Home/Free Governance, Risk & Compliance Tools

Free Governance, Risk & Compliance Tools

Manage governance, risk, and compliance programs with free and open source tools. Browse GRC platforms, audit management, policy management, and compliance automation tools.

408 tools·26 sub-categories·Updated April 2026

Showing 24 of 408 tools

unleash icon

unleash

Unleash/unleash

Tool

Open-source feature management platform

12.2K
10 months ago
the-practical-linux-hardening-guide icon

the-practical-linux-hardening-guide

trimstray/the-practical-linux-hardening-guide

Documentation

This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).

10.2K
8 months ago
how-to-secure-anything icon

how-to-secure-anything

veeral-patel/how-to-secure-anything

Documentation

How to systematically secure anything: a repository about security engineering

10.2K
5 months ago
404StarLink icon

404StarLink

knownsec/404StarLink

Documentation

404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目

9.6K
8 months ago
steampipe icon

steampipe

turbot/steampipe

Tool

Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.

7.7K
about 1 month ago
DevSecOps icon

DevSecOps

sottlmarek/DevSecOps

Documentation

Ultimate DevSecOps library

6.6K
about 1 month ago
Security-101 icon

Security-101

microsoft/Security-101

Educational Resource

8 Lessons, Kick-start Your Cybersecurity Learning.

6.1K
3 months ago
glpi icon

glpi

glpi-project/glpi

Tool

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

4.8K
10 months ago
security-101-for-saas-startups icon

security-101-for-saas-startups

forter/security-101-for-saas-startups

Educational Resource

security tips for startups

4.6K
8 months ago
ciso-assistant-community icon

ciso-assistant-community

intuitem/ciso-assistant-community

Tool

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, Privacy, and Reporting. It supports 100+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

3.5K
3 months ago
inspec icon

inspec

inspec/inspec

Framework

InSpec: Auditing and Testing Framework

3.0K
8 months ago
content icon

content

ComplianceAsCode/content

Tool

Security automation content in SCAP, Bash, Ansible, and other formats

2.6K
3 months ago
kics icon

kics

Checkmarx/kics

Tool

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

2.6K
about 1 month ago
ScubaGear icon

ScubaGear

cisagov/ScubaGear

Tool

Automation to assess the state of your M365 tenant against CISA's baselines

2.4K
3 months ago
cargo-crev icon

cargo-crev

crev-dev/cargo-crev

Tool

A cryptographically verifiable code review system for the cargo (Rust) package manager.

2.2K
8 months ago
sloth icon

sloth

slok/sloth

Tool

🦥 Easy and simple Prometheus SLO (service level objectives) generator

2.2K
10 months ago
tag-security icon

tag-security

cncf/tag-security

Documentation

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!

2.2K
8 months ago
ghorg icon

ghorg

gabrie30/ghorg

Tool

Quickly clone or backup an entire org/users repositories into one directory - Supports GitHub, GitLab, Bitbucket, and more 🐇🥚

1.8K
6 months ago
slsa icon

slsa

slsa-framework/slsa

Documentation

Supply-chain Levels for Software Artifacts

1.7K
8 months ago
cset icon

cset

cisagov/cset

Tool

Cybersecurity Evaluation Tool

1.7K
5 months ago
guac icon

guac

guacsec/guac

Tool

GUAC aggregates software security metadata into a high fidelity graph database.

1.4K
8 months ago
cloudformation-guard icon

cloudformation-guard

aws-cloudformation/cloudformation-guard

Tool

Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

1.4K
8 months ago
pacbot icon

pacbot

tmobile/pacbot

Tool

PacBot (Policy as Code Bot)

1.3K
5 months ago
hubcommander icon

hubcommander

Netflix/hubcommander

Tool

A Slack bot for GitHub organization management -- and other things too

1.3K
8 months ago

Can't find the right tool?

Describe what you need in plain English and our AI will find the best match from 10,000+ security tools.

Frequently Asked Questions

What is GRC in cybersecurity?

GRC (Governance, Risk, and Compliance) is a structured approach to aligning IT with business objectives while managing risk and meeting regulatory requirements. It encompasses policy management, risk assessments, audit management, and compliance tracking across frameworks like ISO 27001, NIST CSF, SOC 2, and PCI DSS.

What are the best free GRC tools?

Open source GRC platforms include Eramba (community edition), SimpleRisk, and OpenGRC. For compliance automation, OpenSCAP provides automated configuration compliance scanning against CIS Benchmarks and STIG profiles. CISO Assistant is a newer open source GRC platform gaining traction.

What is ISO 27001 and how do I achieve it?

ISO 27001 is the international standard for information security management systems (ISMS). Achieving certification requires implementing 93 controls across 4 themes (organizational, people, physical, technological), conducting risk assessments, and passing an external audit. GRC tools help manage the documentation and evidence collection process.

What is the NIST Cybersecurity Framework?

The NIST CSF is a voluntary framework for managing cybersecurity risk, organized around five functions: Identify, Protect, Detect, Respond, and Recover. It's widely adopted as a baseline for security programs and maps to other frameworks like ISO 27001, CIS Controls, and MITRE ATT&CK.