IT Governance
GRC Solutions (formerly IT Governance Ltd) is a UK-headquartered provider of governance, risk, and compliance services delivering consulting, accredited certification (PCI DSS, ISO 27001, Cyber Essentials, SOC 2), penetration testing, training, and documentation software to enterprise and mid-market organisations across the UK, Europe, and North America.
- Company typePrivate
- Founded2002
- HeadquartersEly, United Kingdom
- Headcount251–500
- GTM typeB2B
- OfferingServices
What IT Governance does
IT Governance Ltd, founded in 2002 and headquartered in Ely, United Kingdom, is a specialist provider of governance, risk, and compliance (GRC) services that now operates under the unified GRC Solutions brand following its 2025 merger with DQM GRC and GRCI Law. The company delivers end-to-end governance, compliance, and technical assurance across data privacy (GDPR, UK/EU Representative Services, DPO-as-a-Service), information and cyber security (ISO 27001, Cyber Essentials, SOC 2, NCSC-assured consultancy, Cyber Assessment Framework assessments), payment security (PCI DSS as a Qualified Security Assessor), penetration testing (CREST and NCSC CHECK accredited, including AI Red Teaming and ML/LLM Testing), and emerging EU regulations (NIS2, DORA, EU AI Act, ISO 42001). Its product portfolio combines professional consulting services, recurring e-learning and training (GDPR, CISSP, ISO 27001/22301, PCI DSS, DORA), one-time-licence documentation toolkits and gap analysis tools, and proprietary self-service platforms (CyberComply Portal, GRC eLearning Platform, Cyber Security Platform).
The company operates a hybrid GTM spanning enterprise field sales with expert consultation (UK, Europe, US, Ireland phone coverage), an e-commerce shop for SMEs and individual buyers, and self-serve compliance portals for mid-market customers. Pricing is quote-based across consulting and certification engagements, with subscription/recurring economics on training, DPO, and gap analysis tools and one-time licenses on documentation toolkits. Notable enterprise customers include Volkswagen, Severfield, Slaughter and May, Freshfields, Arkessa, and Congenica across automotive, construction, legal, technology/telecommunications, and healthcare/biotechnology industries.
The competitive position rests on a set of hard-to-replicate accreditations (PCI QSA, CREST member, NCSC CHECK assured provider, founding Cyber Essentials certification body, NCSC-assured cyber security consultancy) that gate regulated buyers' vendor shortlists. Twenty-plus years of operating history, extensive proprietary content/tooling, and certified consultant talent support the moat. As a privately held company with no disclosed revenue, headcount trend, funding, or ownership details beyond the 2025 three-way consolidation, financial visibility is limited.
IT Governance firmographics
Firmographics- Name
- IT Governance
- Legal name
- IT Governance Ltd.
- Website
- https://itgovernance.co.uk
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- GRC Solutions (formerly IT Governance Ltd) is a UK-headquartered provider of governance, risk, and compliance services delivering consulting, accredited certification (PCI DSS, ISO 27001, Cyber Essentials, SOC 2), penetration testing, training, and documentation software to enterprise and mid-market organisations across the UK, Europe, and North America.
- Ownership category
- akta.pro rank
IT Governance industry classification
Industry- Product category
- Governance, Risk & Compliance Services
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371), Services-Testing Laboratories (8734), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO)
- akta.pro secondary industries
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG)
Keywords
Where IT Governance is headquartered
LocationHeadquarters
- HQ city
- Ely
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
IT Governance business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Professional Services: Consultancy services including NIS2 Compliance, DORA Compliance, Incident Response, Business Continuity, SOC 2 Audits, PCI Consultancy, ISO 27001 Consultancy, GDPR Compliance Solutions, NCSC Assured Cyber Security Consultancy, and Cyber Assessment Framework assessments.
- Training & E-Learning: Training courses and staff awareness e-learning covering GDPR, CISSP, ISO 27001, ISO 22301, Cyber Security, DORA, PCI DSS, AI governance, and business continuity. Includes both instructor-led and self-paced e-learning options.
- Documentation Toolkits and Software: Software products including GDPR Documentation Toolkit, ISO 27001 Documentation Toolkit, PCI DSS Documentation Toolkit, and Cyber Essentials Toolkit. Also includes gap analysis tools for various standards.
- Penetration Testing Services: Security testing services including AI Red Teaming & ML/LLM Testing, Application Security Testing, Red Team Assessments, Purple Teaming, IoT/OT Security Testing, Cloud Security Testing, and Infrastructure Penetration Testing.
- DPO as a Service: Data Protection Officer services providing ongoing compliance support for organizations requiring GDPR expertise.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels4 records
IT Governance product offering
Product offeringCore offering
IT Governance (now GRC Solutions) provides governance, risk and compliance (GRC) services and software to organisations across Europe and North America. Its core offering spans six compliance solutions (AI Governance, GDPR, Cyber Essentials, ISO 27001, PCI DSS, SOC 2) supported by consultancy, CHECK and CREST-accredited penetration testing, professional and staff awareness training, and downloadable documentation toolkits and gap analysis tools, delivered direct, via self-service platforms and through partners.
Product overview
GRC Solutions (formerly IT Governance Ltd, DQM GRC, and GRCI Law) operates as a comprehensive governance, risk, and compliance (GRC) solutions provider. The portfolio consists of six core solution areas—AI Governance, Data Privacy/GDPR, Cyber Essentials, ISO 27001, PCI DSS, and SOC 2—supported by four integrated service pillars: consultancy (NIS2, DORA, incident response, business continuity, NCSC-assured services), penetration testing (including AI Red Teaming, application, infrastructure, cloud, IoT/OT, red/purple team), training (professional certifications, staff awareness e-learning, compliance courses), and software tools (documentation toolkits, gap analysis tools). The company also offers professional services including DPO-as-a-Service, EU/UK Representative Services, and DSAR management, delivered through online platforms (CyberComply Portal, GRC eLearning Platform, Cyber Security Platform). The unified brand consolidates three legacy entities to provide end-to-end coverage from assessment through implementation and ongoing assurance.
Differentiator
Problem solved
Functional benefit
Products and services
- AI Governance End-to-end solutions to help organisations manage AI use safely and responsibly, including practical policies, risk controls and compliance support aligned with the EU AI Act, GDPR and ISO 42001.
- Data Privacy and the GDPR Solutions to help organisations meet data privacy objectives and legal obligations under the GDPR and other privacy laws.
- Cyber Essentials Certification support for every stage of a Cyber Essentials project, helping organisations meet requirements, prepare evidence and achieve compliance.
- ISO 27001 End-to-end ISO 27001 implementation and certification support covering gap analysis, implementation and maintenance audits.
- PCI DSS Solutions to help organisations comply with the PCI DSS Standard, protect cardholder data and reduce the risk of breaches, delivered by a PCI QSA company.
- SOC 2 SOC 2 readiness assessments, remediation and maintenance services covering selected Trust Service Criteria (TSC).
- Application Security Testing Services Security testing services for applications designed to identify exploitable weaknesses.
- Red Team Assessments Simulated real-world attacks to evaluate an organisation's security posture and incident response capabilities.
- Purple Teaming Collaborative security testing that combines red team offensive tactics with blue team defensive response to improve detection and prevention capabilities.
- IoT / OT Security Testing Security testing services specifically for Internet of Things (IoT) devices and Operational Technology (OT) environments.
- Cloud Security Testing Independent security testing for cloud environments to identify exploitable weaknesses and support regulatory assurance.
- Infrastructure Penetration Testing Security testing of infrastructure to identify exploitable weaknesses and support regulatory assurance.
- Web Application Penetration Test Security testing of web applications to identify vulnerabilities and security weaknesses.
- AI Red Teaming & ML/LLM Testing Penetration testing service focused on identifying vulnerabilities and security weaknesses in AI systems, machine learning models and Large Language Models (LLMs).
- NIS2 Compliance Consultancy services to help organisations achieve compliance with the EU Network and Information Security Directive 2 (NIS2).
- DORA Compliance Consultancy services to help financial entities achieve compliance with the EU Digital Operational Resilience Act (DORA).
- Incident Response Expert support services for responding to and managing security incidents.
- Business Continuity Consultancy services to help organisations develop and maintain business continuity capabilities.
- NCSC Assured Cyber Security Consultancy Service NCSC-assured cyber security consultancy services.
- NCSC Cyber Assessment Framework (CAF) Assessment Assessment services using the NCSC Cyber Assessment Framework to evaluate organisational cyber security posture.
- GDPR Compliance Solutions Solutions to help organisations achieve and maintain GDPR compliance.
- Cyber Security Audit and Review Auditing services to evaluate and review cyber security controls and posture.
- GDPR Compliance Audit Auditing services to evaluate GDPR compliance.
- Cyber Essentials Plus Cyber Essentials Plus certification support and auditing services.
- IT Audit IT auditing services.
- SOC 2 Audits SOC 2 audit services to evaluate controls against selected Trust Service Criteria.
- PCI Consultancy PCI DSS consultancy services for compliance with the payment card industry data security standard.
- ISO 27001 Consultancy Consultancy services for achieving and maintaining ISO 27001 certification.
- Data Protection Officer (DPO) as a Service Outsourced Data Protection Officer service providing dedicated GDPR expertise and ongoing compliance support.
- UK Representative Service GDPR UK representative service for organisations without a UK establishment.
- EU Representative Service GDPR EU representative service for organisations without an EU establishment.
- DSAR as a Service Data Subject Access Request management service to handle data subject rights requests under GDPR.
- Data Subject Rights Testing Testing service to verify organisations can respond to data subject rights requests.
- Data Seeding Solutions Solutions for data seeding to support compliance testing.
- ISO 27001 Internal Audit Service Internal audit services for ISO 27001 compliance.
- Cyber Security Staff Awareness E-Learning Course E-learning course for staff awareness on cyber security.
- Certified GDPR Foundation Training Course Foundation-level training course for GDPR compliance certification.
- GDPR Documentation Toolkit Documentation toolkit for GDPR compliance.
- ISO 27001 Documentation Toolkit Documentation toolkit for ISO 27001 implementation and certification.
- PCI DSS Documentation Toolkit Documentation toolkit for PCI DSS compliance.
- Cyber Essentials Toolkit Documentation toolkit for Cyber Essentials certification.
- CyberComply Portal Online portal for managing compliance activities and documentation.
- GRC eLearning Platform Online platform for accessing GRC training and e-learning courses.
- Cyber Security Platform Online platform for cyber security management and services.
- CISSP Training Training courses for the Certified Information Systems Security Professional (CISSP) certification.
- ISO 27001 Training Training courses for ISO 27001 information security management systems.
- ISO 22301 Training Training courses for ISO 22301 business continuity management systems.
- DORA Training Training courses focused on the EU Digital Operational Resilience Act (DORA) compliance.
- Cyber Security Training General cyber security training courses.
- GDPR Training Training courses focused on GDPR compliance and data protection.
- PCI DSS Training Training courses for PCI DSS compliance.
- Staff Awareness E-Learning Training E-learning courses for staff awareness on various compliance and security topics.
- ISO 27001 Gap Analysis Tool Tool to assess gaps between current practices and ISO 27001 requirements.
- GDPR Gap Analysis Tool Tool to assess gaps between current practices and GDPR requirements.
- Cyber Essentials Gap Analysis Tool Tool to assess gaps between current practices and Cyber Essentials requirements.
- ISO 22301 Gap Analysis Tool Tool to assess gaps between current practices and ISO 22301 requirements.
- ISO 27701 Gap Analysis Tool Tool to assess gaps between current practices and ISO 27701 requirements.
- DORA Gap Analysis Tool Tool to assess gaps between current practices and DORA requirements.
Companies that use IT Governance
Customer profileNamed customers6 records
Segments3 records
Ideal customer profiles2 records
IT Governance technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
IT Governance partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- CRESTcoreCREST is an international not-for-profit accreditation and certification body. GRC Solutions is a CREST member company, indicating compliance with industry standards for technical information security services.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
IT Governance competitors and assessment
Company assessmentDirect peers
- TrustArc: Privacy compliance and GRC platform focused on GDPR, CCPA and related regulations. Comparable in the data-privacy and DSAR-management portion of IT Governance's offering.
- NCC Group: UK-headquartered cybersecurity and assurance firm offering CHECK/CREST-accredited penetration testing, cyber consulting and managed security. Directly comparable on pen testing, red teaming and security advisory portions of IT Governance's portfolio.
- Vanta: Automated compliance platform for SOC 2, ISO 27001, HIPAA and other frameworks. Directly comparable as it sells tooling and partner-led services to the same mid-market buyer addressing ISO 27001, SOC 2 and Cyber Essentials requirements that IT Governance services.
- Bridewell: UK cybersecurity consultancy providing CREST/CHECK pen testing, NCSC consultancy, ISO 27001, SOC 2 and PCI DSS services. Closest UK mid-market peer across the GRC and security assurance stack.
- Secureframe: Compliance automation platform covering SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR. Comparable on the tooling side of IT Governance's portfolio and increasingly on the audit-readiness services side.
- OneTrust: Privacy, security and GRC platform with strong GDPR, ISO 27001 and third-party risk offerings. Directly competes for enterprise privacy and GRC programme budgets that IT Governance addresses via DPO-as-a-Service and ISO 27001 consultancy.
- Drata: Compliance automation SaaS for SOC 2, ISO 27001, PCI DSS, GDPR and others. Competes with IT Governance's documentation toolkits and consultancy for the same mid-market compliance budgets.
Broad incumbents
- LRQA (formerly Lloyd's Register Quality Assurance): Global assurance and certification provider covering ISO 27001, ISO 22301, SOC 2 and cyber assurance. Comparable on the certification, training and advisory portion of IT Governance's portfolio.
- Protiviti: Global risk consulting and internal audit firm with a strong GRC, cybersecurity and compliance practice. Comparable as a broader incumbent that competes for the same enterprise ISO/SOC/PCI/GDPR mandates.
- BSI Group: Global standards body and certification/consulting firm offering ISO 27001, ISO 22301 and related training and certification. Competes with IT Governance on training, certification support and consultancy for ISO frameworks.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
IT Governance social profiles
Digital presenceIT Governance compliance and trust
Trust signalCompliance3 records
IT Governance financial estimates
Financial estimateRevenue estimate
Valuation estimate
IT Governance leadership team
Management profileNumber of profiles
Profiles1 record
IT Governance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IT Governance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IT Governance
What does IT Governance do?
IT Governance (now GRC Solutions) provides governance, risk and compliance (GRC) services and software to organisations across Europe and North America. Its core offering spans six compliance solutions (AI Governance, GDPR, Cyber Essentials, ISO 27001, PCI DSS, SOC 2) supported by consultancy, CHECK and CREST-accredited penetration testing, professional and staff awareness training, and downloadable documentation toolkits and gap analysis tools, delivered direct, via self-service platforms and through partners.
Is IT Governance a public or private company?
IT Governance is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was IT Governance founded?
IT Governance was founded in 2002. It employs 251 to 500 people.
Where is IT Governance based?
IT Governance is headquartered in Ely, United Kingdom, in the Europe region.
How does IT Governance make money?
Five revenue lines are on record. Professional Services are the primary driver. The others are training & E-Learning, documentation Toolkits and Software, penetration Testing Services and DPO as a Service.
Who are IT Governance's main competitors?
Direct peers on record are TrustArc, NCC Group, Vanta, Bridewell, Secureframe, OneTrust and Drata. Broad incumbents are LRQA (formerly Lloyd's Register Quality Assurance), Protiviti and BSI Group.
Does IT Governance have an API?
No public API is recorded for IT Governance.
What industry is IT Governance in?
IT Governance's product category is Governance, Risk & Compliance Services. Its primary akta.pro industry code is BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory, with a secondary code of HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms. Its NAICS code is 54151 and its SIC code is 7371.