Ross ROSS = Recommend OSS · open-source software intelligence for agents

intuitem/ciso-assistant-community

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more. observed · 2026-08-28

github.com/intuitem/ciso-assistant-community · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

90/100

  • Activity 99
  • Release rhythm 87
  • Longevity 77

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 2.0
  • age_days: 1078
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 249

Full methodology

Adoption not part of the score

4376 stars · 823 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

CISO Assistant is an open-source, self-hostable GRC (Governance, Risk, and Compliance) platform covering risk management, compliance and audit, AppSec, third-party risk, privacy, and reporting. It ships with 150+ built-in regulatory and security frameworks (ISO 27001, NIST CSF, SOC 2, DORA, GDPR, etc.) with automatic control mapping, an API-first design, and an optional local AI engine.

Use cases

  • manage ISO 27001 compliance and ISMS documentation
  • run risk assessments and track remediation plans
  • map controls automatically across multiple frameworks like SOC 2 and NIST CSF
  • manage audits with centralized evidence collection
  • perform third-party risk management (TPRM)
  • conduct GDPR privacy impact assessments
  • generate compliance reports for auditors
  • replace spreadsheet-based GRC tracking

When to choose

  • you need a unified GRC hub instead of scattered Excel sheets
  • you must comply with multiple frameworks and want automatic cross-mapping
  • you want a self-hosted or on-premises compliance tool for sensitive data
  • you need API-first automation and import/export across formats
  • you want built-in risk assessment and audit workflows out of the box

When to avoid

  • you need a lightweight CLI-only compliance checker
  • you require a fully managed SaaS with vendor-held certifications rather than self-hosting
  • your needs are limited to a single narrow framework with no risk or audit management
  • you cannot accept the AGPLv3 license terms

Facets

application · maturity active

security workflow-automation analytics api-framework llm-inference mcp security legal self-hosted self-hosted cloud cross-platform grc compliance iso27001 soc2 nist-csf gdpr audit-management risk-assessment tprm appsec isms framework-mapping agpl reporting risk-management automation web-server docker

5 sources

Member repositories

RepositoryRoleHealth v2
intuitem/ciso-assistant-communitymain90

For agents

markdown · JSON · MCP: product_card(name="intuitem/ciso-assistant-community")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem