claude-grc-engineering
Reduces manual compliance mapping and evidence collection cycles by automating framework crosswalks and gap analysis across NIST, ISO, SOC 2, and other stand…
Official open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
- Generate OSCAL-formatted control mappings across three frameworks simultaneously
- Collect and categorize evidence files against specific control requirements
- Identify gaps between current controls and target compliance frameworks
Reduces manual compliance mapping and evidence collection cycles by automating framework crosswalks and gap analysis across NIST, ISO, SOC 2, and other standards. Cuts audit preparation time from weeks to days.
Compliance engineers and security teams managing multi-framework attestations who need repeatable, auditable evidence workflows without building custom connectors.
https://github.com/GRCEngClub/claude-grc-engineering
By GRCEngClub
How to Get It
claude plugins install GRCEngClub/claude-grc-engineering
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.
After installing, paste this into Claude:
Help me generate OSCAL-formatted control mappings across three frameworks simultaneously
Trust Signals Auto-scanned
Community Pulse Growing
Discussed on Reddit
- I built a Claude skill for PII detection - I work at a compliance company so I a — Reddit · 110 pts
- Vibe Coded Web App Audit - Looking for Fractional CTO/Product Engineering Team — Reddit · 8 pts
- Building AI-powered GRC tooling for startups/small teams - is there actually a m — Reddit · 3 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
Scored from trust signals (evidence-eval-v1): 353 GitHub stars; 23 contributors; last commit 3d ago; license no license.
Things to check
- Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
Scored from trust signals (evidence-eval-v1): 353 GitHub stars; 23 contributors; last commit 3d ago; license no license.