← Back to GRC Skills

Benchmark Results

Side-by-side evaluation of Claude with and without GRC Skills across 150 real-world compliance scenarios for all 30 skills. Raw grading artifacts for every published number are committed under grc-workspace/ in the repository.

94%
With Skill
81%
Baseline (No Skill)
+13%
Improvement
752
Total Assertions
+93
Extra Assertions Passed

July 2026 re-run: FedRAMP, SWIFT CSP, NIS2 and LGPD were re-evaluated with independently authored, primary-source assertions (FedRAMP NTC-0004, SWIFT CSCF v2026, Directive (EU) 2022/2555, LGPD/ANPD resolutions). Raw grading artifacts: grc-workspace/rerun-2026-07/. Accordion transcripts for these four skills below are from the earlier iteration. v1.6.0 re-run: eight further skills (NIS2 after expansion, EU AI Act, CCPA/CPRA, CMMC 2.0, NIST AI RMF, NZISM, VN-PDPL, EU CRA) were re-evaluated the same way; artifacts in grc-workspace/rerun-2026-07b/. All four previously-negative skills were revised against their failure patterns and re-run in July 2026 (artifacts in grc-workspace/rerun-2026-07c/); every skill now scores at or above baseline.

Results by Skill

# Skill With Skill Baseline Delta Assertions Passed
1 ISO 27001 100% 84% +16% 25/25
2 SOC 2 100% 84% +16% 25/25
3 FedRAMP 92% 84% +8% 23/25
4 GDPR 88% 88% +0% 22/25
5 HIPAA 92% 88% +4% 23/25
6 NIST CSF 96% 84% +12% 24/25
7 PCI DSS 92% 88% +4% 23/25
8 TSA Cybersecurity 100% 96% +4% 25/25
9 ISO 42001 92% 80% +12% 23/25
10 ISO 27701 100% 100% +0% 25/25
11 DORA 88% 72% +16% 22/25
12 DPDPA 96% 80% +16% 24/25
13 CMMC 2.0 88% 80% +8% 22/25
14 NIST AI RMF 92% 84% +8% 23/25
15 SWIFT CSP 96% 72% +24% 24/25
16 ISM 96% 52% +44% 24/25
17 NIS2 100% 84% +16% 25/25
18 CCPA/CPRA 100% 80% +20% 25/25
19 ITAR 100% 100% +0% 25/25
20 LGPD 76% 76% +0% 19/25
21 CSRD 100% 72% +28% 25/25
22 CIS Controls v8 100% 80% +20% 25/25
23 EAR 100% 88% +12% 25/25
24 NIST SP 800-53 92% 84% +8% 23/25
25 EU AI Act 92% 72% +20% 23/25
26 Section 508 100% 100% +0% 25/25
27 WCAG 100% 85% +15% 27/27
28 NZISM 96% 64% +32% 24/25
29 VN-PDPL 68% 60% +8% 17/25
30 EU CRA 80% 80% +0% 20/25

Methodology

Each skill was evaluated on 5 real-world compliance scenarios submitted by compliance professionals and software teams. Every test case ran twice — once with the skill active, once as a baseline without it. Responses were graded against 5 objective assertions per test (keyword presence, structural completeness, specific regulatory citations).

Browse Outputs

Expand any skill to see the actual responses side-by-side for each test case.