IT Governance USA
GRC Solutions (formerly IT Governance USA) is a 20+ year-old GRC consultancy and software provider helping enterprises achieve compliance with ISO 27001, GDPR, PCI DSS, Cyber Essentials, SOC 2, DORA, NIS2, and the EU AI Act across the US, UK, Ireland, and Europe.
- Company typePrivate
- Founded2002
- HeadquartersNew York, United States
- Headcount51–100
- GTM typeB2B
- OfferingServices
What IT Governance USA does
IT Governance USA, now operating as GRC Solutions, is a private governance, risk, and compliance (GRC) firm founded in 2002 (under the IT Governance Ltd brand) and headquartered in New York, with operational presence in the United Kingdom, Ireland, and continental Europe. The company delivers end-to-end GRC services and software to organizations navigating regulatory frameworks including the EU AI Act, GDPR, NIS2, DORA, PCI DSS, ISO 27001, ISO 22301, ISO 27701, and Cyber Essentials. Its customer base spans enterprises across automotive, legal, telecommunications, construction, and healthcare/biotech verticals, including named clients such as Volkswagen, Slaughter and May, Freshfields, Arkessa, Severfield, and Congenica.
The company's product and technology portfolio centers on three cloud-based platforms (CyberComply Portal for compliance management, GRC eLearning Platform for training delivery, and a Cyber Security Platform for security management), supplemented by a library of pre-built documentation toolkits and gap analysis tools across major standards. Core service lines include consultancy (ISO 27001, PCI DSS, NIS2, DORA, GDPR), CHECK and CREST-accredited penetration testing (including AI Red Teaming and ML/LLM Testing), auditing services, incident response, business continuity, and managed offerings such as DPO as a Service and DSAR as a Service. The firm holds scarce regulatory accreditations, including founding Cyber Essentials certifications body status, NCSC CHECK assured provider status, and PCI QSA company designation, which serve as meaningful competitive differentiators.
GRC Solutions generates revenue through a hybrid model combining project-based professional services (quote-based consultancy, penetration testing, certification), transactional e-commerce sales of toolkits, e-learning courses, gap analysis tools, and standards documents via its us.grcsolutions.io storefront, and subscription-based managed services (DPO as a Service). The go-to-market motion is sales-led at the enterprise tier, with direct field sales and dedicated regional phone lines in the UK, US, Europe, and Ireland, complemented by a content-driven marketing engine spanning blogs, white papers, case studies, newsletters, and webinars. In 2025, the company consolidated IT Governance Ltd, DQM GRC, and GRCI Law under the unified GRC Solutions brand, signaling a strategic shift toward integrated governance, compliance, and technical assurance.
IT Governance USA firmographics
Firmographics- Name
- IT Governance USA
- Legal name
- IT Governance Ltd
- Website
- https://itgovernanceusa.com
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- GRC Solutions (formerly IT Governance USA) is a 20+ year-old GRC consultancy and software provider helping enterprises achieve compliance with ISO 27001, GDPR, PCI DSS, Cyber Essentials, SOC 2, DORA, NIS2, and the EU AI Act across the US, UK, Ireland, and Europe.
- Ownership category
- akta.pro rank
IT Governance USA industry classification
Industry- Product category
- Governance, Risk and Compliance (GRC) Services
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO), Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Risk, Controls & Governance (GRC) Platforms (FSAFAOAG)
Keywords
Where IT Governance USA is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
IT Governance USA business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Professional Services: Consultancy services including NIS2 Compliance, DORA Compliance, Incident Response, Business Continuity, SOC 2 Audits, PCI Consultancy, ISO 27001 Consultancy, NCSC Assured Cyber Security Consultancy, GDPR Compliance Solutions, and Penetration Testing services.
- Training Courses: Instructor-led and e-learning training courses for GDPR, CISSP, ISO 27001, ISO 22301, Cyber Security, DORA, PCI DSS, and AI governance certifications.
- Software Products: Documentation toolkits, gap analysis tools, and software solutions sold as perpetual licenses or subscriptions for standards compliance.
- Standards and Publications: Sale of official standards documents (ISO 27001, ISO 42001, ISO 22301, ISO 20000, ISO 27701) and professional books on cybersecurity, GDPR, and compliance topics.
- Certification Services: Cyber Essentials and Cyber Essentials Plus certification services, SOC 2 audit services, and PCI QSA assessment services.
- DPO as a Service: Data Protection Officer services provided on a subscription or retainer basis for UK-only organizations requiring GDPR compliance support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | One time/ perpetual license | E-Learning Staff Awareness Courses |
| Subscription | One time/ perpetual license | Training Courses |
| One time/ perpetual license | One time/ perpetual license | Documentation Toolkits |
| One time/ perpetual license | One time/ perpetual license | Gap Analysis Tools |
| Other | Multi-year contract | Professional Services |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
IT Governance USA product offering
Product offeringCore offering
IT Governance USA (now operating as GRC Solutions) provides end-to-end governance, risk and compliance (GRC) solutions spanning consultancy, accredited penetration testing, certification services (Cyber Essentials, ISO 27001, SOC 2, PCI DSS), staff training and e-learning, and pre-built compliance documentation toolkits and gap analysis software. The portfolio also includes AI governance services, DPO-as-a-service, incident response, and managed data protection representation for organizations across the UK, US, Europe and Ireland.
Product overview
GRC Solutions (formerly IT Governance Ltd) offers a comprehensive portfolio of governance, risk, and compliance solutions delivered as both services and software tools. The core offerings include six main solution areas: AI Governance, Data Privacy/GDPR, PCI DSS, Cyber Essentials, ISO 27001, and SOC 2. These are supported by professional services including penetration testing (with AI Red Teaming capabilities), auditing services, and consultancy covering NIS2, DORA, incident response, and business continuity. The software portfolio includes documentation toolkits, e-learning courses, and gap analysis tools across key compliance frameworks. The company operates online platforms including CyberComply Portal, GRC eLearning Platform, and Cyber Security Platform to deliver these solutions. This multi-channel approach combines consulting expertise with self-service tools and training to support organisations throughout their compliance lifecycle.
Differentiator
Problem solved
Functional benefit
Products and services
- AI Governance Solution Comprehensive solution enabling organizations to manage AI use safely and responsibly with practical policies, risk controls and compliance support aligned with the EU AI Act, GDPR and ISO 42001.
- Data Privacy and GDPR Solution
- PCI DSS Solution
- Cyber Essentials Certification Solution
- ISO 27001 Solution
- SOC 2 Solution
- Penetration Testing Services
- AI Red Teaming and ML/LLM Testing
- NIS2 Compliance Consultancy
- DORA Compliance Consultancy
- Incident Response Services
- Business Continuity Services
- Auditing Services
- Data Protection Officer (DPO) as a Service
- UK Representative Service
- EU Representative Service
- DSAR as a Service
- GDPR Documentation Toolkit
- ISO 27001 Documentation Toolkit
- PCI DSS Documentation Toolkit
- Cyber Essentials Toolkit
- CyberComply Portal
- GRC eLearning Platform
- Cyber Security Platform
- Staff Awareness E-learning Courses
- Instructor-Led Training Courses
- ISO 27001 Gap Analysis Tool
- GDPR Gap Analysis Tool
- Cyber Essentials Gap Analysis Tool
- ISO 22301 Gap Analysis Tool
- ISO 27701 Gap Analysis Tool
- DORA Gap Analysis Tool
- Data Seeding Solutions
- Data Subject Rights Testing
- ISO 27001 Internal Audit Service
- NCSC Assured Cyber Security Consultancy Service
- NCSC Cyber Assessment Framework (CAF) Assessment
Companies that use IT Governance USA
Customer profileNamed customers6 records
Segments3 records
Ideal customer profiles3 records
IT Governance USA technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature4 records
IT Governance USA partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- CREST (Council of Registered Ethical Security Testers)coreGRC Solutions is a CREST member company, indicating accreditation for penetration testing and security assessment services meeting international standards. This partnership provides independent verification of technical capabilities in penetration testing, vulnerability assessment, and related security services.
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
IT Governance USA competitors and assessment
Company assessmentEmerging players
- Secureframe: Secureframe provides automated compliance and security management for frameworks including SOC 2, ISO 27001, HIPAA, and PCI DSS. Its self-service platform overlaps directly with GRC Solutions' ISO 27001 and PCI DSS certification toolkit and consultancy offerings at the SMB/mid-market tier.
- Vanta: Vanta is a leading automated compliance platform that helps organizations achieve and maintain SOC 2, ISO 27001, HIPAA, and GDPR via a self-service SaaS model. It competes for the same mid-market and enterprise buyer seeking ISO/SOC compliance, but delivers value through automation rather than traditional consultancy, positioning it as a disruption vector.
- Drata: Drata is a compliance automation platform similar to Vanta, targeting SOC 2, ISO 27001, HIPAA, and PCI DSS with continuous monitoring. It overlaps heavily with GRC Solutions' ISO 27001 and SOC 2 advisory/toolkit offerings but serves buyers looking to minimize professional services engagements.
Broad incumbents
- Diligent (Galvanize / Diligent GRC): Diligent's GRC platform (built on Galvanize) serves enterprises with audit, risk, and compliance management across multiple frameworks. As an incumbent, it competes with GRC Solutions on large enterprise mandates where integrated SaaS platforms are preferred over consultancy-led implementations.
- OneTrust: OneTrust is a broad privacy, security, and GRC platform with deep GDPR and ISO 27701 capabilities, plus ethics and compliance modules. Its privacy-focused platform overlaps with GRC Solutions' data privacy / GDPR offerings, while it scales product and engineering investment well beyond IT Governance's boutique footprint.
- TrustArc: TrustArc is a privacy and compliance platform offering GDPR, CCPA, and broader GRC program support. Its combination of privacy technology plus professional services overlaps with GRC Solutions' GDPR and data protection offerings while serving a larger enterprise segment.
- DNV: DNV is a global assurance and certification giant offering ISO management system certifications, cybersecurity assessments, and GRC advisory across maritime, energy, healthcare, and digital trust. It competes with GRC Solutions for the same enterprise certification and compliance mandates at a much larger scale.
Direct peers
- NCC Group: NCC Group is a UK-headquartered cybersecurity and GRC services firm offering CHECK/CREST-accredited penetration testing, ISO 27001 certification support, and managed compliance services. It is a close analog in scale, geography, accreditation, and service mix to GRC Solutions.
- LRQA (Lloyd's Register Quality Assurance): LRQA is a global certification body providing ISO 27001, ISO 9001, and other management system certifications, alongside cybersecurity and GRC advisory. Its combined certification + consultancy + training model closely parallels GRC Solutions' compliance and risk service stack.
- BSI Group: BSI is the UK's national standards body and a global compliance services provider offering standards publication, certification (ISO 27001, ISO 9001), training, and consultancy. Its business model around standards + certification + training directly mirrors GRC Solutions' toolkit, certification, and training revenue streams.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights6 records
Customer concentration
IT Governance USA social profiles
Digital presenceIT Governance USA compliance and trust
Trust signalCompliance3 records
IT Governance USA financial estimates
Financial estimateRevenue estimate
Valuation estimate
IT Governance USA leadership team
Management profileNumber of profiles
IT Governance USA funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IT Governance USA M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IT Governance USA
What does IT Governance USA do?
IT Governance USA (now operating as GRC Solutions) provides end-to-end governance, risk and compliance (GRC) solutions spanning consultancy, accredited penetration testing, certification services (Cyber Essentials, ISO 27001, SOC 2, PCI DSS), staff training and e-learning, and pre-built compliance documentation toolkits and gap analysis software. The portfolio also includes AI governance services, DPO-as-a-service, incident response, and managed data protection representation for organizations across the UK, US, Europe and Ireland.
Is IT Governance USA a public or private company?
IT Governance USA is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was IT Governance USA founded?
IT Governance USA was founded in 2002. It employs 51 to 100 people.
Where is IT Governance USA based?
IT Governance USA is headquartered in New York, United States, in the North America region.
How does IT Governance USA make money?
Six revenue lines are on record. Professional Services are the primary driver. The others are training Courses, software Products, standards and Publications, certification Services and DPO as a Service.
Who are IT Governance USA's main competitors?
Emerging players on record are Secureframe, Vanta and Drata. Broad incumbents are Diligent (Galvanize / Diligent GRC), OneTrust, TrustArc and DNV. Direct peers are NCC Group, LRQA (Lloyd's Register Quality Assurance) and BSI Group.
Does IT Governance USA have an API?
No public API is recorded for IT Governance USA.
What industry is IT Governance USA in?
IT Governance USA's product category is Governance, Risk and Compliance (GRC) Services. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory. Its NAICS code is 5415 and its SIC code is 7372.