OpenGRC is a web application for cyber governance, risk, and compliance, intended for small and midsized businesses and teams. It covers risk management, controls and implementations, audits, vendor management, incident response, and project management. Audit functions support evidence requests, progress tracking, and report generation. Vendor assessments include a dedicated portal, customizable questionnaires, and weighted scoring. Listed frameworks include NIST 800-171, ISO 27001, SOC 2, CMMC, and PCI DSS. The Enterprise tier adds AI risk assessments, automated vendor survey responses, and AI gap assessments. The platform has no third-party integrations built in, but provides a REST API, limited to 60 requests per minute per user or per IP for unauthenticated requests. Community is free and self-hosted, requiring a web server and database server; installation and upkeep require some technical knowledge. Enterprise Basic costs $4,500/year and Enhanced costs $7,500/year. Hosted plans state a 99.5% monthly uptime commitment and that customer data is not used to train AI models. The maker identifies itself as OpenGRC, LLC.
Who it is for
OpenGRC is intended for small and midsized businesses and teams managing cyber risk, compliance, audits, and vendors. Community may suit technically capable users who can operate a web server and database server.
What is good
- Covers risk, controls, audits, vendors, and incident response.
- Vendor assessments include questionnaires and weighted scoring.
- Community edition is free and self-hosted.
- Hosted plans state a 99.5% monthly uptime commitment.
What to know first
- Community setup and maintenance require technical knowledge.
- No third-party integrations are built into the platform.
- REST API is limited to 60 requests per minute.
Verdict
OpenGRC brings several GRC functions into one web application, with a free self-hosted Community edition and paid Enterprise options. Consider the technical requirements and API limit if planning to use Community or connect other systems.
OpenGRC plans and pricing
All plansCompared on compliance management software
- Free plan
- Yes
- Frameworks supported
- NIST 800-171, ISO 27001, SOC 2, CMMC, PCI DSS
- Control mapping
- Yes
- Evidence collection
- Yes
- Risk assessments
- Yes
- Remediation workflows
- Yes
- Vendor risk management
- Yes


