173 frameworks. No per-framework fees.

Every standard OpenGRC supports, included on every plan. Import as many as you need.

Why we do not charge per framework

Most GRC platforms sell you a framework at a time. Want SOC 2? That is the base. Need ISO 27001 as well because a European customer asked? That is an add-on. HIPAA because you signed a healthcare client? Another one.

We think that is backwards. The whole point of a control framework is that the controls overlap — encrypt data at rest once, and you have satisfied a requirement in a dozen standards. Charging per framework bills you for work you have already done.

So every framework below is on every plan, and OpenGRC aggregates control coverage across all of them. Satisfy a control once and see it credited everywhere it applies.

Framework guides: SOC 2 · ISO 27001 · PCI DSS · NIST CSF · HIPAA · CMMC · FedRAMP · AI governance · DORA · NIS2 · Cyber Essentials · Essential Eight

Every supported framework

Every framework below is included with OpenGRC at no extra cost. There are no per-framework fees on any plan, and no limit on how many you import — 173 bundles covering 39,743 controls.

Import one, and its controls land in your catalogue ready to connect to your implementations, evidence and risks. Import several, and OpenGRC aggregates the overlap so you satisfy a control once rather than once per framework.

Information security management (16)

FrameworkControls
SCF: Secure Controls Framework (2025.2.2)
SCF
1341
SCF: Secure Controls Framework (2024.2)
SCF
1234
Cisco Cloud Controls Framework (CCF) v3.0
Cisco
735
Algemene Beveiligingseisen voor Rijksoverheidsopdrachten (ABRO) 2026
Government of the Netherlands
445
Adobe CCF v5
Adobe
317
CIS Critical Security Controls Implementation Group 3 (IG3)
Center for Internet Security (CIS)
153
International standard ISO/IEC 27001:2013 (Legacy)
ISO/IEC
140
CIS Critical Security Controls Implementation Group 2 (IG2)
Center for Internet Security (CIS)
130
CIS Kubernetes Benchmark
CIS
130
Vehicle CyberSecurity Audit (VCSA) v1.1
ENX
112
ISO 27001:2022
International Standards Organization, International Electrotechnical C
93
Microsoft cloud security benchmark
Microsoft
86
CIS Critical Security Controls Implementation Group 1 (IG1)
Center for Internet Security (CIS)
56
ISO 22301:2019 — Business continuity management systems — Requirements outline
ISO
46
CIS Critical Security Controls
Center for Internet Security (CIS)
18
Agile Security Framework - Baseline
intuitem
14

US federal & defense (20)

FrameworkControls
Criminal Justice Information Services (CJIS) Security Policy 5.9.5 (Legacy)
US CJIS
1567
Criminal Justice Information Services (CJIS) Security Policy
US CJIS
1482
ITAR Compliance Program Guidelines
Directorate of Defense Trade Controls
514
NIST SP 800-53 Security Baseline (High)
NIST
422
GSA FedRAMP Rev5
US General Services Administration
410
NIST SP 800-53 Security Baseline (Moderate)
NIST
287
VENDOR SUPPLY CHAIN RISK MANAGEMENT (SCRM) TEMPLATE
CISA
256
CJIS Security Policy v6
FBI
212
NIST SP 800-53 Security Baseline (Low)
NIST
186
IRS Publication 1075: Tax Information Security Guidelines for Federal, State and Local Agencies
IRS Office of Safeguards
186
Texas Administrative Code 202 (TAC 202) – DIR Security Control Standards Catalog v2.2
Texas Department of Information Resources (DIR)
173
UK Defence Standard 05-138 Issue 4
UK Ministry of Defence (DStan)
148
NIST SP 800-171r2
NIST
110
CMMC Level 2
DoD
110
NIST SP 800-171r3
NIST
97
NIST SP 800-218
NIST
42
CISA Cybersecurity Performance Goals v2.0
CISA
34
Minimum Acceptable Risk Standards for Exchanges (MARS-E) 2.0
CMS/HHS
27
CMMC Level 1
DoD
17
Defense Federal Acquisition Regulation Supplement (DFARS) 252.204
DoD
16

Privacy & data protection (9)

FrameworkControls
E-ITS 2024
RIA
1802
California Consumer Privacy Act Regulations (CCPA)
State of California
425
General Data Protection Regulation
EU
287
California Consumer Privacy Act (CCPA)
State of California
225
Federal Act on Data Protection
Swiss confederation
171
India Digital Personal Data Protection Act 2023
MINISTRY OF LAW AND JUSTICE INDIA
122
NIST PRIVACY FRAMEWORK 1.0
NIST
100
Personal Data Protection Law (KSA)
SDAIA
64
GDPR checklist for data controllers
GDPR.EU
19

AI governance (7)

FrameworkControls
EU Artificial Intelligence Act (AI Act)
EU
347
LLM AI Cybersecurity & Governance Checklist
OWASP
73
NIST AI RMF 1.0
NIST
72
ISO 42001-2023 — Artificial intelligence — Requirements and Controls outline
ISO
67
AI Defense Matrix
AI Defense Matrix
48
Google SAIF Framework
Google
12
OWASP Top 10 for Large Language Model Applications (2025)
OWASP
10

Healthcare & life sciences (9)

FrameworkControls
NIST SP-800-66 rev2 (HIPAA)
NIST
152
HITRUST Common Security Framework (CSF)
HITRUST Alliance
84
HIPAA Security Rule
CMS
49
HIPAA Privacy Rule
HHS
33
21 CFR Part 11 - Electronic Records; Electronic Signatures
FDA
23
42 CFR Part 2 - Confidentiality of Substance Use Disorder Patient Records
HHS/SAMHSA
19
FDA Cybersecurity in Medical Devices: Premarket Guidance (2023)
FDA
19
DEA 21 CFR 1311 - Electronic Prescribing for Controlled Substances (EPCS)
DEA
14
HIPAA Breach Notification Rule
HHS
10

Financial services (20)

FrameworkControls
RTS on ICT risk management framework and on simplified ICT risk management framework
EUROPEAN COMMISSION
554
Cyber resilience oversight expectations for financial market infrastructures
EUROPEAN CENTRAL BANK
331
RTS DORA threat led penetration tests
ESA
295
Digital Operational Resilience Act (DORA)
EU
260
SAMA Cyber Security Fundamentals
SAMA
250
NY DFS 500 with 2023-11 amendments
NEW YORK STATE
165
RBI Master Direction 2023
Ministry of Finance, Government of India
135
NOREA - DORA in Control Framework V3.0
NOREA
95
RTS to specify the policy on ICT services supporting critical or important functions provided by ICT third-party service providers (TPPs)
EUROPEAN COMMISSION
94
RTS on criteria for the classification of ICT-related incidents
EUROPEAN COMMISSION
81
RTS DORA on harmonisation of conditions enabling the conduct of the oversight activities
ESA
78
Standards for Safeguarding Customer Information
Federal Trade Commission
63
RTS DORA - Incident reporting
EUROPEAN COMMISSION
59
Prudential Standard CPS 230
APRA
49
RTS DORA on JET
ESA
47
Swift Customer Security Controls Framework v2025
SWIFT
42
TIBER-EU FRAMEWORK
ECB
36
Prudential Standard CPS 234
APRA
24
SEC Regulation S-P — Privacy of Consumer Financial Information and Safeguarding Customer Information (2024 Amendments)
U.S. Securities and Exchange Commission (SEC)
20
GL-on-costs-and-losses
ESMA
12

Payment & retail (1)

FrameworkControls
Payment Card Industry Data Security Standard (PCI-DSS) 4.0.1
PCI Security Standards Council
351

Operational technology & critical infrastructure (28)

FrameworkControls
NZISM v3
New Zealand Government Communications Security Bureau
1425
ENISA 5G Security Control Matrix v1.3
ENISA
399
NIST SP 800-82 Rev. 3 Appendix F (OT Overlay)
NIST
234
NIST SP 800-82 Annex F
NIST
189
PART-IS.D.OR (Delegated Regulation (EU) 2022/1645)
EU COMMISSION
129
Zero Trust for Operational Technology Activities and Outcomes (ZT OT)
The Department of War (DoW) Chief Information Officer (CIO)
105
IEC 62443-4-2:2019 — Technical security requirements for IACS components (outline)
IEC
92
IEC 62443-2-1:2024 — Security program for IACS asset owners (outline)
IEC
87
IEC 62443-3-3:2013 — System security requirements and security levels (outline)
IEC
54
IEC 62443 - Industrial Automation and Control Systems Security
ISA/IEC
51
Protective Security Policy Framework
Australian Government
51
IEC 62443-4-1:2018 — Secure product development lifecycle requirements (outline)
IEC
47
IEC 62443-3-2:2020 — Security risk assessment for system design (outline)
IEC
32
NERC CIP-003-9 — Security Management Controls
NERC
21
NERC CIP-007-6 — System Security Management
NERC
20
NERC CIP-004-7 — Personnel & Training
NERC
19
NERC CIP-014-3 — Physical Security
NERC
18
NERC CIP-006-6 — Physical Security of BES Cyber Systems
NERC
14
CER directive (Critical Entities Resilience)
EU
14
NERC CIP-005-7 — Electronic Security Perimeter(s)
NERC
12
NERC CIP-008-6 — Incident Reporting and Response Planning
NERC
12
NERC CIP-010-4 — Configuration Change Management and Vulnerability Assessments
NERC
12
IEC 62443-2-4:2023 — Security program for IACS service providers (functional-area outline)
IEC
12
NERC CIP-013-2 — Supply Chain Risk Management
NERC
10
NERC CIP-002-5.1a — BES Cyber System Categorization
NERC
5
NERC CIP-015-1 — Internal Network Security Monitoring
NERC
5
NERC CIP-011-3 — Information Protection
NERC
4
NERC CIP-012-1 — Communications between Control Centers
NERC
3

Application & product security (9)

FrameworkControls
OWASP ASVS 5.0.0
OWASP
345
OWASP Application Security Verification Standard (ASVS) 4.0.3 (Legacy)
OWASP
286
Cyber Resilience Act - Annexes (CRA)
EU
166
OWASP Software Assurance Maturity Model (SAMM) 2.0
OWASP
90
Post-Quantum Cryptography (PQC) Migration Roadmap - May 2025
The MITRE Corporation
26
OWASP Mobile Application Security Verification Standard (MASVS) 2.1.0
OWASP
24
OWASP MASVS 2.1.0
OWASP
24
OWASP API Security Top 10 (2023)
OWASP
10
OWASP Top 10 (2021)
OWASP
10

National & regional schemes (42)

FrameworkControls
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - SYS: IT-Systeme
BSI
1638
K ISMS-P Certification Standard Guide
KISA
1443
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - APP: Anwendungen
BSI
1222
European sustainability reporting standards (ESRS E1/ESRS E2/ESRS E3/ESRS E4/ESRS E5)
EUROPEAN COMMISSION
1051
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - OPS: Betrieb
BSI
1036
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - INF: Infrastruktur
BSI
927
European sustainability reporting standards (ESRS S1/ESRS S2/ESRS S3/ESRS S4/ESRS G1)
EUROPEAN COMMISSION
894
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - NET: Netze und Kommunikation
BSI
892
T.C. CBDDO Bilgi ve İletişim Güvenliği Rehberi (BİGR)
T.C. CBDDO
661
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - CON: Konzeption und Vorgehensweisen
BSI
558
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - DER: Detektion und Reaktion
BSI
546
EUDI_ARF_ANNEX 2.02 - High-Level Requirements by topic
EU
512
European sustainability reporting standards (ESRS 1/ESRS 2)
EUROPEAN COMMISSION
467
Esquema Nacional de Seguridad - ENS (Real Decreto 311/2022)
Ministerio para la Transformación Digital y de la Función Pública - Go
430
Framework Nazionale per la Cybersecurity e la Data Protection (Ed. 2025, v2.1)
ACN
231
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - ORP: Organisation und Personal
BSI
229
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - IND: Industrielle IT
BSI
227
NCSC - Cyber Assessment Framework (CAF) v4.0
NCSC
225
Public AirCyber Maturity Level Matrix
Boost Aerospace
221
CCB CyberFundamentals Framework - 2023-03-01 (Legacy)
CCB
221
CyberFundamentals 2025 (CyFun)
CCB
218
NCSC - Cyber Assessment Framework (CAF) v3.2 (Legacy)
NCSC
184
Trusted Information Security Assessment Exchange (TISAX) v6.0.2
VDA
169
Lietuvos Respublikos kibernetinio saugumo įstatymo reikalavimai subjektams
Lietuvos Respublikos Vyriausybė
163
Operational Technology Cybersecurity Controls
Saudi Arabia's National Cybersecurity Authority
150
Essential Eight Maturity Model (11/2023)
Australian Government
149
Trusted Information Security Assessment Exchange (TISAX) v5.1 (Legacy)
VDA
134
Controlli Minimi AGID
AGID
121
BSI C5 Library
BSI
121
Baseline Information Security for Government 2 (BIO2)
Rijksoverheid
120
Framework Nazionale CyberSecurity v2
CIS-Sapienza & cini
117
Essential Cybersecurity Controls
NCA
114
ICT - Minimum standard
Swiss FONES
108
Cyber Essentials: Requirements for IT infrastructure v3.1
NCSC
100
Mindeststandard-des-BSI-zur-Nutzung-externer-Cloud-Dienste (Version 2.1)
BSI
88
IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - ISMS: Sicherheitsmanagement
BSI
84
National Cybersecurity Controls for Non-CNI Private Sector Entities (NCNICC-1:2025)
NCA
65
NIS2 Directive — Cybersecurity Risk-Management Measures (CIR 2024/2690)
European Union
57
Cloud Cybersecurity Controls (CCC-1:2020)
NCA
55
DE TEKNISKE MINIMUMSKRAV FOR STATSLIGE MYNDIGHEDER
sikker digital
29
Cloud Sovereignty Framework
EUROPEAN COMMISSION
8
CCB CyberFundamentals Small - Self assessment
CCB
8

Other frameworks (12)

FrameworkControls
SOC2-2017 Trust Services Criteria
AICPA
358
SOC2-2017 Trust Services Criteria (revision 2022)
AICPA
330
NIST CSF v1.1 (Legacy)
NIST
108
NIST Cybersecurity Framework (CSF) 2.0
NIST
106
Trust Services Criteria (TSC) 2017 – Revised Points of Focus 2022
AICPA
61
Trust Services Criteria (TSC) 2017 – Security (Common Criteria)
AICPA
33
ITS DORA incident reporting
ESA
25
Trust Services Criteria (TSC) 2017 – Privacy
AICPA
18
OpenGRC Demo Security Standard 1.0
OpenGRC
10
Trust Services Criteria (TSC) 2017 – Processing Integrity
AICPA
5
Trust Services Criteria (TSC) 2017 – Availability
AICPA
3
Trust Services Criteria (TSC) 2017 – Confidentiality
AICPA
2