GRC for SMBs and MSPs
Get audit-ready, and prove it.
Keel helps growing organizations manage risk, meet their obligations, and prove their work through one connected, practical GRC platform.
One control
Third-party / vendor risk managementAccess control policyDocument & records controlAI monitoring & malfunction reportingAsset inventory
- ISO/IEC 27001
- EU AI Act
- SOC 2
- NIST Cybersecurity Framework
- NIST AI Risk Management Framework
- ISO 9001
Computed from Keel’s published crosswalk data, not estimated.
21
crosswalked frameworks
123
crosswalked controls
680
control-to-clause mappings
Open data, CC BY 4.0
How it works
One control, every clause it closes
Pick a control. Showing 8 of the 21 live frameworks, ranked by how much of the starter library maps to each.
- ISO/IEC 27001 5.2, A.5.1
- ESG Essentials G.9
- HIPAA 164.316(a), 164.530(i)(1)
- SOX (Sarbanes-Oxley) Section 404 P12
- NIST SP 800-53 PL-1
- SOC 2 CC5.3
- GDPR Art.24(2)
- PCI DSS 12.1
- ISO/IEC 27001 A.5.15
- ESG Essentials Not mapped
- HIPAA 164.308(a)(3)(ii)(A), 164.308(a)(4)(ii)(B), 164.312(a)(2)(ii)
- SOX (Sarbanes-Oxley) Section 404 P11
- NIST SP 800-53 AC-1, AC-2, AC-3, AC-6
- SOC 2 CC6.1, CC6.3
- GDPR Art.32(1)
- PCI DSS 7.1, 7.2
- ISO/IEC 27001 A.8.13
- ESG Essentials Not mapped
- HIPAA 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)
- SOX (Sarbanes-Oxley) Section 404 P11
- NIST SP 800-53 CP-9
- SOC 2 A1.2
- GDPR Art.32(1)
- PCI DSS Not mapped
- ISO/IEC 27001 A.8.10
- ESG Essentials Not mapped
- HIPAA 164.310(d)(2)(i), 164.310(d)(2)(ii)
- SOX (Sarbanes-Oxley) Section 404 Not mapped
- NIST SP 800-53 MP-6, SI-12
- SOC 2 C1.2
- GDPR Art.5(1)
- PCI DSS 3.2
- ISO/IEC 27001 A.5.7, A.8.8
- ESG Essentials Not mapped
- HIPAA Not mapped
- SOX (Sarbanes-Oxley) Section 404 P11
- NIST SP 800-53 RA-5, SI-2
- SOC 2 CC7.1
- GDPR Art.32(1)
- PCI DSS 6.3, 11.3
What you get
Every GRC job, on one graph
Compliance & controls
One crosswalked control library: collect evidence once, satisfy many frameworks.
Risk management
Risk register with scoring, treatments and owners, linked to controls.
Policy management
50+ framework-mapped policy templates to approve and export as branded PDFs.
Vendor risk
Third parties tracked by criticality, on review cadences.
People & access reviews
Sync staff from Microsoft Entra, Google Workspace or CSV, then certify access.
Evidence & trust center
Attach evidence once, then publish a branded, public trust center.
Frameworks
All of them, on one control library
21 live today, spanning 9 categories.
- ISO/IEC 27001
- CIS Critical Security Controls
- PCI DSS
- SOC 2
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- HIPAA
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
FAQ
What does it cost?
4 plans, all public: Free $0, Starter $99/mo, Pro $299/mo, Enterprise $1,999/mo. The MSP / Partner plan is quoted per client.
Do I need a consultant?
No. Guided setup, one-click pre-mapped control sets and 50+ policy templates get you moving.
Which frameworks are live?
All 21, spanning 9 categories, every one on the same crosswalked control library.
Can I try it first?
Yes. A 14-day Pro trial on every new workspace, no credit card. The demo needs no signup.
Start free