GRC Hub
Tools for security professionals and consultants in regulated environments.
Free. Offline-capable. Export-ready. No tracking. Built for DORA, NIS2, GDPR, CRA with NIST as backbone.
1,200+ controls from NIST, DORA, GDPR, NIS2, CRA. Instant search, maturity tiers, export to CSV, Excel, Markdown.
Applicability checker (essential vs important) plus Article 21 measures self-assessment and Article 23 reporting timeline. Gap report export.
Rate your organisation against all six CSF 2.0 Functions at Category level (22 categories, 0–4 scale). Radar chart, gap analysis, PDF / Excel / JSON export. Scores feed the Board Pack.
Applicability (Art. 2/4/16), Level 1 + RTS 2024/1774 self-assessment, Register of Information generator (Implementing Reg (EU) 2024/2956), TLPT applicability and incident-classification helper.
623+ edges connecting NIST CSF 2.0, SP 800-53 r5, ISO 27001:2022, DORA L1 + RTS, NIS2 Art. 21 + IR 2024/2690, GDPR and CRA. Pivot, framework-pair, "implement once / comply many" coverage.
ISO/IEC 27005-aligned client-side register with multi-engagement support, 5×5 inherent vs. residual heatmaps, optional FAIR-lite Monte Carlo (Web Worker, 10k iters). Excel / CSV / Markdown / PDF.
Pick the frameworks in scope; the generator produces a deduplicated ERL with Excel tracker columns and a client-facing cover letter. Covers NIS2 IR 2024/2690, DORA, GDPR Art 32/28/33, CRA Annex I, ISO 27001 audit list.
12 SME-sized policy templates with YAML front-matter and clause-level trace IDs into the Crosswalk. RACI tables, customise-in-browser, Markdown / Word-friendly HTML / traceability matrix exports.
One click from your saved GRC state to a board-ready PDF. Auto-drafted executive summary, CSF radar, top-10 risk, regulatory exposure, upcoming deadlines, snapshot trends.
Compare your CSF 2.0 maturity to anonymous aggregates by sector and size band. Opt-in submission. k-anonymity ≥ 20. The literal payload you'd send is shown before sending — nothing else leaves.
How every dataset and mapping was built. OLIR / ENISA hierarchy, coverage formula, k-anonymity rule, full manifest with sha256 fingerprints. Plus the free, read-only /api/v1/.
Key EU cybersecurity regulatory deadlines — DORA, NIS2, CRA, GDPR milestones with official source links.
All tools run in your browser. Keyboard shortcuts supported. No account required. Export to CSV, Excel, or Markdown for your workflow.
Every tool produces client-ready exports — PDF checklists, gap analysis reports, maturity assessments. Attribution-free output, ready to brand.
☑ GRC Engagement Checklist
- Identify applicable regulations (DORA / NIS2 / GDPR / CRA)
- Confirm entity classification (essential / important / financial)
- Define assessment scope (systems, processes, third parties)
- Obtain existing policy and procedure documentation
- Identify key stakeholders (CISO, DPO, risk owner, auditor)
- Baseline current controls against target framework
- Map existing policies to regulatory requirements
- Identify missing controls by category and criticality
- Assign maturity tier per CSF Function (T1–T4)
- Prioritise gaps by regulatory risk and effort
- Collect policy documents (IS policy, BCP, IRP, TPRM)
- Gather audit logs and monitoring evidence
- Document incident response history
- Confirm third-party contract clauses (DORA/NIS2 requirements)
- Capture training and awareness records
- Draft findings with regulatory reference per item
- Assign risk rating (High / Medium / Low)
- Write remediation recommendations with timelines
- Prepare executive summary for board/management
- Document residual risks and accepted exceptions
- Deliver report with evidence appendix