Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Compliance Cost Estimator

What does getting to an audit actually cost? Compare three routes side by side: doing it in-house on your own staff hours, buying a compliance automation platform, or engaging a firm. Every assumption is on screen and editable, and the answer is a range, never a single number.

Pick the one your buyer or regulator is actually asking for.

More people means more access reviews, more interviews and wider scope for the same control.

A single managed cloud is far less evidence surface than several clouds plus your own hardware.

With nobody owning the programme, more of the writing and chasing has to come from somewhere.

A committed date does not change the work. It compresses it, which costs more per week, not less overall.

Editable estimate for a senior engineer or founder hour, including benefits and overhead. Set it to 0 to see cash cost only.

Frequently required as evidence, and frequently forgotten when people budget. Scope dependent either way.

Do it yourself
$0
first-year total
    Buy a platform
    $0
    first-year total
      Engage a firm
      $0
      first-year total
        The assumptions behind those numbers
        What this suggests
        What this is not

        An indicative planning range built from the figures in how much SOC 2 costs; we confirm scope and price on a call. Most teams that engage a firm still run a platform, which is why tooling appears in every column.

        Not ready for a call yet?

        Get the compliance playbook

        A few short notes from Jacob on getting audit-ready without months of pain, including where the budget actually goes. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

        From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

        Want it done for you?

        SOC 2 readiness

        A fixed-price gap analysis, then remediation and auditor coordination scoped from the gap.

        Explore SOC 2 readiness →

        Want a fixed price instead of a range?

        Bring these numbers to a call. We will scope the work to your actual environment and quote it, so the cost is predictable and your engineers stay on the product. See our pricing for what the firm route looks like here.

        See our pricing Book a free readiness call

        Frequently asked questions

        Why does the do-it-yourself route not come out cheapest?

        Because it prices the hours. Doing it yourself is cheapest on cash out the door, since you only pay the auditor and the tool, but readiness commonly consumes hundreds of hours of founder and senior engineer time, and that time comes off product and revenue. This estimator puts a number on that line instead of leaving it hidden. If you set the internal hourly cost to zero you get the cash-only view.

        Does a compliance platform replace the auditor or the work?

        Neither. A platform such as Vanta or Drata automates evidence collection and control monitoring, which genuinely removes a chunk of manual effort. It does not write your policies, fix your misconfigurations, decide your scope, or issue your report. The report can only come from an independent licensed CPA firm, and someone still has to run the programme that connects the two.

        Where do these ranges come from?

        The cash lines use typical market ranges: roughly ten to forty thousand dollars for the CPA auditor, seven to twenty-five thousand a year for tooling, four to fifteen thousand for a penetration test, and readiness with a firm commonly running a few thousand dollars a month across the programme. The effort model follows the same logic as our quoting engine: a baseline programme length per framework, adjusted for headcount, cloud footprint, whether anyone owns security today, and whether an audit date is already committed.

        Is this a quote?

        No. It is an indicative planning range built from published figures and your own inputs, and it is deliberately shown as a range rather than a number. Scope, effort and price are confirmed on a call, after we have looked at your actual environment.

        Is the estimator free?

        Yes, free with no signup and no payment. It runs entirely in your browser and nothing you type is sent anywhere unless you choose to give us your email for a copy of the result.

        Want the full picture?

        This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

        Start your free assessment See what is in the Workspace

        No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

        Track record

        Who is actually doing the work

        5
        Published CVEs, including a CVSS 9.1
        Zero
        Exceptions on a SOC 2 Type II built from nothing in-house

        Published vulnerability research

        Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

        A SOC 2 Type II built from nothing

        At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.