GRC & Compliance Automation
Entry signal — what decides who wins here
One thing must be trueEntry turns on a single condition that can be named and tested before much is spent. Clear it and this becomes an execution question; fail it and no amount of operating skill helps.
Take share rather than ride the market. Demand is flat, seasonal or policy-driven, so growth has to come out of a competitor. That is possible and it is slower, and it rewards an operator who can wait.
Measured, not forecast: the share of US establishments opening in one year that were still active later. It counts good operators and bad ones together, which is exactly why it is the honest answer to “what are the odds”. It is for the whole sector rather than this market, and the ten-year figure comes from an older cohort because no younger one has reached ten years.
This is not a probability of success, and it is not a verdict on you. No survival probability is published per market, and inventing one would be worse than saying so. What the bar reads is how much of the outcome sits inside an operator's control: green means the hurdles are ones a better operator clears, red means the binding constraint is capital, an asset or a permission rather than execution. Someone arriving with an advantage this screen did not assume can win a market shown in red.
Companies named in this market · 5
The binding constraint — growth quality
The wedge that built this category has already been driven home. Automating SOC 2 and ISO evidence collection was a genuine opening in 2020; by 2026 Vanta is reported at $300M ARR, up 69%, with about 16,000 customers [C] and Drata and OneTrust hold the rest of the mid-market. OneTrust is put at roughly $550M of revenue on a $4.5B valuation [C]. A new entrant arrives after the land grab, selling to buyers who already passed their audit last year. Growth in the category is now taken from competitors rather than from the unserved, which is a different and much worse business to enter. Open-source GRC exists — Eramba, OpenSCAP — but here it competes with a service promise rather than a licence cost.
Sectors joined: Cybersecurity · SaaS · Technology · Dev Tools · B2B SaaS · AI
[UNVERIFIED] Sector-to-NAICS mapping is analyst judgment — see data/angel-sector-map.json. Counts are a per-record cross-reference and are not additive across records.
The incumbent
Who owns this market and who is coming for it. Fields a screen never reached say so rather than guessing.
The field
Every vendor named on this record, and what each one discloses. Most disclose nothing, which is why the market is not sized.
Competitor set · 4 named · 0 disclose revenue
| Name | Revenue | Share | Note |
|---|---|---|---|
| OneTrustC | not disclosed | — | Private. Reported at roughly $550M revenue and a $4.5B valuation [C] — a secondary estimate, not a filing |
| VantaC | not disclosed | — | Private. Reported at $300M ARR in April 2026, +69% YoY, ~16,000 customers [C, private-market research] |
| DrataC | not disclosed | — | Private; no revenue published |
| ServiceNow GRC / ArcherC | not disclosed | — | Enterprise GRC inside larger platforms; no line reported |
Nobody here publishes revenue. The market is not sized for that reason — an estimate built on nothing would only look like knowledge.
Vendor landscape
Market leaders, the full paid field, and every open-source alternative. Where a free tier exists it is what sets the price floor, so it is analysis rather than an appendix.
~$550M revenue, $4.5B valuation, 14,000+ customers [C]
$300M ARR April 2026, +69% YoY, ~16,000 customers [C]
Paid field · 6 vendors
Privacy, security and vendor risk on one platform
300+ integrations; earliest mover in audit automation
Private
Private
Bundled into the platform
The legacy enterprise GRC system of record
Open source · 3 projects — the price floor
The best-known open-source GRC platform; risk register, controls and audit workflow
Automated configuration compliance against public benchmarks
SOC 2 policy templates and evidence scaffolding
Open-source GRC is real but competes on a different axis: the paid tier sells an auditor-acceptable evidence trail and the integrations that populate it, not the control framework, which is public.
Evidence
Evidence. Market size UNVERIFIED — every revenue and valuation figure on this record is a private-market estimate from secondary research, not a filing [C], and none should be relied on without confirmation. A $15B market projection circulates and is NOT used as a finding. Verify before acting.
Where the industry talks
The associations, forums and events where people in this trade actually talk shop — where to listen before entering, and where the first customers are found. Each link was opened on the date shown.
Individual members in IT audit, governance, risk and security, per its About page; 225 chapters incl. Toronto, Vancouver, Montreal
Members per its About page; basic membership is free, so the count includes free sign-ups. Owns the GRC Capability Model and GRC Professional certification
Members per its About page (90,000+); privacy and AI-governance practitioners, the buyers of the privacy half of GRC suites. Has a Canada section and Toronto/Montreal chapters
Annual joint ISACA/IIA conference for governance, risk and control practitioners; 2026 edition 17-19 Aug, San Diego and online
Trade newsroom for risk and compliance officers (now part of ECI); says it reaches 10,000+ risk and compliance leaders. Runs an annual conference
Blocked automated access (Cloudflare); professional body for corporate compliance officers, runs the Compliance & Ethics Institute
r/GRC could not be reached from this network so is not listed. No Canada-only GRC body was found; Canadian practitioners sit in the ISACA and IAPP chapters.