Christian L.
CL
Security Compliance Program Manager / Senior Security Engineer
Enterprise (> 1000 emp.)
"How a 2-person team manages enterprise-level compliance"
4.5/5
What do you like best about ZenGRC?

Before ZenGRC we were living in spreadsheet hell - endless back-and-forth emails, no central management, and audits were a nightmare to coordinate. Now everything lives in one place across SOC2, HIPAA, NIST, and ISO 27001.

What really sold me is how it handles audit season. Our external auditors fill out ZenGRC's import spreadsheet with their requests and control mappings, it flows right into the platform, and they interact directly with our SMEs to ask questions and approve evidence. We're not playing middleman anymore. A team of 1-2 people can manage a full company audit now.

We've also built PowerBI dashboards pulling from ZenGRC's API, and even have a SharePoint security exception form that auto-generates exceptions in Zen. When we've gotten stuck, their team jumps on a Zoom and walks us through it. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Native reporting and dashboards are limited - that's why we ended up building our own in PowerBI. Sorting and filtering in the UI still needs work. They've been receptive to feedback and we've gotten features added, but development can be slow. Review collected by and hosted on G2.com.

See what 102 reviewers think of ZenGRC

4.4 out of 5 · Verified reviews from real users

Read all reviews