GRC Hub

Tools for security professionals and consultants in regulated environments.

Free. Offline-capable. Export-ready. No tracking. Built for DORA, NIS2, GDPR, CRA with NIST as backbone.

Compliance content is informational only and does not constitute legal or regulatory advice.
📜
Compliance Reference DB

1,200+ controls from NIST, DORA, GDPR, NIS2, CRA. Instant search, maturity tiers, export to CSV, Excel, Markdown.

🔍 Search 📊 Tiers Live
NIS2 Engine

Applicability checker (essential vs important) plus Article 21 measures self-assessment and Article 23 reporting timeline. Gap report export.

🎯 Interactive 📊 Scoring Live
📊
NIST CSF 2.0 Self-Assessment

Rate your organisation against all six CSF 2.0 Functions at Category level (22 categories, 0–4 scale). Radar chart, gap analysis, PDF / Excel / JSON export. Scores feed the Board Pack.

🔭 Self-Assessment 📊 Radar Live
🏦
DORA Engine

Applicability (Art. 2/4/16), Level 1 + RTS 2024/1774 self-assessment, Register of Information generator (Implementing Reg (EU) 2024/2956), TLPT applicability and incident-classification helper.

🏦 Financial 📋 RoI Live
🔗
Cross-framework Crosswalk

623+ edges connecting NIST CSF 2.0, SP 800-53 r5, ISO 27001:2022, DORA L1 + RTS, NIS2 Art. 21 + IR 2024/2690, GDPR and CRA. Pivot, framework-pair, "implement once / comply many" coverage.

🔗 8 frameworks 📊 Coverage Live
🎯
Risk Register

ISO/IEC 27005-aligned client-side register with multi-engagement support, 5×5 inherent vs. residual heatmaps, optional FAIR-lite Monte Carlo (Web Worker, 10k iters). Excel / CSV / Markdown / PDF.

🎯 ISO 27005 🎯 FAIR-lite Live
📝
Evidence Request List Generator

Pick the frameworks in scope; the generator produces a deduplicated ERL with Excel tracker columns and a client-facing cover letter. Covers NIS2 IR 2024/2690, DORA, GDPR Art 32/28/33, CRA Annex I, ISO 27001 audit list.

📝 Wizard ✅ Tracker Live
📄
Policy Templates Library

12 SME-sized policy templates with YAML front-matter and clause-level trace IDs into the Crosswalk. RACI tables, customise-in-browser, Markdown / Word-friendly HTML / traceability matrix exports.

📄 12 templates 🔗 Traceable Live
🎖
Board Reporting Pack

One click from your saved GRC state to a board-ready PDF. Auto-drafted executive summary, CSF radar, top-10 risk, regulatory exposure, upcoming deadlines, snapshot trends.

🎖 PDF 📊 Snapshots Live
🔥
Anonymous CSF Benchmarking

Compare your CSF 2.0 maturity to anonymous aggregates by sector and size band. Opt-in submission. k-anonymity ≥ 20. The literal payload you'd send is shown before sending — nothing else leaves.

🔥 Opt-in 🔒 k ≥ 20 Live
🔌
Methodology & Sources

How every dataset and mapping was built. OLIR / ENISA hierarchy, coverage formula, k-anonymity rule, full manifest with sha256 fingerprints. Plus the free, read-only /api/v1/.

🔌 Trust layer 🗣 API Live
📅
Regulatory Calendar

Key EU cybersecurity regulatory deadlines — DORA, NIS2, CRA, GDPR milestones with official source links.

📅 Calendar 📖 Reference Live
💻
For Practitioners

All tools run in your browser. Keyboard shortcuts supported. No account required. Export to CSV, Excel, or Markdown for your workflow.

💼
For Consultants

Every tool produces client-ready exports — PDF checklists, gap analysis reports, maturity assessments. Attribution-free output, ready to brand.

☑ GRC Engagement Checklist

Scoping
  • Identify applicable regulations (DORA / NIS2 / GDPR / CRA)
  • Confirm entity classification (essential / important / financial)
  • Define assessment scope (systems, processes, third parties)
  • Obtain existing policy and procedure documentation
  • Identify key stakeholders (CISO, DPO, risk owner, auditor)
Gap Assessment
  • Baseline current controls against target framework
  • Map existing policies to regulatory requirements
  • Identify missing controls by category and criticality
  • Assign maturity tier per CSF Function (T1–T4)
  • Prioritise gaps by regulatory risk and effort
Evidence Collection
  • Collect policy documents (IS policy, BCP, IRP, TPRM)
  • Gather audit logs and monitoring evidence
  • Document incident response history
  • Confirm third-party contract clauses (DORA/NIS2 requirements)
  • Capture training and awareness records
Reporting
  • Draft findings with regulatory reference per item
  • Assign risk rating (High / Medium / Low)
  • Write remediation recommendations with timelines
  • Prepare executive summary for board/management
  • Document residual risks and accepted exceptions
  • Deliver report with evidence appendix
⚙ All processing is client-side. No data is sent to any server. No cookies beyond session rate limiting. No tracking.