GRCEngClub/claude-grc-engineering

Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.

What it solves

This project provides a toolkit for automating Governance, Risk, and Compliance (GRC) tasks. It transforms technical evidence from cloud providers, SaaS tools, and codebases into framework-aligned findings, gap reports, and remediation guidance, treating compliance as an engineering problem that is repeatable and versioned.

How it works

The toolkit operates as a plugin marketplace for the Claude ecosystem (Claude Code, Claude Desktop, and Claude Cowork). It uses a pipeline model where connector plugins collect evidence from sources like AWS, GitHub, and Okta, normalize it into a standard "Finding" schema, and then use the grc-engineer hub to map these findings against the Secure Controls Framework (SCF) and various compliance frameworks (e.g., SOC 2, NIST 800-53, ISO 27001).

Who it’s for

It is designed for GRC practitioners, security engineers, auditors, and platform teams who want to automate their compliance workflows and integrate them into their technical environment.

Highlights

  • Multi-Framework Support: Maps evidence to a wide array of standards including SOC 2, FedRAMP, HIPAA, and GDPR.
  • Extensible Plugin System: Includes specialized plugins for different personas (auditors, internal GRC), connectors for various cloud/SaaS tools, and diagramming tools for draw.io.
  • Automated Remediation: Generates remediation code, scripts, and policies to close compliance gaps.
  • OSCAL Integration: Provides tooling for FedRAMP/OSCAL workflows and SSP/SAR/POA&M outputs.
  • Unified Data Contract: Uses a versioned Finding schema to ensure consistency across different evidence connectors.

Related

  • Project
  • Project
  • Project
  • Project
  • Project