Rapid7 Cyber GRC Becomes Generally Available on Rapid7 Command Platform
5th article in the last 90 days, one of 34 articles referencing Rapid7. Previous coverage: Proofpoint and vendors add AI security telemetry - Week of May 25, 2026 (May 2026).
Companies mentioned
Best suited for
- Seniority
- EVP / SVP / VP / AVP
- Job function
- Chief Information Security Officer
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Majority
- Technology maturity
- Market Correction
- Industry
- Information Technology / Software & Services / IT Services / Internet Services & Infrastructure
Our classification, not the publisher's statement. Best suited for, not only for.
Rapid7, Inc. made Rapid7 Cyber GRC generally available, extending its Rapid7 Command Platform with native governance, risk, and compliance capabilities. The company said the update connects governance workflows with live security operations data to support continuous understanding of cyber risk and control performance.
According to the announcement, Rapid7 Cyber GRC addresses a gap between security operations and governance by consolidating security findings, compliance evidence, and organizational risk into a single, continuously updated view. Rapid7 said the shared data foundation is meant to help security and compliance teams track active threats alongside control effectiveness.
Rapid7 Cyber GRC connects governance workflows directly to live telemetry and ties internal controls to current attack-surface visibility. The offering includes AI-powered assistants for compliance workflows and third-party assessments, and it supports policy management, third-party risk management, risk registers, and audit-ready reporting. The announcement also cited optional PCI Approved Scanning Vendor scanning.
Rapid7 said the platform supports capabilities including continuously validating security controls using live platform telemetry, automating audit readiness by collecting evidence and mapping controls across multiple compliance frameworks, and streamlining third-party risk management with an AI Assessment Assistant for vendor questionnaires and reviews. It also described connecting security action to measurable risk reduction by bringing active threats, exposures, and findings into year-round compliance workflows.
“Preemptive security goes beyond detecting and responding to threats. Organizations need to continuously understand where risk exists, whether controls are working, and where action is needed before gaps become incidents,” said Corey Thomas, Executive Chairman of Rapid7. “By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix, and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations.”
The company said it launched Cyber GRC in early access in May 2026 and advanced the offering through customer validation, commercial adoption, and an expanding assurance partner ecosystem, and it described plans to expand the offering as part of its Preemptive Security platform initiatives shown at Black Hat USA 2026.
Press release, provided by Globe Newswire on behalf of Rapid7. Read the original.