Independent and free for buyers. We don't do audits. We help you find and compare the firms that do.

Penetration testing for government

These 22 penetration testing providers say they work with government. Most SOC 2 and ISO audits expect a recent penetration test, and any of these providers say they can run one.

Updated 1 Oct 2026. How we research
Get 3 to 5 quotes
Firms listed (of penetration testing providers)
22
Published prices
$2,500 to $60,000
2 firms, each linked to its source
Checked in an official register
8 of 22
Filters
Credentials
Price
Works with
Also offers
Region
Firm type
22 matching firms
  • BARR Advisory logo
    BARR Advisory2 verified
    Audit firm and certification body and consultantSOC 1SOC 2SOC 3ISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • ControlCase logo
    ControlCase2 verified
    Audit firm, United StatesPCI DSSISO 27001HITRUSTSOC 2
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • DigitalXRAID logo
    DigitalXRAID2 verified
    Consultant, United KingdomSOC 2ISO 27001Cyber EssentialsPCI DSS
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • Fortreum logo
    Fortreum2 verified
    Audit firmSOC 1SOC 2FedRAMPCMMC
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • Audit firm and certification body, United StatesSOC 1SOC 2SOC 3PCI DSS
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • 360 Advanced logo
    360 Advanced1 verified
    Audit firm and certification body, United StatesSOC 1SOC 2SOC 3HIPAA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • AARC-3601 verified
    Audit firm, United StatesSOC 1SOC 2SOC 3ISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • GRSee1 verified
    Consultant and audit firmSOC 2SOC 3ISO 27001ISO 42001
    Starting price
    From $15,000
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • Agency logo
    AgencyNot yet checked
    ConsultantSOC 2ISO 27001GDPRHIPAA
    Starting price
    From $2,500
    Legal entity
    Not stated
    Accreditations
    Not stated
    Get a quoteProfileChecked 1 Oct 2026
  • AuditVisor logo
    AuditVisorNot yet checked
    Audit firm, United StatesSOC 2HIPAAPCI DSSGDPR
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • Brown Edwards logo
    Brown EdwardsNot yet checked
    Audit firm, United StatesSOC 1SOC 2
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • CBIZ logo
    CBIZNot yet checked
    Audit firm
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • CEREIV Advisory LLP logo
    CEREIV Advisory LLPNot yet checked
    Certification body, India. Signs as CEREIV Advisory LLPISO 27001SOC 2
    Starting price
    Not published
    Legal entity
    Firm states
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • CyberSapiens logo
    CyberSapiensNot yet checked
    Audit firm, AustraliaSOC 1SOC 2SOC 3ISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • DNX Solutions logo
    DNX SolutionsNot yet checked
    Consultant, Australia. Signs as DNX SolutionsSOC 2ISO 27001ISO 42001PCI DSS
    Starting price
    Not published
    Legal entity
    Firm states
    Accreditations
    Not stated
    Get a quoteProfileChecked 1 Oct 2026
  • HackerOne logo
    HackerOneNot yet checked
    Pentest platformSOC 2ISO 27001GDPRDORA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • IS Partners logo
    IS PartnersNot yet checked
    Audit firm and certification body, United StatesSOC 1SOC 2SOC 3ISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • OmniCyber Security Ltd logo
    OmniCyber Security LtdNot yet checked
    ConsultantISO 27001ISO 42001Cyber EssentialsPCI DSS
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • Pivot Point Security logo
    Pivot Point SecurityNot yet checked
    Consultant, United StatesISO 27001CMMCSOC 2PCI DSS
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Not stated
    Get a quoteProfileChecked 1 Oct 2026
  • Red Sentry logo
    Red SentryNot yet checked
    Pentest platformSOC 2ISO 27001HIPAAPCI DSS
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • Seiso logo
    SeisoNot yet checked
    Consultant, United StatesISO 27001SOC 2CMMCHIPAA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • Tevora logo
    TevoraNot yet checked
    ConsultantCMMCFedRAMPHITRUSTHIPAA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Not stated
    Get a quoteProfileChecked 1 Oct 2026

How to choose a penetration testing provider

Check what is in scope (web app, API, cloud, mobile), who does the testing, and whether the report is acceptable to your auditor. Ask about re-testing after you fix findings.

Some providers are firms with testers on staff and some are platforms that match you with testers. Both can work, so ask who is accountable for the report.

Related lists
Do I need a penetration test for SOC 2?

It is not strictly required, but many auditors and customers expect a recent one.

What does CREST accredited mean?

CREST is a body that accredits penetration testing companies. We show it only when the firm states it or a register confirms it.

How is this list ordered?

By the sort you choose. The default is the number of verified credentials, then alphabetical. Payment never changes the order, and a Featured slot is shown apart from the results and labelled as paid.