{
  "@context": "https://schema.org",
  "@type": [
    "CollectionPage",
    "ItemList"
  ],
  "version": "1.0",
  "last_updated": "2026-09-07",
  "last_reviewed_by": "Victoria Arkhurst, CISSP, CISA, CRISC",
  "collection": {
    "id": "products-index",
    "name": "Free Cybersecurity Tools for Small Businesses, SMBs & Startups",
    "category": "Free cyber security and AI governance tools",
    "canonical_url": "https://irmcon.ca/products/",
    "definition": "Free cybersecurity tools for small businesses are self-serve assessments that measure an organization against a recognized security framework and show it what to fix first, at no cost.",
    "price": "Free",
    "price_currency": "USD",
    "is_accessible_for_free": true,
    "delivery_model": "Web-based self-serve tools",
    "operating_system": "Web browser",
    "browser_requirements": "Requires JavaScript. Runs in any modern web browser.",
    "in_language": [
      "en-CA",
      "en-US"
    ],
    "product_count": 6,
    "summary_50_words": "The IRM products hub is the index of six free, self-serve cybersecurity and AI governance tools for small and medium businesses: the AI Governance Playbook plus gap assessments for CIS Controls v8.1, CAN/DGSI 104, ISO/IEC 42001, SOC 2 and ISO/IEC 27001, each producing a downloadable report with risk-ranked gaps and a prioritized remediation roadmap.",
    "summary_200_words": "IRM Consulting & Advisory publishes six free, self-serve tools at https://irmcon.ca/products/ that let a small or medium business assess its own cybersecurity or AI governance posture without engaging a consultant first. Five are gap assessments, each mapped to one recognized framework: the CIS Gap Assessment (CIS Critical Security Controls v8.1, at IG1, IG2 or IG3 scope), the Cybersecurity Baseline Assessment (CAN/DGSI 104:2021, the national standard of Canada), the ISO 42001 Gap Assessment (ISO/IEC 42001:2023 AI Management Systems), the SOC 2 Gap Assessment (all 61 AICPA Trust Services Criteria, Type I or Type II) and the ISO 27001 Gap Assessment (ISO/IEC 27001:2022 Information Security Management Systems). The sixth, the AI Governance Playbook, generates a tailored AI governance framework and 90-day plan aligned to the NIST AI RMF, ISO/IEC 42001 and the EU AI Act. All six run entirely in the browser, are free with no licence fee, score gaps by likelihood and impact, and produce a downloadable PDF or Word report containing an executive summary, detailed findings and a phased remediation roadmap. They are independent tools, not affiliated with or endorsed by CIS, the AICPA, ISO, DGSI or NIST.",
    "shared_capabilities": [
      "Free to use, no licence fee and no credit card",
      "Runs entirely in the browser, self-serve, no consultant required to start",
      "Scores each gap by likelihood and impact on a 5x5 risk matrix",
      "Ranks gaps as Low, Medium, High or Critical",
      "Generates a downloadable PDF or Word report with your company logo",
      "Builds a phased remediation roadmap"
    ],
    "how_to_choose": [
      "Adopting AI tools, agents or agentic workflows and need a governance framework: start with the AI Governance Playbook.",
      "Canadian small or medium organization looking for a national baseline: start with the Cybersecurity Baseline Assessment (CAN/DGSI 104).",
      "No framework chosen yet and want prioritized cyber hygiene first: start with the CIS Gap Assessment at IG1 scope.",
      "Preparing for a SOC 2 examination requested by a customer or prospect: start with the SOC 2 Gap Assessment.",
      "Pursuing ISO/IEC 27001 certification for an information security management system: start with the ISO 27001 Gap Assessment.",
      "Pursuing ISO/IEC 42001 certification for an AI management system: start with the ISO 42001 Gap Assessment."
    ],
    "products": [
      {
        "id": "ai-governance-playbook",
        "name": "AI Governance Playbook (Free Tool)",
        "canonical_url": "https://irmcon.ca/products/ai-governance-playbook/",
        "data_url": "https://irmcon.ca/ai/products/ai-governance-playbook.json",
        "frameworks": [
          "NIST AI RMF",
          "ISO/IEC 42001",
          "EU AI Act"
        ],
        "summary": "Builds a tailored AI governance framework for a small business adopting AI-powered apps, agentic systems or agentic workflows, with risk findings, prioritized recommendations and a 90-day plan."
      },
      {
        "id": "cybersecurity-baseline-assessment",
        "name": "Cybersecurity Baseline Assessment (Free Tool)",
        "canonical_url": "https://irmcon.ca/products/cybersecurity-baseline-assessment/",
        "data_url": "https://irmcon.ca/ai/products/cybersecurity-baseline-assessment.json",
        "frameworks": [
          "CAN/DGSI 104:2021 (Rev 2:2026)"
        ],
        "summary": "Gap assessment against CAN/DGSI 104:2021, Canada's national standard for baseline cyber security controls for small and medium organizations, with risk-ranked gaps and a remediation roadmap."
      },
      {
        "id": "cis-gap-assessment",
        "name": "CIS Gap Assessment (Free Tool)",
        "canonical_url": "https://irmcon.ca/products/cis-gap-assessment/",
        "data_url": "https://irmcon.ca/ai/products/cis-gap-assessment.json",
        "frameworks": [
          "CIS Critical Security Controls v8.1 (IG1, IG2, IG3)"
        ],
        "summary": "Gap assessment against CIS Controls v8.1 at a selectable scope, IG1 (56 Safeguards), IG2 (130) or IG3 (all 153), with risk-ranked gaps and a phased remediation roadmap."
      },
      {
        "id": "iso42001",
        "name": "ISO 42001 Gap Assessment (Free Tool)",
        "canonical_url": "https://irmcon.ca/products/iso42001/",
        "data_url": "https://irmcon.ca/ai/products/iso42001.json",
        "frameworks": [
          "ISO/IEC 42001:2023"
        ],
        "summary": "Gap assessment against ISO/IEC 42001:2023, the international standard for AI Management Systems, covering Clauses 4 to 10 and all 38 Annex A controls."
      },
      {
        "id": "soc2",
        "name": "SOC 2 Gap Assessment (Free Tool)",
        "canonical_url": "https://irmcon.ca/products/soc2/",
        "data_url": "https://irmcon.ca/ai/products/soc2.json",
        "frameworks": [
          "AICPA Trust Services Criteria (2017, Revised Points of Focus 2022)"
        ],
        "summary": "Gap assessment against all 61 AICPA Trust Services Criteria across Security, Availability, Processing Integrity, Confidentiality and Privacy, at the SOC 2 Type I or Type II level."
      },
      {
        "id": "iso27001",
        "name": "ISO 27001 Gap Assessment (Free Tool)",
        "canonical_url": "https://irmcon.ca/products/iso27001/",
        "data_url": "https://irmcon.ca/ai/products/iso27001.json",
        "frameworks": [
          "ISO/IEC 27001:2022"
        ],
        "summary": "Gap assessment against ISO/IEC 27001:2022, the international standard for Information Security Management Systems, covering Clauses 4 to 10 and all 93 Annex A controls."
      }
    ],
    "target_audience": [
      "Small and medium businesses",
      "Startups",
      "Organizations preparing for certification or a customer security review"
    ],
    "target_buyers": [
      "Founder",
      "Co-Founder",
      "CEO",
      "CTO",
      "IT Manager",
      "Chief Risk Officer"
    ],
    "geographic_coverage": {
      "primary_markets": [
        "North America"
      ],
      "countries": [
        "Canada",
        "United States"
      ],
      "service_delivery": "Web-based, available anywhere"
    },
    "offered_by": {
      "@type": "Organization",
      "name": "IRM Consulting & Advisory",
      "url": "https://irmcon.ca/"
    },
    "created_by": {
      "@type": "Person",
      "name": "Victoria Arkhurst",
      "url": "https://irmcon.ca/about-victoria-arkhurst/"
    },
    "related_services": [
      {
        "name": "Virtual CISO Services",
        "url": "https://irmcon.ca/virtual-ciso-services-vciso/"
      },
      {
        "name": "Governance Risk & Compliance",
        "url": "https://irmcon.ca/governance-risk-compliance-grc/"
      }
    ]
  }
}
