Show rating breakdown
Save to My Lists
Claimed
Claimed

ZenGRC Reviews & Product Details - Page 6

ZenGRC Overview

What is ZenGRC?

ZenGRC offers an established solution to elevate your company's risk and compliance program to the highest infosec standards. The cloud-based SaaS solution fits your existing GRC program and also evolves to guide you throughout your maturity roadmap. With ZenGRC as the central platform for your organization's entire infosec ecosystem, you can achieve continuous monitoring and efficient audit management capabilities, as well as customizable, end-to-end risk management that's built-in — not bolted on. Companies from SMB all the way to Enterprise use ZenGRC for... — Minimized manual effort through automation — Shortened, simplified audit cycles — Risk management that’s built-in—not bolted on — Increased visibility and reporting with dashboards — Direct integrations with ServiceNow, AWS, Qualys, Slack, JIRA, and more.

ZenGRC Details
Discussions
ZenGRC Community
Languages Supported
English
Show LessShow More
Product Description

ZenGRC is a user-friendly GRC software designed to make compliance easy for nimble enterprises.

How do you position yourself against your competitors?

Our intuitive dashboards, pre-built templates, and built-in risk management features easily solve critical problems at scale. ZenGRC + ZenConnect provide a holistic view of your applications containing critical data within a centralized, cloud-based solution, allowing you to continuously monitor your data and mitigate risk in real-time. With dedicated onboarding specialists, customer success managers, and GRC experts you’ll be up and running in weeks—not months.


Seller Details
Seller
Zengrc
Year Founded
2009
HQ Location
San Francisco, CA
Twitter
@riskoptics
603 Twitter followers
LinkedIn® Page
www.linkedin.com
70 employees on LinkedIn®

Ani B.
AB
Overview Provided by:
Founder | CEO at Bisaria & Co.

Recent ZenGRC Reviews

Verified User
A
Verified UserEnterprise (> 1000 emp.)
3.5 out of 5
"Looking for a ISO and NIST GRC tool?"
Zen is very user friendly when conducting ISO 27001 audits for internal reviews.
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"Great GRC tool for mid size companies!"
The tool is very user-friendly, customizable.
Kert John D.
KD
Kert John D.Small-Business (50 or fewer emp.)
5.0 out of 5
"GRC "easy button""
Being newer to leveraging a GRC tool, what attracted me most to ZenGRC was the functionality and manageability versus the others players in that sp...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

ZenGRC Media

ZenGRC Demo - Compliance Dashboard
ZenGRC Compliance Dashboard
ZenGRC Demo - System of Record Detail
ZenGRC System of Record Detail
ZenGRC Demo - Audit Status Dashboard
ZenGRC Audit Status Dashboard
ZenGRC Demo - Risk Assessment
ZenGRC Risk Assessment
ZenGRC Demo - Heat Map
ZenGRC Heat Map
ZenGRC Demo - InfoSec Dashboard
ZenGRC InfoSec Dasboard
Answer a few questions to help the ZenGRC community
Have you used ZenGRC before?
Yes

93 ZenGRC Reviews

4.4 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
93 ZenGRC Reviews
4.4 out of 5
93 ZenGRC Reviews
4.4 out of 5

Overall Review Sentiment for ZenGRCQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Marketing and Advertising
AM
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

Overview:

Our company got ISO 27001 certified in 2019 and our ISMS was managed through Google docs, spreadsheets, and some of it in Atlassian products. This worked fine but was not much scalable nor did we have a single source of truth to refer to. In addition, we started to prepare for a SOC 2 certification in 2021 and now wanted to map our controls against multiple compliance frameworks. We reviewed several tools mentioned in the 2020 Gartner report for GRC products and narrowed down to ZenGRC for several reasons: It's nimble and faster to adopt than products, and yet strikes a good balance between simplicity and feature coverage. As a SaaS platform, we see ZenGRC growing with us as we progress our compliance programs.

Onboarding experience:

This process was a very pleasant experience with a set of scheduled video calls and hands-on training on the product. There was plenty of time for open questions and in some sessions, a Reciprocity GRC expert joined to answer specific questions on frameworks and how to apply them in the tool. This added a lot of value.

In addition to the onboarding sessions, we got access to the Zen University, an e-learning platform with video courses covering all areas of the product. The course modules are easy to follow tutorials that encourage to use the product while watching to get the most out of it. These courses were a great way to prepare each onboarding video call and note questions.

We also have access to ZenGRC's online documentation which covered all our needs so far. There are tutorials on features and also tips and tricks on how to utilise the product most effectively.

Access to GRC experts:

As mentioned above in the onboarding experience, having access to GRC experts when we are stuck with a certain question adds a lot of value to the services provided. We not only have access to a platform to manage our compliance programs but can also resolve roadblocks through expert advice as.

Data import:

As with all GRC products, data import is an important aspect and the CSV import functionality ZenGRC offers works really well. I was able to pick it up within a very short time and important most of our data already during our onboarding phase. The importer supports copy & paste from a spreadsheet, import of a spreadsheet directly and has useful validation to avoid importing incorrect data.

Ideas portal:

After onboarding, we have been pointed to an ideas portal where Reciprocity customers can vote on existing product ideas submitted by other customers or submit their own. It's really useful to see what features other customers requested and upvote what's of most value for our organization. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

If you come from a very mature Google world, then ZenGRC's interfaces look a little basic in some areas. However, this doesn't really affect functionality or effectivity of the product.

The dashboard functionality served us well for now but could add a little more customizability. That being said, there have been improvements since we have adopted ZenGRC and there are more improvements on the roadmap. Also, we use Tableau and the native integration would solve all our needs for reporting should we ever need more.

The list view navigation and search sometimes require more clicks than necessary depending on what you are looking for. This has been raised in the ideas portal already and improvements are in the works. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

We solved the challenge of adopting multiple compliance frameworks in one product (ISO 27001, SOC 2, as well as privacy frameworks like GDPR, CCPA). The benefits realised is a single source of truth approach where all compliance monitoring sits in ZenGRC. Review collected by and hosted on G2.com.

JG
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

ZenGRC is very adaptable to fit our specific needs for managing our large contract. The fact that we can customize the program to work for us is the best feature in my opinion. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

The only change I would recommend would be the ability to change the standard naming convention. We use the term requirements or outcomes instead of objectives. Although this is a very minor dislike. We have been able to adapt without too many complaints from our business users. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

I would recommend taking a look at ZenGRC. You might be surprised how they have made this product work for a variety of needs. They are also constantly making updates and making the product better. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

ZenGRC allows our users to save documents to one central location rather than saving in their email or in the ShareDrive. It also is a great repository when an employee leaves the company. It is easy to reassign objectives and tasks to other employee so that employee can pick up where the previous employee left off. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

ZenGRC provides a solid risk management solution that is easy to use and integrates well with other tools such as JIRA and Splunk. Assessments such as PCI and NIST are easier to manage and the dash board reporting provides an excellent holistic view of our overall security posture. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

At times it feels like there are too many options when building a program, mapping etc. Having such flexibility is great but sometimes, it would be nice to have existing builds for established industry standards. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

We had been utilizing numerous cumbersome spread sheets, issued constant email requests and at times duplicated efforts for evidence requests for our audits and compliance requirements. ZenGRC combines everything we need to run a successful GRC program, that includes, but is not limited to, auditing, gap assessments and automated continuous monitoring. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

I love that all of the information I need for an audit is connected (mapped) to each other. By opening one control, I can see the objectives it covers, the test plans, the owner, the related policies, any associated risks, etc. It's SO MUCH better than trying to keep it all straight in a spreadsheet. I can take care of vendors, risks, audits.... all in the same pane of glass. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

I would like to see some improvements in queries/filters. Especially for the dashboards. I would love an option for "not assigned." For example, I want to create a dashboard for how many controls don't have any associated tasks. That can help me demonstrate how far along we are on a project. The dashboard section could use some more in depth documentation. Perhaps some more examples on how to get the most out of it. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Definitely take the plunge. You'll thank yourself later. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

We're just getting started building our program. Making sure we have controls to cover all of the requirements (across multiple frameworks) has been amazing. We're utilizing the SCF to take advantage of overlaps. We're also starting to load in our policies, vendors, etc so we can associate everything together, in one place. Previously (without the tool), I've had to manually keep track of that across several documents. This has reduced the time it takes for me to do my job. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: Seller invite
(Original )Information
What do you like best about ZenGRC?

Ease of operations, metrics displaying level of program maturity Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Perhaps the reporting could be made easier Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Don't hesitate, ZenGRC will be very helpful in structuring your INFOSEC / PRIVACY Programs Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Processing information security frameworks, establishing specific programs, ZenGRC allows a structured and efficient approach. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
(Original )Information
What do you like best about ZenGRC?

ZenGRC is a great tool for my company as we do a lot of compliance frameworks so it's easier to track and map to. I like that I can cross-map to all the other frameworks and see what isn't mapped and need to improve on. Great to use to notified process owners about what evidence is needed and what previous evidence was submitted before. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

It can have some improvement be done on it to be more user friendly. We have some process owners that are not experience in Compliance framework and trying to navigate the tool. But once they understand where to go and what to look for it, is convenient for them. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Great tool to use to see all the control you have in the system and control mapping to all other security framworks (i.e. SOC, ISO 27001, 27017, 27018, PCI, FedRAMP, CSA Star, etc). Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Control mapping and easier to gather appropriate evidence from correct process owners. It's a centralized place to see all our controls and the evidence we provided. I like that we are able to integrate it with JIRA as our Engineers are more comfortable with JIRA. Review collected by and hosted on G2.com.

Alessio F.
AF
Information Security and Privacy Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

1. Versatility; it can meet a ton of use cases, and is extremely intuitive.

2. Integrations; ZenGRC easily plugs into common productivity tools like JIRA and Slack, which makes it easy to use across a distrusted organization.

3. Customer support; Zen has dedciated support and customer success managers that make it easy to deploy and get started. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

If you are hard pressed to find a GRC solution that meet some very specific or niche requirements (ex. Article 30 reporting for GDPR), Zen may not hit all of your bases, but this is easily made up for by its low price, and general versatility for any framework. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Large scale compliance management, audit management, risk and control management, vendor risk management, and (soon) asset management. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

ZenGRC is able to help us manage all of our compliance activities from audits to vendor reviews. It is wonderful to be able to use the same tool for multiple use cases. The tool is easy to configure and fairly intuitive. It does not take long to understand how to set it up for your specific needs. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

It would be nice if ZenGRC could help automate the vendor reviews by allowing us to configure the answers we want to see and having the tool flag those questions that don't meet our criteria, which are the ones we need to focus on. I would also like to see the export of the questionnaires in a little more readable format. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

ZenGRC is able to manager our audits and our vendor security reviews seamlessly! Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

We have streamlined our vendor reviews allowing us to manage twice as many questionnaires as we could when it was in a Word document. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
EH
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

PROS:

- Continuous updates and feature upgrades.

- Staff are easy going and friendly to work with.

- Customizable Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

- Since it is so customizable, the things you can't customize sometimes get in the way. However, Reciprocity is very receptive to feedback and often update the product when it makes sense to do so. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

- Complex compliance objectives.

- Complex mapping

- Vendor management/third-party risk. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

Very accomodating onboarding and support functions Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

There was nothing that we disliked about the product at this time. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

The product makes the risk management and compliance process more manageable, and they ensure you know how to use the product with detailed onboarding and great support. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Simplified our SOX compliance process Review collected by and hosted on G2.com.