Free GRC tools for compliance, risk & audit teams
GRC Tools is a free toolkit for Governance, Risk & Compliance work that runs entirely in your browser — no account, no tracking, and nothing sent to a server. It is built for compliance analysts, security engineers, ISMS managers and auditors who need quick, defensible outputs without paying for a heavyweight GRC platform.
Start with the ISO 27001 Control Reference to search all 93 ISO/IEC 27001:2022 Annex A controls and 114 legacy 2013 controls with audit evidence and cross-version mapping — or browse the equivalent SOC 2 Criteria Reference (61 Trust Services Criteria) and NIST CSF 2.0 Reference (106 subcategories). Use the Control Mapper & Gap Assessment to crosswalk ISO 27001, NIST CSF 2.0 and SOC 2 and run a CMMI-style maturity assessment. Build an ISO 27005 / NIST SP 800-30 aligned register with the Risk Register & Matrix Generator, and screen third parties with the Vendor Risk Assessment. Everything exports to PDF, XLSX or JSON so your evidence stays portable.
Also see: SecOps Tools · OSINT Tools · IT Ops Tools · theadminstack.com