A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →The NIST Cybersecurity Framework (CSF) is a voluntary framework from the US National Institute of Standards and Technology for organizing and improving a security programme. Version 2.0, released in 2024, is built around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is a structure for describing and maturing security activity, not a certification you pass or fail.
The usual output of a CSF exercise is two profiles: where you are now and where you intend to be, function by function. The gap between them becomes a prioritised plan, which is more useful to a board than a flat list of missing controls.
Because it is voluntary and unaudited, CSF is only as honest as the assessment behind it. A self-scored profile with nobody testing the claims tends to drift optimistic, which is why it works best alongside hands-on testing and an eventual attestation.
traztech delivers a NIST CSF assessment for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
NIST CSF comes up when somebody wants a common vocabulary for security without committing to an audited standard. Boards, insurers and larger customers often ask where you sit against its functions because the language travels well across industries. We map it to real evidence in a NIST CSF assessment.
The addition of Govern in version 2.0 is the practically important change. It moved governance, roles, policy and supply-chain risk from scattered subcategories into a function of its own, which is where most immature programmes are actually weakest.
No. There is no certificate and no accredited body. It is a framework you assess yourself against, often to produce a current-state and target-state profile that drives a roadmap.
It complements them. CSF organises and prioritises the work; SOC 2 and ISO 27001 are the audited outcomes buyers ask for. Many companies use CSF internally and map it to the controls their attestation or certificate requires.
The headline change is the new Govern function and a broader scope beyond critical infrastructure to organizations of any size and sector, with more emphasis on supply-chain and third-party risk.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.