Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Framework readiness

NIST CSF Assessment

From $2,500 CAD · scoped to you

The NIST Cybersecurity Framework (CSF) 2.0 is a widely used, voluntary framework for organizing and improving a security program. It is not a certification but a common yardstick that buyers, insurers, and boards understand.

Book a discovery call See pricing

We assess your program against all six Functions and hand you a clear, prioritized picture of where you stand and what to fix first.

We have scoped ISO 27001:2022 and SOC 2 Type II together for a data centre operator: how that engagement was scoped.

What we do

Assessment across all six CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, Recover
Current-state maturity rating for each Function and category
Gap analysis against your target profile and risk appetite
Prioritized, cost-aware remediation roadmap you can actually execute
Mapping from CSF findings to SOC 2 or ISO 27001 where relevant
Executive summary suitable for boards, insurers, and enterprise buyers

Built for teams that...

  • Startups and SMEs that want a structured baseline of their security posture
  • Teams whose customers or insurers ask for a NIST CSF-aligned assessment
  • Leaders who need a board- or investor-ready view of security maturity
  • Organizations preparing for SOC 2 or ISO 27001 that want a starting map

What you walk away with

You get an honest, structured read on your security program across the six CSF Functions and a roadmap that tells you what to do first. Because CSF 2.0 added the Govern Function, the assessment also surfaces where security ownership and accountability are missing, which is often the real gap behind the technical ones.

Explore related work

The workspace is included, not quoted

The price above covers the work. It also covers where the work lives, which most buyers are quoted separately as an annual platform subscription.

traztech Workspace Other GRC platforms
Licence cost $0. Free forever, no card, no paid tier $7,500 to $50,000 a year, on an annual contract
Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring Included Included
What it costs inside an engagement with us $0. You need a workspace either way Unchanged. The subscription sits on top of the fee
What it does to your audit quote A documented readiness position the audit firm can scope and price against Nothing. The audit firm prices your readiness, not your tooling

Platform pricing is a publicly reported range, since none of them publish a number. The fuller comparison, including when a paid platform is the better buy, is on the Workspace page.

Frequently asked questions

What are the six Functions of NIST CSF 2.0?

CSF 2.0 organizes cybersecurity into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in version 2.0 to emphasize organizational context, roles, and risk-management strategy alongside the original five.

Is NIST CSF a certification?

No. NIST CSF is a voluntary framework for organizing a security program, not a certifiable standard. There is no official CSF certificate. It is valuable as a shared language and a baseline that maps cleanly to frameworks you can certify against.

How is a CSF assessment different from SOC 2 or ISO 27001?

A CSF assessment measures the maturity of your program and produces a roadmap; SOC 2 and ISO 27001 are formal attestations or certifications with auditors. A CSF assessment is often the best first step before committing to either one.

Who should see the results?

The findings work at two levels: a detailed roadmap for your technical team and an executive summary for boards, investors, or insurers. We produce both so the assessment is useful for decisions, not just documentation.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

NIST CSF Assessment, on your timeline

Book a free 30-minute call, or send an inquiry. We’ll tell you whether it fits, what it costs, and when we can start.

Book a call Send an inquiry