All posts

Open-Source GRC Tools Compared: Four Candidates for SMEs

CISO Assistant, Eramba, verinice and SimpleRisk in a hands-on comparison: frameworks, risk register, operations and licence — and which tool suits which SME.

If you want to get GRC out of Excel, you quickly end up with the big suites — and with five-figure annual licences that bear no relation to the benefit for an SME. Yet the open-source space now has four serious candidates. They are not equally good, but they are good at different things. Here is my comparison, deliberately from the perspective of a company with 30 to 300 employees.

In short: CISO Assistant is the most modern platform with the largest framework library; verinice the best choice when BSI IT-Grundschutz or TISAX are in play; SimpleRisk the simplest tool for a pure risk register; Eramba the established classic whose community edition you should check before using. All four run self-hosted.

The criteria

A GRC tool has to do seven things for an SME, otherwise Excel stays open in the end anyway:

  1. Frameworks included — ISO 27001, NIS2, nDSG-relevant catalogues — and the ability to map several of them onto the same measures.
  2. Risk register with scenarios, assessment and links to measures.
  3. Measures and evidence with owners, deadlines and proof.
  4. Operations that work without your own development department: Docker, updates, backups.
  5. Licence that still applies in three years.
  6. Maturity: active development, community, documentation.
  7. Multi-user capability with roles — auditors read, owners maintain, management sees the dashboard.

Deliberately not on the list: the number of features. A tool that can do everything is used ten percent and ignored ninety percent in an SME. What matters is whether the three people who work with it still open it after a month. That can only be found out by testing — hence the one-week plan further down.

CISO Assistant

The youngest project of the four, developed by intuitem in France, community edition under AGPL. The core is a clean data model: frameworks, assessments, reference and applied controls, evidence and risk scenarios are objects with relationships — not rows in tables. The library covers over a hundred frameworks, from ISO 27001 through NIS2 and DORA to CIS Controls and BSI IT-Grundschutz, and the mapping between them is the strongest function. The interface is modern (SvelteKit), the backend Python.

Weaknesses: the terms need getting used to, SSO is only in the Pro version, and the release frequency is high — whoever does not update regularly quickly falls behind. I have described the tool in detail in CISO Assistant: GRC Without the Excel Graveyard.

Eramba

Eramba is the classic among open-source GRC tools and has been in use for over ten years, developed in Argentina and the United Kingdom. The feature set is broad: compliance management, risks, policies, audits, supplier evaluation, awareness programmes — much of it with workflows and reminders that larger organisations need. The community is experienced, the documentation extensive.

The limitation: the vendor clearly steers new customers towards the Enterprise version, and the community edition has lost importance in recent years; the licence model has changed several times. Whoever starts today should check the current state of the community edition, its update policy and the licence before entering data. Compared with CISO Assistant the interface takes some getting used to.

verinice

verinice comes from SerNet in Göttingen and is the reference for BSI IT-Grundschutz in the German-speaking world. The classic verinice is a desktop application under GPL, complemented by a server version for teams; the new, web-based generation verinice.veo is offered as a subscription. Its strengths lie where German catalogues are required: the IT-Grundschutz compendium, ISO 27001, TISAX (VDA ISA), data protection under GDPR. For a Swiss SME this is relevant when German automotive or industrial customers demand TISAX.

Weaknesses: the classic desktop interface feels old, the modelling is fond of detail, and whoever only needs ISO 27001 carries a lot of IT-Grundschutz ballast.

SimpleRisk

SimpleRisk from Texas does one thing and does it simply: risk management. Record risks, assess them, plan measures, schedule reviews, pull reports — in an interface you understand without training. The core is under the Mozilla Public License; compliance functions, API and notifications come as paid extensions.

For an SME whose first step is a clean risk register, that is enough. For framework assessments with evidence and mapping it is too narrow — that needs the extensions, and then the price advantage is gone.

Comparison at a glance

CISO Assistant Eramba verinice SimpleRisk
Licence (community) AGPL Check, model changed GPL (classic) MPL (core)
Focus Compliance + risk Broad GRC IT-Grundschutz, ISO, TISAX Risk register
Frameworks 100+, mapping Many, manual German catalogues strong Few, extension needed
Risk register Yes, linked Yes Yes Yes, core function
Evidence Yes Yes Yes Extension
Operations Docker Docker Desktop / server Docker, PHP
Roles / SSO Roles yes, SSO Pro Yes Server version Extension
Getting started Medium Medium to high High Easy

Operations and costs compared

All four run on a small server; a virtual host for 20 to 40 francs a month is enough. The difference lies in the operating time: CISO Assistant and SimpleRisk update with one Docker command, Eramba likewise, classic verinice requires installations on every workstation. Backups are database dumps plus uploaded files for all of them — daily, automated, restored once a quarter. Counting the onboarding, the effort in the first year is two to five working days, after that one to two hours a week. Commercial suites take this work off your hands, but typically cost a high four-figure to five-figure amount per year — for an SME usually more than the entire GRC budget.

How to test in one week

A proof of concept does not have to take long. The sequence I suggest:

  1. Day 1: Install two candidates via Docker, create one user each, HTTPS via a reverse proxy — whoever cannot manage that in two hours has answered the first criterion.
  2. Day 2: Import the most important framework and honestly assess ten requirements. How many clicks does an implementation status with a comment take?
  3. Day 3: Migrate twenty risks from the existing spreadsheet and link them to measures. Does import from Excel work or only by hand?
  4. Day 4: Upload five pieces of evidence and give an auditor role read access. Does it see what it should see — and nothing else?
  5. Day 5: Check dashboard and export: can management read the status without explanation? Then decide — and switch the spreadsheet off.

Which tool for whom

  • First step out of Excel, focus on risks: SimpleRisk. Productive in an afternoon, no terms to learn.
  • Demonstrate ISO 27001 or NIS2, several frameworks, data in-house: CISO Assistant. The mapping saves half the work on every second framework.
  • German industrial customers, TISAX or IT-Grundschutz required: verinice. No other tool models the catalogues so precisely.
  • Organisation with 200+ employees and a need for workflows, supplier management and awareness tracking: Eramba — after clarifying the licence question first, otherwise straight to Enterprise.

If you have the path to certification ahead of you, ISO 27001 for Swiss SMEs has the roadmap into which each of these tools fits.

What no tool solves

All four are only as good as the data you enter. A risk register with twenty carefully assessed scenarios is worth more than one with two hundred copied ones. A tool forces nobody to implement measures — it only makes visible that they are missing. And it replaces no decision about how much security the company wants to afford: for that the security budget check gives a guide value before the first tool is installed.