Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

NIST CSF

The NIST Cybersecurity Framework (CSF) is a voluntary framework from the US National Institute of Standards and Technology for organizing and improving a security programme. Version 2.0, released in 2024, is built around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is a structure for describing and maturing security activity, not a certification you pass or fail.

In practice

The usual output of a CSF exercise is two profiles: where you are now and where you intend to be, function by function. The gap between them becomes a prioritised plan, which is more useful to a board than a flat list of missing controls.

Because it is voluntary and unaudited, CSF is only as honest as the assessment behind it. A self-scored profile with nobody testing the claims tends to drift optimistic, which is why it works best alongside hands-on testing and an eventual attestation.

// how traztech helps

traztech delivers a NIST CSF assessment for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

NIST CSF comes up when somebody wants a common vocabulary for security without committing to an audited standard. Boards, insurers and larger customers often ask where you sit against its functions because the language travels well across industries. We map it to real evidence in a NIST CSF assessment.

The addition of Govern in version 2.0 is the practically important change. It moved governance, roles, policy and supply-chain risk from scattered subcategories into a function of its own, which is where most immature programmes are actually weakest.

NIST CSF: common questions

Is NIST CSF a certification?

No. There is no certificate and no accredited body. It is a framework you assess yourself against, often to produce a current-state and target-state profile that drives a roadmap.

How does NIST CSF relate to SOC 2 or ISO 27001?

It complements them. CSF organises and prioritises the work; SOC 2 and ISO 27001 are the audited outcomes buyers ask for. Many companies use CSF internally and map it to the controls their attestation or certificate requires.

What changed in version 2.0?

The headline change is the new Govern function and a broader scope beyond critical infrastructure to organizations of any size and sector, with more emphasis on supply-chain and third-party risk.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.