From zero to GRC analyst — a flight simulator, not a lecture hall.
Eleven roadmap stages, 21 hands-on labs with real company briefs, AI scoring against a rubric, and a portfolio of artifacts you actually produced. Free to start; Pro unlocks full AI grading and company generation.
- Hours
- 55–80
- Labs
- 21
- Companies
- 8 briefs
You joined as the lead GRC analyst last month. Produce a 90-day plan that addresses the most material audit findings, stands up a vendor risk program, and gets the org to its first SOC 2 Type I readiness assessment.
AI rubric items
- Statement quality
- Scoring discipline
- Controls — not vague
- Owner by function
Eleven stages, ordered, with honest time estimates.
From cybersecurity fundamentals to career readiness. Each stage has a summary, the topics it covers, and the hours it actually takes.
CIA triad, threat actors, attack surfaces, and the language every analyst uses
What GRC actually is, where it sits in an org, and how governance differs from security ops
Risk identification, 5×5 scoring, inherent vs residual risk, and the register that auditors love
Policies, standards, procedures — what belongs at each layer and how to draft each
Preventive vs detective, manual vs automated, and how to design tests that prove a control works
Internal vs external audit, evidence requests, and how to keep an auditor happy
NIST CSF/RMF, ISO 27001, SOC 2, PCI, HIPAA, GDPR — what each actually requires
Vendor due diligence, SOC 2 reports, ongoing monitoring, and how to score vendor risk
Executive summaries, board reporting, and translating risk into business language
20 hands-on exercises with real company briefs and AI-graded written answers
Resume, interview prep, the GRC analyst portfolio, and landing your first role
Nine frameworks, one comparison surface.
NIST CSF 2.0, NIST RMF, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, CMMC, and COBIT — the worked examples use the framework the company actually needs.
The DoD's Cybersecurity Maturity Model Certification — the gating posture assessment for defense contractors handling CUI.
Explore →ISACA's governance and management framework for enterprise IT — the language risk and audit committees speak.
Explore →EU data protection. Lawful basis, data subject rights, DPIAs, and the 72-hour breach clock.
Explore →Privacy, Security, and Breach Notification rules for any US entity touching protected health information.
Explore →The international ISMS standard. Annex A controls, certification audits, and the gold-stamp global enterprises ask for.
Explore →A voluntary framework with the six functions Govern, Identify, Protect, Detect, Respond, Recover — language that maps to almost any other standard.
Explore →The federal risk management lifecycle — Categorize, Select, Implement, Assess, Authorize, Monitor — and the playbook most US federal work runs on.
Explore →Cardholder data protection. Twelve requirements, four SAQ levels, and the only one with hard technical mandates.
Explore →Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) — the SaaS default report in the US.
Explore →21 labs. Each one is a real artifact you can show in an interview.
Risk register, 5×5 calibration, ISO 27001 gap analysis, vendor SOC 2 review, executive summary — all with real company briefs and an AI rubric.
Identify, score, and record 8–12 risks for a SaaS company with remote engineers.
Open lab →Build a structured 9-risk register for a mid-size D2C retailer using a guided form with 5×5 scoring and printable output.
Open lab →Write the org-specific likelihood/impact definitions so two analysts score the same risk the same way.
Open lab →Map an existing control set to Annex A and produce a remediation roadmap.
Open lab →Read a SOC 2 Type II and produce a memo on what to trust, what to verify, and which exceptions matter.
Open lab →Translate a 60-page audit report into one page a CFO will actually read.
Open lab →Eight realistic company briefs. Pro users can generate new ones.
Each brief has systems, regulatory exposure, relevant frameworks, risks, control priorities, audit concerns, vendor risk, BCP/DR concerns, and the analyst task to actually do.
North America
US
United States + EU
Global
US
EU
North America + Mexico
APAC
Three tiers. Cancel any time.
The catalog, the briefs, the workbench, manual grading.
- Full roadmap + frameworks
- All 21 labs (you write, save locally)
- Workbench + CSV export
- Job functions + glossary
Billed annually · $239.88/yr
- AI rubric scoring on every lab (sub-scores, strengths, gaps).
- AI company generator — spin up new briefs with one click.
- Full framework walk-throughs (controls, related labs, premium templates).
- Readiness dashboard, tracked achievements, exportable artifacts.
- 200 AI rubric reviews / month.
- Priority email support.
Seats, content cohorts, and team-level reporting.
- Seats across your team
- Cohort progress reporting
- Instructor dashboards
- Priority support
26 concrete analyst responsibilities.
Why it matters, when it is done, inputs and outputs, a beginner example, and the common mistakes — for every job function in the GRC analyst playbook.
Read the 26 job functions →10 templates with seed data + CSV export.
Risk register, control matrix, policy outline, evidence checklist, remediation tracker, issue log, vendor worksheet, executive summary, compliance tracker, control test worksheet.
Open the workbench →Honest answers to the common questions.
Six milestones that map to real GRC analyst behaviors.
First Lab
Submit your first lab answer to start your analyst portfolio.
First Company Analysis
Generate your first AI-created company brief.
Foundations Complete
Complete the first five roadmap stages.
Frameworks Walked
Walk through every framework in the catalog.
Ten Labs Strong
Submit answers across ten distinct labs.
AI Power User
Hit 50 AI calls in a single month.
30 terms you'll hear in every interview.
CIA triad, residual risk, DPIA, RTO/RPO, SIG, TSC, CMMC, KRI — the vocabulary that distinguishes a candidate who has done the prep from one who hasn't.
See all 30 glossary terms →Ready to start your analyst portfolio?
Create an account, take your first lab, and start collecting the artifacts you'll show in interviews.