Direct answer: We published awesome-compliance-automation, a curated list of 357 tools and resources for automating compliance across SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, GDPR, PIPEDA, Quebec Law 25 and NIST CSF. It is organized twice over: by function, so you can find every access review tool in one place, and by framework, so you can find what applies to the standard you are actually being audited against. Released under CC0, with no affiliate links.
Why we built it
Compliance tooling is an unusually opaque market. The category leaders spend heavily on content, so a search for any compliance problem returns their blog explaining that the solution is their platform. That content is often good. It is not neutral, and it is not comprehensive.
Meanwhile there is a substantial open-source layer that almost never appears in those comparisons, because nobody is paying to promote it. Teams with an engineering culture and a modest budget frequently get further with open tooling and a clear control set than with a subscription they have not configured properly.
The list is the thing we would have wanted before recommending anything: a complete picture, with the commercial and open options side by side and no ordering that anybody paid for.
How it is organized
By function first, because that is how the problem usually arrives. You do not wake up wanting a GRC platform. You wake up because access reviews are late.
- GRC platforms. The all-in-one tools, listed without ranking.
- Policy management and evidence collection and automation.
- Access review tools. The single most common reason a first Type II picks up an exception.
- Vendor risk management.
- Security awareness training and background checks.
- Vulnerability management and cloud security posture management.
- Penetration testing platforms and incident response.
- Trust centers and security pages.
- Endpoint security and device management.
Then by framework, which is the view you want when someone has told you which standard you are being held to. SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR and privacy, NIST CSF, Canadian privacy covering PIPEDA and Quebec Law 25, and AI governance under ISO 42001. That last section is the one growing fastest and the one most existing lists do not have at all.
Then a dedicated open-source section: cloud security and posture management, infrastructure as code scanning, vulnerability scanning, compliance as code, Kubernetes security, identity and secrets, incident response and forensics, and privacy tooling.
How to shortlist without burning a quarter
Tool selection expands to fill whatever time you give it. A structure that keeps it to two weeks:
Decide your control set before you look at any tool. This is the step everyone skips and it is the only one that matters. A platform configures itself around a control set. If you do not have one, you will adopt the vendor's default and then spend the audit explaining why your system description does not match your evidence.
Write down the three things that are actually failing. Not the twenty things that could be better. If access reviews and vendor reviews are late and evidence is scattered, you are shopping for three capabilities, and most of the feature matrices you are about to read are irrelevant.
Check integration coverage against your real stack, not the logo wall. The value of an automation platform is almost entirely in what it can connect to. A tool that integrates with your identity provider, your cloud and your source control does most of the work. One that misses your identity provider will generate manual tasks forever, whatever else it does.
Price the second year. First year pricing is frequently discounted against an implementation fee, and the renewal is the real number. Ask for it in writing during the sales process, when you have leverage.
Ask what happens to your data if you leave. Policies, evidence, control descriptions and register contents should be exportable in a usable format. Some platforms make this awkward enough that switching becomes a migration project, which is a supplier decision you want to make knowingly.
What a tool list cannot tell you
Whether you need one of these at all.
Automation platforms earn their fee when you have enough headcount churn, enough systems and enough framework overlap that manual collection genuinely does not scale. Below that, a platform is a subscription that produces a dashboard, and the dashboard being green tells you about the things the platform can see, which is typically cloud configuration, identity and endpoints. It does not know whether your vendor reviews were meaningful, whether your risk register reflects the business, or whether the person who left in March still has access to a system the platform does not connect to.
We have written about this trade-off at length in Vanta versus a compliance consultant and compared the market in best compliance automation software. The short version: the platform is a good answer to the evidence collection problem and a poor answer to the judgment problem, and most first audits fail on judgment.
Open questions and contributions
The AI governance section will date fastest. ISO 42001 tooling barely existed eighteen months ago and the EU AI Act is still producing obligations that vendors are racing to address. If you are working in that space and something is missing, that is the section where a pull request is most valuable.
Same rules as our other lists. One entry per pull request, a sentence saying what the tool does, no affiliate links, and competitors get merged on the same terms as anyone else.
The list is at github.com/TrazTech-Inc/awesome-compliance-automation.
Weighing a platform against people? We will tell you honestly which one your situation calls for, including when the answer is neither yet.
How we run complianceOr book a free call