TRA Consulting & Tier 1 MX — Southern California & Baja Region

The tools your security team
uses. Free. For everyone.

20+ professional-grade assessment tools covering NIST 800-171, CMMC 2.0, vulnerability remediation, tabletop exercises, AI governance, and more. The same methodology TRA uses on paid engagements — now free, browser-based, and private.

No account required
Zero data sent to any server
Works offline after load
Export PDF & JSON
Compliance Suite
14 Framework Assessment Tools
NIST 800-171, CMMC, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, C-TPAT, LFPDPPP & more
SPRS Scoring POA&M Builder AI Gap Report
Cybersecurity Operations
9 Operational Tools + Tabletop
Vulnerability planner, M365 hygiene, IR readiness, BCP/DRP, ransomware scorecard & tabletop exercises
Nessus CSV 8 Scenarios Remote Session
AI Governance — New
COMPASS Framework
Policy, Integration, Control, Education & Audit. Aligned to NIST AI RMF and ISO/IEC 42001
Employee Use AI Deployer ISO 42001
Document Generator
12 Compliance Documents
SSP, POA&M, WISP + 7 appendices, IRP, BCP/DRP, GenAI Policy, CMMC Self-Assessment & more
PDF Export Word Export Multi-Client

$4.9M

Average breach cost

Global average per incident. Every gap in your assessment is a gap in your defense.

IBM Cost of a Data Breach 2024
207d

Days to detect a breach

Average time to identify a compromise. Unpatched systems are the #1 entry point.

IBM Security 2024
$1.5M

Saved with an IR plan

Average savings per incident when a tested IR plan is in place vs. none.

IBM Cost of a Data Breach 2024

FCA damages multiplier

False Claims Act exposure for a falsely self-reported SPRS score. DIBCAC is actively auditing.

31 U.S.C. § 3729

What you get

Four suites. One methodology. All free.

Every tool runs entirely in your browser. Nothing leaves your device. Export to PDF, JSON, or Word when you're ready to act on the results or bring them to TRA.

Compliance Assessment
14 framework tools in one place
NIST 800-171 with live SPRS scoring. CMMC Level 1 & 2. SOC 2, ISO 27001, CIS v8, HIPAA, PCI DSS v4. GDPR and LFPDPPP for cross-border privacy. C-TPAT for supply chain. The most complete free compliance suite available.
NIST 800-171CMMC L1 & L2SOC 2ISO 27001HIPAAPCI DSSGDPRC-TPAT
Built for: Compliance Managers · Defense Contractors · IT Directors
Go to Compliance Hub →
Cybersecurity Operations
9 tools for your security team
Vulnerability remediation planner for Nessus data. M365 security hygiene checklist. Incident response readiness. BCP/DRP assessment. Ransomware scorecard. Tabletop exercises with remote participant view and AI scenario generation.
Nessus CSVM365 HygieneIR ReadinessBCP/DRPRansomwareTabletop Exercises
Built for: Security Teams · IT Directors · CISOs
Go to Cybersecurity Tools →
Document Generator
12 compliance documents from one profile
Fill in your client profile once. Generate SSP, POA&M, WISP with 7 appendices (IRP, GenAI Policy, BCP/DRP), CMMC Self-Assessment Statement, Vendor Risk Assessment, Attestations for 5 roles, AUP, CUI Policy, and Annual Review Checklist.
SSPPOA&MWISP + 7 appendicesPDF & WordMulti-Client
Built for: Compliance Managers · Contracts & Legal · Auditors
Go to Doc Generator →
AI Governance — COMPASS
Govern your organization's AI use
TRA's five-pillar AI governance framework — Policy, Integration, Control, Education, Audit. Two assessment tracks: Employee AI Use and AI Deployer Organizations. Aligned to NIST AI RMF and ISO/IEC 42001. The fastest-growing compliance category in 2026.
COMPASS EmployeeCOMPASS DeployerISO 42001NIST AI RMF
Built for: HR Directors · Legal Counsel · Compliance Officers
Go to COMPASS →
✨ New in 2026 — Fastest-growing compliance category
Is your organization's AI use governed and defensible?
ChatGPT, Copilot, Gemini — whether it's sanctioned or not, someone in your organization is uploading client data and making business decisions with tools you haven't authorized. COMPASS brings it under policy, control, and audit before it becomes a liability.
Policy Integration Control Education Audit

Found a gap? Let’s close it.
TRA closes what the tools surface.

These tools find the problems. Our team fixes them — assessments, policy development, remediation execution, and audit prep across Southern California and the Baja region. Leave your email and we'll reach out within one business day.

Or call: (562) 551-8872 · No spam, ever.

How it works

Open, assess, export, act.

No setup. No account. Everything runs in your browser and saves locally. Four steps from zero to a defensible compliance posture.

01

Pick your framework

Not sure which applies? The Compliance Hub has a built-in framework finder. Or jump straight to the tool you know you need.

02

Assess each control

Work at your own pace. Mark controls Implemented, Partial, Not Implemented, or N/A. Add notes, owners, and target dates. Progress saves in your browser.

03

Review gaps and score

Your score updates live. For NIST 800-171, SPRS is calculated using DoD weights. For vulnerability work, upload a Nessus CSV and get a phased remediation plan.

04

Generate or call us

Use the Doc Generator to produce your SSP, POA&M, WISP, IRP, and CMMC Self-Assessment. Export as PDF or Word. If the gaps require professional remediation, this is where TRA comes in.


About TRA Consulting & Tier 1 MX

Real practitioners. Not a software company that added a compliance checkbox.

TRA Consulting has been delivering managed IT and consulting services across Southern California since 2000. Tier 1 MX is the cybersecurity practice — hands-on work: assessments, ransomware response, compliance buildouts, and policy development in the US-Mexico border region and beyond.

🛡

Compliance & CMMC / DFARS

System Security Plans, POA&M development, SPRS score remediation, WISP creation, and DIBCAC preparation for defense contractors. We've taken contractors from negative SPRS scores to defensible passing postures.

🔍

Vulnerability Assessment & Pen Testing

Internal vulnerability assessments, external pen testing, phishing-as-a-service, dark web monitoring, and breach response. We run the assessment, build the remediation plan, and can execute it or hand it off.

📄

Incident Response & Policy

IR Plan development, tabletop exercises, WISP and security policy creation, BCP/DRP documentation, and ransomware response. When a client discovered a rogue TOR node installed by their IT administrator, Tier 1 MX was the team that cleaned it up.

20+
Tools available
25+
Years experience
12
Documents generated
0
Data sent to server

Privacy & trust

Zero data leaves your browser. Ever.

🔒

Complete Privacy

Nothing you enter is uploaded or transmitted. All data stays in your own browser's local storage.

Works Offline

Runs entirely client-side. No server dependency after the page loads. Works in a SCIF.

🎯

Professional Grade

Built from the same assessment methodology TRA uses on paid client engagements.

💾

Full Export

JSON, PDF, and Word exports whenever you need to hand off results or bring them to TRA.

The False Claims Act risk is real and underappreciated. Under FCA qui tam provisions, a competitor or former employee can sue a contractor on behalf of the government for a falsely inflated SPRS score. The government gets up to 3× damages. DIBCAC is actively auditing. A completed, documented NIST 800-171 assessment with a defensible POA&M is meaningful protection even if your score isn't perfect.

Does my assessment data ever leave my browser?
No. Every tool runs entirely client-side — nothing you enter is uploaded or transmitted anywhere unless you explicitly turn on the optional Claude AI gap analysis and supply your own API key. Even then, only the control status data you choose to analyze is sent, and it goes directly from your browser to Anthropic's API — never through TRA's servers.
Can I use these tools offline?
Yes. Once a tool page has loaded, you can keep working without an internet connection. You'll only need connectivity again if you choose to run the optional AI-powered report generation, or if you use the Remote Session feature in the Tabletop tool.
Do I need an account to use them?
No account, no sign-up, no email required. Open a tool and start assessing. If you want professional help remediating what you find, that's a separate conversation you initiate.
Are these the same tools TRA uses with clients?
Yes. The assessment methodology, control sets, and scoring formulas are the same ones TRA and Tier 1 MX use on paid client engagements. The difference is that on paid engagements, we're the ones working through the tool with you and building the remediation plan that follows.
What if I find gaps I can't close myself?
That's what TRA is for. The tools surface the problems — our team fixes them. You can reach us at traconsulting.mx, by phone at (562) 551-8872, or by leaving your email in the contact form above.

Ready to close the gaps?

Run the tools. Then let’s talk about what comes next.

These tools surface the gaps. TRA Consulting and Tier 1 MX close them — through assessments, remediation execution, policy development, and audit preparation across Southern California and the Baja region.

Contact TRA Consulting → Browse All Tools
⚠ All tools are for gap assessment only — not a substitute for formal certification, audit, or legal advice. Data stays in your browser. TRA Consulting is not responsible for compliance decisions made based on these tools.