Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Claude-Skills-Governance-Risk-and-Compliance — Installable Claude Skills providing expert-level compliance guidance for 30+ frameworks including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, and EU AI Act. Includes gap analysis, policy templates, and control mapping. | Kitploit
Tools/GitHubGitHub/sushegaad/claude-skills-governance-risk-and-compliance
Vulnerability AnalysisCloud SecurityPrivacyThreat IntelligenceIdentity & Access Management (IAM)Learning & EducationCurated ResourcesAI Security
GitHub
sushegaad/claude-skills-governance-risk-and-compliance

Claude-Skills-Governance-Risk-and-Compliance

Installable Claude Skills providing expert-level compliance guidance for 30+ frameworks including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, and EU AI Act. Includes gap analysis, policy templates, and control mapping.

View RepositoryWebsite
8141707514 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Claude Skills for Governance, Risk & Compliance (GRC)

Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, DORA Digital Operational Resilience, India's Digital Personal Data Protection Act (DPDPA), CMMC 2.0 Cybersecurity Maturity Model Certification, NIST AI Risk Management Framework, SWIFT Customer Security Programme (CSP), Australian Information Security Manual (ISM), EU NIS2 Directive, CCPA/CPRA California Privacy, ITAR (International Traffic in Arms Regulations), Brazil's LGPD (Lei Geral de Proteção de Dados), EU CSRD (Corporate Sustainability Reporting Directive), CIS Controls v8 (CIS Top 18), EAR (Export Administration Regulations), NIST SP 800-53 (Security and Privacy Controls for Federal Systems), EU AI Act (Regulation (EU) 2024/1689), Section 508 (US Federal ICT Accessibility), WCAG (Web Content Accessibility Guidelines), NZISM (New Zealand Information Security Manual), Vietnam PDPL (Law on Personal Data Protection No. 91/2025/QH15), EU CRA (Cyber Resilience Act, Regulation (EU) 2024/2847), Saudi Arabia GRC (NCA ECC, Saudi PDPL, SAMA, CST), UAE GRC (Federal PDPL, DIFC, ADGM, CBUAE, ICT Health Law), TISAX (VDA ISA / ENX automotive supplier security), TPRM (third-party/vendor risk), UK Cyber Essentials, and SOX ITGC — powered by Claude Skills. Updated Monthly.

Benchmarked across 180 test cases using the eval framework — each graded against at least 5 verifiable assertions by independent agents (902 assertions in total). Skills scored 89% vs a baseline of 57%.

Release: v2.0.0 License: MIT Skills: 36 Built with Claude GitHub Stars


Table of Contents

  • What Are Claude Skills?
  • Who Is This For?
  • The Skills
    • ISO 27001
    • SOC 2
    • FedRAMP
    • GDPR
    • HIPAA
    • NIST CSF
    • PCI DSS
    • TSA Cybersecurity
    • ISO 42001 AI Management System
    • ISO 27701 Privacy Information Management
    • DORA Digital Operational Resilience
    • DPDPA India Digital Personal Data Protection
    • CMMC 2.0 Cybersecurity Maturity Model Certification
    • NIST AI Risk Management Framework
    • SWIFT Customer Security Programme (CSP)
    • Australian Information Security Manual (ISM)
    • EU NIS2 Directive
    • CCPA/CPRA California Privacy
    • ITAR — International Traffic in Arms Regulations
    • LGPD — Brazil's General Data Protection Law
    • CSRD — EU Corporate Sustainability Reporting Directive
    • CIS Controls v8 — CIS Top 18 Cyber Hygiene
    • EAR — Export Administration Regulations
    • NIST SP 800-53 — Security and Privacy Controls for Federal Systems
    • EU AI Act — Regulation (EU) 2024/1689
    • Section 508 — US Federal ICT Accessibility
    • WCAG — Web Content Accessibility Guidelines
    • NZISM — New Zealand Information Security Manual
    • Vietnam PDPL — Law on Personal Data Protection
    • EU CRA — Cyber Resilience Act
    • Saudi Arabia GRC — Country Compliance Advisor
    • UAE GRC — Country Compliance Advisor
    • TISAX — Trusted Information Security Assessment Exchange
    • TPRM — Third-Party Risk Management
    • Cyber Essentials / CE Plus — UK Baseline Certification
    • SOX ITGC — IT General Controls for SOX 404
  • Potential Use Cases
  • How to Install a Skill
  • Install via Claude Code Marketplace
  • Skill Evaluation
  • Customer Testimonials
  • Support
  • Author
  • Disclaimer

What Are Claude Skills?

Claude Skills are installable knowledge packages that extend Claude's capabilities for specific domains. A skill is a .skill file — a bundled archive containing a SKILL.md instruction file and optional reference materials — that you upload to Claude once and use across all your conversations.

Once installed, a skill activates automatically when your conversation touches its topic area. You don't need to invoke it by name or use special commands. Claude simply becomes a deeper expert in that domain for the duration of your session.

Skills are ideal when you need:

  • Consistent, expert-level responses on a specialized topic
  • Outputs formatted to professional or regulatory standards (e.g., audit-ready control narratives, policy templates with the right clauses)
  • Domain knowledge that goes beyond general LLM training — such as knowing which specific NIST 800-53 controls apply to a given scenario, or which GDPR articles govern international data transfers

How skills work under the hood: Each .skill file contains a primary SKILL.md that is loaded into Claude's context when the skill triggers, plus reference files that are loaded on demand for deeper sub-topics. This "progressive disclosure" pattern keeps context usage efficient while making comprehensive knowledge available when needed.


Who Is This For?

These skills are designed for professionals who work on information security, privacy, and regulatory compliance — whether at organizations seeking certification, development teams building compliant systems, or advisors supporting clients.

Security & Compliance Teams use these skills to accelerate gap assessments, generate first-draft policies, map controls, and prepare evidence packages — compressing weeks of reference work into minutes.

Download Tool