GRC International Group plc
- Company typePublic
- Founded2002
- HeadquartersCambridge, United Kingdom
- Headcount51–100
- GTM typeB2B
- OfferingServices
GRC International Group plc firmographics
Firmographics- Name
- GRC International Group plc
- Legal name
- GRC International Group PLC
- Website
- https://grci.group
- Company type
- Public
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Ownership category
- akta.pro rank
GRC International Group plc industry classification
Industry- Product category
- Governance, Risk and Compliance (GRC) Services
- NAICS
- Computer Systems Design and Related Services (54151), Management, Scientific, and Technical Consulting Services (5416), Management Consulting Services (54161)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Management Consulting Services (8742)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ), Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO), Regulatory Change, Governance & Compliance Management (GRC) (FSACAJAK)
Keywords
Where GRC International Group plc is headquartered
LocationHeadquarters
- HQ city
- Cambridge
- HQ country
- United Kingdom
- HQ region
- Europe
Offices6 records
Markets served
GRC International Group plc business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Subscription Products (Certifications): Annual subscription products including Cyber Essentials and Cyber Essentials Plus certifications that auto-renew. Revenue recognized on subscription basis with recurring billing through payment card or purchase order.
- Training Courses: One-time fee for classroom, virtual, and blended training courses including trainers' time, training rooms, materials, and refreshments. CISSP training with pass guarantee. Exam vouchers included or available as add-on.
- Elearning Licenses: Corporate elearning licenses for staff awareness training courses, sold per user count with time-based access (12 months standard). Extensions available for additional fees.
- Software Tools and Toolkits: Purchase of compliance software tools, document kits, and template toolkits for cyber security and data protection management.
- Professional Services (Consultancy): Penetration testing, vulnerability scanning, DPO as a Service, Privacy as a Service, Cyber Security as a Service, and incident response consultancy billed separately or as part of subscription packages.
- Cyber Security as a Service (CSaaS): Monthly billed annual subscription combining cyber security assessment, advice service, vulnerability scanning, staff awareness training, policies/procedures, and incident response support.
- Standards and Publications: Sale of international standards (ISO standards) and publishing materials for internal business use with single-copy printing rights for end users.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Cyber Essentials - Annual certification subscription |
| Subscription | Annual | Cyber Essentials Plus - Enhanced certification with testing |
| Unit Pricing | Pay-as-you-go | Training Courses - Per course pricing |
| One time/ perpetual license | Pay-as-you-go | CISSP Blended Online Training - Pass guarantee |
| Subscription | Annual | Elearning Corporate License - Per user count |
| Subscription | Monthly | Cyber Security as a Service (CSaaS) - Tiered by organization size |
| Subscription | Annual | DPO as a Service / Privacy as a Service |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
GRC International Group plc product offering
Product offeringCore offering
GRC International Group plc (now GRC Solutions) provides governance, risk management and compliance (GRC) products and services spanning cyber security, data privacy, and risk management. The portfolio includes certification services (Cyber Essentials and Cyber Essentials Plus), managed services (CSaaS, DPO as a Service), professional services (penetration testing, vulnerability scanning, incident response, consultancy), training courses and e-learning, compliance software platforms (CyberComply, GDPR.co.uk), and standards publishing through IT Governance Publishing. The company primarily serves organisations in the UK, EU, and US with a long-term strategic relationship model that scales from automated SMB solutions to bespoke enterprise engagements.
Product overview
GRC International Group plc (trading as GRC Solutions following a 2025 rebrand) operates a diversified portfolio of governance, risk management and compliance (GRC) products and services. The offering is structured as a platform-plus-services model rather than a single unified product. The portfolio spans: certification services (Cyber Essentials and Cyber Essentials Plus via the dedicated portal), managed services (Cyber Security as a Service, DPO as a Service, Privacy as a Service), professional services (penetration testing, vulnerability scanning, training courses, emergency incident response), software tools (CyberComply with DocumentKits, GDPR.co.uk), and elearning platforms (GRC eLearning Management System). The company also publishes books and standards through IT Governance Publishing. The various products are sold both individually and as integrated packages, with subscription options for ongoing services.
Differentiator
Problem solved
Functional benefit
Brands
- IT Governance: Flagship brand providing IT governance, cyber security, and compliance consulting, training, and software solutions including ISO 27001 and GDPR support.
- IT Governance Publishing (ITGP)
- DQM GRC
- GRCI Law
- CyberComply
- GDPR.co.uk
- Cyber Essentials Portal
Products and services
- Cyber Essentials and Cyber Essentials Plus
- Cyber Security as a Service (CSaaS)
- DPO as a Service / Privacy as a Service
- Penetration Testing
- Vulnerability Scanning
- Training Courses
- Staff Awareness eLearning
- Emergency Cyber Incident Response and Digital Forensic Services
- ISO 27001 Support Services
- CyberComply Platform
- GDPR.co.uk Platform
- IT Governance Cyber Essentials Portal
- Standards and Publications
- Software Tools and Toolkits (DocumentKits)
Quantifiable outcome
- Organizations achieve Cyber Essentials certification covering their whole organisation to basic level, qualifying for Cyber Liability Insurance (for UK organisations under £20m turnover)
- +1 more outcomes
Companies that use GRC International Group plc
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles4 records
GRC International Group plc technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
GRC International Group plc partnerships and signals
Strategic signalScale indicators8 records
Recent moves7 records
Expansion highlights6 records
GRC International Group plc competitors and assessment
Company assessmentDirect peers
- SureCloud: UK-based provider of GRC software and cyber security services including compliance management, penetration testing, and certification support. Direct peer in the UK GRC/cyber market with similar product-plus-services model and overlapping customer base in regulated industries.
- Bridewell: UK-headquartered cyber security and compliance consultancy providing penetration testing, managed security services, and GRC advisory. Directly comparable as a UK-focused cyber security and compliance services firm targeting similar mid-market and enterprise clients with overlapping service lines including ISO 27001, PCI DSS, and Cyber Essentials support.
Emerging players
- Drata: Automated compliance and security monitoring platform for SOC 2, ISO 27001, HIPAA, and other frameworks. Emerging player with overlapping ISO 27001 and GDPR compliance automation use cases where it competes with GRC International Group's professional services and DocumentKits offerings.
- Sprinto: Compliance automation platform for SOC 2, ISO 27001, GDPR, and other frameworks with growing global customer base. Emerging player with adjacent automated compliance capabilities targeting the same customer personas in regulated industries and tech-forward SMBs.
- CyberSmart: UK cyber security firm specializing in Cyber Essentials certification automation and SME cyber compliance tooling. Emerging player with direct overlap in Cyber Essentials certification delivery and basic cyber security compliance targeting UK SMB customers.
- Vanta: Compliance automation platform focused on SOC 2, ISO 27001, HIPAA, GDPR, and similar frameworks with strong growth capital and self-service automation approach. Emerging player competing for the same compliance-driven customer budgets via automated tooling that threatens traditional consulting-led GRC services.
Broad incumbents
- OneTrust: Large-scale privacy, security, and GRC platform with broad enterprise offering across consent management, data privacy, ethics, and compliance. Broader incumbent with overlapping capabilities in GRC platforms, GDPR tooling, and compliance management, but at much larger scale and with different go-to-market.
- ServiceNow GRC: Integrated GRC module within ServiceNow's enterprise platform offering risk, compliance, audit, and policy management. Major incumbent serving large enterprises with deeper integration and IT service management workflows than standalone GRC vendors.
- Diligent: Enterprise governance, risk, and compliance platform acquired by Insight Partners, providing board management, audit, risk, and ESG compliance. Broader incumbent in the GRC software space with overlapping risk and compliance management capabilities, but positioned at the enterprise end of the market.
Others
- IASME Consortium: UK-based organization that licenses the Cyber Essentials certification scheme. Indirect relationship as GRC International Group is an IASME-licensed certification body, making IASME both an enabling partner and a potential channel/competitive dependency for Cyber Essentials revenue.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
GRC International Group plc social profiles
Digital presenceGRC International Group plc compliance and trust
Trust signalCompliance4 records
GRC International Group plc financial estimates
Financial estimateRevenue estimate
Valuation estimate
GRC International Group plc leadership team
Management profileNumber of profiles
Profiles3 records
GRC International Group plc subsidiaries and ownership
Company hierarchySubsidiaries10 records
GRC International Group plc funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GRC International Group plc M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GRC International Group plc
What does GRC International Group plc do?
GRC International Group plc (now GRC Solutions) provides governance, risk management and compliance (GRC) products and services spanning cyber security, data privacy, and risk management. The portfolio includes certification services (Cyber Essentials and Cyber Essentials Plus), managed services (CSaaS, DPO as a Service), professional services (penetration testing, vulnerability scanning, incident response, consultancy), training courses and e-learning, compliance software platforms (CyberComply, GDPR.co.uk), and standards publishing through IT Governance Publishing. The company primarily serves organisations in the UK, EU, and US with a long-term strategic relationship model that scales from automated SMB solutions to bespoke enterprise engagements.
Is GRC International Group plc a public or private company?
GRC International Group plc is a public company. It is classified as public and is currently operating.
When was GRC International Group plc founded?
GRC International Group plc was founded in 2002. It employs 51 to 100 people.
Where is GRC International Group plc based?
GRC International Group plc is headquartered in Cambridge, United Kingdom, in the Europe region.
How does GRC International Group plc make money?
Seven revenue lines are on record. Subscription Products (Certifications) is the primary driver. The others are training Courses, elearning Licenses, software Tools and Toolkits, professional Services (Consultancy), cyber Security as a Service (CSaaS) and standards and Publications.
Who are GRC International Group plc's main competitors?
Direct peers on record are SureCloud and Bridewell. Emerging players are Drata, Sprinto, CyberSmart and Vanta. Broad incumbents are OneTrust, ServiceNow GRC and Diligent. IASME Consortium is listed as an others.
Does GRC International Group plc have an API?
No public API is recorded for GRC International Group plc.
What industry is GRC International Group plc in?
GRC International Group plc's product category is Governance, Risk and Compliance (GRC) Services. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of BPAEADAJ, Governance, Risk & Compliance (GRC) Managed Services. Its NAICS code is 54151 and its SIC code is 7370.