Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, CCPA/CPRA, and others. Benchmark 93% (with skills) vs 74% (without skills). Updated Monthly.

891Stars on the repository
66Mods indexed here, across every type
6d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

ccpa

01

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 163 tokens together

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) compliance advisor — business threshold analysis, consumer rights fulfillment, ADMT opt-out (Jan 2027 deadline), cybersecurity audits and risk assessments (live Jan 2026), enforcement precedents (Disney $2.75M record), privacy notice…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

cis-controls

02

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 140 tokens together

CIS Controls v8 (CIS Top 18) advisor — Implementation Group scoping (IG1/IG2/IG3), gap assessments across all 153 safeguards, asset/software inventory, data protection, secure configuration, MFA and access control, vulnerability management, audit log management, malware defenses, incident response, penetration testing.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

cmmc

03

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 215 tokens together

Expert CMMC 2.0 compliance advisor for US defense contractors — gap analysis, SSP drafting, POA&M management, SPRS scoring, CUI scoping, and C3PAO assessment readiness for Level 1, 2, and 3.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

csrd

04

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 197 tokens together

EU CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor — scope & threshold analysis (large PIEs, other large, listed SMEs, non-EU), double materiality assessment (DMA), ESRS gap assessment, ESRS E1–E5 environmental disclosures, ESRS S1–S4 social disclosures, ESRS G1 governance, Scope…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

dora

05

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 207 tokens together

DORA (Regulation (EU) 2022/2554) compliance advisor for EU financial entities — ICT risk management framework, incident classification and reporting, TLPT, ICT third-party risk, Register of Information, and all adopted RTS/ITS with article-level citations.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

dpdpa

06

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 204 tokens together

India's Digital Personal Data Protection Act, 2023 (DPDPA) and DPDP Rules, 2025 compliance advisor — gap analysis, notice and consent requirements, Data Principal rights, breach notification, children's data, Significant Data Fiduciary obligations, cross-border transfers, Data Protection Board proceedings, and GDPR…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

ear

07

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 191 tokens together

EAR compliance advisor — ECCN classification, EAR99 determination, EAR vs ITAR jurisdiction, license requirement analysis, all 14 license exceptions, restricted party screening, deemed exports, FDPR, de minimis, 10 General Prohibitions, SNAP-R licensing, VSD, civil/criminal penalties, and Export Compliance Programme…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

eu-ai-act

08

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 266 tokens together

EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5), Annex III high-risk use cases, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations and systemic risk (Arts. 51–55, enforcement Aug 2, 2026), conformity…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

eu-cra

09

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 133 tokens together

Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847. Covers product classification (Default/Class I/Class II), Annex I essential requirements gap analysis, conformity assessment (self-assessment vs Notified Body), CE marking, SBOM, vulnerability handling, 24/72-hour ENISA reporting, support…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

fedramp

10

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 236 tokens together

End-to-end FedRAMP authorization guidance under CR26 — Certification Classes A-D, FedRAMP 20x pathway, readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, OSCAL mandate, and ConMon support.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

ism

13

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 151 tokens together

Expert Australian Information Security Manual (ISM) advisor for Australian government entities, contractors and supply chains. Gap analysis, system authorisation, IRAP preparation, control scoping, and ASD compliance guidance.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

iso27701

15

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 178 tokens together

ISO 27701 Privacy Information Management System (PIMS) advisor — gap analysis, PIMS implementation, Annex A control guidance, SoA generation, privacy risk assessment, GDPR alignment, and certification readiness for ISO/IEC 27701:2025 (standalone PIMS) and 27701:2019.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

iso42001

16

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 173 tokens together

ISO 42001 AI Management System (AIMS) advisor — gap analysis, AI risk assessment, AI system impact assessment (AISIA), Annex A control guidance, SoA generation, policy writing, and certification readiness for ISO/IEC 42001:2023.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

itar

17

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 142 tokens together

Expert ITAR compliance advisor for US defense contractors, exporters, and manufacturers — USML classification, DDTC registration, export license applications (DSP-5/73/94), Technical Assistance Agreements (TAA), Manufacturing License Agreements (MLA), brokering regulations (Part 129), deemed export rules for foreign…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

lgpd

18

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 178 tokens together

Expert LGPD compliance advisor for Brazil's data protection law (Law 13,709/2018). Covers legal bases, data subject rights, ANPD obligations, DPO appointment, breach notification, DPIA, international transfers including Brazil-EU mutual adequacy (January 2026 — no SCCs/BCRs needed for EU transfers), penalties up to 2%.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

nis2

19

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 195 tokens together

EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities — entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 26), gap assessments, policy drafting, ISO…

not rated 891 +14 changed 5d ago A tokens not measured original MIT

nist-800-53

20

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 177 tokens together

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families, Low/Moderate/High baseline selection, FIPS 199/200 categorization, control tailoring, ODVs, overlays, privacy controls (PT family), supply chain (SR family), SSP narrative writing, assessment procedures (SP 800-53A), POA&M management, RMF steps (SP 800.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

nist-ai-rmf

21

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 168 tokens together

Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor — gap assessments, organizational profiles, GOVERN/MAP/MEASURE/MANAGE function guidance, AI risk registers, trustworthiness evaluation, and cross-framework mapping to ISO 42001, EU AI Act, and NIST CSF.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

nist-csf

22

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 171 tokens together

NIST Cybersecurity Framework (CSF 2.0 and 1.1) advisor — gap assessments, organisational profiles, implementation tiers, roadmaps, cross-framework mapping, and cybersecurity policy generation.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

nzism

23

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Plugin Claude Code

Bundles 1 skill · 128 tokens together

Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies. Gap analysis, system certification & accreditation, classification framework guidance, control implementation, and GCSB/NCSC NZ compliance.

not rated 891 +14 changed 5d ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: