Compliance partner directory
329 listings, ordered alphabetically.Data last checked .
13 Security
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- HITRUST
- GDPR
New York-based penetration testing and vulnerability management provider covering web, API, mobile, network and cloud targets, with testing aligned to SOC 2, ISO 27001, PCI DSS, HIPAA and HITRUST requirements.
2-Control B.V.
- Audit firm
- SOC 2
Breda-based firm with NOREA-registered IT auditors offering SOC 2 Type 1 and Type 2 statements for startups and scale-ups, SaaS, hosting, cloud and managed service providers.
360 Advanced
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- HIPAA
- HITRUST
- PCI DSS
- FedRAMP
- CMMC
- CSA STAR
- GDPR
Florida-licensed, PCAOB-registered CPA firm in St. Petersburg, FL performing SOC 1, SOC 2 and SOC 3 examinations, plus HITRUST, PCI DSS, FedRAMP, CMMC, HIPAA and other assessments and penetration testing.
6clicks
- Compliance platform
- ISO 27001
- ISO 42001
- SOC 2
- IRAP
- DORA
- Cyber Essentials
- PCI DSS
- CMMC
Sydney-based GRC platform with an AI engine (Hailey AI) covering audit, risk, compliance and third-party risk, aimed at government, defence, regulators, critical infrastructure, enterprises and advisors/MSPs; frameworks include ISO 27001, ISO 42001, SOC 2, IRAP and CMMC.
7 River Systems
- Readiness consultant / vCISO
- SOC 1
- SOC 2
- ISO 27001
- ISO 27701
- HIPAA
- HITRUST
- GDPR
Maryland-based security and compliance advisory firm founded in 2013, offering readiness assessments, gap analyses, internal audits, vCISO and DPO services across SOC 2, ISO 27001, ISO 27701, HIPAA, HITRUST and NIST CSF.
A-LIGN
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- ISO 27001
- ISO 27701
- ISO 42001
- FedRAMP
- CMMC
- HITRUST
- HIPAA
- PCI DSS
- GDPR
- NIS2
- CSA STAR
Compliance assessment firm headquartered in Tampa with offices in the UK, Ireland, Panama, Bulgaria and India; SOC 1 and SOC 2 reports are issued through its PCAOB-registered CPA entity, alongside ISO, FedRAMP, CMMC, HITRUST, PCI DSS assessments and penetration testing.
AAA Certification AB
- ISO certification body
- ISO 27001
Swedish certification body based in Alingsås (trading as A3CERT) certifying management systems and products, including ISO 27001, ISO 9001, ISO 14001 and ISO 22301, with a Norwegian subsidiary. Swedac-accredited for ISO 27001.
AAFCPAs
- Audit firm
- SOC 1
- SOC 2
- ISO 27001
- HIPAA
Boston-headquartered accounting and advisory firm with 400+ staff whose audit and assurance practice performs SOC 1 and SOC 2 (Type 1 and Type 2) examinations, alongside ISO 27001 and HIPAA cybersecurity services, for SaaS, fintech, healthcare and other clients.
AARC-360
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- PCI DSS
- HITRUST
- GDPR
- HIPAA
- FedRAMP
Alpharetta, Georgia firm offering SOC 1, SOC 2 and SOC 3 reports plus ISO 27001/27701/42001, PCI DSS, HITRUST, HIPAA and FedRAMP work and penetration testing, for industries including SaaS/cloud providers, AI, fintech, healthcare and financial services.
Accedere
- Audit firm
Denver-headquartered firm with offices in Mumbai and Dubai listing SOC attest reports, ISO/IEC certifications, federal, privacy and cloud security assessments and technical audits.
Accorian
- Audit firm
- Readiness consultant / vCISO
- SOC 1
- SOC 2
Cybersecurity and compliance firm whose SOC 2 page names Accorian Assurance as a licensed CPA firm performing SOC 1 and SOC 2 Type I/II, with offices in New Jersey, Toronto and Bengaluru.
activeMind
- Readiness consultant / vCISO
- GDPR
- EU AI Act
London-based data protection practice, regulated by the Solicitors Regulation Authority, offering DPO services, UK representative, UK GDPR audits, workshops and AI compliance support, with locations in London, Berlin and Munich.
Advantage Partners
- Audit firm
- ISO certification body
- Readiness consultant / vCISO
- SOC 2
- HIPAA
- ISO 27001
- ISO 27701
- ISO 42001
- HITRUST
- CMMC
Firm performing SOC 2 Type 1 and Type 2, HIPAA and ISO 27001 audits for start-up and emerging technology companies, and also offering ISO 27701, ISO 42001, HITRUST, CMMC and penetration testing work.
Adversis
- Readiness consultant / vCISO
- SOC 2
- NIST AI RMF
- CMMC
- GDPR
- ISO 27001
Security consultancy offering penetration testing, AI red teaming, red teaming, compliance assessments and gap analysis (SOC 2, NIST AI RMF, CMMC, GDPR, ISO 27001), security questionnaires and advisory, aimed at B2B SaaS companies from early-stage to enterprise.
Agency
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- GDPR
- HIPAA
- FedRAMP
- CMMC
- ISO 42001
- HITRUST
- PCI DSS
Managed security and compliance service run by US-based compliance engineers, operating SOC 2, ISO 27001, HIPAA, GDPR and other programs end-to-end on top of Vanta or Drata, with vCISO and published flat-rate and monthly pricing.
AIEthica
- Readiness consultant / vCISO
- EU AI Act
Swiss consultancy (Herrliberg) offering EU AI Act compliance consulting, MDR/IVDR alignment, model risk management, impact assessments and responsible AI training, mainly for medical device and eHealth companies.
Airius
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- CMMC
- GDPR
Connecticut-based risk management and compliance consultancy offering risk assessments, US-based vCISO services and compliance support for SOC 2, ISO 27001, HIPAA, PCI, CMMC and GDPR.
Akant
- Readiness consultant / vCISO
- ISO 27001
- ISO 27701
- ISO 42001
- SOC 2
- NIS2
- DORA
- GDPR
- PCI DSS
- HIPAA
- EU AI Act
Lyon-based GRC consultancy supporting ISO 27001, ISO 27701, ISO 42001, SOC 2 and HDS certification, NIS2, DORA, GDPR and AI Act compliance, security audits and outsourced CISO services, for companies in Europe and abroad.
Akitra
- Compliance platform
- SOC 1
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- CMMC
- GDPR
- ISO 42001
- NIST AI RMF
Silicon Valley-based compliance automation platform (Akitra Inc.) supporting 40+ frameworks including SOC 1, SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, GDPR, ISO 42001 and NIST AI RMF, with 325+ integrations across cloud, code and identity tools.
Aligned Technology Group
- Readiness consultant / vCISO
- SOC 2
- HIPAA
- PCI DSS
Raleigh, North Carolina AWS consulting and managed services partner whose compliance-as-a-service offering covers gap assessments, policy creation and evidence collection for SOC 2, HIPAA, PCI, ISO and NIST.
AmagisTech Limited
- Readiness consultant / vCISO
- ISO 27001
- SOC 2
- NIS2
- DORA
- ISO 42001
Managed security and compliance provider with offices in Milan and Malta, running an Italy-based 24/7 SOC and pentests, and using Vanta and Okta to automate evidence for ISO 27001, SOC 2, NIS2 and DORA.
Andersen Consulting
- Readiness consultant / vCISO
Consulting arm of the Andersen global network offering a membership-based cybersecurity service that embeds a senior CISO-level advisor, NIST CSF-aligned baseline assessments and cybersecurity strategy work.
Anecdotes
- Compliance platform
- SOC 1
- SOC 2
- ISO 27001
- ISO 42001
- ISO 27701
- HIPAA
- PCI DSS
- FedRAMP
- CSA STAR
- GDPR
- DORA
- EU AI Act
- Cyber Essentials
- TISAX
Palo Alto-based enterprise GRC platform with AI agents for continuous control monitoring, risk, policy and third-party risk management, with 60+ pre-mapped frameworks including SOC 2, ISO 27001 and ISO 42001.
Apptega
- Compliance platform
- CMMC
- ISO 27001
- PCI DSS
- ISO 42001
- FedRAMP
- GDPR
- HIPAA
- SOC 2
Atlanta-based security and compliance platform for assessments, risk and third-party management across frameworks such as SOC 2, ISO 27001, ISO 42001, CMMC, PCI DSS and HIPAA; sold to in-house teams and to MSPs, MSSPs and consulting firms.
Aprio
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- PCI DSS
- HITRUST
- HIPAA
- FedRAMP
- CMMC
Large US CPA and advisory firm whose risk and compliance practice issues SOC 1, SOC 2 (Type I and II), SOC 3 and SOC for Cybersecurity reports, and offers ISO, PCI DSS, HITRUST, HIPAA, FedRAMP and CMMC assessments plus penetration testing.
ARM Standard Co., Ltd.
- ISO certification body
- ISO 27001
Japanese certification body auditing ISO 9001, ISO 14001 and ISO/IEC 27001, which also offers a document management IT tool (WebMiCS) and e-learning courses, and publishes its audit fee table (¥120,000 per auditor-day). ISMS-AC lists it for ISMS (ISR030).
ART25 Consulting
- Readiness consultant / vCISO
- ISO 42001
- EU AI Act
- GDPR
Stockholm-based consultancy offering ISO 42001 implementation, AI Act and GDPR gap analyses, part-time DPO, DPIA and AI literacy training. Also developing an AI-native GRC platform.
ASR Co., Ltd.
- ISO certification body
Japanese ISO audit and certification body that also runs a training centre and recruits ISO auditors. ISMS-AC lists it for ISMS (ISR025).
Assent Risk Management
- Readiness consultant / vCISO
- ISO 42001
UK risk and compliance consultancy offering ISO 42001 gap analysis, implementation projects, internal audits and certification preparation, plus AI impact assessments, for clients in sectors including tech, finance, healthcare and manufacturing.
Assurance Dimensions
- Audit firm
- SOC 1
- SOC 2
Tampa, Florida CPA firm (founded 2008) offering audit, tax and advisory services, including SOC 1 and SOC 2 examinations and SOC readiness assessments; serves SaaS, cloud, IT service, financial services and healthcare clients from Florida offices.
AssurancePoint
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
Atlanta-based CPA firm offering SOC 1, SOC 2, SOC 3, SOC for Cybersecurity and SOC for Supply Chain examinations, plus ISO 27001, healthcare compliance, FISMA/NIST, privacy and advisory services.
Assure UK
- Audit firm
UK firm specialising in pension scheme audits and assurance reports under AAF 01/20, AAF 02/07, AAF 05/20 and ISAE 3402; no AICPA SOC service named on the homepage.
Astra Security
- Pentest platform
- SOC 2
- ISO 27001
- HIPAA
Pentest-as-a-service platform (ASTRA IT, Inc.) combining automated and manual penetration testing by certified pentesters with DAST, API and cloud scanning; pentest reports are positioned for SOC 2, ISO 27001 and HIPAA evidence.
ATA (Alexander Thompson Arnold)
- Audit firm
Regional CPA and advisory firm headquartered in Jackson, Tennessee, with offices in Tennessee, Indiana, Kentucky and Mississippi, offering financial statement audits, internal audit, risk advisory, IT consulting and tax services.
Atom Assurances LLC
- Audit firm
- SOC 2
- ISO 27001
- ISO 27701
- HIPAA
- GDPR
Audit firm operating through a Wyoming-licensed US CPA entity and an Indian affiliate, offering SOC 2 Type 1 and Type 2 attestations and ISO 27001/27701 certifications (via partner certification bodies), plus HIPAA and GDPR assessments; works with Vanta, Drata and Sprinto.
Atoro
- Readiness consultant / vCISO
- ISO 27001
- SOC 2
- ISO 42001
- GDPR
Irish cyber compliance consultancy founded in 2018 that builds and runs ISO 27001, SOC 2, ISO 42001 and GDPR programmes for software companies in Ireland, the UK and Europe, with vCISO, outsourced DPO, internal audit, pentest and a Drata/Vanta-based managed service.
Audit Advantage Group
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
Firm offering SOC 1, SOC 2 (Type I and II) and SOC 3 audits with readiness assessments, ISO 27001 internal audits, outsourced internal audit and tax services, for cloud, SaaS, healthcare, e-commerce, lending and payments companies.
Audit Peak
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HIPAA
- GDPR
New York-based firm offering SOC 1, SOC 2 (Type 1 and Type 2, with readiness assessments) and SOC 3 engagements, agreed-upon procedures, and HIPAA, GDPR, GLBA, FISMA/NIST 800-53, MARS-E and IRS Publication 1075 compliance work.
AuditBadger
- Compliance platform
- SOC 2
- ISO 27001
AI-assisted SOC 2 and ISO 27001 compliance software (formerly Humadroid) for startups, including AI companies, at a flat monthly price with unlimited users; third-party audit fees are paid separately. Data controller is a Polish company in Poznań.
AuditBoard
- Compliance platform
Enterprise GRC platform covering audit, risk, IT risk and compliance, and AI governance, now presented under the Optro brand (auditboard.com redirects to optro.ai); says it is used by over half of the Fortune 500.
Auditsuisse Assurance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- GDPR
- HIPAA
US and Swiss audit firm offering SOC 1, SOC 2, SOC 3, GDPR, HIPAA, ISAE 3000 and ISAE 3402 reports plus penetration testing, aimed at SaaS and cloud service providers.
AuditVisor
- Audit firm
- SOC 2
- HIPAA
- PCI DSS
- GDPR
- FedRAMP
Fort Lauderdale, Florida-based firm with offices listed in the US, Canada, India and Australia, offering SOC 2 attest and readiness, ISO, HIPAA, PCI DSS, GDPR, NIST and FedRAMP compliance services and penetration testing, for SaaS, AI, fintech and other technology companies.
Auditwerx
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- PCI DSS
- CMMC
- HIPAA
- HITRUST
- ISO 27001
Tampa, Florida-based security compliance division of CPA firm Carr, Riggs & Ingram, issuing SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports and performing PCI DSS, CMMC, HIPAA, HITRUST and ISO 27001 assessments; clients include SaaS, healthcare and fintech companies.
Baker IT Solutions LLC
- Readiness consultant / vCISO
- SOC 2
- HIPAA
Irving, Texas managed IT and cybersecurity provider whose Security and Compliance tier runs SOC 2 and HIPAA compliance programmes end to end and remediates infrastructure gaps; serves businesses in Texas, California and Nevada.
Baker Newman Noyes
- Audit firm
- SOC 1
- SOC 2
- SOC 3
New England accounting firm with offices in Maine, Massachusetts and New Hampshire offering SSAE 18 SOC 1, SOC 2, SOC 3, SOC for Cybersecurity and SOC for Supply Chain reports plus readiness assessments, including for SaaS and cloud providers.
Baker Tilly
- Audit firm
- SOC 2
- HITRUST
- ISO 27001
US member of Baker Tilly International whose attest services are provided by Baker Tilly US, LLP, a licensed CPA firm; performs SOC engagements including SOC 2 Type 1 and Type 2, SOC 2+ and SOC for Cybersecurity, with offices in 25 US states and Washington DC.
Bankole, Okoye & Associates, P.C.
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Houston, Texas CPA firm offering SOC 1, SOC 2 and SOC 3 audits alongside audit and assurance, internal audit, SOX/internal control, IT audit, tax and accounting services.
Barnes Dennig
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 42001
- CMMC
- GDPR
- HIPAA
- PCI DSS
CPA and consulting firm with offices in Ohio, Kentucky and Indiana offering SOC 1, SOC 2 (Type 1 and Type 2), SOC 3 and SOC 2+ reports, SOC readiness assessments and combined SOC 2 / ISO 42001 AI governance work; SaaS is among the industries named.
BARR Advisory
- Audit firm
- ISO certification body
- Readiness consultant / vCISO
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- HIPAA
- HITRUST
- PCI DSS
- FedRAMP
- CMMC
- CSA STAR
Cybersecurity and compliance firm performing SOC 1, SOC 2 (Type 1 and 2), SOC 3 and SOC for Cybersecurity examinations and ISO, HITRUST, PCI DSS, FedRAMP and CMMC assessments, plus readiness reviews, penetration testing and virtual CISO services; clients in 20+ countries.
BD Emerson
- Audit firm
- Readiness consultant / vCISO
- SOC 1
- SOC 2
- SOC 3
US cybersecurity, compliance and AI governance firm that states it performs SOC 1, SOC 2 (Type 1 and 2) and SOC 3 examinations through its CPA attest arm, and offers ISO 27001/42001, HIPAA, HITRUST, FedRAMP, CMMC and PCI DSS consulting, penetration testing and vCISO services.
BDO
- Audit firm
- SOC 1
- SOC 2
- SOC 3
US member firm of BDO International (BDO USA, P.C., a Virginia professional corporation) performing SOC 1, SOC 2, SOC 3, SOC for Cybersecurity and SOC for Supply Chain examinations and SOC readiness work for technology, SaaS, healthcare and financial services clients.
BEMO
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- CMMC
Managed IT and cybersecurity provider (MSP) serving US companies from startups up to 500 employees, offering managed compliance for SOC 2, ISO 27001 and CMMC on Drata and Vanta, using third-party auditors; monthly pricing published by company size.
Bennett Thrasher
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Tax, audit, advisory and outsourcing firm with offices in Atlanta, Dallas and Denver that offers SOC 1, SOC 2 and SOC 3 reporting services.
BerryDunn
- Audit firm
- SOC 1
- SOC 2
US firm whose attest services are provided by BDMP Assurance, LLP, a licensed CPA firm; offers SOC readiness assessments, SOC 1 and SOC 2 audits, including for financial institutions, gaming, trust companies, technology, insurance and K-12 education.
Bird Rock Systems
- Readiness consultant / vCISO
San Diego managed IT and security services provider with regional offices in Aliso Viejo and Los Angeles; services cover security (including penetration testing), cloud, network and privacy and compliance; lists Drata among technology partners.
Blackmores (UK) Ltd
- Readiness consultant / vCISO
- ISO 27001
- ISO 42001
UK ISO consultancy based in Hitchin, Hertfordshire, established 2006, implementing ISO management systems (incl. ISO 9001, 27001, 45001, 14001 and 42001) through its Isology roadmap, consultants, support plans and online membership.
Boulay
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
Minnesota CPA and advisory firm founded in 1934, with offices in Eden Prairie, Minneapolis and Mankato, whose risk advisory practice provides SOC 1 and SOC 2 (Type 1 and 2) and SOC 3 reports, SOC 2 readiness assessments, ISO 27001 compliance and Microsoft SSPA attestations.
BPM
- Audit firm
- SOC 1
- SOC 2
- SOC 3
California-headquartered CPA firm (BPM LLP) performing SOC 1 and SOC 2 examinations, SOC 3 reports and SOC readiness assessments, including for SaaS providers; firm industries include AI & machine learning and software & SaaS.
Brand Compliance B.V.
- ISO certification body
- ISO 27001
- ISO 27701
Certification and audit firm whose homepage states RvA accreditation C548 to certify ISO 27001, ISO 27701, NEN 7510 and ISO 9001, with locations in the Netherlands, Belgium, Sweden, the UK, Ireland and Luxembourg.
BreachLock Inc.
- Pentest platform
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- GDPR
New York-based penetration testing provider offering pentest-as-a-service (web, API, mobile, network, cloud), red teaming and attack surface management via its platform, with offices in the US, UK, Netherlands and India.
Bright Defense
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- CMMC
- PCI DSS
- ISO 42001
Culver City, Los Angeles cybersecurity compliance firm offering continuous compliance (SOC 2, ISO 27001, HIPAA, CMMC and others), virtual CISO, penetration testing, vulnerability management and security awareness training for startups, SaaS/AI and defense contractors.
British Assessment Bureau (Amtivo)
- ISO certification body
- ISO 27001
- ISO 27701
- ISO 42001
- Cyber Essentials
UK certification body in Kings Hill, Kent, trading as Amtivo and part of Amtivo Group, offering UKAS-accredited ISO certification including ISO 27001, 27701 and 42001 alongside ISO 9001, 14001, 45001, Cyber Essentials and other schemes, plus training.
BRL
- Audit firm
- SOC 1
- SOC 2
- SOC 3
German audit firm (Böge, Rohde & Lübbehuesen) performing SOC 1, SOC 2 and SOC 3 audits (Type 1 and Type 2) alongside IDW PS 951, ISAE 3000, ISAE 3402 and SSAE 18, with offices in Hamburg, Berlin, Munich and Essen.
Brown Edwards
- Audit firm
- SOC 1
- SOC 2
Mid-Atlantic CPA firm (Brown Edwards & Company, L.L.P.) with offices in Virginia, West Virginia and Tennessee; its IT audit and advisory practice lists SOC 1, SOC 2 and SOC for Cybersecurity audits, IT security and vulnerability assessments and penetration testing.
BSI Group
- ISO certification body
- ISO 27001
- ISO 42001
Standards and certification group offering ISO 27001 and ISO 42001 (AI management system) certification, with AI and cybersecurity under its digital trust work. Register entries: BSI Group The Netherlands B.V. (RvA, ISO 42001) and BSI Group Japan (ISMS-AC, ISO 27001/27701).
Bureau Veritas
- ISO certification body
- ISO 27001
- ISO 27701
- ISO 42001
Certification group; Bureau Veritas (India) Pvt. Ltd. is NABCB-accredited for ISO 27001 and ISO 42001, and Bureau Veritas Japan's System Certification division is ISMS-AC accredited for ISO 27001 and publishes an indicative ISO 27001 audit fee.
Buzzacott
- Audit firm
- SOC 1
- SOC 2
- SOC 3
UK firm (Buzzacott LLP) delivering ISAE 3402, AAF 01/20 and SOC 1 reports and ISAE 3000 / SOC 2 reports, plus SOC 3, with readiness and remediation support, for financial services, technology and SaaS clients.
C1 Certification AB
- ISO certification body
Certification body listed in the Swedac register (no. 10432) as accredited for ISO/IEC 27001 certification.
Carbide
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- CMMC
- GDPR
- PCI DSS
Compliance automation and risk management platform combined with advisory support, covering 20+ frameworks including SOC 2, ISO 27001, HIPAA, CMMC, PCI DSS and GDPR, with published annual plans by number of frameworks. Carbide does not perform audits itself.
CAS Assurance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- CSA STAR
- HIPAA
- GDPR
- ISO 27001
- PCI DSS
- CMMC
Miramar, Florida firm (CAS Assurance, LLC) offering SOC 1, SOC 2 and SOC 3 attestation, SOC 2 + CSA STAR attestation, compliance work across HIPAA, GDPR, ISO 27001, PCI DSS and CMMC, penetration testing, plus accounting and tax services.
CBIZ
- Audit firm
US accounting, tax, advisory and technology firm; attest services are provided by CBIZ CPAs P.C. under an alternative practice structure with CBIZ, Inc. Its cybersecurity practice offers penetration testing and cyber risk management (CMMC, HIPAA, NIST).
Ceel
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- PCI DSS
- FedRAMP
- ISO 42001
- EU AI Act
- NIST AI RMF
- CMMC
San Francisco-based compliance and AI-governance platform (with a Montréal office) covering SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, ISO 42001, EU AI Act and more, with independent AICPA peer-reviewed auditors built into the platform.
Center for Better Living, System Certification Center (BL-QE)
- ISO certification body
- ISO 27001
- ISO 27701
Tokyo-based certification centre opened in 1996 within the Center for Better Living foundation, certifying ISO/IEC 27001, 27017 and 27701 alongside ISO 9001, 14001 and 45001. ISMS-AC lists it for ISMS (ISR022).
Centraleyes
- Compliance platform
- SOC 1
- SOC 2
- ISO 27001
- PCI DSS
- CMMC
- HIPAA
GRC platform with offices in Hoboken, NJ and New York covering risk registers, vendor risk, questionnaires and regulatory change across 180+ frameworks including SOC 2, ISO 27001, PCI DSS, CMMC and HIPAA; also offers GRC as a service.
CEREIV Advisory LLP
- ISO certification body
- ISO 27001
- SOC 2
Kerala-based firm offering ISO 27001 readiness, training and certification audits, SOC 2 assessments, VAPT and Indian regulatory audits (RBI, CERT-In). NABCB lists it for ISO/IEC 27001 (IS 015).
CERTIFICATO IWZ - FZCO
- ISO certification body
- ISO 27001
Dubai-based certification body (EIAC accredited) certifying ISO 9001, 14001, 45001, 50001 and ISO 27001, with a regional network in Syria, Kuwait, Saudi Arabia, Türkiye, Jordan, Italy and the UK. Audits on-site or remotely.
CertPro
- Audit firm
- SOC 2
- ISO 27001
- ISO 42001
- ISO 27701
- HIPAA
- GDPR
Compliance audit firm with offices in Newark, Delaware and Bangalore, India; states that CertPro CPA LLC issues SOC 2 Type 1 and Type 2 reports, and offers SOC 2 readiness plus ISO 27001, ISO 42001, ISO 27701, HIPAA and GDPR audits, delivered remotely.
CertValue
- Audit firm
- ISO 27001
- ISO 27701
- HIPAA
- GDPR
- SOC 2
- PCI DSS
Consulting, training and certification company covering ISO management-system standards, CE marking and other schemes; lists SOC 2 among its services. No CPA firm or SOC report signer is named on its site.
CGVantage (formerly CyberGuard Advantage)
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- PCI DSS
- ISO 27001
- ISO 42001
- HIPAA
- HITRUST
Cybersecurity compliance firm (CyberGuard Advantage and Control Gap, now CGVantage) offering SOC 1, SOC 2 and SOC 3 assessments, PCI, ISO 27001/42001 and HIPAA/HITRUST work, readiness and penetration testing for SaaS, financial services, healthcare and retail firms.
Cherry Bekaert
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HITRUST
- HIPAA
- PCI DSS
- CSA STAR
- CMMC
US accounting and advisory firm headquartered in Richmond, Virginia; Cherry Bekaert LLP provides attest services including SOC 1, SOC 2 and SOC 3 reporting, and the firm also offers ISO 42001 preparation and other cybersecurity compliance services.
Chiaro (Y Assurance PLLC)
- Audit firm
- SOC 2
Austin, Texas-based SOC 2 service from Y Assurance PLLC, a CPA firm stating Texas State Board licensing; offers SOC 2 Type I and Type II examinations plus readiness, aimed at teams building with AI, with a published base price.
Cibersafety
- Readiness consultant / vCISO
- DORA
- ISO 27001
- NIS2
Spanish cybersecurity firm based in Alquerias (Murcia) offering ethical hacking, and consulting and implementation for ISO 27001, DORA, NIS2 and ENS for financial institutions and other companies.
CISO Assistant (intuitem)
- Compliance platform
- ISO 27001
- SOC 2
- NIS2
- DORA
- GDPR
Open-source (AGPLv3) GRC platform by French company intuitem for risk, audit and compliance management across 150+ frameworks including ISO 27001, SOC 2, NIS2, DORA and GDPR; free self-hosted Community edition and paid Pro SaaS or on-premises editions.
CISOnow
- Readiness consultant / vCISO
- CMMC
CISO advisory firm (advisors described as former CISOs) offering vCISO and deputy CISO services, managed GRC, AI governance and security services, data governance, managed EDR/ITDR and security assessments including CMMC.
CLA (CliftonLarsonAllen)
- Audit firm
- SOC 1
- SOC 2
US accounting firm (CliftonLarsonAllen LLP, a Minnesota LLP with 120+ US locations) offering SOC 1, SOC 2, SOC 2+ and SOC for Cybersecurity examinations, with readiness assessments before the examination.
Clark Nuber
- Audit firm
- SOC 2
Accounting and consulting firm based in Bellevue, Washington; its SOC 2 article states it offers SOC 2 readiness assessments, system description development and CPA attestation engagements (not readiness and audit for the same engagement).
Clark Schaefer Hackett
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Accounting and advisory firm (Clark, Schaefer, Hackett & Co.) with 10 offices across Ohio, Kentucky, Michigan and Mumbai; lists SOC 1, SOC 2, SOC 3, SOC for Supply Chain and SOC for Cybersecurity reports on its consulting site.
Coalfire
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- PCI DSS
- HITRUST
- ISO 27001
- ISO 27701
- ISO 42001
- FedRAMP
- GDPR
- HIPAA
Cybersecurity advisory and assessment firm (Coalfire Systems, Inc.) whose affiliate CPA firm Coalfire Controls performs SOC 1, SOC 2 and SOC 3 examinations; also offers FedRAMP, PCI DSS, HITRUST, ISO and CMMC assessments and readiness work.
Cobalt
- Pentest platform
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
Pentest-as-a-service provider (Cobalt Labs, Inc.) combining a testing platform with a network of vetted pentesters for application, network, cloud and AI/LLM testing, red teaming and code review, sold via annual credit packages.
CohnReznick
- Audit firm
- SOC 1
- SOC 2
- SOC 3
US accounting and advisory firm with 39 US offices and affiliates in India, the Cayman Islands and the Philippines; CohnReznick LLP provides attest services including SOC 1, SOC 2 (Type I and II), SOC 3 and SOC for Cybersecurity examinations, plus readiness assessments.
Comp AI
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- FedRAMP
Open-source compliance automation platform for SOC 2, ISO 27001, HIPAA, GDPR and FedRAMP, with code published on GitHub. Offices in Florida and New York, US.
Comply (strongDM)
- Compliance platform
- SOC 2
Open-source (Apache-2.0) SOC 2-focused compliance automation framework from strongDM: a markdown policy document pipeline, ticketing integration (Jira, GitHub, GitLab) and SOC 2 policy templates. Self-run command-line tool; last commit seen July 2022.
Complyance
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- CMMC
- DORA
- FedRAMP
- GDPR
- HITRUST
- ISO 27701
- ISO 42001
- NIS2
- NIST AI RMF
- TISAX
AI-driven GRC platform for enterprise teams with 100+ prebuilt frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, DORA, NIS2, ISO 42001 and others) and integrations across cloud, identity, HR and ticketing tools. Operated by Securely Technology Ltd.
ComplyJet
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
Compliance automation platform for SaaS startups covering SOC 2, ISO 27001, HIPAA and 25+ frameworks; published plans for teams up to 50 employees include implementation support and one external audit by an independent accredited firm.
Compyl
- Compliance platform
- SOC 2
- ISO 27001
- ISO 42001
- HIPAA
- GDPR
- PCI DSS
- NIS2
GRC platform founded by former CISOs covering governance, risk, compliance and audit, with a control library cross-mapped to 70+ frameworks and 125+ in-house integrations; serves financial services, healthcare, insurance, legal, energy and higher education.
Conformly AS
- Readiness consultant / vCISO
- NIS2
- SOC 2
- HIPAA
Norwegian company (Stokmarknes address) offering compliance management, cybersecurity training in short monthly lessons, and consulting; frameworks named include NIS 2, NIST, ISO, SOC 2 and HIPAA.
Considerati
- Readiness consultant / vCISO
- GDPR
- EU AI Act
Amsterdam legal advisory firm for innovators offering legal and compliance services in privacy and data protection, AI compliance and AI governance, and compliance training, with a focus on GDPR and the AI Act.
Consilium Labs
- Audit firm
- ISO certification body
- ISO 27001
- ISO 27701
- ISO 42001
- SOC 2
- CSA STAR
Accredited ISO certification body based in El Dorado Hills, California, offering ISO 27001/27701/42001 certification, CSA STAR, SOC 2 engagements and penetration testing for SaaS, AI and cloud-native companies.
Constellation GRC
- Audit firm
- SOC 2
California-licensed CPA firm (ConstellationGRC CPA PC) in Seal Beach, CA, issuing SOC 2 Type I and Type II reports, with pages aimed at startups, SaaS companies and agencies.
Control Logics
- Audit firm
- ISO 27001
- GDPR
Tampa, Florida risk and compliance firm offering SOC readiness assessments, ISO 27001 implementation, SOX and Model Audit Rule compliance, and GDPR/CCPA services; no SOC report issuance stated.
ControlCase
- Audit firm
- PCI DSS
- ISO 27001
- HITRUST
- SOC 2
- GDPR
- HIPAA
- FedRAMP
- CMMC
Compliance assessment firm headquartered in Fairfax, Virginia, offering PCI DSS (QSA/ASV), SOC 2 Type I/II, ISO 27001, HITRUST, FedRAMP and CMMC services plus penetration testing, for SaaS, hosting, healthcare and government service providers.
ControlCase Infosec Pvt. Ltd.
- ISO certification body
- ISO 27001
Mumbai-incorporated certification body, a subsidiary of ControlCase International Pvt. Ltd., offering ISO/IEC 27001 (ISMS) certification under NABCB (IS005) and RvA (C 584) accreditation.
CORAL eSecure
- Readiness consultant / vCISO
- ISO 42001
Cybersecurity services firm with offices in the USA, Canada, India and Mauritius offering ISO 42001 AI management system consulting, penetration testing, GRC outsourcing and fractional CISO services.
Core Business Solutions
- Readiness consultant / vCISO
- ISO 27001
- ISO 42001
- CMMC
US ISO consulting firm headquartered in Lewisburg, PA offering consulting, auditing, training and cloud compliance software for ISO 9001, ISO 27001, ISO 42001, CMMC and other standards, serving manufacturers, service companies, government contractors and SMBs.
Councilor, Buchanan & Mitchell (CBM)
- Audit firm
Bethesda, Maryland accounting and advisory firm (now branded Councilor) offering audit and assurance, including System and Organization Control (SOC) audits for third-party service organisations, plus tax and advisory services.
ctrl:cyber
- Readiness consultant / vCISO
Australian-owned cybersecurity firm offering penetration testing, governance risk and compliance, privacy, data risk and AI governance services, plus its own Rio platform. CREST penetration testing accreditation shown on the CREST marketplace.
Cyber Ally
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
Sydney-based security consultancy offering SOC 2 and ISO 27001 compliance support, virtual CISO, penetration testing and GRC services to startups and SMBs; SOC 2 audits are performed by partner AssuranceLab.
Cyber Dynamo
- Readiness consultant / vCISO
- NIST AI RMF
- ISO 42001
Consultancy offering AI risk management and cyber security services: NIST AI RMF and ISO 42001-series implementation and training, ACSC Essential 8 consulting, and CISO as a service.
CyberArrow
- Compliance platform
CyberSapiens
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HIPAA
- PCI DSS
Cybersecurity compliance and VAPT consultancy with an address in Port Melbourne, Australia and offices listed in Canada, the US and India; offers SOC 1/2/3, ISO 27001, HIPAA and PCI DSS compliance services and says it collaborates with an independent CPA firm for SOC 2 audits.
Cybertryzub Infosec Private Limited
- ISO certification body
- ISO 27001
- PCI DSS
- HIPAA
- SOC 2
- GDPR
Gurgaon-based, CERT-In empanelled security firm offering penetration testing, ISO 27001:2022 certification, PCI DSS, HIPAA, SOC and Indian regulatory (RBI, SEBI, IRDAI) audits, with offices in Mumbai, Bangalore and Noida. NABCB lists it for ISO/IEC 27001 (IS 017).
Cycore Secure
- Readiness consultant / vCISO
- SOC 2
- HIPAA
- PCI DSS
- ISO 27001
- HITRUST
- CMMC
- GDPR
- NIS2
- FedRAMP
- DORA
- Cyber Essentials
- ISO 42001
- NIST AI RMF
- EU AI Act
Cybersecurity, AI and privacy compliance consultancy offering vCISO and vDPO services, GRC implementation on Vanta, Drata, Secureframe and Thoropass, SOC 2, ISO 27001, GDPR and other framework compliance, and AI governance (ISO 42001, NIST AI RMF, EU AI Act).
Cynomi
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- CMMC
vCISO and security/compliance management platform sold to MSPs, MSSPs and vCISO consultancies to deliver assessments, risk management, TPRM and compliance services to SMB clients across 40+ frameworks including SOC 2, ISO 27001, HIPAA and CMMC. Founded in Israel and the UK; offices in London and Boston.
Cypago
- Compliance platform
- SOC 2
- ISO 27001
- ISO 27701
- ISO 42001
- NIST AI RMF
- HIPAA
- PCI DSS
- GDPR
- CMMC
- FedRAMP
Cyber GRC automation platform using AI agents for compliance automation, continuous control monitoring, user access reviews and risk management across SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, CMMC, FedRAMP and other frameworks. Audit fees are paid separately to the audit firm.
Dannible & McKee, LLP
- Audit firm
- SOC 1
- SOC 2
- SOC 3
CPA firm headquartered in Syracuse, New York, with offices in New York and Tampa, Florida; its assurance practice offers SOC 1, SOC 2 (Type 1 or 2) and SOC 3 audits and SOC readiness assessments.
Dansa D'Arata Soucia LLP
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HIPAA
Accounting firm in Buffalo, New York, with an information security compliance practice offering SOC 1, SOC 2 and SOC 3 reports, ISO 27001 ISMS implementation support and HIPAA compliance work.
Dash ComplyOps
- Compliance platform
- HIPAA
- SOC 2
- HITRUST
- ISO 27001
- PCI DSS
- GDPR
Healthcare-focused compliance platform for HIPAA, SOC 2, HITRUST, ISO 27001, PCI DSS and GDPR, with policy templates and audit evidence tools; standard plan published at $250/month with unlimited users.
DCR Partners Ltd
- Readiness consultant / vCISO
Leeds-based UK advisory firm covering resilience and crisis management, third-party risk, cyber resilience, internal audit and data governance for financial services, betting and gaming, and energy clients. CREST penetration testing accreditation on the CREST marketplace.
Decrypt Compliance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- PCI DSS
- HIPAA
- HITRUST
- GDPR
San Jose, California CPA firm performing SOC 1, SOC 2 and SOC 3 audits and ISO 27001, ISO 27701, ISO 42001, PCI DSS, HIPAA, HITRUST and GDPR work, with a stated focus on B2B SaaS and AI-product companies.
Defense Facilities Environment Improvement Association, System Audit Center
- ISO certification body
- ISO 27001
Tokyo-based public-interest foundation supporting Japan's defence sector; its System Audit Center certifies ISO 27001, ISO 9001, ISO 14001 and JIS Q 9100 (aerospace/defence), including audits involving Ministry of Defense protected information. ISMS-AC lists it for ISMS (ISR019).
Deloitte
- Audit firm
- SOC 1
- SOC 2
- FedRAMP
- HITRUST
Big Four professional services network; its US third-party assurance practice (Deloitte & Touche LLP) provides SOC 1 and SOC 2 attestation reports, FedRAMP and HITRUST attestation services, and readiness services.
Design Assurance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Licensed CPA firm (M W Schroth & Associates LLC d/b/a Design Assurance) performing SOC 1, SOC 2 Type 1 and Type 2 and SOC 3 examinations, with published SOC 2 starting prices; sister company Design Compliance and Security LLC provides advisory and penetration testing.
DigitalXRAID
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- Cyber Essentials
- PCI DSS
Doncaster, UK-based managed security provider offering a CREST-accredited SOC, MDR/XDR, CHECK and CREST penetration testing, incident response, and ISO 27001, Cyber Essentials and SOC 2 compliance services.
DNV Business Assurance B.V.
- ISO certification body
Business assurance unit of the DNV group offering management system certification, supply chain assurance and training. Register-accredited entities: DNV Business Assurance B.V. (RvA, ISO 27001/27701/42001) and DNV Business Assurance Japan (ISMS-AC, ISO 27001).
DNX Solutions
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- ISO 42001
- PCI DSS
Sydney-based AWS-focused cloud consultancy whose cybersecurity and compliance practice offers SOC 2 readiness, ISO 27001 readiness and uplift, ISO 42001 alignment, PCI DSS gap assessments, vCISO retainers and penetration testing.
Doeren Mayhew
- Audit firm
- SOC 1
- SOC 2
- SOC 3
US accounting and advisory firm headquartered in Troy, Michigan; Doeren Mayhew Assurance, PC provides SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reporting and SOC readiness evaluations.
DPO Consultancy
- Readiness consultant / vCISO
- GDPR
- EU AI Act
Dutch privacy consultancy based in 's-Hertogenbosch offering DPO-as-a-Service, GDPR assessments, DPIA, data protection representative services, AI literacy training and EU AI Act compliance services.
DPO Consulting
- Readiness consultant / vCISO
- GDPR
- EU AI Act
Neuilly-sur-Seine (France) data protection consultancy offering outsourced DPO, GDPR audits, EU/UK representative, CISO-as-a-service and EU AI Act compliance support. Site states it is joining Grant Thornton and also offers its myDPO platform.
DPO Europe
- Readiness consultant / vCISO
- GDPR
- EU AI Act
- ISO 42001
- ISO 27701
- ISO 27001
Data privacy and AI compliance consultancy (DPO Europe GmbH, part of DP Group) with offices in Germany, the USA and the UK, offering EU AI Act compliance documentation, ISO 42001 implementation, GDPR, DPO outsourcing, EU representative service and training.
DQS Japan Inc.
- ISO certification body
- ISO 27001
- ISO 42001
- TISAX
Japanese entity of the DQS certification group, offering ISO 27001, ISO 42001 and TISAX audits on-site or remotely, naming SaaS, cloud and AI developers among target clients. ISMS-AC accredited for ISO 27001.
Drata
- Compliance platform
- SOC 2
- ISO 27001
- ISO 42001
- GDPR
- HIPAA
- PCI DSS
- DORA
- FedRAMP
- CMMC
Compliance automation and risk management platform using AI agents to collect evidence and monitor controls for SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, FedRAMP, CMMC and other frameworks. Founded 2020; offices in the US, UK and Australia.
Drummond Group
- Audit firm
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
Testing, certification and audit firm in Durham, North Carolina offering SOC 2 Type I and II audits (reports issued through partner CPA entity Drummond Assurance, LLC), ISO 27001, PCI DSS QSA, HIPAA, ONC health IT certification and penetration testing.
Eastandart Inc.
- Readiness consultant / vCISO
Tokyo-based IT services company (founded January 2024) offering Vanta and Okta implementation and operations support, outsourced IT/security department operations, SaaS rollout, network build and AI development.
Echelon Risk + Cyber
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- CMMC
- PCI DSS
US cybersecurity consultancy with offices in Pittsburgh, Austin, Charlotte, Atlanta, Raleigh and Philadelphia offering SOC 2 readiness, ISO 27001, HIPAA and CMMC compliance, penetration testing and red teaming, vCISO-led security teams, managed detection and AI governance.
eDelta Consulting
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- CMMC
- PCI DSS
- ISO 27001
Advisory and assurance firm headquartered in New York City; its CPA entity eDelta CPA Services provides SOC 1, SOC 2 and SOC 3 reports, alongside CMMC, PCI DSS and ISO work, for clients including cloud hosting, financial services, healthcare and AI providers.
Eden Data
- Readiness consultant / vCISO
- SOC 2
- GDPR
- HIPAA
- ISO 27001
- ISO 42001
- HITRUST
- CMMC
- FedRAMP
Austin, Texas-based compliance and security firm (branded 'A Riveron Co') offering managed SOC 2, ISO 27001, HIPAA and other framework readiness programs on monthly retainers, GRC tool management for Drata and Vanta, pentesting services and CISO support.
Eide Bailly
- Audit firm
- SOC 1
- SOC 2
- SOC 3
US accounting and advisory brand whose attest services are provided by Eide Bailly LLP; offers SOC 1, SOC 2, SOC 3, SOC for Cybersecurity and SOC for Supply Chain reports, plus SOC readiness assessments.
EisnerAmper
- Audit firm
- SOC 1
- SOC 2
- SOC 3
US accounting and advisory firm whose attest services are provided by EisnerAmper LLP; performs SOC 1, SOC 2, SOC 2+ and SOC 3 examinations (Type 1 and Type 2), naming AI and SaaS companies among industries, with 30+ US offices.
Elasticito
- Readiness consultant / vCISO
- NIS2
- SOC 2
- ISO 27001
- TISAX
London-based company offering compliance automation and governance, continuous cyber risk assessment, third-party risk management, managed security and automated penetration testing, with readiness for NIS 2, SOC 2, ISO 27001, TISAX and Part-IS.
Elliott Davis
- Audit firm
- SOC 1
- SOC 2
- HITRUST
Licensed CPA firm (Elliott Davis, LLC) with offices in South Carolina, North Carolina, Tennessee and Bengaluru, India, offering SOC 1, SOC 2, SOC 2 + HITRUST, SOC for Cybersecurity, SOC for Supply Chain and SOC readiness assessments.
Eramba
- Compliance platform
- ISO 27001
- NIS2
- DORA
- GDPR
- SOC 2
Open-source GRC and compliance software with a free on-premises Community edition and paid Enterprise editions (on-premises or EU/US-hosted SaaS) at a flat annual fee with unlimited users; supports ISO 27001, NIS2, DORA, GDPR and SOC 2. Offices in Bratislava and London.
ETL consit GmbH
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Bad Oldesloe-based member of the ETL Group offering audits of outsourced services and control systems under IDW PS 951, ISAE 3402 and SSAE 18 (SOC 1, SOC 2, SOC 3 named), for banks, insurers, pharmaceutical and finance clients.
eVerity Ltd
- Readiness consultant / vCISO
England-registered information and cyber security firm (eVerity Ltd, operating since 2012) providing advisory and technical services including discovery and analysis, incident response, monitoring and ongoing management.
EY (Ernst & Young)
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HITRUST
- TISAX
Big Four professional services network; its US technology risk practice offers SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports, SOC readiness assessments, other attestations (e.g. HITRUST, TISAX) and ISO certifications through EY CertifyPoint.
FinAudit CPA
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- HIPAA
- PCI DSS
- GDPR
- CMMC
US CPA firm based in Billings, Montana, offering SOC 1, SOC 2 (Type I and II) and SOC 3 reports, SOC readiness, ISO/HIPAA/PCI DSS/GDPR work and penetration testing, serving SaaS/technology, financial services, healthcare and e-commerce clients.
Fine Assurance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- HIPAA
- GDPR
Pennsylvania-licensed CPA firm (Fine CPA LLC dba Fine Assurance) offering SOC 1, SOC 2, SOC 2+ and SOC 3 audits, ISO 27001/42001 internal audits, HIPAA and privacy assessments, and a SOC report quality certification for CPA firms.
Flexible IT
- Readiness consultant / vCISO
- HIPAA
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
Hauppauge, New York managed IT provider serving Long Island businesses since 1984, offering IT support, cybersecurity and compliance support for HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR, NIST and NYDFS, working with Vanta.
Formalize
- Compliance platform
- NIS2
- DORA
- GDPR
- ISO 27001
- EU AI Act
European compliance/GRC platform for NIS2, DORA, GDPR, ISO 27001 and the EU AI Act, with offices in Denmark, Spain, Italy and Germany. The same company also offers the Whistleblower Software product.
Formiti Data International
- Readiness consultant / vCISO
- GDPR
Data privacy and AI governance consultancy offering outsourced DPO, EU/UK/Swiss GDPR representative services, Thailand PDPA compliance, AI vendor risk management and AI governance services. Also sells a Privacy360 platform.
Fortreum
- Audit firm
- SOC 1
- SOC 2
- FedRAMP
- CMMC
- ISO 27001
- ISO 27701
- HIPAA
- PCI DSS
Assessment firm for FedRAMP, CMMC, GovRAMP, PCI DSS, ISO 27001/27701, HIPAA and SOC 1/SOC 2, serving cloud providers, SaaS and defense contractors; SOC attestation is provided by affiliated CPA firm Fortreum Associates.
Forvis Mazars
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HITRUST
US accounting firm (Forvis Mazars, LLP, member of Forvis Mazars Global) with a national SOC and HITRUST practice offering SOC 1, SOC 2 and SOC 3 reports, SOC readiness and HITRUST e1/i1/r2 assessments.
Frank, Rimerman + Co. LLP
- Audit firm
- SOC 1
- SOC 2
- CSA STAR
- ISO 27001
- ISO 27701
San Francisco Bay Area accounting firm (Baker Tilly International member) whose IT audit team performs SOC 1 and SOC 2 examinations, CSA STAR Level 2 audits and, via an ANAB-accredited unit, ISO 27001/27701 certification audits.
Frazier & Deeter
- Audit firm
US-licensed public accounting firm (Frazier & Deeter, LLC) with offices across the US and in Cambridge and London, UK; lists SOC reporting and cybersecurity advisory among services for technology and SaaS/PaaS/IaaS companies.
Gabriel Registrar
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- CSA STAR
Dubai-based registrar offering SOC 1, SOC 2 and SOC 3 readiness, gap analysis, implementation and audit support; states attestation is provided by CPA auditors and describes CSA STAR and ISO 17021 accreditation.
GBQ Partners
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HIPAA
- HITRUST
- GDPR
CPA and business advisory firm with offices in Columbus, Cincinnati, Toledo and Indianapolis, offering SOC 1, SOC 2, SOC 2+ and SOC 3 examinations with readiness, plus cybersecurity services including penetration testing and vCISO.
GDPRLocal
- Readiness consultant / vCISO
- GDPR
- EU AI Act
- ISO 27001
- SOC 2
- HIPAA
Brighton, England-based data protection consultancy (GDPRLocal Ltd) providing GDPR Article 27 EU/UK representative, Swiss FADP representative, outsourced DPO, GDPR consultancy, AI governance and EU AI Act representative services, plus SOC 2 / ISO 27001 information security advice.
Geels Norton
- Audit firm
- SOC 1
- SOC 2
Durham, North Carolina firm (Geels Norton PLLC) performing SOC 1 and SOC 2 Type 1/Type 2 audits and SOC readiness for emerging and high-growth cloud technology and SaaS companies; also lists ISO and SSPA services.
Genius GRC
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
Cybersecurity compliance consultancy founded in 2022 offering SOC 2, ISO 27001, HIPAA, PCI and FTC Safeguards compliance consulting, vCISO and advisory CISO services, security architecture consulting and Vanta compliance operations monitoring.
Grant Thornton
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HITRUST
- ISO 27001
- HIPAA
- FedRAMP
- CMMC
US member of the Grant Thornton network; attest services by Grant Thornton LLP, a licensed CPA firm. Offers SOC 1, SOC 2/SOC 2+, SOC 3, SOC for Supply Chain and SOC for Cybersecurity reports, HITRUST assessments and readiness for ISO 27001, HIPAA, FedRAMP and CMMC.
Grassi
- Audit firm
- SOC 1
- SOC 2
Accounting and advisory firm whose attest services are provided by Grassi & Co. Certified Public Accountants, PC; offers SOC 1 and SOC 2 audits and SOC readiness assessments, with offices in NY, NJ, CT, MA, CO, FL and Rome, Italy.
GRC Concierge
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
Ottawa-based GRC consultancy (affiliate of WCS North America / Wesley Clover International) offering GRC and audit-readiness support, vCISO services and managed security (MSSP) for SOC 2, ISO 27001 and HIPAA, working with Vanta and Drata.
GRSee
- Readiness consultant / vCISO
- Audit firm
- SOC 2
- SOC 3
- ISO 27001
- ISO 42001
- ISO 27701
- PCI DSS
- HIPAA
- HITRUST
- GDPR
- CMMC
- DORA
- NIS2
- EU AI Act
Compliance and security firm (GRSee Consulting, founded 2009, offices in the US, Europe and Middle East) offering SOC 2, ISO 27001/42001/27701, PCI DSS, HIPAA, GDPR, DORA, NIS2 and EU AI Act compliance, penetration testing and vCISO for SaaS, fintech, health tech and AI companies.
HackerOne
- Pentest platform
- SOC 2
- ISO 27001
- GDPR
- DORA
Offensive security platform offering bug bounty programs, pentest-as-a-service (agentic AI plus human testers), continuous testing and AI red teaming; pentest reports are positioned for SOC 2, ISO 27001, GDPR and DORA evidence.
Harmless
- Readiness consultant / vCISO
Technology ethics coaching and advisory service. Its homepage lists ethical leadership, an independent ethics advisor service, AI innovation confidence and aligned AI strategy.
Hicomply
- Compliance platform
- ISO 27001
- SOC 2
- GDPR
- DORA
- ISO 42001
UK compliance management (ISMS) platform automating ISO 27001, SOC 2, NIST, GDPR, DORA, NHS DSPT and ISO 42001 compliance, with a customer success manager on every plan and published annual UK and US pricing. Based in North Shields, England, with offices in Manchester and Denver.
HLB Mann Judd
- Audit firm
Australian and New Zealand accounting and advisory firm, member of HLB International, with 10 offices. No SOC service found on the homepage.
Hopae Inc.
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- GDPR
Seoul-based Hopae Inc. offers Vanta to Korean companies (local tax invoicing, government subsidy/voucher eligibility) for SOC 2, ISO 27001, HIPAA and GDPR compliance.
Hyperproof
- Compliance platform
- HIPAA
- CMMC
- PCI DSS
- SOC 2
- ISO 27001
- DORA
- NIS2
- FedRAMP
- GDPR
- HITRUST
GRC and compliance platform headquartered in Seattle, US, supporting 160+ frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, CMMC, DORA and NIS2, with an audit module; serves healthcare, technology, fintech, aviation and manufacturing.
IMJ Assessment and Registration Center Co., Ltd.
- ISO certification body
- ISO 27001
- ISO 27701
Yokohama-based certification body founded in 2000, certifying ISO/IEC 27001, 27017 and 27701 alongside ISO 9001, 14001, 45001, 22301, 39001, 50001 and SA 8000, including integrated audits. ISMS-AC lists it for ISMS (ISR029).
Innovative Quality Certifications Pvt. Ltd.
- ISO certification body
- ISO 27001
- ISO 27701
Pune-based certification body offering assessment and certification for ISO 27001, ISO 27701, ISO 22301 and other ISO standards, plus CMMI, VAPT and cyber security training. NABCB lists it for ISO/IEC 27001 (IS 018).
Insight Assurance
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- HIPAA
- HITRUST
- PCI DSS
- FedRAMP
- CMMC
- GDPR
- CSA STAR
Assurance firm offering SOC 1, SOC 2 and SOC 3 examinations plus ISO 27001/27701/42001, HITRUST, PCI DSS, FedRAMP, CMMC, CSA STAR assessments and penetration testing, with SaaS and cloud providers among its stated focus.
INT Inc.
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- GDPR
- HIPAA
Lincolnshire, Illinois firm offering information security program discovery, implementation, audit preparation and GRC platform (Vanta) management for SOC 2, ISO 27001, GDPR and HIPAA, alongside IT, operations and marketing services.
International Certificate authority of Management System Co., Ltd. (ICMS)
- ISO certification body
- ISO 27001
- PCI DSS
Tokyo-based certification body performing ISMS (ISO/IEC 27001) and cloud security certification and PCI DSS assessments, serving card companies, fintech firms, service providers and merchants. Offices in Sapporo, Seoul and Bangkok. ISMS-AC lists it for ISMS (ISR010).
International Certification Services Pvt. Ltd.
- ISO certification body
- ISO 27001
Mumbai-based certification, inspection and training body with 30 offices in India, certifying ISO 9001, 14001, 22000, ISO 27001 and other management system and product standards. NABCB lists it for ISO/IEC 27001 (IS 019).
International System Audit Co., Ltd. (ISA)
- ISO certification body
- ISO 27001
Nagoya-based certification body founded in 2000, certifying ISO/IEC 27001 and ISMS cloud security (ISO/IEC 27017) alongside ISO 9001, 14001 and 45001, for new certifications and transfers from other bodies. ISMS-AC lists it for ISMS (ISR024).
Iru
- Compliance platform
Device, identity and endpoint management platform (formerly Kandji) with a separate AI-driven compliance automation product that maps controls and evidence; supports migrating controls from other compliance tools.
IS Certification Co., Ltd.
- ISO certification body
- ISO 27001
Tokyo-based ISMS certification body, accredited by ISMS-AC in November 2023, certifying ISO/IEC 27001 and ISO/IEC 27017 (cloud security) with auditors who are cybersecurity consultants and engineers. ISMS-AC lists it for ISMS (ISR031).
IS Partners
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 42001
- PCI DSS
- HIPAA
- HITRUST
- CMMC
- GDPR
- DORA
Firm whose site lists SOC 1, SOC 2, SOC 3, ISO 27001, ISO 42001, PCI DSS, HIPAA, HITRUST and CMMC services plus penetration testing, with offices in Dresher, Pennsylvania and London.
ISMS.online
- Compliance platform
- ISO 27001
- ISO 42001
- ISO 27701
- SOC 2
- GDPR
- NIS2
- DORA
- PCI DSS
- HIPAA
- Cyber Essentials
UK-based platform (branded 'IO') for managing information security, privacy and AI governance management systems, covering ISO 27001, ISO 42001, ISO 27701, SOC 2, GDPR, NIS2, DORA, Cyber Essentials and other standards. Pricing is quote-based. Based in Brighton, England.
ISSPL Limited (IRQS)
- ISO certification body
- ISO 27001
- ISO 27701
- SOC 2
- GDPR
- HIPAA
Mumbai-based certification body (Indian Register Quality Systems) of the Indian Register of Shipping group, certifying ISO 27001, ISO 27701 and many other ISO standards, with offices in India and abroad. Also offers SOC 2 readiness and VAPT; SOC 2 reports come from an outside CPA.
J-VAC Co., Ltd.
- ISO certification body
- ISO 27001
Tokyo-based certification body auditing and certifying ISO/IEC 27001 alongside ISO 9001, 14001, 45001, ISO/IEC 20000-1 and ISO 21401 (accommodation sustainability). ISMS-AC lists it for ISMS (ISR017).
Japan Approvals Institute for Telecommunications Equipment (JATE), ISMS Registration Center
- ISO certification body
- ISO 27001
Tokyo-based telecommunications terminal equipment approval body whose ISMS Registration Center audits and registers ISO/IEC 27001 (JIS Q 27001) information security management systems. ISMS-AC lists it for ISMS (ISR013).
Japan Audit and Certification Organization (JACO)
- ISO certification body
- ISO 27001
- ISO 27701
Tokyo-based certification body founded in 1994 with a Kansai branch in Osaka, certifying ISO/IEC 27001, 27017 and 27701 alongside ISO 9001, 14001, 45001, 20000, 22301 and other management system standards. ISMS-AC lists it for ISMS (ISR007).
Japan Chemical Quality Assurance Ltd. (JCQA)
- ISO certification body
- ISO 27001
Tokyo-based certification body founded in 1993, certifying ISO/IEC 27001 and ISMS cloud security alongside ISO 9001, 14001, 22000, 45001, 55001, HACCP and GHG verification, serving chemical, pharmaceutical, plastics, metals and food sectors among others. ISMS-AC lists it for ISMS (ISR026).
Japan Electrical Safety & Environment Technology Laboratories (JET), ISO Registration Center
- ISO certification body
- ISO 27001
Tokyo-based electrical safety testing foundation whose ISO Registration Center certifies ISO/IEC 27001 alongside ISO 9001, 14001, 45001, 50001 and 13485, with integrated audits available. ISMS-AC lists it for ISMS (ISR028).
Japan Inspection Certification Quality Assurance (JICQA)
- ISO certification body
- ISO 27001
- ISO 27701
Japanese certification body founded in 1992, certifying ISO/IEC 27001, 27017 and 27701 among many ISO standards, plus JIS product certification and sustainability verification, for organisations of all sizes. ISMS-AC lists it for ISMS (ISR002).
Japan Quality Assurance Organization (JQA), Management System Division
- ISO certification body
- ISO 27001
- ISO 27701
- ISO 42001
Japanese general incorporated foundation certifying management systems including ISO/IEC 27001, 27017, 27701 and 42001 (AI), with offices across Japan and in Thailand, Vietnam and Germany. ISMS-AC lists it for ISMS and ISMS-PIMS (ISR001).
Japanese Standards Association Solutions (JSA-SOL), Certification Division
- ISO certification body
- ISO 27001
Certification division of JSA Solutions Co., Ltd., based in Tokyo with a Kansai branch in Osaka, certifying ISO/IEC 27001 and 27017 alongside ISO 9001, 14001, 45001, 22301 and other standards in Japan. ISMS-AC lists it for ISMS (ISR006).
JMA Quality Assurance Registration Center (JMAQA)
- ISO certification body
- ISO 27001
- ISO 42001
Certification division of the Japan Management Association, founded 1994, certifying ISO/IEC 27001 and 27017 among many ISO and food-safety schemes, and announcing ISO/IEC 42001 certification from October 2026. Has a Kansai office in Osaka. ISMS-AC lists it for ISMS (ISR011).
Johanson Group LLP
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 42001
- HIPAA
- GDPR
- PCI DSS
Colorado Springs-based audit firm offering SOC 1, SOC 2 and SOC 3 reports, SOC 2 readiness, and ISO 27001/42001, PCI DSS, HIPAA and GDPR work for technology/SaaS, AI, financial services, healthcare, government and education clients.
JUSE ISO Center (Union of Japanese Scientists and Engineers)
- ISO certification body
- ISO 27001
- ISO 27701
ISO certification centre of the Union of Japanese Scientists and Engineers (a Tokyo-based general incorporated foundation), certifying ISO/IEC 27001, 27017, 27018 and 27701 among other standards. ISMS-AC lists it for ISMS and ISMS-PIMS (ISR005).
Kaamel Technology
- Readiness consultant / vCISO
- SOC 2
- GDPR
- HIPAA
- ISO 27001
- ISO 27701
- EU AI Act
- PCI DSS
- ISO 42001
- TISAX
Mountain View, California compliance firm (Silicon Valley and Asia delivery) offering SOC 2, ISO 27001/27701, GDPR, HIPAA and EU AI Act compliance, vCISO and vDPO services and penetration testing, with Drata and Vanta partnerships.
Kaufman Rossin
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Florida-based accounting and advisory firm offering SOC 1, SOC 2 and SOC 3 reports (Type 1 or Type 2), plus SOC 2 Plus, SOC for Cybersecurity and SOC for Supply Chain, with offices in Florida, New York, India and Ivory Coast.
Kertos
- Compliance platform
- ISO 27001
- ISO 42001
- ISO 27701
- GDPR
- NIS2
- EU AI Act
- SOC 2
- TISAX
Munich-based compliance automation platform (Kertos GmbH, also in Berlin) for ISO 27001, ISO 42001, ISO 27701, GDPR, NIS2, EU AI Act, SOC 2, TISAX and C5, serving healthtech, fintech and SaaS companies; higher plans add expert, external DPO and CISO support.
KirkpatrickPrice
- Audit firm
- SOC 1
- SOC 2
- PCI DSS
- HITRUST
- ISO 27001
- ISO 42001
- HIPAA
- CMMC
Nashville-headquartered licensed CPA firm, PCI QSA and HITRUST assessor performing SOC 1 and SOC 2 audits, PCI DSS, HITRUST, ISO 27001, ISO 42001 and HIPAA assessments, and penetration testing, with US offices in ten cities.
Kiwa
- ISO certification body
- SOC 1
- SOC 2
Certification body whose Dutch-language page covers ISAE 3402 and ISAE 3000 audits and SOC 1 and SOC 2 reporting (Type I and II) for hosting providers, SaaS vendors, datacenters and healthcare.
Klaay
- Compliance platform
- SOC 2
- HIPAA
AI-native compliance platform for SaaS startups covering SOC 2 and HIPAA, with monthly plans priced by employee count; audits and pentests are paid separately to third-party firms. Offices in San Diego and Copenhagen.
Kobalt.io
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- ISO 42001
- HIPAA
- GDPR
- PCI DSS
- CMMC
- FedRAMP
- HITRUST
Vancouver-founded security and compliance provider (Kobalt Security Inc.) offering SOC 2, ISO 27001/42001, HIPAA and other compliance programs, vCISO, penetration testing, privacy/AI governance and 24/7 managed threat detection; works on Vanta, Drata and Scrut for SaaS, fintech and health tech firms.
Konfirmity
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- GDPR
Compliance platform offered self-run or as a managed service, covering SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR for SaaS, fintech and healthtech companies; coordinates with external auditors. Serves clients in Singapore, US, Australia, Thailand and Germany.
KPMG
- Audit firm
US member of the KPMG network (KPMG LLP) offering advisory, audit and assurance, and tax services, including cyber security advisory. No SOC service page was found on the US homepage.
Latacora
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- GDPR
Latacora, LLC builds and runs in-house-style security programs for technology companies on a month-to-month basis: virtual CISO, risk and compliance (SOC 2, ISO 27001, HIPAA, GDPR), application security, cryptography, infrastructure and IT security, and detection and response.
Lazarus Alliance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- CMMC
- FedRAMP
- HIPAA
- PCI DSS
- ISO 27001
Describes itself as a licensed CPA firm specializing in SOC 1 and SOC 2 audits, also offering SOC 3, SOC for Cybersecurity, SOC for Supply Chain and virtual CISO advisory, for technology, finance, healthcare, government and fintech clients.
LBMC
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HIPAA
- HITRUST
- ISO 27001
- ISO 27701
- ISO 42001
- PCI DSS
- FedRAMP
- CMMC
Accounting and advisory firm based in Brentwood, Tennessee, performing SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity examinations with readiness, plus HITRUST, PCI DSS, penetration testing and ISO certification via LBMC Certification Services, LLC; serves healthcare, financial services and SaaS.
Linford & Company LLP
- Audit firm
- SOC 1
- SOC 2
- HIPAA
- HITRUST
- FedRAMP
- CMMC
- ISO 27001
- ISO 27701
- ISO 42001
- PCI DSS
- CSA STAR
Denver-based CPA firm (Linford & Company, LLP) performing SOC 1 and SOC 2 audits plus HIPAA, HITRUST, FedRAMP/GovRAMP, CMMC, ISO 27001/27701/42001, PCI DSS and CSA STAR assessments and penetration testing.
Logic Weave
- Readiness consultant / vCISO
- ISO 27001
- SOC 2
Melbourne cyber security consultancy (Synverra Pty. Ltd. trading as Logic Weave) offering fractional CISO, ISO 27001 readiness, SOC 2 Type 2, Essential Eight, CPS 230/234, GRC-as-a-service, internal audit and penetration testing for Australian SaaS, fintech and health tech firms.
LogicGate
- Compliance platform
- ISO 27001
- PCI DSS
- SOC 2
- GDPR
- HIPAA
Chicago-based GRC platform (Risk Cloud) with AI agents and 30+ applications for risk and compliance programmes, supporting frameworks such as SOC 2, ISO 27001, PCI DSS, HIPAA and GDPR; serves financial services, insurance, healthcare, manufacturing and technology.
LowerPlane
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- PCI DSS
Compliance automation platform for SOC 2, ISO 27001, HIPAA, GDPR and PCI DSS with published annual plans (one to three frameworks); solution pages target AI startups, SaaS, fintech, healthcare and ecommerce. Auditor fees are paid separately.
LRQA
- ISO certification body
- ISO 27001
- ISO 27701
- ISO 42001
Birmingham, UK-headquartered certification and assurance body offering accredited ISO/IEC 27001:2022 certification plus ISO 27701, 27017, 27018, 22301 and 42001, with training, gap analysis and integrated audits, delivered on-site or remotely; states it operates in over 55 countries.
Lyrical Security Ltd.
- Readiness consultant / vCISO
Security services firm co-founded in 2014 serving North American customers from SMBs to Fortune 500 with advisory, professional and managed services, offensive security, managed compliance automation, MDR and vulnerability management.
Mallette
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Canadian firm offering SOC 1 / CSAE 3416 audits and SOC 2, SOC 2+ and SOC 3 reporting, with support at every stage; SOC 2 page targets SaaS vendors, healthcare providers and financial institutions.
Management System Assessment Center Co., Ltd. (MSA)
- ISO certification body
- ISO 27001
- ISO 27701
Tokyo-based certification body with branches across Japan (Kansai, Sapporo, Tohoku, Hokuriku, Chubu, Kyushu), certifying ISO/IEC 27001, 27017 and 27701 alongside ISO 9001, 14001, 45001, 55001 and JIS product certification. ISMS-AC lists it for ISMS (ISR016).
Manning Elliott LLP
- Audit firm
Chartered professional accountancy firm in British Columbia offering tax, audit, accounting and business advisory services. No SOC service found on the homepage.
Mastermind
- ISO certification body
- Audit firm
- ISO 27001
- ISO 27701
- ISO 42001
- CSA STAR
Alpharetta, Georgia-based certification body accredited by IAS (claimed) for management systems, offering ISO 27001, 27701, 42001, 27017/27018 and CSA STAR certification audits plus lead auditor training; states 500+ certification audits.
Maverick Quality Advisory Services Pvt. Ltd.
- ISO certification body
- ISO 27001
- ISO 27701
Indian ISO certification body that also runs CMMI appraisals, process consulting and training, with offices in Delhi NCR (India) and Virginia (US). NABCB lists it for ISO/IEC 27001 (IS002) and ISO/IEC 42001 (AI 003) certification.
McKonly & Asbury
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HIPAA
- HITRUST
- CMMC
- ISO 27001
Pennsylvania CPA firm founded in 1973 with offices in Camp Hill, Lancaster, Bloomsburg and Philadelphia, performing SOC 1, SOC 2 (Type 1 and 2) and SOC 3 audits and readiness, plus HIPAA, HITRUST, CMMC and ISO 27001 services.
MGO (Macias Gini & O'Connell)
- Audit firm
- SOC 2
- ISO 27001
- HIPAA
- CMMC
- NIS2
- DORA
- NIST AI RMF
Accounting and consulting firm (Macias Gini & O'Connell LLP) with a cybersecurity practice listing SOC 2 among framework readiness services. No SOC examination service found on the pages checked.
Mirai Security
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- CMMC
- FedRAMP
North American cyber security firm (Mirai Security Inc.) offering SOC 2 and ISO 27001 gap assessments and implementation guidance, penetration testing, a 'Virtual Security Office', incident response, cloud assessments and CMMC/CPCSC and FedRAMP compliance.
MJD Advisors, LLC
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 42001
- HIPAA
- HITRUST
- GDPR
CPA firm founded in 2021 that focuses on SOC 1, SOC 2 and SOC 3 reports and also offers ISO 27001/42001 readiness and HIPAA, HITRUST and GDPR services, with fixed-fee pricing and clients across the Americas, Europe, Africa and Asia-Pacific.
Modern Assurance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- CMMC
- HIPAA
- GDPR
Peer-reviewed CPA firm registered in Oregon, licensed in most US jurisdictions, performing SOC 1, SOC 2 and SOC 3 examinations and ISO 27001, ISO 27701, ISO 42001, CMMC, HIPAA and GDPR audits, plus financial statement work.
Moore Colson
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Atlanta-based CPA firm offering SOC 1, SOC 2 (Type 1 or Type 2) and SOC 3 reports, plus SOC readiness, to service organizations including clients in Illinois.
Moore Kingston Smith
- Audit firm
- SOC 1
- SOC 2
London-area firm whose control assurance team helps organisations design, assess and evidence internal controls, with an insight page covering SOC 1, SOC 2 and ISO-to-SOC routes, for financial services, SaaS and fintech clients.
MOOS Accountants
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Audit-only accountancy firm with registered accountants and EDP auditors, stating it issues ISAE 3402, SOC 1, SOC 2, SOC 3 and ISAE 3000 reports; offices in Diemen, Emmeloord and Podgorica; focus includes SaaS, payment services and crypto.
Mycroft
- Compliance platform
- SOC 2
- ISO 27001
- ISO 42001
- HIPAA
- GDPR
- CMMC
- FedRAMP
- EU AI Act
AI-driven security and compliance platform from a Canadian company (Toronto) combining GRC for SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CMMC and FedRAMP with cloud security, awareness training and a trust center; higher tiers add penetration testing and a dedicated CISO.
NDB
- Audit firm
- SOC 1
- SOC 2
- HIPAA
- HITRUST
- ISO 27001
- PCI DSS
- GDPR
Atlanta-addressed firm offering fixed-fee SOC 1 (SSAE 18) and SOC 2 Type 1 and Type 2 audits and readiness, including SOC 2 for AWS, Azure and GCP environments and SOC 2 + HIPAA/HITRUST, plus ISO 27001 and PCI DSS audits; works with Vanta, Drata and other platforms.
Nippon Kaiji Kentei Quality Assurance Ltd. (NKKK QA)
- ISO certification body
- ISO 27001
Tokyo-based certification body founded in 1993, certifying ISO 27001 alongside ISO 9001, 14001, 22000, FSSC 22000, 39001 and 45001, with roots in the maritime sector; also runs training courses. ISMS-AC lists it for ISMS (ISR023).
OmniCyber Security Ltd
- Readiness consultant / vCISO
- ISO 27001
- ISO 42001
- Cyber Essentials
- PCI DSS
- GDPR
Security services firm with offices in Birmingham (UK) and Vancouver (Canada) offering penetration testing, red teaming, security audits, virtual CISO, third-party risk management and training; listed as a CREST member for penetration testing.
Oneleet
- Compliance platform
- SOC 2
- HIPAA
- ISO 27001
- GDPR
- PCI DSS
- DORA
US security and compliance platform (Oneleet Inc., Delaware) for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, DORA and other frameworks, aimed at SaaS companies; it manages auditor interactions for customers.
OpenGRC
- Compliance platform
- ISO 27001
- SOC 2
- HIPAA
GRC web application for small and mid-sized businesses and MSSPs covering risk management, controls, audits, vendor risk and incident response for ISO 27001, SOC 2 and HIPAA. Free self-hosted Community edition (Elastic License 2.0) and paid cloud-hosted Enterprise packages.
Openlane
- Compliance platform
- SOC 2
- ISO 27001
- ISO 42001
- HIPAA
- PCI DSS
- GDPR
Open-source compliance platform for defining controls and linking policies and evidence, supporting SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, GDPR and NIST 800-53. Compliance module published at $450/month with unlimited users and a read-only auditor role.
Oread Risk & Advisory
- Audit firm
- Readiness consultant / vCISO
- HIPAA
- PCI DSS
Attestation, information security and compliance consulting firm offering SOC reporting and audits, IT audits, HIPAA assessments, PCI consulting, vulnerability assessments and penetration testing, and vendor due diligence.
PA Consulting
- Readiness consultant / vCISO
- GDPR
Large management and technology consultancy with offices in the UK, US and Nordics/Europe whose data privacy and ethics practice offers privacy maturity programmes, managed privacy services, DPIAs, privacy tooling and data/AI ethics frameworks, alongside cyber security services including CISO support.
Paramify
- Compliance platform
- FedRAMP
- CMMC
- SOC 2
- HITRUST
Compliance automation platform for US government authorizations, generating SSPs, policies, procedures and POA&Ms and running continuous monitoring for FedRAMP (incl. 20x), GovRAMP, CMMC, DoD ATO and FISMA, plus SOC 2 and HITRUST. Published annual pricing per framework. Based in Lehi, Utah.
Patronusec
- Readiness consultant / vCISO
- DORA
- PCI DSS
- ISO 27001
- TISAX
- NIS2
- Cyber Essentials
Poznan (Poland) security and compliance firm offering DORA compliance consulting, PCI certification audits, ISO 27001, TISAX, NIS2 and Cyber Essentials support, vCISO, penetration tests and vulnerability scans for banks, insurers and payment providers.
PBMares
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Mid-Atlantic CPA and consulting firm (PBMares, LLP) offering SOC 1, SOC 2 and SOC 3 reports and readiness assessments, with offices in Virginia, North Carolina and Maryland.
Pease Bell CPAs
- Audit firm
- SOC 1
- SOC 2
Cleveland-headquartered US CPA firm with offices in Ohio, New Jersey and Florida whose audit and assurance practice performs SOC 1 and SOC 2 examinations; also issues ISO 27001 certificates (stated as unaccredited, IAS applicant).
Pentest-Tools.com
- Pentest platform
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- GDPR
Cloud pentesting and vulnerability scanning platform (PentestTools SA) with 25+ scanners; also sells human-led web, network, API, mobile and AI adversarial pentests and red teaming, with reports positioned for SOC 2, ISO 27001, PCI DSS, HIPAA and GDPR.
Penti
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- PCI DSS
- CMMC
Agentic AI penetration testing platform with human-validated findings and human-led expert pentest credits, plus virtual CISO services covering SOC 2, ISO 27001, NIST and GDPR audit preparation. Operated by Certypie Inc from Boca Raton, Florida.
Periculo
- Readiness consultant / vCISO
- ISO 27001
- ISO 42001
- HIPAA
- TISAX
- Cyber Essentials
UK cyber security consultancy (Melksham, Wiltshire) focused on digital health, medical devices, defence and AI platforms; offers CREST-listed penetration testing, ISO 27001 gap analysis and ISMS implementation, ISO 42001 and Gen AI governance, NHS DSPT and Cyber Essentials support.
Perry Johnson Holding Co., Ltd. / Perry Johnson Registrar (Japan)
- ISO certification body
Japanese certification body listed by ISMS-AC (Japan) as accredited for ISO/IEC 27001 certification (ISR012).
Pivot Point Security
- Readiness consultant / vCISO
- ISO 27001
- CMMC
- SOC 2
- PCI DSS
- FedRAMP
- GDPR
- HIPAA
- HITRUST
- TISAX
- ISO 42001
Site branded 'CBIZ Pivot Point Security' offering ISO 27001 certification support, virtual CISO, privacy, application and cloud security, penetration testing and a GRC platform. Headquarters shown as Hamilton, NJ with other US offices.
Prescient Security & Assurance
- Audit firm
- ISO certification body
- Readiness consultant / vCISO
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 27701
- ISO 42001
- PCI DSS
- HIPAA
- HITRUST
- CMMC
- FedRAMP
- DORA
- NIS2
- GDPR
Nashville-based security and assurance group whose CPA firm, Prescient Assurance LLC, performs SOC 1/2/3 audits; the group also offers ISO, PCI DSS, HIPAA, HITRUST, CMMC, FedRAMP, DORA and NIS2 assessments plus penetration testing, in the US, Europe, Australia and Asia-Pacific.
Probo
- Compliance platform
- SOC 2
- ISO 27001
- ISO 27701
- ISO 42001
- GDPR
- HIPAA
- NIS2
- DORA
Compliance platform with an open-source, self-hostable core, paired with a service where Probo compliance officers run the customer's program; covers SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, HIPAA, NIS2 and DORA.
Quality Asia Certifications Private Limited
- ISO certification body
- ISO 27001
Delhi-based certification body (trading as QualityAsia) offering management system certification including ISO 27001, alongside ISO 9001, 14001, 45001, 50001 and 22000. NABCB lists it for ISO/IEC 27001 (IS 013).
Qvalify AB
- ISO certification body
- ISO 27001
Swedish certification and inspection body headquartered in Jönköping with offices in Gothenburg and Stockholm, certifying ISO 27001, ISO 9001, ISO 14001, ISO 45001 and other standards. Swedac-accredited for ISO 27001.
Razorthorn Security
- Readiness consultant / vCISO
- DORA
- ISO 27001
- Cyber Essentials
- GDPR
- NIS2
- SOC 2
UK cybersecurity consultancy in Tunbridge Wells, active since 2007, offering consultancy, penetration testing and managed services, with compliance work on DORA, ISO 27001, SOC 2, NIS2, GDPR and Cyber Essentials.
Realize Security Ltd
- Readiness consultant / vCISO
UK application security firm offering code review-led pentests, AppSec diagnostics and retainers, vulnerability management programs, threat modelling and supply chain security; CREST member for penetration testing, fewer than 10 employees per CREST listing.
Red Citadel Limited
- Readiness consultant / vCISO
- PCI DSS
- Cyber Essentials
UK penetration testing company covering web apps, infrastructure, APIs, mobile, social engineering and AI/LLM systems, plus cloud security audits and IASME Cyber Essentials assessments; CREST member for penetration testing; pentest day rate published.
Red Sentry
- Pentest platform
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
Penetration testing provider with a PTaaS (penetration testing as a service) platform for tracking quotes, vulnerabilities and remediation reports; tests web apps, APIs, networks and cloud, including SOC 2 pentesting, for clients in SaaS, healthcare, finance and other sectors.
RegScale
- Compliance platform
Continuous controls monitoring and compliance automation platform covering 60+ frameworks, aimed at federal agencies, government contractors and the defence sector, financial services and high-tech companies.
Render Compliance
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HIPAA
- HITRUST
- FedRAMP
Seattle-based firm describing itself as a licensed CPA firm offering SOC 1, SOC 2, SOC 2+ and SOC 3 attestations and gap assessments, focused on SaaS companies with 200 to 2,000 employees.
Revolution InfoSec
- Readiness consultant / vCISO
- ISO 27001
- ISO 42001
- NIST AI RMF
Wellington, New Zealand security consultancy serving New Zealand and Australia with vCISO/vISM governance (ISO 27001, NIST CSF, Essential 8), OWASP-based penetration testing, training and tabletop exercises, and AI readiness, usage policy and governance advice referencing ISO 42001 and NIST AI RMF.
Rhymetec
- Readiness consultant / vCISO
- SOC 1
- SOC 2
- ISO 27001
- ISO 42001
- HIPAA
- HITRUST
- PCI DSS
- FedRAMP
- CMMC
- GDPR
- DORA
- NIS2
- EU AI Act
- Cyber Essentials
New York security firm (Rhymetec LLC, founded 2015 as a pentest company) offering vCISO, managed security, gap assessments, ISO internal audits and a wide range of pentesting incl. LLM pentesting, across SOC 2, ISO 27001/42001, HIPAA, PCI DSS, GDPR and EU AI Act for SaaS, AI, fintech and healthtech.
Richter
- Audit firm
Canadian independent business advisory and family office firm with offices in Montreal, Toronto, Calgary and Chicago. No SOC service found on the homepage.
RINKE TREUHAND GmbH Wirtschaftsprüfungsgesellschaft
- Audit firm
- SOC 1
- SOC 2
Wuppertal audit and tax firm offering service-provider control audits under IDW PS 951, ISAE 3402 and SSAE 18 with SOC 1 and SOC 2 reports, serving financial services, IT and technology, real estate and other sectors.
Riskpro
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HIPAA
- GDPR
Mumbai-based provider of SOC 1, SOC 2 and SOC 3 audits plus ISO 27001, HIPAA and GDPR services; states an in-house US-certified CPA and a Vanta partnership. Report signer not stated.
Riveron
- Readiness consultant / vCISO
Dallas-based finance, accounting and technology consulting firm (states it is not a CPA firm) that lists Drata among its technology alliance partners and publishes a partnership with Eden Data on risk advisory.
Rödl & Partner
- Audit firm
International legal, tax, audit and advisory firm with an IT audit and assurance practice offering ISAE 3402 (Type I and II), ISAE 3000 (C5) and IDW PS 951 audits. No SOC 1 or SOC 2 wording found on the pages checked.
RS Assurance & Advisory (RSAA)
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- HIPAA
- HITRUST
- CMMC
Southlake, Texas firm offering SOC 1/2/3 readiness and examinations, HIPAA and HITRUST support, CMMC and NIST readiness, and penetration testing coordination, mainly for SaaS, cloud and technology organisations.
RSM
- Audit firm
US member of the RSM International network offering assurance, tax and consulting, including risk, fraud and cybersecurity consulting. No SOC examination service was found on the pages that robots.txt allows.
Saepio Information Security
- Readiness consultant / vCISO
- Cyber Essentials
Cybersecurity services company offering cyber advisory, managed services and penetration testing (infrastructure, web app, API, red teaming), plus Cyber Essentials and NIST framework advisory; states Drata Elite partnership and NCSC Assured Service Provider status.
Sapphire
- Readiness consultant / vCISO
- Cyber Essentials
UK-owned IT and OT cyber security provider (Sapphire Technologies Ltd) with offices in Newcastle and Glasgow and a 24/7 SOC in Glasgow, offering managed detection and response, penetration testing (PTaaS), red teaming, vCISO/vISM, GRC consulting and Cyber Essentials.
SAV Associates
- Audit firm
- SOC 1
- SOC 2
- SOC 3
Canadian CPA firm and ISO certification body offering SOC 1, SOC 2 and SOC 3 examinations, CSAE/ISAE engagements, ISO certification and readiness, and threat and risk assessments.
SBcert AB
- ISO certification body
- ISO 27001
- SOC 2
Swedish certification body (website name Scandinavian Business Certification AB) certifying ISO 27001, ISO 9001, ISO 14001, ISO 45001 and industry schemes, and offering SOC 2 Type 1 and Type 2. Swedac-accredited for ISO 27001 and ISO 27701.
Schellman & Company
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- PCI DSS
- FedRAMP
- CMMC
- ISO 42001
Tampa-based, Florida-licensed and PCAOB-registered CPA firm focused on IT compliance: SOC 1, SOC 2, SOC 3 and SOC for Cybersecurity reports, plus PCI, ISO (incl. ISO 42001), FedRAMP and CMMC assessments and penetration testing.
Screenata
- Compliance platform
- SOC 2
- HIPAA
- ISO 27001
- ISO 42001
- GDPR
AI-driven compliance automation platform for 5-50 person B2B SaaS companies, using an AI agent to collect SOC 2 evidence via APIs and screenshots; also covers HIPAA, ISO 27001, ISO 42001 and GDPR. Priced per framework per year; the audit is bought separately.
Scrut Automation
- Compliance platform
- SOC 2
- ISO 27001
- GDPR
- PCI DSS
- HIPAA
- NIST AI RMF
Compliance automation and GRC platform covering SOC 2, ISO 27001, GDPR, PCI DSS, HIPAA and NIST AI RMF among 70+ frameworks, with cloud, code-repository and identity integrations; industries listed include financial services, healthcare and education.
Scytale
- Compliance platform
- SOC 2
- ISO 27001
- ISO 42001
- GDPR
- HIPAA
- PCI DSS
- CMMC
AI-assisted GRC and compliance automation platform with in-house compliance experts, covering SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, PCI DSS and CMMC; startup bundles add consulting and web-app pentests. Founded 2021; offices in the US, Israel, Czechia, Portugal and South Africa.
Secfix
- Compliance platform
- ISO 27001
- SOC 2
- TISAX
- GDPR
- DORA
- NIS2
- ISO 27701
- ISO 42001
German compliance automation platform (Secfix GmbH, offices in Berlin and Munich) for ISO 27001, SOC 2, TISAX, GDPR, DORA, NIS2 and ISO 42001, with cloud, identity, HR and device-management integrations; positions TISAX for automotive suppliers.
Securance
- Audit firm
- SOC 1
- SOC 2
- ISO 27001
- NIS2
- DORA
- GDPR
European assurance, cybersecurity and advisory firm with offices in the Netherlands, UK, Germany and Sweden that issues SOC 2 Type I and II reports under ISAE 3000, plus SOC 1/ISAE 3402 reports, ISO 27001, NIS2 and DORA support and penetration testing.
Secure Audit
- Audit firm
- SOC 2
- ISO 27001
- NIS2
- DORA
Eindhoven-based firm (Secure Audit B.V.) offering SOC 2, ISAE 3402 and ISAE 3000 assurance reports, ISO 27001 implementation, DigiD/BIO/NIS2/DORA assessments and pentesting through a continuous-auditing platform.
Secure Measure
- Readiness consultant / vCISO
- ISO 27001
- PCI DSS
- GDPR
Sydney-based security firm (incorporated 2018) offering a Vanta-powered virtual security office (vCISO), compliance for ISO 27001, PCI DSS and Essential Eight, risk management, AI governance and secure architecture, mainly for Australian SaaS and software businesses.
Secureframe
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- GDPR
- CMMC
Compliance automation platform with in-house compliance experts, covering SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST and CMMC 2.0. Founded 2020; 200+ employees; offices in the US, Canada and UK.
SecurePoint 360, LLC
- Readiness consultant / vCISO
- SOC 2
Security services firm for SMBs offering audit preparation and management (including SOC 2 Type II review), virtual CISO, penetration testing and vulnerability management as a service.
SecureSlate
- Compliance platform
- SOC 2
- ISO 27001
- ISO 42001
- HIPAA
- GDPR
- PCI DSS
- HITRUST
- CMMC
- FedRAMP
- NIS2
- EU AI Act
- DORA
- Cyber Essentials
London-based compliance automation and GRC provider for SOC 2, ISO 27001, ISO 42001, HIPAA and other frameworks, sold at fixed prices; serves financial services, healthcare and SaaS companies and coordinates with external auditors rather than auditing itself.
Securis360
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- GDPR
US-headquartered (Dallas, Texas) managed security provider offering 24x7 managed security operations, MDR, vulnerability assessment and penetration testing, and compliance services including SOC 2 audit readiness and ISO 27001; also lists its own compliance products.
Security Decoded
- Readiness consultant / vCISO
- ISO 27001
- SOC 1
- SOC 2
- PCI DSS
- GDPR
- HIPAA
Singapore-based security firm offering virtual CISO, virtual DPO, audits and compliance support (ISO 27001, SOC 1/SOC 2, PCI DSS, SWIFT CSP, GDPR, HIPAA), continuous pentesting, threat intelligence and incident response for startups and SMEs; partners with Vanta.
Seiso
- Readiness consultant / vCISO
- ISO 27001
- SOC 2
- CMMC
- HIPAA
Pittsburgh-area (Warrendale, PA) security consultancy, Seiso LLC, offering vCISO, managed GRC, ISO 27001, SOC 2 and CMMC programs, penetration testing, application/product and cloud security for growing companies incl. SaaS, healthtech, fintech and defense.
Sensiba LLP
- Audit firm
- ISO certification body
- SOC 1
- SOC 2
- SOC 3
- ISO 27001
- ISO 42001
- HITRUST
- HIPAA
- GDPR
- CSA STAR
CPA firm (formerly Sensiba San Filippo, rebranded 2023) whose governance, risk and compliance practice performs SOC 1, SOC 2 and SOC 3 engagements for SaaS, fintech and financial services firms, alongside HITRUST, HIPAA, CMMC readiness, NIST and penetration testing services.
Sentry Assurance
- Audit firm
- SOC 1
- SOC 2
- HIPAA
- ISO 27701
Cleveland, Ohio CPA firm performing SOC 1 and SOC 2 examinations and HIPAA, ISO 27701 and CCPA privacy and healthcare assessments.
SGS Japan Inc.
- ISO certification body
Japanese entity of the SGS group, listed by ISMS-AC (Japan) as accredited for ISO/IEC 27001 certification (ISR021).
SimpleRisk
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- GDPR
- FedRAMP
GRC platform covering governance, risk management, compliance testing, asset management and self-assessments, with a free open-source Core edition (self-hosted, unlimited users) and paid packages of add-on extras available on-premise or hosted. Claims 250+ mapped frameworks.
Software Secured
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- GDPR
Canadian penetration testing company (founded 2010) offering web/API, mobile, AI, cloud, network, IoT and hardware pentesting, secure code review, threat modelling and PTaaS, including pentests for SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR, for SaaS, AI, healthcare and finance firms.
Soter Advisory
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- HITRUST
- GDPR
Security compliance consultancy guiding small and medium businesses and startups from gap assessment to certification for SOC 2, ISO 27001, PCI DSS, HIPAA/HITRUST and GDPR, with vCISO and penetration testing services.
Sprinto
- Compliance platform
STQC IT Certification Services
- ISO certification body
- ISO 27001
Certification arm of the STQC Directorate, an attached office of India's Ministry of Electronics and IT. Offers ISO/IEC 27001 certification (NABCB IS003) since 2001 to IT, banking, telecom, healthcare, manufacturing and government organisations.
Strac (Strac Comply)
- Compliance platform
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- GDPR
- ISO 27701
- ISO 42001
- HITRUST
- CMMC
- FedRAMP
- DORA
- NIS2
- NIST AI RMF
- EU AI Act
- Cyber Essentials
- CSA STAR
- TISAX
Strac Comply is the compliance automation product of data-security (DLP/DSPM) vendor Strac, covering SOC 2, ISO 27001, PCI DSS, HIPAA and 25+ other frameworks for AI teams, SaaS companies and startups. Published annual plans; top plan bundles a vCISO, audit and pentest.
Strike Security
- Readiness consultant / vCISO
Offensive security company (founded 2021) offering pentesting as a service on an AI-powered continuous testing platform combined with human pentesters, plus manual pentest projects, red teaming, asset discovery and remediation support for finance, technology, telecom, energy, healthcare and manufacturing.
SureCloud
- Compliance platform
- ISO 27001
- ISO 42001
- SOC 2
- GDPR
- DORA
- NIS2
- PCI DSS
UK-headquartered GRC platform with a US office in Plano, TX, offering three plans (Assure, Automate, Orchestrate) and an AI assistant across compliance, risk, third-party risk, privacy, audit and AI governance; frameworks include ISO 27001, ISO 42001, SOC 2, DORA and NIS2.
Sustainable Certification
- ISO certification body
- SOC 2
Melbourne-based provider offering SOC 2 Type 1 and Type 2 audits where an AICPA member signs the attestation report, for SaaS, fintech, cloud and financial services clients.
Svensk Brand- och Säkerhetscertifiering AB
- ISO certification body
- ISO 27001
Stockholm-based certification body (SBSC) owned by Brandskyddsföreningen and Stöldskyddsföreningen, certifying companies, people and products in fire safety and security, plus ISO 27001 information security. Swedac-accredited for ISO 27001.
Svensk Certifiering Norden AB
- ISO certification body
- ISO 27001
- ISO 42001
Swedish certification body based in Åkersberga with auditors across Sweden, certifying ISO 27001, ISO 9001, ISO 14001, ISO 45001 and others. Swedac-accredited for ISO 27001; offers ISO 42001 as a non-accredited certification.
SystemBind Consulting & IT Services
- Readiness consultant / vCISO
Toronto-based IT services company offering IT consulting, data centre hosting, hybrid cloud and Azure services, managed desktop, disaster recovery, robotic process automation and information security consulting, with Ontario locations.
T3 Consultants
- Readiness consultant / vCISO
- EU AI Act
- ISO 42001
- NIST AI RMF
London-based AI governance and assurance consultancy (T3 Consultants Ltd) with a US contact number, offering AI inventory, human oversight, model assurance and AI compliance services covering the EU AI Act, ISO/IEC 42001 and NIST AI RMF.
Tagore AS
- Readiness consultant / vCISO
- ISO 27001
- SOC 2
- GDPR
Oslo-based security and compliance consultancy (founded 2021) and Vanta partner offering Vanta implementation and health checks, SOC 2 readiness, ISO 27001 and GDPR support, vCISO, penetration testing, internal audit and awareness training for SaaS, fintech and healthtech companies.
TechGDPR
- Readiness consultant / vCISO
- GDPR
Berlin-based GDPR consultancy offering compliance programmes, outsourced DPO, Art. 27 EU representative, DPIAs, AI ethics and compliance, and GDPR training, serving tech, fintech, health-tech and SaaS clients.
Tempo Audits
- Audit firm
- ISO certification body
- SOC 2
- ISO 27001
- ISO 42001
Certification and assurance provider (Tempo Audits Limited) offering ISO 27001 and ISO 42001 certification audits, stated as UKAS-accredited, and SOC 2 Type 1 and Type 2 assurance for SaaS, fintech and healthtech companies, with published GBP prices by headcount.
TestPros
- Readiness consultant / vCISO
- DORA
Sterling, Virginia testing and assessment firm offering accessibility audits plus security-framework and privacy-law assessments, including DORA compliance consulting for banks, insurers, payment providers and fintechs.
Tevora
- Readiness consultant / vCISO
- CMMC
- FedRAMP
- HITRUST
- HIPAA
- ISO 27001
- ISO 42001
- PCI DSS
- SOC 2
Cybersecurity consultancy offering compliance support (SOC 2, ISO, HITRUST, PCI, CMMC, FedRAMP), penetration testing, vCISO services, AI security programs and managed threat services for financial services, government and healthcare clients.
Thoropass
- Compliance platform
- Audit firm
- SOC 1
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- HITRUST
- CMMC
- Cyber Essentials
- GDPR
Compliance software combined with audit delivery: its CPA affiliate performs audits such as SOC 1, SOC 2, HITRUST and PCI DSS on its own audit lifecycle platform. Serves healthcare, SaaS and fintech companies. Founded 2019.
Throughline
- Audit firm
- SOC 1
- SOC 2
- ISO 27001
- ISO 42001
- GDPR
- HIPAA
Australia-based firm describing itself as a registered CPA firm and certification body, offering SOC 1 and SOC 2 audits and ISO 27001 and ISO 42001 certification, plus GDPR, HIPAA and Consumer Data Right work.
Trava Security
- Readiness consultant / vCISO
- ISO 42001
- FedRAMP
- GDPR
- SOC 2
- ISO 27001
- HITRUST
- HIPAA
Indianapolis-based security firm offering vCISO and advisory, penetration testing and managed compliance, pen test, training, vulnerability management and SOC programs for SaaS, AI, healthcare, financial services and defense clients.
Trilateral Research
- Readiness consultant / vCISO
- EU AI Act
UK and Irish research and consulting organisation founded in 2004 offering AI governance and compliance, responsible AI training, data protection and cybersecurity services, plus its Trilateral GRC Suite platform.
TrustCloud
- Compliance platform
- SOC 2
- ISO 27001
- CMMC
- HIPAA
- HITRUST
- GDPR
- ISO 27701
- ISO 42001
- NIST AI RMF
AI-based GRC and cyber risk assurance platform turning first- and third-party security signals into risk management, supporting SOC 2, ISO 27001, ISO 42001, HIPAA, HITRUST, CMMC and NIST AI RMF; aimed at CISOs in regulated industries, SMBs through enterprises.
Trustero
- Compliance platform
- SOC 1
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- CMMC
- FedRAMP
- DORA
Multi-agent AI GRC platform for enterprise, mid-market and MSSP security and compliance teams, covering evidence management, continuous control monitoring, policy assessment, questionnaire automation and a trust portal across SOC 1, SOC 2, ISO 27001, HIPAA, PCI, CMMC, FedRAMP and DORA.
TSC Security
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- GDPR
Security consultancy offering vCISO, SOC 2 readiness and compliance (using Vanta), ISO 27001 implementation, GDPR and HIPAA compliance, security program development and vulnerability management.
TÜV NORD
- ISO certification body
- ISO 27701
- TISAX
Hannover-based inspection and certification group. Register entries: TÜV NORD Nederland B.V. (RvA, ISO 27001/27701/42001) and TÜV India Pvt. Ltd. (NABCB, ISO 27001/42001), which runs system certification from offices across India.
TÜV Rheinland Japan Ltd.
- ISO certification body
- ISO 27001
- ISO 27701
Japanese subsidiary of the TÜV Rheinland group offering ISO/IEC 27001 certification, with ISO/IEC 27701 and cloud (27017/27018) extensions and remote audits under certain conditions. ISMS-AC accredited for ISO 27001.
TUV SUD South Asia Pvt. Ltd.
- ISO certification body
Indian entity of the TÜV SÜD group, listed by NABCB as accredited for ISO/IEC 27001 (IS001) and ISO/IEC 42001 (AI 002) certification.
UMIT Technologies
- Readiness consultant / vCISO
Tribal-owned managed service provider and systems integrator based in King William, Virginia, offering managed IT, cloud, cybersecurity and compliance, networking and Microsoft 365 services to government, healthcare and other clients.
URM Consulting Services
- Readiness consultant / vCISO
- ISO 27001
- PCI DSS
- SOC 2
- CMMC
- DORA
- NIST AI RMF
- ISO 42001
- GDPR
- Cyber Essentials
- NIS2
UK consultancy offering ISO 27001 and other management-system implementation, gap analysis, internal audit, penetration testing and training, including ISO 42001 AI management support, DORA, NIS 2 and GDPR advice. Also sells Abriska and Alurna software.
Uzado
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- GDPR
- PCI DSS
Canadian MSP and MSSP based in Richmond Hill, Ontario, offering SOC 2 readiness, ISO 27001 implementation, penetration testing and vCISO alongside managed detection, SIEM and IT services; Vanta partner serving clients in Canada and the US.
V-Comply
- Compliance platform
- ISO 27001
- PCI DSS
Palo Alto-based GRC suite (VComply) with compliance, policy, risk and case/incident modules for regulated organisations such as financial services, higher education, healthcare and manufacturing; supports ISO 27001, PCI DSS, SOX and NIST among others.
Valiido
- Compliance platform
- ISO 27001
- TISAX
ISMS software for ISO 27001 and TISAX (VDA ISA), formerly ISMS Connect, based in Darmstadt, Germany. Flat monthly plans include templates, policies, risk and vendor management, an expert pre-audit review and monthly expert calls. Serves corporate customers only.
Vanta
- Compliance platform
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- HITRUST
- ISO 42001
- NIST AI RMF
- FedRAMP
- CMMC
- NIS2
- DORA
- EU AI Act
- Cyber Essentials
Compliance automation platform covering 35+ frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA and FedRAMP, with automated evidence collection, trust center and questionnaire tools. Offices in the US, Australia, Ireland and the UK.
VerifyWise
- Compliance platform
- EU AI Act
- NIST AI RMF
- ISO 42001
- GDPR
- SOC 2
- HIPAA
- PCI DSS
- DORA
AI governance platform with model inventory, AI risk management, LLM evaluations, policy and evidence management, covering the EU AI Act, ISO 42001, NIST AI RMF and other frameworks. Available as SaaS or self-hosted; code is source-available under BSL 1.1. UK-registered company with a Toronto office.
Vexil Business Process Services Pvt. Ltd.
- ISO certification body
- ISO 27001
Delhi-based certification and training body (Vexil BPS) offering management system certification (ISO 9001, 14001, 45001, 50001, 22000, 10002 and ISO 27001), FSSAI third-party audits, ZED certification and safety audits. NABCB lists it for ISO/IEC 27001 (IS 014).
VioletX
- Readiness consultant / vCISO
- SOC 2
- CMMC
VISTA InfoSec
- Readiness consultant / vCISO
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
- NIS2
- DORA
- TISAX
- HIPAA
- ISO 42001
- EU AI Act
Cybersecurity audit and consulting group founded in 2004 with offices in India, the US, UK, Singapore, UAE and Estonia, offering penetration testing, PCI DSS, SOC 2, ISO 27001, GDPR, NIS2, DORA, ISO 42001 and EU AI Act services.
Wattlecorp Cybersecurity Labs
- Readiness consultant / vCISO
- DORA
- ISO 27001
- GDPR
- PCI DSS
- HIPAA
Cybersecurity firm with offices in the USA, UAE, India and Saudi Arabia offering vulnerability assessment and penetration testing, ISO 27001 consulting, DORA and other compliance consulting, and managed security services.
Welch LLP
- Audit firm
Chartered Public Accounting firm with offices across Ontario and Quebec, offering assurance and accounting and a cybersecurity service. No SOC service found on the homepage.
WeTransform
- Readiness consultant / vCISO
- ISO 27001
- SOC 2
Sydney-area (Rockdale, NSW) security consultancy offering security architecture, compliance and governance, risk and control assurance and security assessments, with frameworks including ISO 27001, SOC 2, APRA CPS 234/230 and Essential Eight.
White Label Consultancy
- Readiness consultant / vCISO
- GDPR
- NIS2
- DORA
- EU AI Act
- ISO 27001
- ISO 42001
Consultancy with offices in Oslo, Copenhagen, Warsaw and Dubai covering data protection, cybersecurity, AI governance and EU/Gulf regulation. Also sells its own Pritect GRC platform.
Workstreet
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- ISO 42001
- CMMC
- HIPAA
- HITRUST
- PCI DSS
- GDPR
- FedRAMP
Security and compliance services firm offering virtual CISO, SOC 2/ISO 27001 and other framework compliance, penetration testing, AI governance and security questionnaire support, with Vanta implementation, for tech and AI companies.
Xorabyte
- Readiness consultant / vCISO
- SOC 2
- ISO 27001
- HIPAA
- PCI DSS
- GDPR
Toronto-area fractional CISO practice for startups in Canada and the US, offering SOC 2 and ISO 27001 audit readiness, security questionnaires and ongoing security leadership on monthly retainers or fixed-scope projects, working in clients' existing Vanta or Drata.
YGI Solutions
- Readiness consultant / vCISO
- FedRAMP
- CMMC
- SOC 2
- PCI DSS
- HIPAA
- HITRUST
Compliance consulting firm focused on FedRAMP (including 20x) and CMMC, also offering audit readiness, virtual CISO, virtual GRC and Vanta implementation for defense, financial, healthcare and SaaS clients.
Zania
- Compliance platform
- SOC 2
- ISO 27001
- PCI DSS
- HIPAA
- GDPR
- ISO 42001
Agentic AI platform for risk and compliance work such as controls testing, risk assessments, third-party/vendor risk assessments and security questionnaires, covering SOC 2, ISO 27001, PCI, HIPAA, GDPR and ISO 42001. Enterprise plan with custom pricing. Based in Palo Alto, California.
Zaviant
- Readiness consultant / vCISO
- GDPR
- ISO 27001
- HIPAA
- SOC 2
- EU AI Act
- NIST AI RMF
- NIS2
Data privacy, security and risk consulting firm with offices in Philadelphia and Dublin, offering AI governance, third-party risk, regulatory compliance and managed services, with expertise on OneTrust, ZenGRC, Osano and BigID.
ZenGRC
- Compliance platform
- HIPAA
- HITRUST
- PCI DSS
GRC platform (founded 2009) using agentic AI for compliance, risk and audit programmes, covering frameworks including HIPAA, HITRUST, PCI and SOC, with integrations across AWS, GCP, Azure, identity, ticketing and security tools.
Zero Day CPA
- Audit firm
- SOC 1
- SOC 2
- SOC 3
- HIPAA
Michigan-based CPA firm performing SOC 1, SOC 2 and SOC 3 engagements and HIPAA audits, plus penetration testing, readiness and vCISO services, for SaaS, healthcare, fintech and MSP clients.
No listings match these filters yet. Clear filters