grcboard.io
Risk and compliance, made simple. The spreadsheet alternative for ISO 27001 and NIS2 — now live.
grcboard.io is live: one place to run a whole GRC programme. The simple alternative to Excel and Google Sheets for risks, controls, non-conformities and policy exceptions — built for CISOs, compliance managers and GRC consultants. We designed and built the entire product: application, design system and operational backend. It's our flagship project and proof that purposeful software ships faster than feature-bloated software.
What it does
Six connected registers, one source of truth: risks, controls, non-conformities and policy exceptions, plus assets and vendors on Pro. Everything is linked — residual scores recompute the moment a control changes, and every edit is captured in an audit trail.
Compliance built in, not bolted on
ISO 27001:2022, NIS2 and NIS2 CyFun ship preloaded, with gap analysis, Statement of Applicability and live compliance dashboards. Custom frameworks cover GDPR, DORA or SOC 2, and Pro adds EBIOS RM, AI Governance (EU AI Act, NIST AI RMF) and FAIR quantitative risk analysis.
Who it serves
- CISOs — the whole risk and compliance posture at a glance, proved with audit-ready reports.
- Compliance managers — track gaps, close non-conformities, keep every piece of evidence in one place.
- GRC consultants — every client in one multi-tenant workspace, with unlimited organisations.
