Show rating breakdown
Save to My Lists
Claimed
Claimed

ZenGRC Reviews & Product Details - Page 9

ZenGRC Overview

What is ZenGRC?

ZenGRC offers an established solution to elevate your company's risk and compliance program to the highest infosec standards. The cloud-based SaaS solution fits your existing GRC program and also evolves to guide you throughout your maturity roadmap. With ZenGRC as the central platform for your organization's entire infosec ecosystem, you can achieve continuous monitoring and efficient audit management capabilities, as well as customizable, end-to-end risk management that's built-in — not bolted on. Companies from SMB all the way to Enterprise use ZenGRC for... — Minimized manual effort through automation — Shortened, simplified audit cycles — Risk management that’s built-in—not bolted on — Increased visibility and reporting with dashboards — Direct integrations with ServiceNow, AWS, Qualys, Slack, JIRA, and more.

ZenGRC Details
Discussions
ZenGRC Community
Languages Supported
English
Show LessShow More
Product Description

ZenGRC is a user-friendly GRC software designed to make compliance easy for nimble enterprises.

How do you position yourself against your competitors?

Our intuitive dashboards, pre-built templates, and built-in risk management features easily solve critical problems at scale. ZenGRC + ZenConnect provide a holistic view of your applications containing critical data within a centralized, cloud-based solution, allowing you to continuously monitor your data and mitigate risk in real-time. With dedicated onboarding specialists, customer success managers, and GRC experts you’ll be up and running in weeks—not months.


Seller Details
Seller
Zengrc
Year Founded
2009
HQ Location
San Francisco, CA
Twitter
@riskoptics
603 Twitter followers
LinkedIn® Page
www.linkedin.com
70 employees on LinkedIn®

Ani B.
AB
Overview Provided by:
Founder | CEO at Bisaria & Co.

Recent ZenGRC Reviews

Verified User
A
Verified UserEnterprise (> 1000 emp.)
3.5 out of 5
"Looking for a ISO and NIST GRC tool?"
Zen is very user friendly when conducting ISO 27001 audits for internal reviews.
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"Great GRC tool for mid size companies!"
The tool is very user-friendly, customizable.
Kert John D.
KD
Kert John D.Small-Business (50 or fewer emp.)
5.0 out of 5
"GRC "easy button""
Being newer to leveraging a GRC tool, what attracted me most to ZenGRC was the functionality and manageability versus the others players in that sp...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

ZenGRC Media

ZenGRC Demo - Compliance Dashboard
ZenGRC Compliance Dashboard
ZenGRC Demo - System of Record Detail
ZenGRC System of Record Detail
ZenGRC Demo - Audit Status Dashboard
ZenGRC Audit Status Dashboard
ZenGRC Demo - Risk Assessment
ZenGRC Risk Assessment
ZenGRC Demo - Heat Map
ZenGRC Heat Map
ZenGRC Demo - InfoSec Dashboard
ZenGRC InfoSec Dasboard
Answer a few questions to help the ZenGRC community
Have you used ZenGRC before?
Yes

93 ZenGRC Reviews

4.4 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
93 ZenGRC Reviews
4.4 out of 5
93 ZenGRC Reviews
4.4 out of 5

Overall Review Sentiment for ZenGRCQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Computer Software
AC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

ZenGRC is a great place to start GRC program in your company as it centralizes management of core requirements to meet the requirements of your desired certification and/or audit requirements. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

ZenGRC lacks advanced workflows and the ability to self-service complex, custom modules. API integrations are also currently a bit limited. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

SOC 2, ISO audits as well as Vendor Risk Management. Review collected by and hosted on G2.com.

JS
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

Ease of use of the ZenGRC portal combined with the ability to run the audit and give your audit direct access to controls & related evidence makes the entire process friction-less. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

The ability to take a full image backup, locally, is a small but manageable risk. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Setting up your initial controls can be a little time consuming, but the ability to use common controls across multiple compliance frameworks & to mitigate risks is extremely valuable. Time is saved with the cross mapping capability and the value is realized very quickly. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

The main benefit is the way we can share audit evidence from within the secure portal, by directly provisioning the auditor, is a valuable benefit. The time to audit was reduced by at least 30%. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

The product is very user friendly. The ZenGRC training was well organized and very informative. We are preparing for our annual ISO audit and wished we had this product last year! Alejandro, our Customer Success Manger, has insured that all our questions and requests have been met thus far. The ZenGRC subject matter experts are very helpful and knowledgeable. Follow-up has been very good! We are looking forward to using the product!! Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Additional demo scenarios would be good. No dislikes to speak of. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Identify your requirement, # of required admins and audit types. This will assist in building your site and identify training. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Streamline our internal and external security audits. Compliance with industry requirement and standards. We have realized other ways that we can use this ZenGRC to track audit findings and resolve issues. Review collected by and hosted on G2.com.

Verified User in Government Administration
AG
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about ZenGRC?

Having used a few different GRC tools and I do like this one quite a bit due to the ability to customize things. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Although the customizeable features are great, there's also a mini drawback that I can customize EVERYTHING. Also, being able to do batch adding and removing of things (e.g., objectives, controls, etc.) would be fantastic. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Just having a centralized program and this definitely helps. Review collected by and hosted on G2.com.

AW
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

ZenGRC brings all the tools you need to run a successful GRC program to the table in a clear, concise and minimalist package that's nimble and efficient. Our company had been utilizing the old method of email/spreadsheets and was getting lost in the weeds even on the smallest of audits and struggling to keep up each year to stay ahead. Our evaluations with other tools fell flat, didn't meet our requirements or introduced complexity. Our evaluation of ZenGRC started with skepticism, but quickly turned positive once we realized how logically organized the system was on the back-end. During our testing period, we were able to quickly create a Sarbanes-Oxley program, using both their template import and the GUI, in a matter of days. Since that time only a few short weeks ago we have now almost completed a full internal audit of our SOX program, complete with evidence collection and control evaluations. Our rough estimate has us gaining back a full week of time from previous audits last year and year prior using the old email/spreadsheet method. We are now rolling out an ISO27001, SOC2 and internal security control framework on the heels of the SOX success. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

As with any SaaS from a small company that is new to market (less than 5 years), there are aspects of the tool that require some creative thinking and clever workarounds. This is not necessarily a dislike in my opinion, however less technical individuals may find this aspect difficult or troublesome. ZenGRC staff do redeem themselves on this front as they're quick to respond to feature requests and have already implemented several suggestions our team has submitted. Since starting to use the product, they have continually updated the product with new features, fixes and updates to existing functionality. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

This is a light, minimal and logical GRC tool that has a lot to offer a company that has never used a GRC tool in the past. Definitely worth a demo and serious consideration. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Traditionally our audit cycles were difficult in that we rarely hit our target evidence collection windows. Adding to that difficulty we typically have sample requests that introduce complexity and cross-collection on requests with similar subjects and titles making it easy to get lost in email weeds. With ZenGRC, we removed all that complexity by making each and every evidence request unique. Sample requests were entered as new requests in the system so as not to get confused with the original request. Accountability was easily visible with the Request status on the Audit dashboard and escalations were efficient. On our first run, after a small 30 minute training session, we achieved 98.5% completion ahead of our submission deadline. That would have been impossible without ZenGRC. Review collected by and hosted on G2.com.

AO
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

The general consensus from the team is that this tool is really great. We are really happy to use it, and I do believe it is going to make our compliance efforts really streamlined. Our organization tends to be a little bit resistant to rigor and control, so tools like ZenGRC are helping to make it easy and less intrusive. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Looking forward to the custom survey feature! Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Internal and External audit, ISO 27001 certification, SOC 2 reporting, Risk Assessment and vendor security Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
EH
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

We've been using zGRC for 18 months. It is the best tool I've found for mapping compliance obligations, controls, risks, vendors, and the myriad of other objects that need to be modeled for a solid risk and compliance program. It's ability to cross-link objects to each other, especially linking controls to multiple frameworks (SOC 2, HITRUST, PCI, etc) is invaluable. I could not do my job without it. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

The ability to model risks could be improved. We've extended it with custom fields to fit our needs. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

It's a great product. The Reciprocity team is easy to work with, and they listen to customer product suggestions. We looked at a lot of other software. Nothing came close to zGRC for the money. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Our company is subject to multiple compliance frameworks. We needed a system to map all our controls to those frameworks to simplify audit and compliance. Also, we needed a way to track risks, especially as related to our vendors. zGRC has greatly enhanced our ability to get and stay compliant. It cuts our audit times in half. Review collected by and hosted on G2.com.

Gemma B.
GB
Compliance Program Lead, Quality Assurance
Internet
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

Using ZenGRC, we've automated tracking of compliance issues that pose potential risks. It has allowed us to remediate these issues swiftly. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Exporting reports to CSV then takes a decent amount of reformatting to ready them for Executive review, but the new dashboard functionalities are providing new options in reporting key results which is great.

Overall the team has been quick to respond to requests for changes or additional functionality. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Centralized and systematic issue tracking across review types, programs and teams. Review collected by and hosted on G2.com.

Travis R.
TR
CISO
Computer Software
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about ZenGRC?

ZenGrC provided use with a single platform under which we could manage multiple, complex audits. The evidence collection and workflows replaced what was an otherwise tedious and duplicative process with JIRA tickets. The ability to present evidence from previous years as an example is immensely helpful when dealing with turnover in engineering and operations teams. Simple implementation, very lightweight, but not lacking for features. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

The JIRA integration is rapidly improving but isn't quite as richly features as we would like. That being said, our use of JIRA is probably on the extreme side off complex so the current integration is likely acceptable for the majority of customers. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Take the time to do a POC and you will not be disappointed. Their support and go-live is exceptional. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

GRC, multiple concurrent audits, understanding audit readiness, coordination between multiple teams and auditors. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

I have been using ZenGRC for over two years now and it has been an essential tool helping us get and stay organized when we embarked on gaining a SOC 2 attestation. We have since been through two SOC 2 audits and are using ZenGRC to help us assess and remediate our gaps against ISO 27001. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

There's a fair amount of things you have to edit by exporting to CSV, editing in your favorite spreadsheet app, then re-importing, so it would be nice if some of that functionality was built into the UI. That being said, that workflow is actually ideal for some tasks.

Our last audit firm wasn't able to use the app directly for requesting and managing audit evidence so there was a bit of duplication of effort. The ZenGRC team is making some changes to make that better though. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

GRC program management, controls gap analysis, compliance reporting. Because it's so well organized we've managed to keep the required staff to manage compliance at a minimum. Review collected by and hosted on G2.com.