OpenGRC is a governance, risk and compliance (GRC) platform built for small and mid-sized security teams who need to run a real compliance program without enterprise pricing or a months-long implementation.
It connects standards, controls and your actual implementations in one place, so evidence and status sit alongside the requirements they satisfy instead of in separate spreadsheets. Import common frameworks including ISO 27001, SOC 2, NIST CSF and HIPAA, then run internal and external audits end to end — requests, evidence, findings and remediation — and generate reports you can hand to an auditor.
Beyond compliance it covers the rest of a security program: a risk register linked to the controls and assets each risk actually concerns, vendor risk management with security questionnaires and document tracking, incident response with playbooks, tasks and timelines, policy management with approval workflows, and asset and application inventory.
The Community edition is free to self-host, with no user seats or data caps. It covers risk management, controls and implementations, vendor management, project management and incident response.
The hosted Enterprise edition adds AI-assisted risk and gap assessments, automated vendor survey responses, and an MCP server that connects OpenGRC directly to Claude and ChatGPT, so an assistant can read and update your program rather than guess at it. It includes a 99.5% monthly uptime commitment and an annual SOC 2 Type II examination by an independent auditor. Pricing starts at $4,500 per year with unlimited users and unlimited frameworks — there are no per-seat fees on any plan.