Everything about this sub-market is easy, and that is the problem.
The labour is the cheapest of the eight: $97,659/yr, $46.95/hr, median $82,100 (ZipRecruiter, Aug 2026). The pool is the largest and the most reachable: ISACA has 185,000 members across 188 countries and 225 chapters, and ISC2 has 270,000+ certified members. And unlike every other page in this dossier, there is a live, confirmed, currently-open buyer with a published rate.
There is also no verifier, no benchmark, and a lab that has written into a job advert that it intends to automate this function with Codex.
What the artefact is
A control framework plus a system description in; control mapping, evidence assessment, gap analysis, policy language and a risk decision out.
But the product Mercor is actually buying is narrower and more interesting than that, and the listing says so outright. It wants contributors to "design cybersecurity scenarios, draft reference outputs, and write rubrics that capture how senior security leaders think", and specifically to "author rubrics that distinguish authentic security judgment from generic textbook or certification-exam-level recall" (listing).
Rubrics, not labels. That is the only sellable artefact available where no verifier exists: if you cannot check the answer, you sell the scoring instrument. What you can actually sell makes the general case; this is its purest instance.
The licence position constrains what the rubric can quote. NIST frameworks are US-government work and free. ISO 27001 is a paid, copyrighted standard and cannot be redistributed. SOC 2 Trust Services Criteria are AICPA copyright. CIS Benchmarks are Creative Commons but the variant could not be established — if it is NonCommercial, commercial use is barred. You can write about the controls; you cannot ship the text. See The terms of service bite first.
Is there a verifier
No. This is the defining fact of the sub-market and everything else follows from it.
GRC's unit of work is a judgement about sufficiency: is this evidence adequate for this control, is this risk acceptance defensible, does this policy language satisfy this clause. There is no execution, no crash, no flag, no compile. The 2026 literature confirms the absence rather than filling it.
- Compliance mapping as retrieval. A study built 3,499 semantic pairs from five European security standards, expanded to 13,996 samples by back-translation and paraphrasing, fine-tuned five sentence-transformer architectures and reached 0.870 nDCG@10 on cross-standard control association, with up to +23 nDCG@10 points on control-to-metric mapping (arXiv 2607.06364). Real work — and retrieval, not judgement. Note the corpus size: 3,499 hand-built pairs is a small, tractable annotation job, which is precisely why the labour is cheap.
- OSCAL artefact generation. An MCP-grounded multi-agent pipeline converts natural-language system descriptions into NIST System Security Plans and Security Assessment Reports, reaching 0.90 CVE recall and perfect D3FEND recall on a synthetic water-utility scenario. The authors' own conclusion is that grounding "shifts errors into the first phase of asset extraction", where "a single incorrectly extracted entity can lead to genuine but irrelevant CVEs", leaving risk "visible, verifiable, and suitable for a time-efficient manual review" (arXiv 2607.08288). The success condition is that a human still checks it.
- The nearest thing to a GRC benchmark is a code-compliance study: three frontier models across four use cases — S3 CLI, auth service, RDS Terraform module, file-upload handler — with 24 outputs scored against binary rubrics mapped to specific SOC 2 Trust Services Criteria. Unprompted conformance ran 47–88%; adding one SOC 2 sentence moved every case to 86–100%, worth 23 to 50 points, and removed every insecure construction (arXiv 2608.07776).
That last paper contains the whole sub-market in one clause: "the pattern-matching scorer proved unreliable, disagreeing with semantic grading on 27 of 216 judgments and passing a real defect."
Even in the most mechanisable corner of GRC — checking whether generated code turns encryption on — the automated scorer failed on 12.5% of judgements and let a real defect through. Defense scores 1. GRC is a human-graded discipline, it will stay one, and a human-graded discipline with cheap labour and no scarcity has no moat.
Is anyone buying
Budget scores 4, the joint-highest defensive score in the dossier, and it is earned by one live URL.
Mercor's Cybersecurity Expert listing is open right now at $80–90/hr, posted 5 August 2026 and still accepting applications as of 30 August. It runs two tracks — a US track covering the NIST Cybersecurity Framework and SOC 2, and an International track covering ISO 27001 and the EU NIS2 Directive. Forty hours a week, weekly payment through Stripe or Wise, independent contractor, no H-1B or STEM OPT.
Its bar is unusually high for the rate: "5+ years working as a security engineer or CISO at a major company or security firm (Mandiant, CrowdStrike, or an in-house CISO/security lead)", direct ownership of incident response programmes, security architecture or compliance initiatives, and "a recognized professional credential is strongly preferred (CISSP, CISM, or an international equivalent); prior rubric or training authorship is a plus."
Lab-side hiring corroborates the demand and prices it internally:
| Buyer | Role | Band |
|---|---|---|
| OpenAI | Cybersecurity & Technology Audit Leader | $342K – $380K |
| OpenAI | GRC Program Manager, Assurance Engineering & Control Systems | $216K – $252K |
| Anthropic | Security Controls Assurance Lead | $270,000 – $345,000 |
| Anthropic | Safeguards Policy Analyst, Cyber Harms | $190,000 – $285,000 |
| Scale AI | Security Assurance Lead; Program Manager, Compliance | not disclosed |
The $216K–$252K OpenAI GRC band is the lowest security band found at either frontier lab — GRC is the cheapest tier internally as well as externally. And the same posting says its holder will "build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks… Use Codex to build and test evidence checks."
An OpenAI GRC posting states, as a job responsibility, that the work will be automated with OpenAI's own coding agent. That is not a competitive inference drawn from a trend line; it is the buyer describing its intent in a document it wrote. Any long-run value in GRC evaluation data has to be argued around that sentence.
What the expert costs
Cost scores 5, the cheapest pilot of the eight. Arbitrage runs 1.7–1.9x on the mean and 2.1–2.3x on the median of $82,100. No infrastructure, no corpus to license, no estate to run, no scanner, no binaries. Twenty credentialed practitioners, a framework spec and a rubric template.
The 3,499-pair European standards corpus is the scale reference: a tractable annotation job, not a five-thousand-hour build. Compare Malware reverse engineering at roughly 19 expert-hours per instance. That difference is the ranking. See Paying the crowd.
Getting to them
Reach scores 5, and this is the best-evidenced reach in the whole security dossier.
ISACA — 185,000 members across 188 countries and 225 chapters, working in "information security, governance, assurance, risk, privacy and quality", with CISA, CISM, CRISC, CGEIT, CDPSE and CMMC assessor credentials. This is the single largest addressable, chaptered, verifiable register anywhere in this research, and the chapter structure makes it geographically reachable — you can run a room in a named city next month.
ISC2 — 270,000+ certified members; CISSP is the credential Mercor names. GIAC's Management, Legal and Audit focus area sits inside 290,000+ certifications issued. Big-4 and audit-firm alumni networks are the obvious fourth channel [UNVERIFIED — no register].
Where the benchmarks sit
There is no GRC benchmark. That absence is the most important entry in the table.
| Nearest proxy | Scale | Result |
|---|---|---|
| SOC 2 code conformance | 3 models, 4 use cases, 24 outputs, 216 judgements | 47–88% unprompted → 86–100% with one SOC 2 sentence; scorer wrong on 27/216 |
| Cross-standard control mapping | 3,499 pairs → 13,996 samples, 5 architectures | 0.870 nDCG@10; +23 points on control-to-metric |
| OSCAL SSP/SAR generation | Synthetic water-utility scenario | 0.90 CVE recall, perfect D3FEND recall — errors displaced into asset extraction |
Proof scores 2: with no scoreboard, "visibly the best source" has nothing to be visible against. You cannot publish a win. Compare The measurement gap, where every other sub-market has a public number to beat.
What would kill it
Codex, by the buyer's own account. See the warning above.
Anyone can do this tomorrow. Cheapest labour, largest pool, no verifier to build, no corpus to license, no infrastructure. Every barrier that protects Malware reverse engineering is absent here. Room scores 2 because Mercor is already in the position and nothing stops the next entrant.
The standards are copyrighted. ISO 27001 and the SOC 2 Trust Services Criteria cannot be redistributed, so the corpus you build is a corpus of paraphrase and judgement — thinner than it looks, and harder to defend if the standards bodies ever take an interest.
Where the record is thin
Mercor's client is undisclosed, as it is on every Mercor cyber listing, so the demand is intermediary-observed rather than lab-disclosed. No GRC evaluation dataset has been observed changing hands at any price. And ISACA's and ISC2's figures are first-party membership counts, not counts of people willing to do contract work — the conversion rate from 185,000 members to a working cohort is unknown and probably small.
Include GRC as a volume service line and a beachhead into a buyer relationship. Do not build the company on it. The ranked read is at The security read; the shape that survives is at The one shape that survives.