Cybersecurity Marketplace

Governance Risk & Compliance (GRC)

Our Marketplace offers free cybersecurity solutions to help startups and small businesses with limited budgets manage cyber risk. In addition to solutions, we offer Virtual CISO services to help small businesses meet cybersecurity standards. Our Cybersecurity Marketplace combined with our Virtual CISO Services helps ensure that small businesses receive best-in-class cybersecurity consulting and services at a fraction of the market cost.

Marketplace

Contact Us

All Products

32Products
Logo for SOC 2 Gap Assessment

SOC 2 Gap Assessment

Governance Risk & Compliance (GRC)

The SOC 2 Gap Assessment is a free tool that measures your organization against the AICPA 2017 Trust Services Criteria (with Revised Points of Focus, 2022) used in SOC 2 examinations. Assess all 61 criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy at the SOC 2 Type I or SOC 2 Type II level; generate a downloadable report that includes a remediation roadmap.

Free
Visit
Logo for ISO 27001 Gap Assessment

ISO 27001 Gap Assessment

Governance Risk & Compliance (GRC)

The ISO 27001 Gap Assessment is a free tool that measures your organization against ISO/IEC 27001:2022, the international standard for Information Security Management Systems (ISMS). Assess the Clause 4 to 10 management system requirements at the Clauses Only (Level 1) scope, or add all 93 Annex A controls at the Clauses & Annex Controls (Level 2) scope; generate a downloadable report that includes a remediation roadmap.

Free
Visit
Logo for ISO 42001 Gap Assessment

ISO 42001 Gap Assessment

Governance Risk & Compliance (GRC)

The ISO 42001 Gap Assessment is a free tool that measures your organization against ISO/IEC 42001:2023, the international standard for Artificial Intelligence Management Systems (AIMS). Assess the Clause 4 to 10 management system requirements at a Basic (Level 1) scope, or a Standard (Level 2) scope; generate a downloadable report that includes a remediation roadmap.

Free
Visit
Logo for CIS Gap Assessment

CIS Gap Assessment

Governance Risk & Compliance (GRC)

The CIS Gap Assessment is a free tool that measures your organization against the 56 Implementation Group 1 (IG1) Safeguards of the CIS Critical Security Controls v8.1, the essential cyber hygiene baseline every enterprise should implement first, with likelihood and impact risk scoring, a ranked gap list, and a downloadable report with a prioritized remediation roadmap.

Free
Visit
Logo for Canada Cybersecurity Baseline Assessment

Canada Cybersecurity Baseline Assessment

Governance Risk & Compliance (GRC)

The Cybersecurity Baseline Assessment is a free tool that measures a small or medium organization against CAN/DGSI 104:2021 (Rev 2:2026), Canada's national standard for baseline cyber security controls, with likelihood and impact risk scoring, a ranked gap list, and a downloadable report with a prioritized remediation roadmap.

Free
Visit
Github Logo image

CISO Assistant

Governance Risk & Compliance (GRC)

Open-source GRC platform for cyber risk management and compliance

Free
Visit
Eramba Logo

Eramba (Community)

Governance Risk & Compliance (GRC)

Open-source GRC platform for risk management, compliance, and audit

Free
Visit
Watchdog Security Logo

Watchdog Security

Governance Risk & Compliance (GRC)

The All Inclusive Cyber Security Platform That Startups & SMBs Trust. Affordable cybersecurity subscriptions offering complete protection that scale with your business.

Free
Visit
RegScale

RegScale

Governance Risk & Compliance (GRC)

RegScale GRC Platform helps you stay continuously compliant with the vast number of growing regulations that govern your organization and industry - all in real-time.

Free
Visit
SimpleRisk

SimpleRisk

Governance Risk & Compliance (GRC)

SimpleRisk is a comprehensive GRC platform that can be used for all of your Governance, Risk Management and Compliance needs. SimpleRisk Core can be downloaded for free, installed in minutes, and provides all of the capabilities that you need when first launching your GRC program.

Free
Visit
A logo with the word e-learning on it.

Open Source GRC

Governance Risk & Compliance (GRC)

Welcome to OpenSource GRC. This is a free, open and collaborative platform for GRC compliance mappings, controls and policies templates.

Free
Visit
The logo for ccm cloud control matrix.

Cloud Controls Matrix (CCM)

Governance Risk & Compliance (GRC)

The CSA Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing. It is composed of 197 control objectives that are structured in 17 domains covering all key aspects of cloud technology. The controls framework is aligned to the CSA Security Guidance for Cloud Computing, and is considered a de-facto standard for cloud security assurance and compliance.

Free
Visit

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.