Alternatives to CMMC Map
Compare CMMC Map alternatives for your business or organization using the curated list below. SourceForge ranks the best alternatives to CMMC Map in 2026. Compare features, ratings, user reviews, pricing, and more from CMMC Map competitors and alternatives in order to make an informed decision for your business.
-
1
RealCISO
RealCISO
RealCISO is a compliance intelligence platform for two audiences: MSPs and MSSPs managing security across multiple clients, and enterprise teams running compliance in-house. Security providers get multi-tenant architecture, white-label branding, and portfolio-level risk visibility. Enterprise teams get assessments, risk tracking, remediation management, and board-ready reporting — without spreadsheets. Supports NIST CSF 2.0, SOC 2, HIPAA, NIST 800-171, CIS Controls, CMMC, ISO 27001, and 30+ frameworks. Tracks maturity per control over time — L1 through L5 — so you show boards trend lines, not checkboxes. 3,000+ security providers. Built by practitioners. -
2
Onspring
Onspring GRC Software
Onspring is an award-winning GRC automation and reporting software. Our SaaS platform is known for flexibility and ease of use for end-users and administrators. Simple, no-code, drag-and-drop functionality makes it easy to create new applications, workflows, and reports independently without IT or developers. - Manage a centralized risk register with multiple hierarchies - Keep tabs on financial impacts & probabilities based on risk tolerance - Capture & relate financial, operational, reputational & third-party risks - Map controls to regulations, frameworks, incidents & risks - Remediate findings through workflows or the POA&M process Ready-made products get you started in as quickly as 30 days: - Governance, Risk & Compliance Suite - Risk Management - Third-party Risk - Controls & Compliance - Audit & Assurance - Policy Lifecycles - CMMC - BC/DR FedRAMP moderate environment available.Starting Price: $20,000/year -
3
Etactics CMMC Compliance Suite
Etactics
Preparing for the Cybersecurity Maturity Model Certification (CMMC) assessment is a considerable investment from both time and money perspectives. Organizations handling Controlled Unclassified Information (CUI) within the defense industrial base should expect to have an authorized CMMC 3rd Party Assessment Organization (C3PAO) certify their implementation of NIST SP 800-171 security requirements. Assessors will evaluate how the contractor implements each of the 320 objectives across all applicable assets within the scope, including people, facilities, and technologies. The assessment process is expected to involve a review of artifacts, interviews of key personnel, and tests of the technical, administrative, and physical controls. As organizations prepare their body of evidence, they should establish a relationship between the artifacts, the security requirement objectives, and assets within scope. -
4
1TEN
1TEN, Inc
1TEN is a CMMC Level 2 compliance platform purpose-built for small and mid-size Defense Industrial Base contractors. Unlike cloud-based competitors, 1TEN runs entirely on-premises, air-gapped, with zero cloud dependencies, ensuring Controlled Unclassified Information never leaves your facility. The platform covers all 110 NIST SP 800-171 requirements across 14 domains through 23 integrated modules, including an Assessment Wizard, Evidence Manager, POA&M Tracker, SSP Builder, Policy Generator, Asset Inventory, and Incident Response tools. It calculates your live SPRS score as you document controls, generates C3PAO-ready System Security Plans automatically from your actual configuration data, and produces all 14 required domain policies from your answers, eliminating weeks of manual documentation work.Starting Price: $12,500 -
5
Mycroft
Mycroft
Mycroft is an end-to-end security and compliance platform built to get companies CMMC certified and turn security busywork into work done for them. It combines a security and compliance stack with AI Agents that operate like teammates, helping teams achieve enterprise-grade security without the overhead of managing multiple tools, endless checklists, or a massive internal team. Mycroft identifies CUI boundaries, creates required documentation, including SSP and POA&M, implements controls, configures the security stack, collects evidence, and supports compliant SPRS score submission on a continual basis. Its integrated platform supports CMMC, SOC 2, GDPR, HIPAA, PCI, FedRAMP, ISO 27001, ISO 42001, CPRA/CCPA, PIPEDA, and other frameworks, with cross-mapping designed to reduce unnecessary overhead. For audits and compliance, Mycroft provides a security frameworks dashboard, custom controls, automated tests, evidence collection, real-time dashboards, integrations, monitoring, etc. -
6
CMMC+
CMMC+
The only compliance platform you will ever need to become and stay CMMC compliant. Our modern and easy-to-use platform solves cybersecurity and compliance challenges facing the DIB (Defense Industrial Base) supply chain through education and collaboration. Use our intuitive tool to rapidly assess your cybersecurity posture and how to mature your program. Collaborate with trusted practitioners to create a holistic approach, nesting security into existing business practices. Save time and money by accelerating your cybersecurity compliance with our transparent dashboard approach. Track and manage all of the relevant hardware and systems that fall within your CMMC boundaries. Continuously monitor your CMMC program and collect evidence for assessments and audits. Get easy-to-read reporting that not only provides ongoing status awareness, but directs your compliance activities efficiently, saving time, money, and effort. -
7
PreVeil
PreVeil
PreVeil makes military-grade security accessible to everyone. Its encrypted Drive and Email platform is used by over 3,000 organizations to improve their security and achieve CMMC, DFARS, and ITAR compliance. PreVeil Drive works like DropBox for file sharing and collaboration, but with far better security. PreVeil Email works with existing apps like Outlook or Gmail, letting users keep their regular email addresses. Because it works with your existing tools, PreVeil is easy to use and can be deployed in hours. All documents and messages are automatically encrypted end-to-end, which eliminates central points of attack and means that no one other than intended recipients can read or scan your sensitive information—not even PreVeil. PreVeil’s solution has been used by 75+ defense contractors & C3PAOs to achieve perfect 110/110 scores in CMMC assessments. Visit PreVeil to learn more.Starting Price: $20 per user per month -
8
Cybrance
Cybrance
Protect your company with Cybrance's Risk Management platform. Seamlessly oversee your cyber security and regulatory compliance programs, manage risk, and track controls. Collaborate with stakeholders in real-time and get the job done quickly and efficiently. With Cybrance, you can effortlessly create custom risk assessments in compliance with global frameworks such as NIST CSF, 800-171, ISO 27001/2, HIPAA, CIS v.8, CMMC, CAN-CIOSC 104, ISAME Cyber Essentials, and more. Say goodbye to tedious spreadsheets. Cybrance provides surveys for effortless collaboration, evidence storage and policy management. Stay on top of your assessment requirements and generate structured Plans of Action and Milestones to track your progress. Don't risk cyber attacks or non-compliance. Choose Cybrance for simple, effective, and secure Risk Management.Starting Price: $199/month -
9
MyCyber360
Fortify1
Fortify1 is CMMC compliance simplified. Customers using our platform easily demonstrate how requirements are achieved. Our structured and automated approach to managing CMMC practices and processes reduces risk and minimizes the cost of compliance. Sole reliance on front-line defenses does not demonstrate holistic cyber security risk management. Holistic cyber security risk management is an emerging requirement accomplished through organizational alignment, insight and awareness. Failure to meet this emerging requirement may result in increased exposure to litigation or non-compliance with regulatory standards. Apply diligence and compliance utilizing MyCyber360 CSRM’s simple approach to holistically managing activity related to cyber security initiatives, governance, incident response, assessments and security controls. -
10
SecurePoint USA
SecurePoint USA
SecurePoint USA provides defense-grade visitor management and sanctions screening software for regulated U.S. facilities. The platform screens visitors and counterparties against OFAC, BIS, UN, EU, and UK lists, supports ITAR, EAR, CMMC, and DFARS workflows, and generates audit-ready evidence packs. SecurePoint Education extends OFAC screening to schools and universities. Distinct from unrelated "Securepoint" companies in network security, SecurePoint USA focuses on compliance, sanctions screening, and regulated access for U.S. organizations.Starting Price: $99/month -
11
MailRoute
MailRoute
Stop Ransomware, spam and phishing, other viruses and threats for SMB, Enterprise, Healthcare, and Government agencies and contractors. API-level integration for Microsoft Office 365 & GCC High, Google Workplace, other email hosts and all servers. MailRoute stops email-instigated attacks on your information and hardware, with cost-effective, multi-layered protection. We offer CMMC, NIST 800-171, HIPAA, DFARS compliant and DISA accepted email security services. No single point of failure. Wholly owned solution includes geo-distributed datacenters with redundant network feeds, power sources and cooling, for 99.999% uptime. MailRoute prevents forgeries and email spoofing by identifying malicious messages with email authentication tools through assisted and managed DNS changes. Continually managed and updated email-network security stops cybercrime and threats like downtime, ensuring cost-predictability and reliability.Starting Price: $2 per user per month -
12
SentrIQ
SentrIQ Labs
SentrIQ is an AI-native compliance automation platform that helps cloud and SaaS companies turn technical evidence into assessor-ready packages faster. Instead of relying on manual spreadsheets, screenshots, and static documents, SentrIQ ingests artifacts like policies, cloud configurations, scan results, tickets, and identity data, maps them to security requirements, identifies gaps, and generates structured compliance documentation tied back to real evidence. The platform is built to support complex public-sector and regulated compliance efforts, especially federal authorization workflows such as FedRAMP and CMMC. Examples of functionality include automated control mapping, evidence traceability, draft narrative generation, readiness gap detection, machine-readable export support, and continuous alignment between changing infrastructure and compliance documentation. -
13
GetCybr
GetCybr
GetCybr is an AI-powered vCISO and GRC platform built for MSPs and security consultancies delivering cybersecurity services at scale. It gives service providers the infrastructure to run a scalable, repeatable, and high-quality vCISO practice without relying on spreadsheets, point tools, compliance checklists, and manually assembled board reports. It supports the full service delivery lifecycle, from initial client assessment through ongoing compliance, remediation, reporting, and executive communication. Its AI engine maps each client’s risks, compliance gaps, and security maturity, then generates a prioritized roadmap that can be presented from day one. GetCybr replaces weeks of manual assessment work with AI-powered gap analysis, control mapping, compliance scoring, and remediation planning across frameworks such as SOC 2, ISO 27001, NIST CSF, HIPAA, CMMC, NIS2, and DORA. -
14
Cuick Trac
Cuick Trac
With Cuick Trac, your organization can meet the technical practices of NIST SP 800-171, in as few as 14 days, making the implementation and management of the administrative and physical requirements much easier to accomplish, as CMMC 2.0 continues to evolve. Chockful of scoping diagrams, team exercises, questions to ask, and much more, our ebook is your guide to all things CUI. Take your team through the steps of identifying sensitive information using our sample business process flow to follow the data. Learn how to identify information as CUI, CTI, or CDI using our determination workflow. -
15
SafeLogic
SafeLogic
Do you need FIPS 140 validation or FIPS 140 certification for your technology to enter new government markets? Get a NIST certificate in just two months and make sure it remains active over time with SafeLogic's FIPS 140 simplified solutions. Whether you need FIPS 140, Common Criteria, FedRAMP, StateRAMP, CMMC 2.0, or DoD APL, SafeLogic helps you maximize your public sector business. Companies selling technology that performs encryption to the federal government must obtain NIST certification per its FIPS 140 regulation that confirms their cryptography has been tested and approved for use by government agencies. FIPS 140 validation has been so successful, that it has been adopted as mandatory by several additional security regulations including FedRAMP, StateRAMP, CMMC v2, Common Criteria, and DoD APL. -
16
CyberCompass
CyberCompass
We build Information Security, Privacy, and Compliance Programs to improve your cyber resilience – saving you and your organization time and money. CyberCompass is a cyber risk management consulting and software firm. We navigate organizations through the complexity of cybersecurity and compliance at half the cost of full-time employees. We design, create, implement, and maintain information security and compliance programs. We provide consulting services and a cloud-based GRC workflow automation platform to save our clients over 65% of the time to become and remain cybersecure and compliant. We provide expertise and support for the following standards and regulations – CCPA/ CPRA, CIS-18, CMMC 2.0, CPA, CTDPA, FTC Safeguards Rule, GDPR, GLBA, HIPAA, ISO-27001, NIST SP 800-171, NY DFS Reg 500, Singapore PDPA, SOC 2, TCPA, TPN, UCPA, VCDPA. We also provide third-party risk management within the CyberCompass platform.Starting Price: $5000/year -
17
TechIDManager
Ruffian Software
Are you implementing MFA everywhere but sharing admin accounts among your techs? If you are, you have not implemented MFA with fidelity. All modern security frameworks are clear that 1:1 is what account access should look like. Most MSPs have some sort of solution in place that ultimately puts the tech to client access outside of those parameters. TechIDManager creates and manages the accounts and credentials of your techs across all of your domains and networks - in a fashion that is more efficient, more secure, and more cost effective than any other platform on the market. Features Helps you become security framework compliant (NIST, CMMC, CIS, HIPAA, PCI.) Eliminates the need to share admin accounts (meeting modern security framework requirements like NIST 800-171 3.3.2 and many others) Automatic creation and disabling of accounts; right and permissions management Downtime tolerant Inject your unique credentials into client access points with minimal effortStarting Price: $200/month/100 licenses -
18
Microsoft 365 GCC High
Microsoft
Microsoft 365 Government Community Cloud High (GCC High) is a highly secure, compliance-focused cloud productivity platform designed specifically for U.S. federal agencies and defense contractors that handle sensitive or regulated data, extending the core Microsoft 365 applications within a hardened, government-only environment. It runs on Azure Government infrastructure and is logically isolated from commercial Microsoft 365 environments, ensuring that all customer data is stored exclusively in U.S.-based data centers and accessible only by screened U.S. personnel, reinforcing strict data sovereignty and access controls. It is built to meet the most stringent regulatory standards, including FedRAMP High, DFARS, ITAR, CMMC, and Department of Defense security requirements, making it suitable for handling Controlled Unclassified Information (CUI) and other export-controlled or defense-related data. -
19
Hypori
Hypori
Hypori is a secure virtual workspace platform that enables employees to access enterprise apps and data from personal mobile devices with total privacy. It streams pixels instead of data, ensuring that no sensitive information is stored or transmitted on the device. Hypori is designed to simplify Bring Your Own Device (BYOD) adoption by protecting personal privacy while maintaining organizational security and compliance. The platform supports industries with stringent requirements such as defense, government, healthcare, and other regulated sectors. Hypori meets robust certifications including FedRAMP High, CMMC, HIPAA, and others. It offers role-based virtual workspaces that isolate corporate data from personal apps, reducing risk and liability. -
20
Orchid Security
Orchid Security
Orchid Security utilizes a passive listening service to continuously discover self-hosted applications (those that you manage/maintain) and SaaS applications (developed and maintained by others), providing you with a comprehensive inventory of your enterprise applications, along with their key identity characteristics (e.g. MFA enforcement, rogue or orphaned accounts, RBAC privilege data). Orchid Security leverages advanced AI analytics to automatically assess the identity technologies, protocols, and native authentication/ authorization flows for each application. Identity controls are compared against privacy regulations, cyber security frameworks, and identity best practices (e.g. PCI DSS, HIPAA, SOX, GDPR, CMMC, NIST CSF, ISO 27001, SOC2) to detect potential exposure in cyber security posture and compliance coverage. Orchid Security goes beyond providing visibility into weaknesses, to enable organizations with quick and effective remediation of those weaknesses without recoding. -
21
UC ControlSight
Unified Compliance
UC ControlSight is a web-based compliance intelligence and control-management platform built on the Unified Compliance Framework’s Intelligent Common Controls that helps organizations simplify and accelerate compliance by providing an intuitive interface to explore and understand how regulatory mandates relate to harmonized controls, access curated Intelligent Insight Packs tailored to industries and technologies (e.g., NIST 800-53, ISO 27001/27002, SOC 2, CMMC), and visualize overlapping requirements across frameworks with dynamic mapping that highlights how single controls satisfy multiple mandates. It offers streamlined research and navigation of authority documents alongside a powerful compliance dictionary, customizable views to focus on controls that matter most, and reporting and analytics tools to track posture, gaps, and progress. -
22
comaea
comaea
Discover the capability and competency of your employees. Competency assessor presents a true 180 and 360 approach to employee assessment. Self-assessment is made by individuals which then allows line managers to moderate and validate their scores. Create plans, goals and actions to fill competency gaps and evaluate and capture feedback from employees, line managers and independent assessors. Engage with employees through dialog using a structured and consistent approach. At the heart of a competence-led approach is being able to analyze and interrogate the data and use it to make decisions. Gain valuable insights into employee capability, competency and compliance by team, by role, by project and holistically across the organization. -
23
Venvera
Venvera
Venvera is an AI-assisted GRC and compliance automation platform for regulated companies navigating frameworks such as DORA, NIS2, ISO 27001, SOC 2, GDPR, HIPAA, and CMMC 2.0. Cross-framework control mapping lets organisations prove a control once and count it across every active framework. Evidence Autopilot routes collection requests, tracks expiry, and closes controls on approval. Regulatory clocks auto-start DORA, NIS2, and GDPR incident timers on classification. The DORA Register of Information produces xBRL-CSV exports for one-click filing. Third-party risk management covers unlimited vendor questionnaires, sub-outsourcing mapping, and concentration analytics. An AI Virtual CISO delivers regulatory answers grounded in live data using the organisation's own API key. Further capabilities include a risk register, access reviews, policy library, security awareness training, trust center, and tamper-evident audit log.Starting Price: €399/month flat -
24
RateYourCyber
RateYourCyber
RateYourCyber is an AI-powered GRC automation platform spanning 18 regulatory frameworks (ISO 27001, SOC 2, GDPR, DORA, HIPAA, CMMC, NCA ECC, SAMA CSF, Financial Crime Compliance (FCC), and more) so your team can demonstrate compliance to investors, enterprise clients, and regulators. No dedicated compliance hire needed to get full value from day one. RateYourCyber unifies what the GRC market sells as four separate products: assessment, threat monitoring, third-party risk, and compliance evidence. Single cloud platform, single data model, 17 regulatory frameworks. Controls satisfied in one framework count toward the others. FAIR Monte Carlo risk quantification expresses gaps in financial terms rather than traffic lights. A reporting engine produces one unified board document across every module, three tones, three formats, three languages, 2,430 execution permutations. Free tier to enterprise. Live across seven geographies.Starting Price: £799 -
25
Axio
Axio
The only platform that rapidly aligns security initiatives to address risks that matter and actually protect the business. Analyze the unique risks to your business and calculate how individual scenarios would impact the bottom line. Plan for the cyber threats that will have the largest financial impact across your organization. Get actionable results fast with transparent pre-built calculations. Facilitate meaningful communication without training in statistical analysis methods. Continuously model how security decisions will impact business strategy. Improve your cybersecurity program’s posture in a single dashboard. Assessments can be completed 70% faster so you can spend more time addressing priorities on your roadmap. Cybersecurity risk assessments readily available (NIST CSF, C2M2, CIS20, CMMC, and Ransomware Preparedness) with the option to custom configure your own mode. -
26
Apptega
Apptega
Simplify cybersecurity and compliance with the platform that’s highest rated by customers. Join thousands of CISOs, CIOs, and IT professionals who are dramatically reducing the cost and burden of managing cybersecurity and compliance audits. Learn how you can save time and money, have great cybersecurity, and grow your business with Apptega. Go beyond one-time compliance. Assess and remediate within a living program. Confidently report with one click. Quickly complete questionnaire-based assessments and use Autoscoring to pinpoint gaps. Keep your customers’ data safe in the cloud and out of the hands of cybercriminals. Ensure your compliance with the European Union's official privacy regulation. Prepare for the new CMMC certification process to maintain your government contracts. Enjoy Enterprise-class capabilities paired with consumer app. Quickly connect your entire ecosystem with Apptega’s pre-built connectors and open API. -
27
ComplyUp
ComplyUp
Easy enough for the self-reliant small business, and powerful enough for the compliance professional. NIST 800-171 contains 110 requirements. Assess your organization to determine where you stand. This is often referred to as a gap analysis or a readiness assessment. Create your system security plan (a formal document describing how you satisfy the 110 requirements) and POA&Ms (remediation plans for the requirements you don't satisfy). Address the requirements you don't satisfy by changing configurations, deploying solutions, or updating your company policies. Keep an eye on your organization, and update your documentation periodically to accurately reflect your security posture. We take security as seriously as you do. Your assessment data is auto-encrypted, keystroke-by-keystroke, with a unique encryption key you generate before it's sent to our servers. ComplyUp can help get you compliant while you still run your business as usual.Starting Price: $1,800 per year -
28
securityprogram.io
Jemurai
Excellent security for small companies. Easily build a standard and audit-ready cybersecurity program. We want to make excellent security accessible to smaller organizations, and help them build legitimate security programs so they can win deals. Perfect for startups, you're already sprinting. Leverage a tool and a team that can keep pace with you. Document templates and built-in training allow you to make pragmatic improvements that improve security and demonstrate alignment to standards that customers trust. Your security program begins with reviewing and adopting security policies. We built the simplest possible policies that adhere to NIST 800-53 standards. We mapped the standards so that you'll know you're covered. We cross-reference our program activities to other standards including SOC 2, ISO 27001, NIST CSF, CIS 20, and CMMC to make sure you get credit for the work you do with customers and your management team.Starting Price: $99 one-time payment -
29
AirCISO
Airiam
AirCISO is Airiam’s extended detection and response (XDR) software that gives CISOs, IT Managers, CIOs, and other leaders the insights they need to improve their organization’s cybersecurity. Understand the threats in your environment and relate them to the MITRE ATT&CK® framework. Keep software patched by knowing what vulnerabilities exist within your system using common vulnerabilities and exposures (CVE) data. Satisfy elements of compliance and regulatory frameworks like the PCI DSS, CMMC, NIST SP 800-53, and HIPAA. AirCISO provides a unified view across your entire IT landscape. Users can get visibility into endpoints, email, servers, Cloud, network, third-party, and IoT systems. The information simplifies the ability to detect and isolate threats. AirCISO services as the single source of truth for your teams and tools. Take a strategic view of your cybersecurity with dashboards and metrics that show your business risk, maturity over time, and ROI.Starting Price: $0 -
30
CovertThreat
CovertThreat
CovertThreat is an offensive security platform that continuously finds, validates and prioritizes the weaknesses an attacker would actually use — then maps every finding to the compliance frameworks you report against. One platform replaces a stack of point tools: external attack surface discovery, network and web/API vulnerability testing, mobile app and source-code analysis, cloud and container posture, OT/ICS scanning, dark web and breach-credential monitoring, DNS and certificate typosquat detection, and AI/LLM security testing. A lightweight agent extends the same testing inside the firewall for internal vulnerability scanning, CIS hardening audits and credential hygiene. Every finding is auto-mapped to PCI DSS, HIPAA, NIST, CIS, CMMC, NERC CIP, SOC 2 and NACHA, with AI-written remediation plans, attack-path modelling, firewall config audits, ransomware simulations, tabletop exercises, and branded executive and technical reports. Multi-tenant with white-label MSP options. -
31
XQ Vault
XQ
Unlike other security and compliance tools, XQ never has your data. By separating tool access from data access, XQ offers external security controls for your data across all platforms, eliminating any gaps in data governance. Vault integrates seamlessly with popular file-sharing platforms like Sharepoint, OneDrive, Google Drive, Windows Fileshare, Citrix File Share, and more. Whether you need to meet specific industry regulations or international privacy standards, the XQ Vault covers all your data compliance and regulatory needs, including CMMC, GDPR, GLBA, HIPAA, ITAR, NIST-CUI, FINRA, and more. Protect each file with separate quantum-resistant credentials. Simply store your data in a desktop folder synced to your cloud. XQ’s no-size-limit rule opens up huge possibilities at a fraction of the cost of other services. XQ microsegments and encrypts data during transfer, meticulously tracking and controlling access at every stage of data's journey. -
32
Kiteworks
Kiteworks
The only security platform authorized by FedRAMP that provides support for file sharing, managed file transfer, and email data communications to meet the compliance requirements of standards such as CMMC 2.0, ITAR, IRAP, NIS 2, HIPAA, and others. A content communication “tool soup” ratchets up cost and resource inefficiencies. Managing zero-trust security policies centrally is virtually impossible, and organizations lack consolidated security and compliance visibility over the communications of sensitive content, which increases security and compliance risks. Compliance and security risks increase due to the lack of governance. Organizations must control and track who can access content, who can edit it, to whom it can be sent and shared, and where it is sent and shared. Cybercriminals and malicious insiders target sensitive content like PII, IP, financial documents, and PHI because it can be monetized or even weaponized. -
33
Lynxify.me
Lynxify.me
Lynxify.me is 360-degree feedback software for small teams. It gives growing companies (roughly 30 to 200 people) a focused way to run structured 360 reviews and performance feedback without adopting a full performance-management platform. You define who is being reviewed, choose the raters (peers, managers, and direct reports), and set the criteria. Each rater completes one form that combines written answers and criteria ratings. When the round finishes, Lynxify.me produces one clear report per person: aggregated scores, every written response in full, an AI-generated summary of the themes, and a visual skill report showing strengths, development areas, and the gap between self-assessment and the peer average. Lynxify.me is built to set up in minutes, not weeks. There is no implementation project, no annual contract, and no credit card required to start, so a single person can launch a review without procurement or IT.Starting Price: $0 -
34
my360plus
my360plus
my360plus for outstanding leadership development; for leaders, teams, developing talent and growing your own career. More than an assessment, my360plus delivers a clear, easy-to-read, report, plus coaching tips and ongoing colleague feedback options in multiple languages. In addition to the my360plus classic online feedback tool, we offer individual self-assessment, team development and tailored services. The report gives a strengths profile in a visual format alongside clear explanations and development ideas. It also has online coaching tips, which means people take control of their own development too. The online questionnaire is suitable for individual self-assessment, 360 degree feedback, as well as team building. The standard version has 48 questions, and for detailed insights there's also a 96 question version. -
35
Cub Cyber
Cub Cyber
Our applications support DoD contractors of all sizes, from small family businesses to large enterprises with thousands of employees. Our company has helped businesses around the country perform NIST SP 800-171 assessments, identify compliance gaps, create system security plans, and create plans of action and milestones. We develop innovative solutions to solve NIST SP 800-171 related challenges. Use Quantum Assessor to generate new revenue opportunities for your business. In the past few months alone we have transformed dozens of businesses and enabled them to generate thousands in additional revenue. Quantum Assessor provides you with automation, project management, and workflow capabilities allowing you to efficiently provide consulting services, increasing company profits. Join the dozens of clients that have been able to multiply the capability and workload of their consultants! -
36
SmartAssessor
SmartAssessor
SmartAssessor is an AI-powered digital platform designed to streamline compliance, inspection, certification, and audit processes by capturing, structuring, and reviewing evidence in a centralized system. It enables organizations to upload and manage documents, photos, videos, reports, and checklists from both field and office environments, ensuring that all compliance evidence is organized, accessible, and audit-ready at all times. It maps collected evidence directly to regulatory standards, inspection criteria, or frameworks, creating structured assessments that improve consistency and clarity across reviews while reducing manual effort. Using advanced multi-model AI, SmartAssessor can automatically evaluate evidence against standards, delivering fast, objective, and data-driven assessments while still allowing human oversight and control over the process. It supports automated review of documents, images, audio, and video, significantly reducing assessment time. -
37
Isora GRC
SaltyCloud, PBC
Streamline your IT Risk Assessments with Isora GRC. Leverage a lightweight, yet powerful surveying solution for conducting IT Risk Assessments. Launch self-assessment questionnaires for departments, people, facilities, devices, and applications. Leverage our library of preloaded questionnaires like NIST, HIPAA, GLBA, and more. Build or upload your custom questionnaires. Change question weights, allow partial credit, gate conditional questions, and add other question logic to simplify your questionnaires. Automatically rollup and score collected quantitative and qualitative survey data. Gain access to dynamic risk reports. Use the risk map to identify the highest-risk units or the trend graph to track risk scores year-over-year. Easily export the raw data to data analytics tools like Microsoft PowerBI using the RESTful API. -
38
CMX1 Platform
CMX
Leverage the same Audit Software some of the world's best known brands trust. CMX1's ActivityStudio® makes it easy to develop and execute audit, self-assessment, inspection, evaluation, certification, checklist, and survey programs to ensure quality, safety, compliance and mitigate operational risk. With drag-and-drop policy and visual form building, automated scheduling, comprehensive scoring, ratings & reporting, and CAPA workflows, our clients describe ActivityStudio® as a game changer. The CMX1 Platform enables companies of all sizes to gain control and transparency over their supply chains, deliver quality products and services, and ensure compliance and drive performance across their locations. CMX1 is a user-friendly, cloud-based platform that 800,000+ users across 120 countries use to achieve and maintain Quality and Operational Excellence. Via a single platform, you can manage all your supply chain partners, products, and locations effectively and with confidence. -
39
AWS Audit Manager
Amazon
Map your AWS usage and controls with prebuilt and custom frameworks. Save time with automated evidence collection, and focus on confirming that your controls work properly. Streamline collaboration across teams, and ensure the integrity of your audits with read-only permissions. Use AWS Audit Manager to map your compliance requirements to AWS usage data with prebuilt and custom frameworks and automated evidence collection. The transition from manual to automated evidence collection. Avoid the need to collect, review, and manage evidence with automated evidence collection. Automatically collect evidence, monitor your compliance posture, and proactively reduce risk by fine-tuning your controls. Upload manual evidence for your hybrid environment. AWS Audit Manager helps you continuously audit your AWS usage to simplify how you assess risk and compliance. When you define and launch an assessment based on an assessment framework, the Audit Manager will execute resource assessments.Starting Price: $1.25 per assessment -
40
Rizzqo
Rizzqo GmbH
Rizzqo is an asset-first compliance execution platform for regulated organizations, built and hosted in Germany. It models your organization first: critical services, information and processes, the systems and suppliers they depend on, and who is responsible for each. Controls from ISO 27001, NIS2, DORA, GDPR, EU AI Act, TISAX, NIST CSF 2.0 and custom rule sets become requirements per asset type and are applied automatically to every matching asset. Owners answer, attach evidence and confirm with a logged timestamp. Status is calculated from confirmed answers, never self-declared. Open requirements become gaps. Gaps become risk assessments with inherent, current and residual scoring, monetary evaluation and a treatment decision. Remediation tasks sync with Jira. Dashboards show ISMS teams and CISOs framework readiness and which critical services are exposed. Supplier risk, PII flows and AI assets live in the same model. 30-day free trial. -
41
Cetbix GRC & ISMS
Cetbix
In three steps, you can achieve information security self-assessment, ISO 27001, NIST, GDPR, NFC, PCI-DSS, HIPAA, FERPA, and more. Cetbix® ISMS strengthens your certification. Information security management system that is comprehensive, integrated, documents ready and paperless. Cetbix® online SaaS ISMS. ISMS software from Cetbix®. Other features include IT/OT Asset Management, Document Management, Risk Assessment and Management, Scada Inventory, Financial Risk, Software Implementation Automation, Cyber Threat Intelligence Maturity Assessment, and others. More than 190 enterprises worldwide rely on Cetbix® ISMS to efficiently manage information security and ensure ongoing compliance with the Data Protection Regulation and other regulations. -
42
TraceSecurity
TraceSecurity
Our Cybersecurity Assessment Tool (CSAT) is a great way to determine where your organization stands when it comes to cybersecurity posture. Once you get your results, you'll be able to identify your next steps and fit these into a road map for boosting your defense against malicious attackers. Our tool meets the requirements of the Automated Cybersecurity Examination Tool (ACET) with the ability to run our standard report and the NCUA ACET report from the same place. Our cybersecurity assessment tool delivers a step-by-step process for evaluating your organization’s overall cybersecurity preparedness. It’s based on the NIST cybersecurity framework, allows you to easily perform a self-assessment to determine preparedness, and gives detailed reporting, along with recommendations to strengthen cybersecurity. Use our CSAT to get your organization's cybersecurity maturity level based on your size and complexity.Starting Price: Free -
43
TaxNav
TaxNav
Making Tax Digital for Income Tax Self-Assessment Simplified for Self-Employment and Landlords. TaxNav is HMRC-recognised software that makes this easy, affordable, and fully compliant, helping you save time, reduce your tax bill, and navigate your income tax with ease. TaxNav is HMRC-recognised, MTD-compliant software, designed to: - Simplify digital record-keeping and submissions - Improve data safety with encryption and authentication Our software will help you reduce confusion and save time, reduce errors and avoid penalties, provide guidance to maximise deductions, and navigate self-assessment obligations with ease. TaxNav software is Excel spreadsheet-friendly and is purpose-built for the self-employed and landlords to manage their own records.Starting Price: £100 -
44
Clearity
Clearity
Clearity.io is a security compliance management application that provides covered entities, business associates, and their partners the ability to measure their security program by conducting self-assessments, managing corrective action plans, and working towards industry-driven compliance while viewing real-time data on our dashboard. Does your risk and compliance intelligence come from pages and pages of paper-based reports? How much time do you spend manually creating or combing through spreadsheets and PDFs from 3rd party vendors? If this is your organization, it’s time to automate that process. Clearity gives you the ability to feel in control of your security risks and to know what work needs to be completed. As you head down that road, visually see your risks diminish over time. Create your own HIPAA, HIPAA (Vendors), CSC, NIST CSF, or NIST 800-53 Security Assessments. Work on them on your own time.Starting Price: $199 per month -
45
Gen Income Tax Software
SAG Infotech Pvt Ltd
Gen Income Tax Return Filing is one of the best compliance software which calculates income tax, advance and self-assessment tax, and interest under sections 234B, 234A, and 234C. It is an easy-to-use software that permits you to prepare and e-file your online ITR with accuracy and convenience. The software has all the required features that help with tax returns, automatic selection of return forms, generation of XML/JSON files, import/export master data, calculation of arrear relief, E-payment etc.Starting Price: ₹7000 per year -
46
The COVID-19 Employee Screening Platform is focused on helping employers keep their workers and workplace safe during the pandemic. Let’s work together to stop the spread. Workers can self-assess for coronavirus risk factors and then determine if they should report to work. Employers can monitor the status of their workforce with real-time reporting and dashboards. Prior to reporting to work, employees fill out the COVID-19 self-assessment form in the secure app for Android, iOS (Apple) or Windows. If the employee is at risk of transmitting COVID-19 or has symptoms, the app will instruct them to stay home and automatically notify their manager. All personal information is protected and only shared with the employer. Users can easily provide details about the vaccines they received for COVID-19 and Influenza and securely upload proof of vaccination. Organization administrators will have insights into who has been vaccinated.
-
47
OneAdvanced Clinical Decision Support
OneAdvanced
OneAdvanced Clinical Decision Support is a healthcare solution designed to deliver fast, accurate, and safe patient triage across multiple care settings. It supports telephone and digital assessments within ambulance services, GP practices, clinical assessment services, out-of-hours care, and national triage systems. The platform enables clinicians and call handlers to assess patient acuity efficiently using conversational, structured question flows. With products like TeleAssess, FirstCall Core, FirstCall Lite, and Patient, the solution adapts to different clinical and operational needs. Patients can also self-assess on mobile devices, allowing services to prioritize urgent cases effectively. The system is built on over 25 years of clinical safety evidence and is maintained with regular updates by in-house clinicians. Integrated with existing healthcare systems, it helps ensure timely intervention and consistent triage decisions. -
48
Astelia
Astelia
Astelia is an attack-driven exposure management platform designed to help security and IT teams identify which vulnerabilities in their environment are truly reachable and exploitable. It maps network topology through read-only integrations and applies agentic AI to analyze the technical requirements of each vulnerability, correlating reachability and exploitability data to surface the small fraction of risks that actually matter. Instead of relying on probability-based scoring alone, Astelia provides evidence-based prioritization that helps organizations cut through massive vulnerability backlogs and focus remediation efforts where they will have the greatest impact. It also visualizes potential attack paths using graph-based models, showing exactly how an attacker could move through the network to compromise assets. In addition, it exposes coverage gaps by mapping infrastructure down to the port level, revealing unscanned assets and third-party connections. -
49
Kruspin
Necktip s.r.o.
Kruspin is a wedding workspace for professional wedding coordinators and agencies. It keeps guest lists, RSVPs, seating plans, menus and dietary requirements, accommodation, timelines, checklists, supplier details, budgets, documents and client-facing information connected in one operational workspace. Teams can import and export structured data, assign access by role, separate internal planner notes from client-visible information, reuse event templates and create focused handoffs for clients, kitchens, service teams and reception. Kruspin is delivered as a web application, supports multilingual teams and selected integrations including Pinterest, read-only Google Calendar subscriptions, and an expanding API. -
50
SACT (Self-Assessment Compliance Toolkit) by SwiftSafe is a comprehensive tool designed to help organizations stay compliant with major cybersecurity regulations like GDPR, HIPAA, PCI DSS, and ISO 27001. The platform simplifies compliance management by offering hassle-free assessments, real-time reporting, and automated updates on regulatory changes. SACT helps businesses generate instant audit reports, track security improvements, and maintain compliance without the need for costly consultations. With its user-friendly interface and 24/7 support, SACT streamlines the process, making it easy for businesses to meet their compliance obligations efficiently.Starting Price: $150