theadminstack.com

GRC Tools

Free browser-based Governance, Risk & Compliance tools for compliance analysts, security engineers, and auditors — control mapping, gap assessment, risk register, and vendor risk. No accounts, no tracking, nothing sent to servers.

ISO 27001 Control Reference
Search all 93 ISO 27001:2022 Annex A controls and all 114 ISO 27001:2013 controls. Each entry includes a description, common audit evidence, and 2013 ↔ 2022 cross-version mapping. Export filtered results to CSV.
93 + 114 controls · Client-side · No data sent Open →
SOC 2 Criteria Reference
Search all 61 Trust Services Criteria — Security (CC1–CC9), Availability, Confidentiality, Processing Integrity, and Privacy. Each entry includes a description, common audit evidence, and ISO 27001 mapping. Export filtered results to CSV.
61 criteria · Client-side · No data sent Open →
NIST CSF 2.0 Reference
Search all 106 subcategories of NIST CSF 2.0 across Govern, Identify, Protect, Detect, Respond, and Recover. Each entry includes the official Core text, evidence examples, and ISO 27001 mapping. Export filtered results to CSV.
106 subcategories · Client-side · No data sent Open →
Control Mapper + Gap Assessment
Map controls across ISO 27001:2022, NIST CSF 2.0 and SOC 2 with confidence-tagged crosswalks. Run a CMMI-style maturity self-assessment, see radar and heatmap rollups, and export a branded gap report — all in your browser.
260 controls mapped · Client-side · No data sent Open →
Risk Register + Matrix Generator
Build an ISO 27005 / NIST SP 800-30 aligned risk register. Likelihood × impact scoring with a configurable matrix, optional SLE/ALE analysis, treatment tracking with residual risk, and an interactive heatmap. Export to XLSX, PDF or JSON.
Inherent → residual · Client-side · No data sent Open →
Vendor Risk Assessment
Assess new and existing vendors against security, compliance, and operational controls. Guided questionnaire with weighted risk scoring, a tiered risk rating, and reusable assessment records. Export to PDF or JSON.
Security · Compliance · Ops · Client-side · No data sent Open →

Free GRC tools for compliance, risk & audit teams

GRC Tools is a free toolkit for Governance, Risk & Compliance work that runs entirely in your browser — no account, no tracking, and nothing sent to a server. It is built for compliance analysts, security engineers, ISMS managers and auditors who need quick, defensible outputs without paying for a heavyweight GRC platform.

Start with the ISO 27001 Control Reference to search all 93 ISO/IEC 27001:2022 Annex A controls and 114 legacy 2013 controls with audit evidence and cross-version mapping — or browse the equivalent SOC 2 Criteria Reference (61 Trust Services Criteria) and NIST CSF 2.0 Reference (106 subcategories). Use the Control Mapper & Gap Assessment to crosswalk ISO 27001, NIST CSF 2.0 and SOC 2 and run a CMMI-style maturity assessment. Build an ISO 27005 / NIST SP 800-30 aligned register with the Risk Register & Matrix Generator, and screen third parties with the Vendor Risk Assessment. Everything exports to PDF, XLSX or JSON so your evidence stays portable.

Frequently asked questions

Are these GRC tools really free?

Yes. Every tool on this site is completely free with no account, no sign-up and no trial. They are built by TheAdminStack as practical utilities for working GRC, security and audit teams.

Is my data sent to a server?

No. All six tools run 100% in your browser — control searches, gap scores, risk registers and vendor assessments never leave your machine. You can export your work to PDF, XLSX or JSON to save it locally.

Which compliance frameworks are covered?

The tools cover ISO/IEC 27001:2022 and 2013, NIST CSF 2.0, SOC 2 Trust Services Criteria, and risk methodology from ISO 27005 and NIST SP 800-30.

Who are these tools for?

Compliance analysts, security engineers, ISMS managers, internal auditors and consultants who need quick, defensible GRC work — control mapping, gap assessments, risk registers and vendor reviews — without buying a full GRC platform.