Free tools, plain-language guides and framework reference. Everything here is free, and none of it needs an account.
Downloads
Thirteen self-scoring workbooks and complete production-ready documents, built to the same standard we deliver to paying clients. The four below are the most used; the rest are on the free tools page.
Eighty questions across all six framework functions. Every control is asked twice: do you do this, and could you prove it today.
DownloadAuto-scoring matrix, likelihood and impact before and after treatment, with a worked example and adaptable scales.
DownloadEight pages. Severity definitions, roles, contact list, the six phases, incident log and after-action record.
DownloadFifteen sections, written to be cut down to your organization rather than adopted whole.
DownloadFree guides
Plain-language explainers, written for the person who has to answer a questionnaire rather than for a security team.
| Guide | What it answers | Status |
|---|---|---|
| Answering a customer security questionnaire | What the forty questions are really asking, and how to answer each with evidence rather than a claim | In preparation |
| Policies vs standards vs procedures vs evidence | Why documentation fails audits, and which layer is missing when it does | In preparation |
| Which framework applies to you | NIST CSF, ISO 27001, SOC 2 and CMMC, and how to tell which one your buyers mean | In preparation |
| What an insurer is really asking at renewal | The controls behind the application questions, and what evidence supports each | In preparation |
Guides are published as they are written. If one of these would be useful now, tell us and we will send a draft.
Framework reference
| Framework | Who asks for it | What we provide |
|---|---|---|
| NIST CSF 2.0 | Boards, insurers, general customer due diligence | The spine of our 242-control assessment, and the Security Program Pack |
| ISO 27001 / 27002 | Overseas customers, tender processes | Crosswalked control set and mapped documentation |
| CIS Controls v8 | Technical reviewers, MSP contracts | Crosswalked control set |
| SOC 2 Trust Services Criteria | US customers of service providers | SOC 2 Readiness Pack and evidence structure |
| CMMC / NIST SP 800-171 | US defense supply chain | Level 1 and Level 2 packs. We prepare; assessment is by an authorized body |
Not sure which applies?
The right framework is usually decided by whoever is asking you for proof. Tell us who that is and we will say which one matters, with the reasoning.