In summary
- Rapid7 has launched Rapid7 Cyber GRC, adding native governance, risk and compliance capabilities to its Command Platform.
- The offering connects GRC workflows with live security telemetry, giving teams a shared view of control performance, threats and risk.
- Capabilities include continuous control validation, automated audit readiness across compliance frameworks, and an AI Assessment Assistant for third-party risk management.
Rapid7 has announced the general availability of Rapid7 Cyber GRC, adding native governance, risk and compliance (GRC) capabilities to its Command Platform and, the company said, making it the first major security operations platform to unify SecOps and GRC functions.
The new offering connects GRC workflows with live security telemetry from the Command Platform, giving security and compliance teams a shared, continuously updated view of control performance, active threats and organisational risk. Rapid7 said the integration supports what it calls its Preemptive Security strategy - extending that approach across risk, controls and compliance.
Rapid7 Cyber GRC includes capabilities for continuously validating security controls using live platform telemetry, automating audit readiness by mapping controls across multiple compliance frameworks, and streamlining third-party risk management through an AI Assessment Assistant designed to accelerate vendor questionnaires and reviews.
The platform also supports policy management, risk registers, audit-ready reporting and optional PCI Approved Scanning Vendor scanning.
"By bringing GRC into our platform, Rapid7 Cyber GRC connects what teams detect, what they fix, and what they can prove, turning compliance from a point-in-time exercise into an active part of security operations," said Corey Thomas, executive chairman at Rapid7.




