173 frameworks. No per-framework fees.
Every standard OpenGRC supports, included on every plan. Import as many as you need.
Why we do not charge per framework
Most GRC platforms sell you a framework at a time. Want SOC 2? That is the base. Need ISO 27001 as well because a European customer asked? That is an add-on. HIPAA because you signed a healthcare client? Another one.
We think that is backwards. The whole point of a control framework is that the controls overlap — encrypt data at rest once, and you have satisfied a requirement in a dozen standards. Charging per framework bills you for work you have already done.
So every framework below is on every plan, and OpenGRC aggregates control coverage across all of them. Satisfy a control once and see it credited everywhere it applies.
Framework guides: SOC 2 · ISO 27001 · PCI DSS · NIST CSF · HIPAA · CMMC · FedRAMP · AI governance · DORA · NIS2 · Cyber Essentials · Essential Eight
Every supported framework
Every framework below is included with OpenGRC at no extra cost. There are no per-framework fees on any plan, and no limit on how many you import — 173 bundles covering 39,743 controls.
Import one, and its controls land in your catalogue ready to connect to your implementations, evidence and risks. Import several, and OpenGRC aggregates the overlap so you satisfy a control once rather than once per framework.
Information security management (16)
| Framework | Controls |
|---|---|
| SCF: Secure Controls Framework (2025.2.2) SCF | 1341 |
| SCF: Secure Controls Framework (2024.2) SCF | 1234 |
| Cisco Cloud Controls Framework (CCF) v3.0 Cisco | 735 |
| Algemene Beveiligingseisen voor Rijksoverheidsopdrachten (ABRO) 2026 Government of the Netherlands | 445 |
| Adobe CCF v5 Adobe | 317 |
| CIS Critical Security Controls Implementation Group 3 (IG3) Center for Internet Security (CIS) | 153 |
| International standard ISO/IEC 27001:2013 (Legacy) ISO/IEC | 140 |
| CIS Critical Security Controls Implementation Group 2 (IG2) Center for Internet Security (CIS) | 130 |
| CIS Kubernetes Benchmark CIS | 130 |
| Vehicle CyberSecurity Audit (VCSA) v1.1 ENX | 112 |
| ISO 27001:2022 International Standards Organization, International Electrotechnical C | 93 |
| Microsoft cloud security benchmark Microsoft | 86 |
| CIS Critical Security Controls Implementation Group 1 (IG1) Center for Internet Security (CIS) | 56 |
| ISO 22301:2019 — Business continuity management systems — Requirements outline ISO | 46 |
| CIS Critical Security Controls Center for Internet Security (CIS) | 18 |
| Agile Security Framework - Baseline intuitem | 14 |
US federal & defense (20)
| Framework | Controls |
|---|---|
| Criminal Justice Information Services (CJIS) Security Policy 5.9.5 (Legacy) US CJIS | 1567 |
| Criminal Justice Information Services (CJIS) Security Policy US CJIS | 1482 |
| ITAR Compliance Program Guidelines Directorate of Defense Trade Controls | 514 |
| NIST SP 800-53 Security Baseline (High) NIST | 422 |
| GSA FedRAMP Rev5 US General Services Administration | 410 |
| NIST SP 800-53 Security Baseline (Moderate) NIST | 287 |
| VENDOR SUPPLY CHAIN RISK MANAGEMENT (SCRM) TEMPLATE CISA | 256 |
| CJIS Security Policy v6 FBI | 212 |
| NIST SP 800-53 Security Baseline (Low) NIST | 186 |
| IRS Publication 1075: Tax Information Security Guidelines for Federal, State and Local Agencies IRS Office of Safeguards | 186 |
| Texas Administrative Code 202 (TAC 202) – DIR Security Control Standards Catalog v2.2 Texas Department of Information Resources (DIR) | 173 |
| UK Defence Standard 05-138 Issue 4 UK Ministry of Defence (DStan) | 148 |
| NIST SP 800-171r2 NIST | 110 |
| CMMC Level 2 DoD | 110 |
| NIST SP 800-171r3 NIST | 97 |
| NIST SP 800-218 NIST | 42 |
| CISA Cybersecurity Performance Goals v2.0 CISA | 34 |
| Minimum Acceptable Risk Standards for Exchanges (MARS-E) 2.0 CMS/HHS | 27 |
| CMMC Level 1 DoD | 17 |
| Defense Federal Acquisition Regulation Supplement (DFARS) 252.204 DoD | 16 |
Privacy & data protection (9)
| Framework | Controls |
|---|---|
| E-ITS 2024 RIA | 1802 |
| California Consumer Privacy Act Regulations (CCPA) State of California | 425 |
| General Data Protection Regulation EU | 287 |
| California Consumer Privacy Act (CCPA) State of California | 225 |
| Federal Act on Data Protection Swiss confederation | 171 |
| India Digital Personal Data Protection Act 2023 MINISTRY OF LAW AND JUSTICE INDIA | 122 |
| NIST PRIVACY FRAMEWORK 1.0 NIST | 100 |
| Personal Data Protection Law (KSA) SDAIA | 64 |
| GDPR checklist for data controllers GDPR.EU | 19 |
AI governance (7)
| Framework | Controls |
|---|---|
| EU Artificial Intelligence Act (AI Act) EU | 347 |
| LLM AI Cybersecurity & Governance Checklist OWASP | 73 |
| NIST AI RMF 1.0 NIST | 72 |
| ISO 42001-2023 — Artificial intelligence — Requirements and Controls outline ISO | 67 |
| AI Defense Matrix AI Defense Matrix | 48 |
| Google SAIF Framework | 12 |
| OWASP Top 10 for Large Language Model Applications (2025) OWASP | 10 |
Healthcare & life sciences (9)
| Framework | Controls |
|---|---|
| NIST SP-800-66 rev2 (HIPAA) NIST | 152 |
| HITRUST Common Security Framework (CSF) HITRUST Alliance | 84 |
| HIPAA Security Rule CMS | 49 |
| HIPAA Privacy Rule HHS | 33 |
| 21 CFR Part 11 - Electronic Records; Electronic Signatures FDA | 23 |
| 42 CFR Part 2 - Confidentiality of Substance Use Disorder Patient Records HHS/SAMHSA | 19 |
| FDA Cybersecurity in Medical Devices: Premarket Guidance (2023) FDA | 19 |
| DEA 21 CFR 1311 - Electronic Prescribing for Controlled Substances (EPCS) DEA | 14 |
| HIPAA Breach Notification Rule HHS | 10 |
Financial services (20)
| Framework | Controls |
|---|---|
| RTS on ICT risk management framework and on simplified ICT risk management framework EUROPEAN COMMISSION | 554 |
| Cyber resilience oversight expectations for financial market infrastructures EUROPEAN CENTRAL BANK | 331 |
| RTS DORA threat led penetration tests ESA | 295 |
| Digital Operational Resilience Act (DORA) EU | 260 |
| SAMA Cyber Security Fundamentals SAMA | 250 |
| NY DFS 500 with 2023-11 amendments NEW YORK STATE | 165 |
| RBI Master Direction 2023 Ministry of Finance, Government of India | 135 |
| NOREA - DORA in Control Framework V3.0 NOREA | 95 |
| RTS to specify the policy on ICT services supporting critical or important functions provided by ICT third-party service providers (TPPs) EUROPEAN COMMISSION | 94 |
| RTS on criteria for the classification of ICT-related incidents EUROPEAN COMMISSION | 81 |
| RTS DORA on harmonisation of conditions enabling the conduct of the oversight activities ESA | 78 |
| Standards for Safeguarding Customer Information Federal Trade Commission | 63 |
| RTS DORA - Incident reporting EUROPEAN COMMISSION | 59 |
| Prudential Standard CPS 230 APRA | 49 |
| RTS DORA on JET ESA | 47 |
| Swift Customer Security Controls Framework v2025 SWIFT | 42 |
| TIBER-EU FRAMEWORK ECB | 36 |
| Prudential Standard CPS 234 APRA | 24 |
| SEC Regulation S-P — Privacy of Consumer Financial Information and Safeguarding Customer Information (2024 Amendments) U.S. Securities and Exchange Commission (SEC) | 20 |
| GL-on-costs-and-losses ESMA | 12 |
Payment & retail (1)
| Framework | Controls |
|---|---|
| Payment Card Industry Data Security Standard (PCI-DSS) 4.0.1 PCI Security Standards Council | 351 |
Operational technology & critical infrastructure (28)
| Framework | Controls |
|---|---|
| NZISM v3 New Zealand Government Communications Security Bureau | 1425 |
| ENISA 5G Security Control Matrix v1.3 ENISA | 399 |
| NIST SP 800-82 Rev. 3 Appendix F (OT Overlay) NIST | 234 |
| NIST SP 800-82 Annex F NIST | 189 |
| PART-IS.D.OR (Delegated Regulation (EU) 2022/1645) EU COMMISSION | 129 |
| Zero Trust for Operational Technology Activities and Outcomes (ZT OT) The Department of War (DoW) Chief Information Officer (CIO) | 105 |
| IEC 62443-4-2:2019 — Technical security requirements for IACS components (outline) IEC | 92 |
| IEC 62443-2-1:2024 — Security program for IACS asset owners (outline) IEC | 87 |
| IEC 62443-3-3:2013 — System security requirements and security levels (outline) IEC | 54 |
| IEC 62443 - Industrial Automation and Control Systems Security ISA/IEC | 51 |
| Protective Security Policy Framework Australian Government | 51 |
| IEC 62443-4-1:2018 — Secure product development lifecycle requirements (outline) IEC | 47 |
| IEC 62443-3-2:2020 — Security risk assessment for system design (outline) IEC | 32 |
| NERC CIP-003-9 — Security Management Controls NERC | 21 |
| NERC CIP-007-6 — System Security Management NERC | 20 |
| NERC CIP-004-7 — Personnel & Training NERC | 19 |
| NERC CIP-014-3 — Physical Security NERC | 18 |
| NERC CIP-006-6 — Physical Security of BES Cyber Systems NERC | 14 |
| CER directive (Critical Entities Resilience) EU | 14 |
| NERC CIP-005-7 — Electronic Security Perimeter(s) NERC | 12 |
| NERC CIP-008-6 — Incident Reporting and Response Planning NERC | 12 |
| NERC CIP-010-4 — Configuration Change Management and Vulnerability Assessments NERC | 12 |
| IEC 62443-2-4:2023 — Security program for IACS service providers (functional-area outline) IEC | 12 |
| NERC CIP-013-2 — Supply Chain Risk Management NERC | 10 |
| NERC CIP-002-5.1a — BES Cyber System Categorization NERC | 5 |
| NERC CIP-015-1 — Internal Network Security Monitoring NERC | 5 |
| NERC CIP-011-3 — Information Protection NERC | 4 |
| NERC CIP-012-1 — Communications between Control Centers NERC | 3 |
Application & product security (9)
| Framework | Controls |
|---|---|
| OWASP ASVS 5.0.0 OWASP | 345 |
| OWASP Application Security Verification Standard (ASVS) 4.0.3 (Legacy) OWASP | 286 |
| Cyber Resilience Act - Annexes (CRA) EU | 166 |
| OWASP Software Assurance Maturity Model (SAMM) 2.0 OWASP | 90 |
| Post-Quantum Cryptography (PQC) Migration Roadmap - May 2025 The MITRE Corporation | 26 |
| OWASP Mobile Application Security Verification Standard (MASVS) 2.1.0 OWASP | 24 |
| OWASP MASVS 2.1.0 OWASP | 24 |
| OWASP API Security Top 10 (2023) OWASP | 10 |
| OWASP Top 10 (2021) OWASP | 10 |
National & regional schemes (42)
| Framework | Controls |
|---|---|
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - SYS: IT-Systeme BSI | 1638 |
| K ISMS-P Certification Standard Guide KISA | 1443 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - APP: Anwendungen BSI | 1222 |
| European sustainability reporting standards (ESRS E1/ESRS E2/ESRS E3/ESRS E4/ESRS E5) EUROPEAN COMMISSION | 1051 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - OPS: Betrieb BSI | 1036 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - INF: Infrastruktur BSI | 927 |
| European sustainability reporting standards (ESRS S1/ESRS S2/ESRS S3/ESRS S4/ESRS G1) EUROPEAN COMMISSION | 894 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - NET: Netze und Kommunikation BSI | 892 |
| T.C. CBDDO Bilgi ve İletişim Güvenliği Rehberi (BİGR) T.C. CBDDO | 661 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - CON: Konzeption und Vorgehensweisen BSI | 558 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - DER: Detektion und Reaktion BSI | 546 |
| EUDI_ARF_ANNEX 2.02 - High-Level Requirements by topic EU | 512 |
| European sustainability reporting standards (ESRS 1/ESRS 2) EUROPEAN COMMISSION | 467 |
| Esquema Nacional de Seguridad - ENS (Real Decreto 311/2022) Ministerio para la Transformación Digital y de la Función Pública - Go | 430 |
| Framework Nazionale per la Cybersecurity e la Data Protection (Ed. 2025, v2.1) ACN | 231 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - ORP: Organisation und Personal BSI | 229 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - IND: Industrielle IT BSI | 227 |
| NCSC - Cyber Assessment Framework (CAF) v4.0 NCSC | 225 |
| Public AirCyber Maturity Level Matrix Boost Aerospace | 221 |
| CCB CyberFundamentals Framework - 2023-03-01 (Legacy) CCB | 221 |
| CyberFundamentals 2025 (CyFun) CCB | 218 |
| NCSC - Cyber Assessment Framework (CAF) v3.2 (Legacy) NCSC | 184 |
| Trusted Information Security Assessment Exchange (TISAX) v6.0.2 VDA | 169 |
| Lietuvos Respublikos kibernetinio saugumo įstatymo reikalavimai subjektams Lietuvos Respublikos Vyriausybė | 163 |
| Operational Technology Cybersecurity Controls Saudi Arabia's National Cybersecurity Authority | 150 |
| Essential Eight Maturity Model (11/2023) Australian Government | 149 |
| Trusted Information Security Assessment Exchange (TISAX) v5.1 (Legacy) VDA | 134 |
| Controlli Minimi AGID AGID | 121 |
| BSI C5 Library BSI | 121 |
| Baseline Information Security for Government 2 (BIO2) Rijksoverheid | 120 |
| Framework Nazionale CyberSecurity v2 CIS-Sapienza & cini | 117 |
| Essential Cybersecurity Controls NCA | 114 |
| ICT - Minimum standard Swiss FONES | 108 |
| Cyber Essentials: Requirements for IT infrastructure v3.1 NCSC | 100 |
| Mindeststandard-des-BSI-zur-Nutzung-externer-Cloud-Dienste (Version 2.1) BSI | 88 |
| IT-Grundschutz-Kompendium – Werkzeug für Informationssicherheit - ISMS: Sicherheitsmanagement BSI | 84 |
| National Cybersecurity Controls for Non-CNI Private Sector Entities (NCNICC-1:2025) NCA | 65 |
| NIS2 Directive — Cybersecurity Risk-Management Measures (CIR 2024/2690) European Union | 57 |
| Cloud Cybersecurity Controls (CCC-1:2020) NCA | 55 |
| DE TEKNISKE MINIMUMSKRAV FOR STATSLIGE MYNDIGHEDER sikker digital | 29 |
| Cloud Sovereignty Framework EUROPEAN COMMISSION | 8 |
| CCB CyberFundamentals Small - Self assessment CCB | 8 |
Other frameworks (12)
| Framework | Controls |
|---|---|
| SOC2-2017 Trust Services Criteria AICPA | 358 |
| SOC2-2017 Trust Services Criteria (revision 2022) AICPA | 330 |
| NIST CSF v1.1 (Legacy) NIST | 108 |
| NIST Cybersecurity Framework (CSF) 2.0 NIST | 106 |
| Trust Services Criteria (TSC) 2017 – Revised Points of Focus 2022 AICPA | 61 |
| Trust Services Criteria (TSC) 2017 – Security (Common Criteria) AICPA | 33 |
| ITS DORA incident reporting ESA | 25 |
| Trust Services Criteria (TSC) 2017 – Privacy AICPA | 18 |
| OpenGRC Demo Security Standard 1.0 OpenGRC | 10 |
| Trust Services Criteria (TSC) 2017 – Processing Integrity AICPA | 5 |
| Trust Services Criteria (TSC) 2017 – Availability AICPA | 3 |
| Trust Services Criteria (TSC) 2017 – Confidentiality AICPA | 2 |
™