Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Free SOC 2 Self-Assessment Tools

Direct answer: A SOC 2 self-assessment is you walking the Trust Services Criteria and recording, honestly, whether each control is in place at your company. It is free to do, it is the correct first step, and it is not a gap analysis. A self-assessment records what you believe. A gap analysis is somebody independent testing whether that belief survives contact with your systems and your auditor.

What you get from a free self-assessment

  • Real scope. How many controls apply to you, and which ones you have never thought about.
  • A budget conversation. A count of what is missing is what makes an internal budget request concrete.
  • A starting evidence list. Every control names the artefacts it expects.
  • An honest baseline. Answering "not in place" forty times is uncomfortable and useful.

What it does not give you

It does not tell you whether your answers are right. You can mark a control in place because you have MFA on email, while the auditor is asking about MFA on the production console. That distinction is the whole job of a gap analysis, and it is the reason a self-assessment score is not a readiness score.

The options

traztech Workspace

Free, no card, no trial clock. All 61 SOC 2 criteria in plain English with what the standard asks for and what to do about it, an evidence register that maps one artefact to every control needing it, policy templates, a risk register, vendor records, and a security testing register. It flags controls you answered "in place" with nothing collected against them, which is the most common way a self-assessment flatters itself. We build it, so check it yourself.

Vendor readiness quizzes

Most compliance platforms offer a short free readiness quiz. Useful for a rough sense of scale, but they are lead capture and they stop well short of the full criteria.

The AICPA criteria themselves

The Trust Services Criteria are published. Free, authoritative, and written for practitioners rather than founders, which is why most people want a plain-English layer over them.

A spreadsheet

Genuinely viable, and plenty of companies have passed with one. You lose control mapping across frameworks and the evidence links, and you own the maintenance.

What to do after

Once you know the real count, there are three honest options: fix it yourself if the list is short and technical, hire a prep partner if it is long or you have a deadline, or wait if no customer is actually asking. The point of doing the assessment first is that you can now tell which of the three you are in.

Frequently asked

Is a self-assessment worth anything to a customer?

Not as assurance. It is for you. Customers want the report from an independent CPA firm.

How long does one take?

A focused pass over the SOC 2 criteria is a few hours if you know your environment. Chasing the answers you do not know takes longer, and that is the useful part.

Does a free assessment expire?

Your answers go stale as your systems change. Re-run it before an audit and after any significant change.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation