Skip to main content

Rapid7 Cyber GRC Becomes Generally Available on Rapid7 Command Platform

Rapid7, Inc. made Rapid7 Cyber GRC generally available, extending its Rapid7 Command Platform with native governance, risk, and compliance capabilities. The company said the update connects governance workflows with live security operations data to support continuous understanding of cyber risk and control performance.

According to the announcement, Rapid7 Cyber GRC addresses a gap between security operations and governance by consolidating security findings, compliance evidence, and organizational risk into a single, continuously updated view. Rapid7 said the shared data foundation is meant to help security and compliance teams track active threats alongside control effectiveness.

Rapid7 Cyber GRC connects governance workflows directly to live telemetry and ties internal controls to current attack-surface visibility. The offering includes AI-powered assistants for compliance workflows and third-party assessments, and it supports policy management, third-party risk management, risk registers, and audit-ready reporting. The announcement also cited optional PCI Approved Scanning Vendor scanning.

Rapid7 said the platform supports capabilities including continuously validating security controls using live platform telemetry, automating audit readiness by collecting evidence and mapping controls across multiple compliance frameworks, and streamlining third-party risk management with an AI Assessment Assistant for vendor questionnaires and reviews. It also described connecting security action to measurable risk reduction by bringing active threats, exposures, and findings into year-round compliance workflows.

“Preemptive security goes beyond detecting and responding to threats. Organizations need to continuously understand where risk exists, whether controls are working, and where action is needed before gaps become incidents,” said Corey Thomas, Executive Chairman of Rapid7. “By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix, and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations.”

The company said it launched Cyber GRC in early access in May 2026 and advanced the offering through customer validation, commercial adoption, and an expanding assurance partner ecosystem, and it described plans to expand the offering as part of its Preemptive Security platform initiatives shown at Black Hat USA 2026.

Provided by Globe Newswire on behalf of Rapid7. Click to read original content.