Palette Tools

Smart tools for faster framework alignment

Free self-assessment tools from Palette Technologies. Find out where your security posture actually stands before someone else does it for you.

How it works

Step 1

Pick your framework

NIST CSF 2.0, HIPAA, SOC 2 Type II or ISO 27001 — whichever your customers, insurer or regulator asks about.

Step 2

Answer honestly

Targeted questions grouped by domain, weighted by how much each control actually matters. Roughly fifteen minutes.

Step 3

Read your baseline

Domain scores, letter grades and a ranked list of what to fix first — rendered in your browser, and yours to print.

The GRC Assessment Tool

82 weighted questions across four frameworks, scored by domain, with a ranked remediation list at the end. It runs entirely in your browser — there is no account to create, and nothing you type is sent anywhere.

NIST CSF 2.0

All SMBs, cyber insurance, vendor relationships

25 questions

HIPAA

Healthcare providers, health IT, business associates

15 questions

SOC 2 Type II

SaaS companies, MSPs, cloud services, B2B tech vendors

21 questions

ISO 27001

International recognition, enterprise sales, global operations

21 questions

A self-assessment is a starting point, not an audit

The tool scores what you tell it. When you need the other thing — 200 to 400 control tests, evidence collection, gap analysis and an audit-ready report package — that is an engagement with our team.

Talk to Palette