Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Rate your cybersecurity maturity across all six NIST Cybersecurity Framework 2.0 Functions. Get an implementation tier, a per-function breakdown, and the weakest functions to prioritize.
NIST CSF 2.0 organizes cybersecurity outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in the 2.0 release and sits at the center, covering strategy, roles, policy, and oversight.
The framework describes four tiers that characterize the rigor of your cybersecurity risk governance and management practices: Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable, and Tier 4 Adaptive. Tiers describe how you manage risk, not a grade or certification.
No. The Cybersecurity Framework is a voluntary framework for organizing and improving your cybersecurity program. There is no official CSF certification, though many organizations use it to structure their program and report maturity to leadership and customers.
Yes, it is free with no signup and nothing you rate is sent anywhere. If you want help building a target profile and closing the gaps, our team can run a full CSF assessment with you.
Not ready for a call yet?
A few short notes from Jacob on maturing a cybersecurity program with NIST CSF. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
Fractional CISO
We run a full CSF assessment and build your target profile and roadmap.
Explore Fractional CISO →We run a full NIST CSF 2.0 assessment, define your target profile, and build the roadmap to close the gaps across all six Functions. Turn this snapshot into a plan.
Talk to a Fractional CISO Book a callThis gives you the shape of the problem. The full picture is all 106 subcategories of NIST CSF 2.0, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.