GRC software built for small & mid-sized businesses
Track ISO 27001, SOC 2, ISO 9001, GDPR, ISO 22301 and Sri Lanka’s PDPA without an enterprise GRC platform, a consultant or a compliance department. Adopt a standard, record your controls against real evidence, and produce audit-ready reports — starting this afternoon.
Maturity
Calculated
from the evidence recorded against each control, never declared
Coverage
Tracked
so a score over half a standard never passes for a whole one
Outcomes
Split three ways
fully, partially and not complied — counted, not averaged away
Free, no account
Answer a short questionnaire against a published standard and get an executive summary of where you stand — scored the same way the product would score it. Nothing to install, and no sign-up.
Why SMEs choose Govnex
The established GRC suites assume a dedicated risk and compliance function, a rollout project and a budget to match. Most small and mid-sized businesses have none of those, and still have to answer the security questionnaire in front of them. This is the compliance tracking software for that situation.
Track obligations against standards such as ISO 27001, SOC 2, GDPR or Sri Lanka’s PDPA with the wording captured at adoption. A revision never silently rewrites what you signed up to, so last year’s audit still means something.
Every control is recorded against its evidence — verdict by verdict, with notes and document locations. Your compliance score is calculated from what is actually there, never typed into a box.
An executive report for the board, a compliance report an auditor can follow, and an AI review written from your own recorded evidence. No consultant needed to assemble the pack.
Assign controls to the people who already do the work, track what is outstanding, and see where you stand. Designed for a business where compliance is somebody’s second job.
Adopt a published standard from the Compliance Library, or write your own controls for contractual and internal obligations and track them in the same cycle.
ISO 22301
ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements
Standard · edition 2019
21 controls
ISO 27001
ISO/IEC 27001:2022 — Information security management systems
Standard · edition 2022
103 controls
ISO 37002
ISO 37002:2021 — Whistleblowing management systems — Guidelines
Standard · edition 2021
17 controls
ISO 42001
ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system
Standard · edition 2023
15 controls
ISO 9001
ISO 9001:2015 — Quality management systems — Requirements
Standard · edition 2015
28 controls
ITIL 4
ITIL 4 — Information Technology Infrastructure Library
Framework · edition 4
14 controls
OECD AI Principles
OECD Principles on Artificial Intelligence
Framework · edition 2024
5 controls
PMBOK 7th Ed (PMP)
A Guide to the Project Management Body of Knowledge (PMBOK® Guide) – Seventh Edition
Framework · edition 7th Edition
9 controls
SOC 2 (TSC 2017)
AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
Standard · edition 2017
20 controls
ASD Essential Eight
ASD Essential Eight Maturity Model
Framework · edition Current
8 controls
Privacy Act & APPs
Privacy Act 1988 (Cth) - Schedule 1: Australian Privacy Principles (APPs)
Legislation · edition Current Consolidated
13 controls
PSPF
Protective Security Policy Framework (PSPF)
Framework · edition Current
16 controls
SOCI Act
Security of Critical Infrastructure Act 2018 (Cth) (including CIRMP Rules)
Legislation · edition Current Consolidated
7 controls
WHS Act 2011
Work Health and Safety Act 2011 (Model WHS Act)
Legislation · edition Current Consolidated
11 controls
EU AI Act
Regulation (EU) 2024/1689 — Artificial Intelligence Act (EU AI Act)
Regulation · edition 2024
15 controls
GDPR
Regulation (EU) 2016/679 — General Data Protection Regulation
Regulation · edition 2016
17 controls
Sri Lanka ETA
Electronic Transactions Act, No. 19 of 2006 (Consolidated with Act No. 25 of 2017)[cite: 1]
Legislation · edition 2017 Consolidated
9 controls
Sri Lanka PDPA
Personal Data Protection Act, No. 9 of 2022 (Consolidated with Act No. 22 of 2025)
Legislation · edition 2025
18 controls
NIST AI RMF 1.0
NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)
Framework · edition 1.0
12 controls
NIST CSF 2.0
NIST Cybersecurity Framework (CSF) 2.0
Framework · edition 2.0
22 controls
01
Choose from the Compliance Library — ISO 27001, SOC 2, ISO 9001, GDPR, ISO 22301, Sri Lanka PDPA — or write controls of your own. Adopting one copies its controls into your register in a single step.
02
Open an assessment cycle and let your team answer control by control, attaching the documents that prove it. Maturity is computed from the evidence, not asserted.
03
Close the cycle for a sealed result, hand over the reports, and open the next one. The gaps come out stated plainly enough to act on this quarter.
The executive review reads your recorded controls and evidence and writes the key risks, the strengths and the priorities for the next thirty days — the read-out a consultant would give you, from the same source data. It says on its face that it is AI-generated, so nobody mistakes a draft for a verdict.
Pricing
Per organization, in USD. Paying annually takes 10% off and includes free consultation hours.
First 3 months free — on every plan
Start without a credit card and without a commitment. Nothing is charged while you are inside the free period, and there is nothing to cancel if you decide it is not for you.
Individual
A single seat, just you.
$15/ month
or $162 a year — saving $18
Small business
A team, with structure.
$25/ month
or $270 a year — saving $30
Mid business
Many units, many hands.
$100/ month
or $1,080 a year — saving $120
Adopt it, open a cycle, and see where your business actually stands. three months free, no credit card, no commitment, and the quick start has you tracking in minutes.