intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more. observed · 2026-08-28
Health v2 · maintenance only
90/100
- Activity 99
- Release rhythm 87
- Longevity 77
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 2.0
- age_days: 1078
- days_rel: 7
- days_push: 7
- n_releases_24m: 249
Adoption not part of the score
4376 stars · 823 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
CISO Assistant is an open-source, self-hostable GRC (Governance, Risk, and Compliance) platform covering risk management, compliance and audit, AppSec, third-party risk, privacy, and reporting. It ships with 150+ built-in regulatory and security frameworks (ISO 27001, NIST CSF, SOC 2, DORA, GDPR, etc.) with automatic control mapping, an API-first design, and an optional local AI engine.
Use cases
- manage ISO 27001 compliance and ISMS documentation
- run risk assessments and track remediation plans
- map controls automatically across multiple frameworks like SOC 2 and NIST CSF
- manage audits with centralized evidence collection
- perform third-party risk management (TPRM)
- conduct GDPR privacy impact assessments
- generate compliance reports for auditors
- replace spreadsheet-based GRC tracking
When to choose
- you need a unified GRC hub instead of scattered Excel sheets
- you must comply with multiple frameworks and want automatic cross-mapping
- you want a self-hosted or on-premises compliance tool for sensitive data
- you need API-first automation and import/export across formats
- you want built-in risk assessment and audit workflows out of the box
When to avoid
- you need a lightweight CLI-only compliance checker
- you require a fully managed SaaS with vendor-held certifications rather than self-hosting
- your needs are limited to a single narrow framework with no risk or audit management
- you cannot accept the AGPLv3 license terms
Facets
application · maturity active
security workflow-automation analytics api-framework llm-inference mcp security legal self-hosted self-hosted cloud cross-platform grc compliance iso27001 soc2 nist-csf gdpr audit-management risk-assessment tprm appsec isms framework-mapping agpl reporting risk-management automation web-server docker
5 sources
- readme: https://github.com/intuitem/ciso-assistant-community · fetched 2026-08-28 · c8eddaeb80bc
- homepage: https://intuitem.com · fetched 2026-08-29 · cac9cbc633e6
- site_page: https://intuitem.com/about · fetched 2026-08-29 · 654fd765d9b2
- site_page: https://intuitem.com/pricing · fetched 2026-08-29 · de1994af87eb
- site_page: https://intuitem.com/faq · fetched 2026-08-29 · 35020b13fc76
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| intuitem/ciso-assistant-community | main | 90 |
For agents
markdown · JSON · MCP: product_card(name="intuitem/ciso-assistant-community")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem