Open source GRC platform for self-service security assessments and compliance documentation
- Stars214
- Forks67
- Open Issues43
Other
- Python
- HTML
- JavaScript

About GovReady-Q
GovReady-Q is an open source GRC platform for self-service security assessments and compliance documentation. It targets the bottleneck where applications take months to authorize even though they deploy and redeploy in minutes.
The platform automates assessments and document generation using reusable compliance content built on the NIST OSCAL and OpenControl data standards. Workflows are designed to be self-service so teams can run their own compliance steps rather than depend on manual review.
GovReady-Q is built in Python and licensed under Apache 2.0. It runs as a self-hosted compliance server, and a hosted version is offered by GovReady, making it a fit for DevSecOps teams that authorize applications on a continuous basis.
Key features
- Automated security assessments and compliance documentation
- Reusable compliance content via NIST OSCAL and OpenControl
- Self-service workflows for authorizing applications
- Built for continuous DevSecOps deployment cycles
Details
- On GitHub since
- 2016
- Language
- Python
- License
- Apache 2.0
- Standards
- NIST OSCAL, OpenControl
- Self-hosted
- Compliance server
- Hosted
- Offered by GovReady
