TRA Consulting — Free Compliance Tools

14 frameworks.
One place.
No account.

From NIST 800-171 and CMMC for defense contractors, to GDPR for EU data privacy, to COMPASS for AI governance — the most complete free compliance assessment suite available anywhere.

14
Frameworks covered
NIST, CMMC, SOC 2, ISO 27001, CIS v8, HIPAA, PCI DSS, GDPR, LFPDPPP, C-TPAT, COMPASS AI & more
600+
Total controls
Across all frameworks combined — each with real implementation guidance, not just checkbox descriptions
0
Data sent to any server
Everything stays in your browser. Export JSON or PDF when you're ready to act on the results

Not sure which framework applies?

3-question finder

🎯 Framework Finder

Answer 3 questions and we'll recommend the right tool for your situation.

All 14 compliance tools

14 frameworks  —  600+ controls
The problem
Your SPRS score is self-reported and DIBCAC is coming to verify it.
NIST SP 800-171 Assessment
110 controls across 14 families (Rev 2) and 97 controls (Rev 3). Live SPRS score calculation using DoD weighting. POA&M builder with target dates and owners. The foundation for every CMMC and defense contract engagement.
110 controls Rev 297 controls Rev 3Live SPRS scorePOA&M builderDFARS
The problem
Your contract requires CMMC Level 1 and you need to document it.
CMMC 2.0 Level 1 Assessment
17 practices across 6 domains — the foundational tier for Federal Contract Information (FCI). Covers basic safeguarding requirements for contractors who don't handle CUI but still need to demonstrate CMMC compliance.
17 practices6 domainsFCI scopeAnnual self-assessment
The problem
You need a C3PAO assessment and can't afford to walk in unprepared.
CMMC 2.0 Level 2 Readiness
All 110 NIST SP 800-171 Rev 2 practices mapped to CMMC Level 2. Live SPRS score with DoD weighting. POA&M builder with target dates. Designed to surface every gap before a C3PAO assessment — because failing costs $30K–$80K and you pay again.
110 practicesLive SPRSPOA&M builderC3PAO prepCUI scope
The problem
Your enterprise prospects are asking for a SOC 2 report and you don't have one.
SOC 2 Readiness Assessment
58 criteria across 5 Trust Service Categories — Security, Availability, Processing Integrity, Confidentiality, and Privacy. Designed to identify gaps before engaging an auditor for your Type I or Type II report.
5 TSCs58 criteriaType I / II prepGap report
The problem
You need a prioritized security roadmap that's actually actionable.
CIS Controls v8 Assessment
154 Safeguards across 18 Controls with Implementation Group tiering (IG1/IG2/IG3). CIS Controls are the most practical, prioritized baseline in cybersecurity — start with IG1 and you'll stop the majority of attacks.
18 controls154 safeguardsIG1/IG2/IG3Prioritized roadmap
The problem
Your international clients and contracts require ISO 27001 certification.
ISO/IEC 27001:2022 Assessment
Clauses 4–10 plus all 93 Annex A controls organized by the 2022 structure. Measures your readiness for formal ISO 27001 certification — and doubles as the control baseline for ISO 42001 AI governance work.
Clauses 4–1093 Annex A controls2022 structureCert readiness
The problem
Leadership wants a cybersecurity posture report they can actually understand.
NIST CSF 2.0 Assessment
106 subcategories across 6 functions — Govern, Identify, Protect, Detect, Respond, and Recover. The 2024 update adds Govern as a core function for the first time. The most widely used cybersecurity framework for board-level risk communication.
6 functions106 subcategoriesCSF 2.0Board-ready report
The problem
A breach or OCR audit would expose exactly what safeguards you don't have.
HIPAA Security & Privacy Assessment
Full Security Rule (Administrative, Physical, Technical Safeguards), Privacy Rule, and Breach Notification Rule. Covers both Covered Entities and Business Associates. Built for healthcare organizations who need to demonstrate defensible compliance, not just check a box.
Security RulePrivacy RuleBreach NotificationCE & BA
The problem
You take card payments and have no idea where you stand against PCI DSS v4.
PCI DSS v4.0 Assessment
12 requirements covering network security, cardholder data protection, access control, monitoring, and testing. PCI DSS v4.0 introduced significant new requirements in 2024. Use this to identify gaps before your Qualified Security Assessor engagement.
12 requirementsv4.0SAQ A/B/DQSA prep
The problem
You handle EU personal data and haven't mapped your GDPR compliance posture.
GDPR Compliance Assessment
52 controls across 9 categories covering lawful basis, data subject rights, consent management, DPO requirements, data transfers, breach notification, and DPA article obligations. Built for organizations processing EU personal data under the GDPR.
52 controls9 categoriesData subject rightsDPA mapping
El problema
Manejas datos personales de mexicanos y no tienes un inventario de cumplimiento con la LFPDPPP.
LFPDPPP — Ley Federal de Protección de Datos Personales
Evaluación completa para Responsable y Encargado. Interfaz completamente bilingüe (ES/EN). Cubre aviso de privacidad, derechos ARCO, medidas de seguridad, transferencias de datos, y cumplimiento con INAI. Full bilingual interface — Español / English.
ResponsableEncargado🇲🇽 ES / 🇺🇸 ENINAI
The problem
A CBP suspension would halt your cross-border shipments with no warning.
C-TPAT Supply Chain Security Assessment
110 minimum security criteria across 12 categories for Highway Carriers (HC) and Mexican Long Haul Highway Carriers (MLHC). Full CBP implementation guidance shown inline — built to teach, not just check a box. TRA-EXCLUSIVE tool unavailable anywhere else.
110 criteria12 categoriesHC & MLHCCBP guidanceTRA-EXCLUSIVE
The problem
You have a Nessus scan with 3,000 findings and no idea where to start.
Vulnerability Remediation Tracker
Import Nessus scans (CSV or XML), track remediation by host and phase, assign owners and target dates, and get a phased remediation plan sorted by risk. Multi-client with Claude AI advisor scoped to your data.
Nessus CSV/XMLPhase 1/2/3 planHost exposureAI advisorXLSX export
New tool
You have the assessment. Now you need the actual documents.
NIST 800-171 Document Generator
Fill in your client profile once and generate 12 professional compliance documents: SSP, POA&M, WISP (with 7 appendices including IRP, GenAI Policy & BCP/DRP), CMMC Self-Assessment Statement, Vendor Risk Assessment, Attestations, AUP, CUI Policy, and Annual Review Checklist. Pulls data from the NIST assessment tool automatically.
12 documents SSP & POA&M WISP + 7 appendices PDF & Word
✨ AI Governance — Fastest-growing compliance category 2026
COMPASS — TRA's AI Governance Framework
Two assessment tracks: Employee AI Use (43 criteria across PICEA pillars) and AI Deployer Organizations (38 criteria, NIST AI RMF + ISO/IEC 42001). Before an unmanaged AI tool becomes a liability nobody saw coming.
COMPASS Employee Use COMPASS Deployer ISO/IEC 42001 NIST AI RMF 43 + 38 criteria

What every tool includes

🤖
AI Gap Analysis
Claude-powered gap analysis and prioritized remediation roadmaps. Objective and Expert Opinion modes. Your own API key — never sent through TRA servers.
📄
PDF Reports
Formatted multi-page reports with cover page, executive summary, gap tables, evidence columns, score history, and sign-off block.
👥
Multi-Client
Separate profiles per organization. Each with its own data, score history, notes, and settings. Export/import JSON for backup or transfer.
🔒
100% Private
All assessment data stored in your browser only. Nothing sent to any server. Works fully offline after the first page load.

Framework coverage matrix

✓ Covered  ◐ Partial  — N/A
Topic Area
NIST 171
CMMC L1
SOC 2
CIS v8
ISO 27001
CSF 2.0
HIPAA
PCI DSS
GDPR
LFPDPPP
C-TPAT
COMPASS

Need expert guidance?

TRA closes what the tools surface.

These tools find the gaps. Our team helps you close them — with assessment services, policy development, remediation support, and audit preparation across Southern California and the Baja region.

Get in Touch → Cybersecurity Tools
⚠ All tools are for internal gap analysis only — not a substitute for formal certification, audit, or legal advice. Data stays in your browser. TRA Consulting is not responsible for compliance decisions made based on these tools.