Logo Menu

3 platforms Β· Last updated

Open-source SOC 2 software: choose the operating model

Open-source SOC 2 software can give you control over the code, data, and deployment. It also gives your team the operating work. Comp AI is closest to connector-led evidence automation, CISO Assistant is built for wider GRC and ISMS work, and SimpleRisk starts with risk management. None replaces the independent CPA examination.

Eligible: production-relevant public code, a named licence, documented self-hosting, current SOC 2 or reusable control-framework support, an active release path, and enough evidence to identify the commercial boundary and buyer-owned operations. OpenGRC and Eramba remain on the watchlist because their current licence terms do not clear this gate.

Choose your route

Choose the job before you choose the repository

All three routes put hosting, configuration, and audit preparation on your team. The difference is the workflow each product documents most clearly. Confirm the licence, deployment path, and commercial boundary before treating a public repository as an operating model.

Need connector-led evidence work

Start with Comp AI

Its reviewed record most clearly documents connected evidence and recurring checks, plus an in-product auditor workflow. Claims remain vendor-reported or desk-researched.

Need wider GRC and ISMS work

Start with CISO Assistant

Its documented scope reaches risk, controls, assessment, privacy, and many mapped frameworks. Connector-led evidence collection is not established.

Need risk management first

Start with SimpleRisk

Its reviewed Core path centers risk, controls, scheduled tests, and evidence. Cloud and identity connector coverage is not established.

Need an issued SOC 2 report

Bring in an independent CPA

None of these tools performs or signs the examination. Your software choice does not remove the need for an auditor.

The deciding question

The details that change the buying decision

Start with the job the platform must do, then check the licence, deployment burden, and auditor handoff. We reviewed code and commercial terms separately from deployment guides and public product documentation. β€œNot established” is a limit of the reviewed source set, not a claim that a feature is absent.

ProductBest fitLicence and core scopeSelf-host pathSOC 2 workflowEvidence automationAuditor handoffPaid boundaryOperating owner
Comp AI An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.Open core: AGPL-3.0 outside the top-level /ee Enterprise Edition directoryDocumented. The current Docker Compose path requires an external PostgreSQL 14+ database with SSL, Resend for transactional email, Trigger.dev for background workflows, and production TLS and monitoring owned by the deployer.SOC 2-centered controls, policies, tasks, daily connected checks, hourly checks for four device controls, evidence export, and audit findings. Most claims remain vendor-reported or desk-researched.Best-documented connector-led evidence in this set. The record confirms automated evidence and continuous testing. 590 vendor-listed integrations; verify the required connector and test behavior. One G2 reviewer reported intermittent automation failures.Built-in auditor role, auditor-only bulk evidence export, findings, revisions, and remediation states. A CPA firm still performs and signs the examination.The repository describes roughly 99% of the code as AGPLv3 and the top-level /ee Enterprise Edition directory as commercially licensed. Managed-cloud pricing is quote-only.Buyer owns infrastructure, database, email, background jobs, TLS and reverse proxy, backups, monitoring, upgrades, incident response, support
CISO Assistant A team that needs broad GRC and ISMS coverage, wants code and data under its control, and can operate a multi-service deployment without expecting connector-led SOC 2 evidence automation from Community.Open core: AGPL-3.0 outside the top-level enterprise directoryDocumented. The repository supplies Docker Compose and production-hardening guidance. A production operator owns the database, Huey task worker, mail delivery, TLS, backups, version pinning, secrets, network restrictions, and monitoring.Broad risk, control, assessment, evidence, audit, privacy, and TPRM workflow with SOC 2 among more than 150 mapped frameworks. External-auditor portal depth is not established.Community has API access, evidence management, tasks, and reminders. Connector-based evidence collection is not established; the current pricing page separately labels an Automation Engine as coming soon.Community supports evidence management and exports. The reviewed sources do not establish a scoped external-auditor request portal or a named CPA network.Files in the top-level enterprise directory use the Intuitem Commercial Software License. Pro SaaS starts at EUR 39 per contributor per month when billed annually; Pro On-premises starts at EUR 2,400 per instance per year.Buyer owns infrastructure, database, email, background jobs, TLS and reverse proxy, backups, monitoring, upgrades, incident response, support
SimpleRisk A risk-management-first team that wants a conventional MPL-2.0 GRC core, unlimited self-hosted users, scheduled control tests, and a path to paid modules only when the program outgrows Core.Open source: MPL-2.0Documented. SimpleRisk publishes full and minimal Docker images plus a Compose stack with the application, MySQL 8, and SMTP. The operator owns infrastructure, TLS, backups, upgrades, monitoring, and incident response.Risk-first GRC with SOC 2 controls, scheduled tests, evidence across a Type 2 window, and mapping through the Secure Controls Framework. Auditor-portal depth is not established.Scheduled tests and evidence records are documented. Core connector-based collection from cloud, identity, code, and endpoint systems is not established.Controls, tests, and evidence support audit preparation. The reviewed Core sources do not establish scoped external-auditor access or a named CPA network.SimpleRisk Core is free with unlimited users. Paid Extras are unavailable in the Open Source deployment and require an On-Premise or SaaS package; current packages start at USD 5,000 per year.Buyer owns infrastructure, database, email, TLS and reverse proxy, backups, monitoring, upgrades, incident response, support

Licence, deployment, pricing, and capability facts were rechecked against the linked repositories and vendor documentation on 2026-08-11. Product behavior was desk-researched, not hands-on tested. OpenGRC and Eramba were evaluated but did not clear the licence gate, so they appear in the watchlist discussion rather than the qualified table.

The eligible set

3 platforms that qualify.

Membership is computed from our registry rather than chosen by hand, so this list changes when the underlying facts do.

Platform Best for Pricing Integrations Frameworks
Comp AI Engineering-led startups and growing software companies pursuing SOC 2 or adjacent frameworks, especially teams that… Quote-based 590+ SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, SOC 1, FedRAMP, ISO 42001, ISO 9001, CCPA, NEN 7510
CISO Assistant Security and compliance teams that need one self-hosted system for risk management, ISMS, audit, privacy, third-party… Free tier Not published SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR
SimpleRisk Risk and compliance teams that need a self-hosted risk register and multi-framework control system, and can accept more… Free tier Not published SOC 2, ISO 27001, PCI DSS, HIPAA, NIST 800-171
The workflow map

What the public record documents

Use this as a research map, not a scorecard. It shows where the current source set establishes a workflow, where it establishes only part of one, and where a buyer should ask for a proof rather than assume the answer.

Platform Connected evidenceRecurring checksAudit workspaceFramework mapping
Comp AI Documented Documented Partial Partial
CISO Assistant Not established Not established Partial Partial
SimpleRisk Partial Documented Partial Partial

Documented in the reviewed source set Partial support or a stated limitation Not established by the reviewed source set

Registry capability states reflect the product records rechecked on 2026-08-11. They describe published evidence, not a hands-on certification or an overall product ranking.

Read the licence before the repository badge

A public repository is a starting point, not a licence classification. This comparison requires production-relevant code under a named licence and a documented self-hosted path. Open core means usable community code sits beside commercial code, modules, or services. Source-available code can be inspected while still restricting a right that conventional open-source licences grant.

SimpleRisk Core uses MPL-2.0. Comp AI and CISO Assistant publish AGPLv3 community code, but each places a top-level enterprise directory under commercial terms, so both are open core. A Community edition can be free and still carry different rights from the code your production deployment needs. Check the repository, image, module, and hosted service separately.

ClassMeaning in this comparison
Open sourceProduction-relevant code under a conventional open-source licence.
Open coreA usable open-source core plus named commercial code, modules, or services.
Source availableInspectable code whose current terms restrict a right required by this comparison.
Managed SaaSVendor-operated delivery that may coexist with open-source, open-core, or source-available code.

Classification uses the Open Source Definition and the licence attached to the production components, not a repository badge.

Start with the job you need the platform to do

Choose Comp AI when an engineering team wants SOC 2 to be the main workflow and needs connector-led evidence automation. Its public record covers automated evidence, daily connected checks, hourly checks for four device controls, policy and task work, an auditor role, and evidence export. Before committing, run a failed-control test against your own systems and inspect the retry path and auditor output.

Choose CISO Assistant when the security team needs one place for risk, controls, evidence, privacy, TPRM, incident work, and an ISMS. It maps more than 150 vendor-listed frameworks. Community documentation supports API access, tasks, reminders, evidence management, and exports; it does not establish connector-led evidence collection for a SOC 2 program.

Choose SimpleRisk when risk management is the center of the program. Its MPL-2.0 Core supports unlimited users, scheduled compliance tests, evidence across the Type 2 window, and a large mapped-framework library after free registration. Expect to own more of the evidence collection work and verify any paid Extra before assuming it is in the open-source deployment.

Ask for proof of the workflow, not a feature tour

Control mapping can reduce duplicate work, but a framework count does not prove that each framework has its own tests. Inspect the actual map for every framework in scope. Then ask the vendor to show one control from connection through evidence, a failed test, remediation, export, and auditor review.

Comp AI publishes the deepest auditor-handoff detail in this set: an auditor role, auditor-only bulk evidence export, findings, revisions, and remediation states. CISO Assistant Community documents exports and evidence management. SimpleRisk documents controls, scheduled tests, evidence, and audit preparation. The reviewed sources do not establish a scoped external-auditor portal for either CISO Assistant or SimpleRisk Core. Bring your intended CPA firm into the proof session.

Price the operating work, not just the licence

Self-hosting moves cost from a software invoice into engineering and operations. Budget for the production owner, infrastructure, database, email, jobs, TLS, backups, monitoring, upgrades, incident response, security review, and support. Compare both routes over the same 12-month period and availability target.

The deployment guides make the trade-off concrete. Comp AI requires external PostgreSQL with SSL, Resend, and Trigger.dev. CISO Assistant’s Compose path includes a database, backend, frontend, Huey worker, mail configuration, and reverse proxy hardening. SimpleRisk’s Compose stack includes the application, MySQL, and SMTP; the operator owns installation, backups, upgrades, and an email-only support path with no SLA.

Managed deliverySelf-hosted delivery
Subscription and tierCompute or container platform
Onboarding and implementationDatabase and storage
Included support and SLAEmail and background-job services
Overages and paid modulesLogging, monitoring, backups, and restore tests
Storage and retentionPatching, upgrades, and incident response
Contract and renewal termsEngineering and on-call time
Independent audit feeIndependent audit fee

Find the commercial edge before you self-host

The expensive features often sit at the boundary: enterprise administration, managed operations, integrations, audit logs, support, and advanced workflow. CISO Assistant has a commercial enterprise directory; SimpleRisk removes paid Extras from the open-source deployment; Comp AI’s top-level /ee directory is commercially licensed and its managed price is quote-only.

CISO Assistant publishes the clearest split: Community covers core GRC, evidence, exports, API access, SSO/SAML, tasks, TPRM, incidents, and framework customization, while the premium group includes items such as fine-grained permissions, SCIM, audit logs, SIEM forwarding, Jira, advanced webhooks, and analytics. SimpleRisk paid packages start at USD 5,000 per year; CISO Assistant Pro SaaS starts at EUR 39 per contributor per month, and Pro On-premises at EUR 2,400 per instance per year. Ask for an itemized map of every required feature, edition, licence, deployment mode, and support obligation.

A practical licence review before procurement signs

Procurement and counsel should review the exact production path: repository, top-level directory, image, package, hosted service, commercial module, and support contract. The checklist below is procurement context, not legal advice.

CheckWhat to confirm
Licence scopeWhich licence governs each repository, directory, image, package, and hosted service you need.
Deployment rightsInternal use, modification, redistribution, and hosting rights for affiliates or customers.
Network obligationsHow AGPLv3 or MPL-2.0 applies to your actual architecture and distribution.
Commercial edgeWhich required features sit outside Community or Core, and what each costs.
Exit pathWhether controls, risks, evidence metadata, attachments, users, audit history, and mappings export in a usable form.

Review network-use and modification obligations with counsel; a summary page cannot determine the result for a particular architecture.

Why OpenGRC and Eramba are on the watchlist

OpenGRC and Eramba both provide self-hosted GRC functions, but their current terms do not clear this comparison’s licence gate. That says nothing about their security, usability, or value.

OpenGRC’s current code uses CC BY-NC-SA 4.0, permits internal commercial use, and prohibits hosting for customers; older commits before 2025-04-14 remain MIT. Eramba’s custom terms permit modification for the buyer’s own use but restrict redistribution. Those limits may work for a particular internal deployment, but they are not equivalent to a conventional open-source production licence. Both remain source-available watchlist products here.

Make the final call with a proof session

Choose Comp AI for connector-led SOC 2 automation, CISO Assistant for broad GRC and ISMS coverage, and SimpleRisk for a risk-first program with a conventional MPL-2.0 core. Remove any option that fails a licence, deployment, integration, auditor, data-location, support, or operating-capacity requirement.

In the proof session, use one control from your own environment. Ask the team to connect it, collect evidence, show a failed state and retry, export the record, and let your intended CPA firm inspect the result. Then map every required feature to a licence and price. If no one owns the production stack or you need a vendor SLA, managed SaaS may cost less overall even with a higher subscription.

Buyer questions

Frequently asked.

Is there open-source software for SOC 2 compliance?

Yes. SimpleRisk Core uses MPL-2.0, while Comp AI and CISO Assistant provide AGPLv3 community code around commercially licensed enterprise directories. All three document SOC 2 or reusable control-framework workflows and self-hosting. The software can support controls, evidence, tests, and audit preparation; it does not issue the SOC 2 report.

What is the difference between open source, open core, and source available?

Open-source software gives production code the use, modification, and redistribution rights required by a conventional open-source licence. Open core combines that core with commercial code, modules, or services. Source-available code can be inspected, but its terms restrict at least one right required by this comparison. Review the licence on every production component.

Can open-source SOC 2 software make a company compliant?

Open-source SOC 2 software can organize controls, policies, evidence, tests, exceptions, and audit preparation. The company still designs and operates the controls, management signs the assertion, and an independent CPA firm performs the examination and issues the report. Software can reduce workflow effort; it cannot grant compliance or replace the attestation.

What does self-hosting SOC 2 software cost?

Self-hosting cost includes infrastructure, database, email, job processing, TLS, backups, monitoring, upgrades, security review, incident response, support, and engineering time. Comp AI also requires external PostgreSQL, Resend, and Trigger.dev in its documented Docker path. Compare a 12-month self-hosted total against the same availability and support target in managed SaaS rather than comparing licence fees alone.

Which compliance features are usually paid?

Paid editions commonly add managed hosting, support SLAs, SCIM, fine-grained permissions, audit logs, SIEM forwarding, integrations, advanced exports, and specialized workflow. CISO Assistant lists several of those in Pro. SimpleRisk makes paid Extras unavailable in the Open Source deployment. Comp AI uses a commercial /ee directory but does not publish a complete public edition matrix.

Does open-source SOC 2 software replace the CPA auditor?

No. Open-source and commercial SOC 2 tools prepare controls and evidence, but an independent licensed CPA firm performs the examination and signs the report. Before choosing software, ask candidate auditors to validate the evidence export, request workflow, sampling support, exception trail, and access model. The tool can reduce coordination without becoming the auditor.

Related