What is it?
CISO Assistant is a self-hosted GRC (governance, risk, compliance) platform built by intuitem, a French company based in Vélizy-Villacoublay. Compliance assessments, risk analysis, vendor risk, business impact analysis and action plans all live in the same database. intuitem pitches it as a "one-stop shop" for cybersecurity management and a way out of the Excel sheets that every team keeps realigning by hand. The backend is Django, the frontend SvelteKit.
The open source GRC software comparison sets CISO Assistant against the other open source tools on bundled frameworks, server requirements and what the Pro edition keeps for itself.
Why is it interesting?
- One control, many frameworks: requirements and the security measures that answer them are separate objects. A measure put in place once counts toward ISO 27001 and NIS2 alike, and 45+ mapping sets carry an assessment over from one framework to another.
- 220+ frameworks out of the box, many of them French: the ANSSI hygiene guide and SecNumCloud, HDS, ReCyF for NIS2, the CNIL data security guide. Your own framework loads straight from an Excel file.
- Built-in EBIOS RM: the risk analysis method published by France's ANSSI has its own module, next to cyber risk quantification and business impact analysis.
- Scriptable: REST API, CLI, Kafka connector and an MCP server, set to read-only in the shipped docker-compose. The AI assistant is off by default and runs against a local LLM (Ollama, LM Studio, llama.cpp).
- No user cap in Community: the free edition includes SAML SSO, and the UI is translated into more than 27 languages.
Good to know
What Pro keeps for itself. The README lists 73 features without saying which edition each belongs to. intuitem's Community vs Pro comparison puts the audit log, per-object history, SCIM, custom fields, multi-level domains (the way to model subsidiaries), the Jira and ServiceNow integration and assessment campaigns in Pro only. Pro costs €39 per contributor per month as SaaS, billed annually, or €2,400 per instance per year on-premises. Only users with write access count as contributors.
Two licenses in one repository. Everything outside the enterprise/ directory is AGPL v3. That directory falls under intuitem's commercial license, which requires a contract for production use. Container images follow the same line: those under ghcr.io/intuitem/ciso-assistant-community/ are AGPL, those sitting directly under ghcr.io/intuitem/ are commercial. Contributors sign a CLA that lets intuitem use their code in its commercial products.
Compared with Probo and ISMS Builder. Probo, under the MIT license, advertises immutable audit logs, and ISMS Builder, under AGPL, records every create, update, delete and login. CISO Assistant has the largest framework catalog of the three and is the only one to advertise an EBIOS RM module, but a record of who changed what requires Pro.
Plan for 16 GB of RAM. The prerequisites page asks for at least 4 cores, 16 GB of RAM and 10 GB of disk for an on-premises install, less for a trial. The shipped docker-compose starts five containers: Django backend, Huey worker, SvelteKit frontend, Qdrant and a Caddy proxy. SQLite is the default database, PostgreSQL 16 or later is optional, and a Helm chart covers Kubernetes. That compose file is meant for testing and exposes the full API, which the README says is "not yet recommended for production". A config builder generates a more hardened file that still needs manual steps, and the main branch is not meant for production use.
A fast release pace. Version 4.1.0 shipped on October 4, 2026, after ten application releases in September, and the repository's publiccode.yml declares the project "stable".
