFD (Enterprise)
Client-side encryptionNot listed on its plans pageOptional AES-256-GCM on every plan; the server stores only ciphertext
Getting startedSales-led for paid plans, with onboardingSelf-serve sign-up and checkout

Generated threats or attack trees?

This is the real difference between the two, and it's worth thinking about before comparing feature lists.

IriusRisk's rules engine looks at each component you draw, such as a web server, a database or a message queue, and attaches the threats and countermeasures its library associates with that component. That's fast and consistent, and it scales across a portfolio. The trade-off is that the threats are about the kind of component rather than your system, so the list is long, and the business-logic risks that are specific to what you've built aren't in any library.

ThreatTree asks your team to identify the threats, using STRIDE and the other frameworks as a checklist, and to decompose the important ones into attack trees: the goal an attacker wants, the alternative routes to it, and the steps each route needs. It's slower to start and doesn't scale to a thousand applications without people. It does produce a shorter, more specific list, shows where one control breaks several paths, and leaves a record of the reasoning behind each risk score.

When IriusRisk is the better choice

  • You need consistent threat coverage across a large portfolio with limited security staff per application.
  • You want threats and countermeasures generated and pushed to developers automatically.
  • You need an on-premise deployment, or a vendor with a long enterprise track record and dedicated customer success.
  • You already have IriusRisk libraries and integrations tuned to your organisation.

When ThreatTree is the better choice

  • You've outgrown three models or one user and want a price you can approve without a sales cycle.
  • You want to see how attacks combine, not just which threats apply to each component.
  • You want a single scored risk register per system, with treatment decisions and owners, for leadership and auditors.
  • Your threat models are sensitive enough that you want them encrypted in the browser, so the vendor can't read them.

About the ThreatModeler acquisition

ThreatModeler announced on January 8, 2026 that it had acquired IriusRisk, creating one company that owns two of the best-known enterprise platforms. When we checked, both products were still being sold. If you're an IriusRisk customer, the useful questions to ask at renewal are which product the combined company will invest in, whether your models and libraries will migrate, and whether pricing and the Community Edition will change. None of this is a reason to switch on its own, but it is a good moment to review whether the tool still fits.

Moving from IriusRisk to ThreatTree

There's no direct import, so you redraw the architecture as a DFD; Enterprise customers can generate it from Terraform, CloudFormation or OpenAPI. Then take the threats you actually acted on, rather than the full generated list, and turn each one into an attack tree leaf with its STRIDE or OWASP tag. Countermeasures become treatment plans, mapped to the same ISO 27001 or NIST controls on Pro. Most teams find the migration doubles as a useful clean-up.

Frequently asked questions

What are the limits of IriusRisk Community Edition?

According to IriusRisk's plans page, Community Edition is free with three active threat models, one user and limited collaboration. Larger use needs the Enterprise plan, which is priced on request.

Who owns IriusRisk now?

ThreatModeler announced on January 8, 2026 that it had acquired IriusRisk. When we checked in October 2026, both products were still being sold.

How much does ThreatTree cost compared with IriusRisk?

ThreatTree publishes its pricing: a Free plan for up to three systems, and Pro at $29 per user per month. Enterprise, which adds SSO, SCIM, ticketing sync and import from code, is priced on request. IriusRisk's paid plan is priced on request.

Does ThreatTree generate threats automatically like IriusRisk?

No. IriusRisk generates threats and countermeasures from rules attached to the components you draw. ThreatTree has your team identify threats with frameworks such as STRIDE and decompose the important ones into attack trees, which produces a shorter, system-specific list but takes more of the team's time.

Can ThreatTree run on-premise?

ThreatTree is a hosted service. Enterprise customers can ask about a dedicated deployment. If you need a fully on-premise installation today, IriusRisk offers one.

Weighing more options? See the best threat modeling software in 2026, or our ThreatModeler alternative page. IriusRisk details come from its plans page and public announcements, checked on October 8, 2026. IriusRisk is a trademark of its owner, which is not affiliated with ThreatTree.

Try ThreatTree with your team

Start free with three systems, then upgrade to Pro for $29 per user per month when you need unlimited models, collaboration and standards mapping. No sales call needed.

Get started free