Generic software42% entry signalMarket screenOne thing must be truegrowth quality

GRC & Compliance Automation

Prepared 2026-09-16

Entry signal — what decides who wins here

One thing must be true
Structure decides One thing must be true Execution decides

Entry turns on a single condition that can be named and tested before much is spent. Clear it and this becomes an execution question; fail it and no amount of operating skill helps.

What you would have to beat

Take share rather than ride the market. Demand is flat, seasonal or policy-driven, so growth has to come out of a competitor. That is possible and it is slower, and it rewards an operator who can wait.

How it was read
Binding constraintUNVERIFIEDgrowth quality — Market shape — being better does not, by itself, clear it.
Measured inputsUNVERIFIEDnot applied — This is a software market. The industry’s business counts describe its BUYERS, not the market being entered, so they are left out of the signal.
How many new establishments are still tradingA
Professional, Scientific, and Technical Services, US · opened 2020
83.3%
1 year
64%
3 years
50.8%
5 years
34.3%
10 years
opened 2015

Measured, not forecast: the share of US establishments opening in one year that were still active later. It counts good operators and bad ones together, which is exactly why it is the honest answer to “what are the odds”. It is for the whole sector rather than this market, and the ten-year figure comes from an older cohort because no younger one has reached ten years.

This is not a probability of success, and it is not a verdict on you. No survival probability is published per market, and inventing one would be worse than saying so. What the bar reads is how much of the outcome sits inside an operator's control: green means the hurdles are ones a better operator clears, red means the binding constraint is capital, an asset or a permission rather than execution. Someone arriving with an advantage this screen did not assume can win a market shown in red.

Companies named in this market · 5

The binding constraint — growth quality

The wedge that built this category has already been driven home. Automating SOC 2 and ISO evidence collection was a genuine opening in 2020; by 2026 Vanta is reported at $300M ARR, up 69%, with about 16,000 customers [C] and Drata and OneTrust hold the rest of the mid-market. OneTrust is put at roughly $550M of revenue on a $4.5B valuation [C]. A new entrant arrives after the land grab, selling to buyers who already passed their audit last year. Growth in the category is now taken from competitors rather than from the unserved, which is a different and much worse business to enter. Open-source GRC exists — Eramba, OpenSCAP — but here it competes with a service promise rather than a licence cost.

Angel-backed companies130
in the Canadian portfolio dataset
Province mixON 43, QC 34, AB 19, NB 9, NS 8, NL 6, BC 4, PE 3, US 2, SK 1, — 1

Sectors joined: Cybersecurity · SaaS · Technology · Dev Tools · B2B SaaS · AI

[UNVERIFIED] Sector-to-NAICS mapping is analyst judgment — see data/angel-sector-map.json. Counts are a per-record cross-reference and are not additive across records.

I

The incumbent

Who owns this market and who is coming for it. Fields a screen never reached say so rather than guessing.

Incumbent
OneTrust, with Vanta and Drata owning the automation tier
Scale
OneTrust is reported at roughly $550M revenue, a $4.5B valuation and 14,000+ customers [C]
Challengers
Vanta, Drata, Secureframe, Sprinto, ServiceNow GRC, Archer, LogicGate
Lock-in mechanism
The evidence history. An auditor wants continuity year over year, and that record lives in the tool
Price movement
Compressing in the mid-market as three funded vendors compete for the same SOC 2 buyer
Is the buyer consolidating?
Yes — Privacy, security compliance and vendor risk keep merging into one platform, which is how OneTrust grew
V

The field

Every vendor named on this record, and what each one discloses. Most disclose nothing, which is why the market is not sized.

Competitor set · 4 named · 0 disclose revenue

NameRevenueShareNote
OneTrustC not disclosed — Private. Reported at roughly $550M revenue and a $4.5B valuation [C] — a secondary estimate, not a filing
VantaC not disclosed — Private. Reported at $300M ARR in April 2026, +69% YoY, ~16,000 customers [C, private-market research]
DrataC not disclosed — Private; no revenue published
ServiceNow GRC / ArcherC not disclosed — Enterprise GRC inside larger platforms; no line reported

Nobody here publishes revenue. The market is not sized for that reason — an estimate built on nothing would only look like knowledge.

V

Vendor landscape

Market leaders, the full paid field, and every open-source alternative. Where a free tier exists it is what sets the price floor, so it is analysis rather than an appendix.

OneTrustC

~$550M revenue, $4.5B valuation, 14,000+ customers [C]

VantaC

$300M ARR April 2026, +69% YoY, ~16,000 customers [C]

Paid field · 6 vendors

OneTrustEnterprise

Privacy, security and vendor risk on one platform

VantaSMB / mid-market

300+ integrations; earliest mover in audit automation

DrataSMB / mid-market

Private

Secureframe / SprintoSMB

Private

ServiceNow GRCEnterprise

Bundled into the platform

ArcherRegulated enterprise

The legacy enterprise GRC system of record

Open source · 3 projects — the price floor

ErambaCommunity edition

The best-known open-source GRC platform; risk register, controls and audit workflow

OpenSCAPLGPL-2.1

Automated configuration compliance against public benchmarks

ComplyApache-2.0

SOC 2 policy templates and evidence scaffolding

Open-source GRC is real but competes on a different axis: the paid tier sells an auditor-acceptable evidence trail and the integrations that populate it, not the control framework, which is public.

Evidence

Evidence. Market size UNVERIFIED — every revenue and valuation figure on this record is a private-market estimate from secondary research, not a filing [C], and none should be relied on without confirmation. A $15B market projection circulates and is NOT used as a finding. Verify before acting.

#

Where the industry talks

The associations, forums and events where people in this trade actually talk shop — where to listen before entering, and where the first customers are found. Each link was opened on the date shown.

AssociationInternationalA
ISACA
isaca.org · 185,000 members (2026-09)

Individual members in IT audit, governance, risk and security, per its About page; 225 chapters incl. Toronto, Vancouver, Montreal

Checked 2026-09-22
AssociationInternationalA
OCEG
oceg.org · 225,000 members (2026-09)

Members per its About page; basic membership is free, so the count includes free sign-ups. Owns the GRC Capability Model and GRC Professional certification

Checked 2026-09-22
AssociationInternationalA
IAPP (International Association of Privacy Professionals)
iapp.org · 90,000 members (2026-09)

Members per its About page (90,000+); privacy and AI-governance practitioners, the buyers of the privacy half of GRC suites. Has a Canada section and Toronto/Montreal chapters

Checked 2026-09-22
EventUSA
GRC Conference (ISACA and The IIA)
isaca.org

Annual joint ISACA/IIA conference for governance, risk and control practitioners; 2026 edition 17-19 Aug, San Diego and online

Checked 2026-09-22
PublicationUSA
Compliance Week
complianceweek.com

Trade newsroom for risk and compliance officers (now part of ECI); says it reaches 10,000+ risk and compliance leaders. Runs an annual conference

Checked 2026-09-22
AssociationInternationalC
SCCE (Society of Corporate Compliance and Ethics)
corporatecompliance.org

Blocked automated access (Cloudflare); professional body for corporate compliance officers, runs the Compliance & Ethics Institute

Checked 2026-09-22

r/GRC could not be reached from this network so is not listed. No Canada-only GRC body was found; Canadian practitioners sit in the ISACA and IAPP chapters.