Palette Tools
Smart tools for faster framework alignment
Free self-assessment tools from Palette Technologies. Find out where your security posture actually stands before someone else does it for you.
How it works
Step 1
Pick your framework
NIST CSF 2.0, HIPAA, SOC 2 Type II or ISO 27001 — whichever your customers, insurer or regulator asks about.
Step 2
Answer honestly
Targeted questions grouped by domain, weighted by how much each control actually matters. Roughly fifteen minutes.
Step 3
Read your baseline
Domain scores, letter grades and a ranked list of what to fix first — rendered in your browser, and yours to print.
The GRC Assessment Tool
82 weighted questions across four frameworks, scored by domain, with a ranked remediation list at the end. It runs entirely in your browser — there is no account to create, and nothing you type is sent anywhere.
NIST CSF 2.0
All SMBs, cyber insurance, vendor relationships
25 questions
HIPAA
Healthcare providers, health IT, business associates
15 questions
SOC 2 Type II
SaaS companies, MSPs, cloud services, B2B tech vendors
21 questions
ISO 27001
International recognition, enterprise sales, global operations
21 questions
A self-assessment is a starting point, not an audit
The tool scores what you tell it. When you need the other thing — 200 to 400 control tests, evidence collection, gap analysis and an audit-ready report package — that is an engagement with our team.
Talk to Palette