Three open source GRC tools can run an ISO 27001, NIS2 or SOC 2 compliance program on your own server, and what sets them apart is how much of the groundwork each one ships. CISO Assistant bundles more than 220 frameworks, including an outline of ISO 27001 with a description for every requirement, asks for 16 GB of RAM on-premises and keeps its audit log for the paid Pro edition. Probo is MIT-licensed throughout and imports thirteen frameworks as bare lists of controls; what its vendor sells is a compliance officer who runs the program for you. ISMS Builder is sized for a security team of one to a handful on a single instance, ships no ISO 27001 controls, and has a single maintainer.
Which frameworks ship, and what's left to you
ISO 27001:2022 has 123 entries in both CISO Assistant and Probo: clauses 4 to 10 plus the 93 Annex A controls. CISO Assistant's file calls itself an outline of the standard, whose full text you buy from ISO, and gives every requirement a short description and a link to a reference control. Probo's file holds only an ID and a title per entry: after the import, its docs ask you to create or link the measures that satisfy each control, give them an owner and attach the evidence. ISMS Builder ships nothing for ISO 27001. Because the standard is copyrighted, its Statement of Applicability tabs arrive empty, and the administrator copies the controls from a licensed copy into a JSON file, then runs scripts/import-iso-controls.sh.
CISO Assistant's README lists more than 220 bundled frameworks, among them SOC 2, NIS2, DORA and a long run of French texts: the ANSSI hygiene guide and SecNumCloud, HDS, ReCyF for NIS2, the CNIL data security guide. More than 45 mapping sets carry an assessment over from one framework to another. Two frameworks, CIS Controls v8 and the CSA Cloud Controls Matrix, load from the Excel file their publisher distributes, since their licences rule out bundling them. Probo imports ISO 27001, ISO 27701, ISO 42001, SOC 2, NIS 2, DORA, GDPR, HDS, HIPAA, PCI DSS, CCPA, FERPA and 21 CFR Part 11 from its console, and only HDS describes its controls. ISMS Builder ships 147 controls covering BSI IT-Grundschutz, the Cyber Resilience Act, EUCS, the AI Act and NIS2; SOC 2 only shows up there as a supplier triage criterion.
NIS2 gets a module of its own in ISMS Builder: a 30-item checklist for Article 21, and Article 23 deadlines computed for each incident (early warning within 24 hours, notification within 72 hours, final report one month after the notification), with an email reminder to the CISO before each one. Probo's docs state that it doesn't audit you or replace the auditor, and ISMS Builder's README that the tool certifies nothing.
What each tool needs to run
Read from the repositories and documentation on 7 October 2026.
| Tool | Licence | What you run | Bundled frameworks | Paid offer | Latest release |
|---|---|---|---|---|---|
| CISO Assistant | AGPL-3.0 or later, except the enterprise/ directory | five containers, SQLite or PostgreSQL; 4 cores and 16 GB of RAM on-premises | 220+, ISO 27001 as an outline | Pro edition: €39 per contributor per month, or €2,400 per instance per year | 4.1.0, 4 Oct 2026 |
| Probo | MIT | probod, PostgreSQL, SeaweedFS and headless Chrome behind a reverse proxy; memory not documented | 13, as lists of controls | no commercially licensed code; a service with no published price | 0.305.0, 7 Oct 2026 |
| ISMS Builder | AGPL-3.0 | Node.js 18 or later, JSON files or an SQL database; memory not documented | 147 controls; ISO 27001 imported by hand | none | 1.40.4, 3 Sep 2026 |
CISO Assistant is the only one to put a figure on the server it needs: its prerequisites page asks for at least 4 cores, 16 GB of RAM and 10 GB of disk for an on-premises install, less for a trial. The shipped docker-compose starts a Django backend, a Huey worker, a SvelteKit frontend, the Qdrant vector database and a Caddy proxy, on SQLite by default or PostgreSQL 16 and later. That file is meant for testing and exposes the whole API, which the README says is "not yet recommended" for production; a config builder generates a hardened version that still needs manual steps.
Probo's production docker-compose runs probod, PostgreSQL, SeaweedFS for S3-compatible storage and a headless Chrome, behind a reverse proxy that terminates TLS; a Helm chart covers Kubernetes. Its docs give no memory figure beyond the 4 GB of shared_buffers that the bundled PostgreSQL configuration claims on its own, and they advise swapping the latest image for a tested release. Self-hosters create the OAuth client credentials for every connector themselves.
ISMS Builder is a Node.js and Express application that keeps its data in JSON files by default, with no database at all. SQLite, MariaDB and PostgreSQL are supported, but .env.example recommends JSON until the SQL migration is finished, and users and roles stay in a JSON file whichever backend you pick. The project publishes no installer or archive, only the source code and, since v1.40.0, a Docker image.
Who is behind each project, and where it stands
CISO Assistant comes from intuitem, a French company based in Vélizy-Villacoublay. Version 4.1.0 shipped on 4 October 2026 after ten application releases in September, and the repository's publiccode.yml declares the project "stable". The README tells you to deploy a tagged release or a prebuilt image, since the main branch can carry breaking changes.
Probo is published by Probo Inc., and its README aims it at engineering and security teams. The customer testimonials the vendor shows come from about twenty companies, most of them announcing an ISO 27001 certification or a SOC 2 report. The probod server is still on 0.x: v0.305.0 came out on 7 October 2026, after 30 releases in September. A minor release can remove a feature, as v0.277.0 did on 3 September when it dropped personal API keys in favour of scoped OAuth tokens.
ISMS Builder rests on one person, who works on it alongside a full-time job, authored 126 of the 146 commits and only patches the latest release. The public repository dates from March 2026, and its seventeen releases came in bursts: five from 10 to 13 March, then twelve from 27 July to 3 September, the date of v1.40.4, with no commit on the main branch since. The README calls the project "not yet a finished product" and sizes it for an ISMS team of one person, sometimes a handful: several entities of a group fit in one instance, but it isn't built to host multiple customers. Version 1.40.3 closed a hole that let any logged-in account, read-only ones included, read the SMTP and WebDAV passwords.
Licences and paid editions
CISO Assistant splits one repository between two licences. The Community edition is AGPL-3.0, with no user cap and SAML SSO included; the enterprise/ directory falls under intuitem's commercial licence, which requires a contract for production use. intuitem's Community vs Pro comparison keeps the audit log, per-object history, SCIM, custom fields, multi-level domains, the Jira and ServiceNow integration and assessment campaigns for Pro, while Probo and ISMS Builder both ship an audit log in their open source code. Pro costs €39 per contributor per month as SaaS, billed annually, or €2,400 per instance per year on-premises, and only users with write access count as contributors. Contributors sign a CLA that lets intuitem reuse their code in its commercial products.
Probo is under MIT, with no part of the repository under a commercial licence; only its catalog of 562 vendors and its 82 risk templates are CC BY-SA 4.0, and contributions need a DCO sign-off rather than a CLA. What Probo Inc. sells is a service: one of its compliance officers takes over policies, controls, reviews and assessments and answers in Slack, with no published price. Probo Cloud, hosted in the EU or the US, is provisioned through onboarding, and the only functional difference documented is that newer OAuth connectors work there without your own client credentials.
ISMS Builder is AGPL-3.0, with no hosted version, no support contract and no guaranteed response time; for anyone who needs one, the README itself points to a commercial vendor.
