{
  "directory": "ISMS Directory",
  "lastUpdated": "2026-09-05",
  "count": 161,
  "services": [
    {
      "name": "360 Advanced",
      "url": "https://360advanced.com",
      "briefSummary": "US CPA and compliance assessment firm for SOC 1/2, ISO 27001, HITRUST, HIPAA, and PCI with hands-on mid-market delivery.",
      "description": "360 Advanced is a Florida-based CPA and IT compliance firm focused on security and assurance engagements. It provides SOC examinations, ISO 27001 certification support as an accredited body where applicable, HITRUST, HIPAA, and PCI assessments, with a reputation for named engagement teams and actionable findings for mid-market organizations.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "HITRUST",
        "HIPAA",
        "PCI DSS",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Audit Preparation",
        "Compliance",
        "Certification Assistance",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "Healthcare",
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/360+advanced/r/d8ede397-d722-41c0-8425-fd3123ddb639"
    },
    {
      "name": "6clicks",
      "url": "https://www.6clicks.com",
      "briefSummary": "Cyber GRC platform with a strong US presence for risk, compliance, and third-party assessments.",
      "description": "6clicks is a cyber GRC platform used in the US and Australia for risk, compliance, and vendor assessments. Teams use it as a content-plus-workflow system across multiple frameworks. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Australia",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "NIST CSF",
        "Multi-framework",
        "DORA",
        "TISAX"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Automation",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "All industries",
        "Technology"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/6clicks/r/26d7f7ec-6a71-40c4-9597-e99f307fa1b8"
    },
    {
      "name": "A-LIGN",
      "url": "https://www.a-lign.com",
      "briefSummary": "High-volume multi-framework audit firm for SOC 2, ISO 27001, HITRUST, FedRAMP, CMMC, and PCI, with dual ANAB/UKAS ISO pathways.",
      "description": "A-LIGN is a global compliance and cybersecurity audit firm. It is widely known for SOC 2 issuance at scale and for ISO 27001 certification under ANAB and UKAS accreditation options. Additional programs cover HITRUST, FedRAMP, CMMC, PCI, and multi-framework coordinated assessments for SaaS and enterprise clients.",
      "serviceType": [
        "External audit",
        "Certification body"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Europe",
        "United Kingdom",
        "Asia"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "ISO 27701",
        "ISO 42001",
        "HITRUST",
        "FedRAMP",
        "CMMC",
        "PCI DSS",
        "HIPAA",
        "Multi-framework",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Audit Preparation",
        "Compliance",
        "Certification Assistance",
        "Risk Management"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "Healthcare",
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/a-lign/r/1cbedf47-7432-4006-a535-3f750a5f419e"
    },
    {
      "name": "AdaptiveGRC",
      "url": "https://adaptivegrc.com",
      "briefSummary": "Polish GRC software platform for integrated risk, compliance, audit, and information security management including ISO 27001 programs.",
      "description": "AdaptiveGRC is a governance, risk, and compliance platform developed in Poland for organizations managing multi-framework compliance. The product supports risk management, compliance workflows, audit, and information security programs including ISO 27001, with published guidance on European regulatory topics such as NIS2 and DORA.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Poland",
        "Europe",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "NIS2",
        "DORA",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Automation",
        "Audit Preparation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "All industries",
        "Finance",
        "Technology"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "Polish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/adaptivegrc/r/b5a48bc6-7be4-4c70-9062-58cb63a145c7"
    },
    {
      "name": "Advisera",
      "url": "https://advisera.com/",
      "briefSummary": "Provider of ISO 27001 documentation, training, and consultancy services to help businesses achieve compliance.",
      "description": "Advisera offers a comprehensive range of tools and consultancy services tailored for ISO 27001, helping businesses at every stage of compliance.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework",
        "ISO 9001",
        "ISO 14001",
        "ISO 45001",
        "ISO 13485",
        "ISO 22301",
        "ISO 42001",
        "NIS2",
        "DORA",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Policy Creation",
        "Compliance",
        "Risk Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German",
        "Spanish",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/advisera/r/rectqw4hmsFm6tlxh"
    },
    {
      "name": "AENOR",
      "url": "https://www.aenor.com",
      "briefSummary": "Leading Spanish certification body for ISO 27001, ENS (Spanish National Security Scheme), and multi-standard management systems.",
      "description": "AENOR is Spain's best-known certification and standards-related organization for business assurance. It certifies ISO/IEC 27001 information security management systems and is a primary provider of ENS (Esquema Nacional de Seguridad) certification for Spanish public-sector and regulated environments. AENOR also delivers training and multi-standard certification across quality, environment, and security schemes.",
      "serviceType": [
        "Certification body",
        "Training"
      ],
      "regionCovered": [
        "Spain",
        "Europe",
        "Latin America"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "All industries",
        "Government",
        "Technology"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "Spanish",
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/aenor/r/ad52f407-3928-44fe-85e0-86d735a08c2b"
    },
    {
      "name": "Amtivo",
      "url": "https://amtivo.com",
      "briefSummary": "International ISO certification group (including former Certification Europe) offering INAB-accredited ISO 27001 certification and training.",
      "description": "Amtivo is a certification group delivering accredited management system certification and training. In Ireland it continues the Certification Europe heritage with INAB accreditation for ISO schemes including ISO 27001. Amtivo also operates in the UK, US, and other markets, helping organizations obtain internationally recognized ISO certificates.",
      "serviceType": [
        "Certification body",
        "Training"
      ],
      "regionCovered": [
        "Ireland",
        "United Kingdom",
        "United States",
        "Europe",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "ISO 45001",
        "Multi-framework",
        "Cyber Essentials",
        "ISO 13485",
        "ISO 14001"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/amtivo/r/17903f93-e620-4dfe-af02-3a65d9b559ef"
    },
    {
      "name": "Anecdotes",
      "url": "https://www.anecdotes.ai",
      "briefSummary": "Enterprise agentic GRC platform with 230+ integrations and 40+ pre-mapped frameworks for Fortune 500 compliance programs.",
      "description": "Anecdotes provides an AI-native enterprise GRC platform featuring agentic automation, data normalization across 230+ integrations, and customizable applications for governance, risk, and compliance management.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 27701",
        "ISO 42001",
        "ISO 22301",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "NIST CSF",
        "PCI DSS",
        "SOX",
        "TISAX",
        "DORA",
        "FedRAMP",
        "Cyber Essentials",
        "CCPA",
        "ISO 9001",
        "CSA STAR",
        "NIST SP 800-171",
        "CIS Controls"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Continuous Monitoring",
        "Risk Management",
        "Audit Preparation",
        "Gap Analysis",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "Finance",
        "Healthcare",
        "Technology"
      ],
      "targetClientsSize": [
        "Enterprise"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/anecdotes/r/1447af41-9cdd-42b0-9f6d-fee3a52dad50"
    },
    {
      "name": "Apptega",
      "url": "https://www.apptega.com",
      "briefSummary": "Atlanta continuous-compliance platform built for MSSPs and security teams running multi-framework programs.",
      "description": "Apptega is a US compliance platform used by MSSPs and internal security teams to run assessments, risk, and multi-framework programs. It is commonly used for NIST CSF, CIS, CMMC, and similar control sets. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "NIST CSF",
        "CIS Controls",
        "SOC 2",
        "CMMC",
        "HIPAA",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Continuous Monitoring",
        "Vendor Management",
        "Automation"
      ],
      "industrySpecialization": [
        "Technology",
        "All industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/apptega/r/955f14b4-ab94-4580-b125-ce064fba8050"
    },
    {
      "name": "Archer",
      "url": "https://www.archerirm.com",
      "briefSummary": "US integrated risk management platform (formerly RSA Archer) for enterprise GRC programs.",
      "description": "Archer is a US integrated risk management platform used by large enterprises for operational risk, compliance, and audit. It is the long-running Archer product, not a startup evidence tool. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOX",
        "NIST CSF",
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Vendor Management",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/archer/r/82c045e4-e459-45c7-a37e-592d4ae6b6f4"
    },
    {
      "name": "Armanino",
      "url": "https://www.armanino.com",
      "briefSummary": "California CPA firm with a technology assurance practice for SOC 2 and related reports.",
      "description": "Armanino is a US CPA firm with a technology assurance practice used by California and national SaaS companies for SOC 2. It is an auditor, not a GRC platform. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/armanino/r/94f6cf83-3a6e-4033-b264-459719ffc33a"
    },
    {
      "name": "Arrow Cyber Advisors",
      "url": "https://arrowcyberadvisors.com/",
      "briefSummary": "Arrow Cyber Advisors enables organizations to build measurable cybersecurity maturity and resilience. We specialize in governance, risk and compliance advisory, providing clear security direction, maturity benchmarking, and execution support tailored to regulated and high-risk environments.",
      "description": "Key Differentiators: \n-Maturity-Driven Approach: We combine a cybersecurity maturity assessment, customized roadmap, and execution support to ensure strategic alignment and measurable progress rather than one-off audit outputs.\n-GRC First, Technology Second: We guide clients on governance, risk and compliance fundamentals before technology spend, ensuring investment clarity and improved security ROI.\n-Execution Ecosystem: We design the strategy and partner with vetted MSSPs/MSPs and technology providers to implement solutions efficiently and in alignment with business priorities.\n-Regulated-Industry Focus: Deep experience in private equity, financial services, healthcare, and professional services environments where compliance, risk management, and reliability are critical.\n-Accessible On-Ramp: We offer an initial cybersecurity maturity assessment at no cost to help organizations gain visibility and build a prioritized roadmap quickly.\n\nFrameworks and Standards\n-NIST Cybersecurity Framework (CSF)\n-ISO/IEC 27001\n-CIS Controls\n-NIST 800-53 / 800-171 (as applicable by client environment)\n\nWe build programs designed to support compliance obligations across HIPAA, GLBA, SOX, and other sector-driven requirements.\n\nPricing Model\nPricing is scoped based on organizational size, complexity, and maturity level needs. Typical engagement structure:\n-Initial maturity assessment: Complimentary\n-Roadmap development: Fixed-scope advisory fee\n-Implementation support: Project-based services or monthly advisory subscription depending on client preference\n\nThis model delivers flexibility while ensuring clients can scale support as their security maturity grows.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "NIST CSF"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Continuous Monitoring",
        "Security Awareness",
        "Incident Response",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/arrow+cyber+advisors/r/recCNLI8aJU4uqYTM"
    },
    {
      "name": "Atoro",
      "url": "https://www.atoro.io",
      "briefSummary": "Atoro offers specialized ISO 27001 certification services for SaaS companies, simplifying compliance with expert tools.",
      "description": "Atoro is a cybersecurity consultancy firm focused on ISO 27001 implementation, internal audits, and risk management for SaaS.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "SOC 2",
        "ISO 42001",
        "DORA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Certification Assistance",
        "Continuous Monitoring",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "SaaS",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/atoro/r/recgBZ1pCNO6kKL6S"
    },
    {
      "name": "AuditBoard",
      "url": "https://auditboard.com",
      "briefSummary": "Enterprise connected risk platform trusted by over 50% of the Fortune 500 for audit, risk, and compliance management.",
      "description": "AuditBoard is a connected risk platform covering audit management, enterprise risk, third-party risk, information security compliance, and ESG. Named a Leader in the 2025 Gartner Magic Quadrant for GRC Tools.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "SOX",
        "NIST CSF",
        "PCI DSS",
        "ISO 22301"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Risk Management",
        "Continuous Monitoring",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Enterprise"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/auditboard/r/fd1c6fbe-a2f7-4ce1-94bb-141990073e67"
    },
    {
      "name": "Auro Security",
      "url": "https://www.aurosecurity.com/",
      "briefSummary": "Most modern product teams, including SaaS, FinTech and cloud-native startups are moving fast, building with AI, and operating in an environment where enterprise buyers, regulators, and investors expect real security. Auro Security exists to help those teams get there.\n\nOperating across India and the Middle East, we work with founders, CTOs, and compliance leads to build security programs that hold up under scrutiny, not just on paper.\n\nWhat We Do\n\nWe offer a focused suite of cybersecurity services:\n- SOC 2 and ISO 27001 Compliance: End-to-end audit readiness, gap assessments, policy creation, evidence collection support, and continuous monitoring.\n- VAPT (Vulnerability Assessment and Penetration Testing): Deep technical testing for web apps, mobile apps, APIs, cloud infrastructure, and networks to uncover risks before attackers do.\n- vCISO Services: Fractional cybersecurity leadership to help you build a security roadmap, manage risk, and meet enterprise expectations as you scale.\n\nWho We Serve\n\nWe primarily work with:\nSaaS companies and cloud-native startups, FinTech and payments platforms, early-stage teams preparing for enterprise sales or compliance audits.",
      "description": "Auro Security is a team of experienced cybersecurity professionals with 20+ years of security and compliance experience. We are building Auro to help digital businesses strengthen security, meet global compliance standards, and build long-term trust with customers.\nOur consultants bring hands-on experience across SOC 2, ISO 27001, NIST, DORA, and enterprise security programs, having worked with SaaS companies, Fintechs, and digital platforms at various stages of growth.\n\nWhat Defines our Team:\n- Security Practitioners not just auditors\n- Built for modern, cloud-native businesses\n- Global Exposure\n- Advisory-first mindset\n\nOur Role with Clients\n\n- Translate compliance frameworks into clear, implementable actions\n- Act as long-term security partners through vCISO and continuous advisory\n- Complement automation tools with expert-led assurance and security leadership",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Incident Response",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries",
        "Cryptocurrency",
        "Finance",
        "Insurance",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "Hindi"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/auro+security/r/9eb2c04c-edd1-4207-8341-07516ddc9286"
    },
    {
      "name": "BARR Advisory",
      "url": "https://www.barradvisory.com",
      "briefSummary": "Cloud-native compliance firm offering SOC 2 audits and ISO 27001 certification with coordinated multi-framework programs for SaaS.",
      "description": "BARR Advisory is a US cybersecurity and compliance firm specializing in cloud and SaaS organizations. Services include SOC 2 examinations, ISO 27001 certification as an accredited body, and coordinated programs spanning HITRUST, FedRAMP, PCI DSS, and CMMC so evidence can be reused across frameworks.",
      "serviceType": [
        "External audit",
        "Certification body"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "FedRAMP",
        "HITRUST",
        "CMMC",
        "PCI DSS",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Audit Preparation",
        "Compliance",
        "Certification Assistance",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "Healthcare",
        "All industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/barr+advisory/r/9f2f99cd-2ac2-4d83-8516-fe0e0eda305c"
    },
    {
      "name": "Bitsecura",
      "url": "https://bitsecura.com/",
      "briefSummary": "*** Helping Businesses Achieve Compliance & Certification Success ***\n\nBitsecura is a IT governance, risk, and compliance (GRC) firm specialising in helping organisations protect their critical assets, navigate complex regulatory landscapes, and build sustainable cybersecurity frameworks. With over 20 years of industry experience, we offer strategic guidance, bespoke solutions, and operational support that align seamlessly with your business objectives. Our commitment to practical innovation and long-term partnerships ensures that working with Bitsecura not only strengthens your current security posture, but also builds a lasting foundation for future resilience.",
      "description": "Frameworks we focus on: \n- ISO/IEC 27001: Information Security\n- ISO/IEC 27701: Privacy Information Management\n- ISO/IEC 42001: AI Management Systems\n- Digital Operational Resilience Act (DORA)\n- NIS2 Directive\n- SOC 2\n- NIST Cybersecurity Framework (CSF)\n\n",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Australia",
        "Canada",
        "Europe",
        "Middle East",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "Multi-framework",
        "ISO 27701",
        "DORA",
        "NIS2",
        "NIST CSF",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/bitsecura/r/recL18E17SnGp6urw"
    },
    {
      "name": "BitSight",
      "url": "https://www.bitsight.com",
      "briefSummary": "Boston security-ratings platform used in third-party risk and cyber underwriting programs.",
      "description": "BitSight is a US security-ratings company. Buyers use the ratings inside vendor risk and cyber insurance workflows. It is not a replacement for an audit or a GRC system of record. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "NIST CSF",
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Vendor Management",
        "Continuous Monitoring",
        "Risk Management"
      ],
      "industrySpecialization": [
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/bitsight/r/62834454-05ed-4d65-bc2c-e56934f6e05c"
    },
    {
      "name": "Bizoneo GRC",
      "url": "https://www.bizoneo.eu/compliance_solutions/",
      "briefSummary": "Integrated and comprehensive solution to assist Governance, Risk and Compliance",
      "description": "Integration of over 70 modules to assist GRC: GDPR, DORA, NIS2 POPIA etc. Data is reused which means it's easy to have a 360 degree view of the data processing landscape. Easy to use. Price is based on number of users (plans). We also offer a Consultant edition with specific features such as a built-in timesheet system.\nBizoneo is fully developed and hosted in the EU (no GAFAM). In business for over 20 years.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Africa",
        "Canada",
        "Europe",
        "United Kingdom",
        "France",
        "Ireland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "DORA",
        "NIS2"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/bizoneo+grc/r/rec7MJTO12HOPV0zh"
    },
    {
      "name": "BSI",
      "url": "https://www.bsigroup.com",
      "briefSummary": "Global standards body and UKAS-accredited certification organization for ISO 27001, privacy, AI management, and related management systems, plus training.",
      "description": "BSI (British Standards Institution) is a leading standards and certification body. Organizations worldwide use BSI for ISO/IEC 27001 information security certification, related ISO schemes, and formal training through BSI Training Academy. BSI is widely recognized for rigorous audits and the association with UK national standards.",
      "serviceType": [
        "Certification body",
        "Training"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 27701",
        "ISO 42001",
        "ISO 22301",
        "ISO 9001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance",
        "Lead Implementer Training",
        "Security Awareness Training"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/bsi/r/cc71f0ef-a71e-4bb4-8c15-e8c137ba416d"
    },
    {
      "name": "Bureau Veritas",
      "url": "https://www.bureauveritas.com",
      "briefSummary": "French-rooted global certification and inspection leader providing ISO 27001 and related management system certification.",
      "description": "Bureau Veritas is a major global certification body with strong presence in Europe and France. It certifies information security management systems to ISO/IEC 27001 and supports organizations seeking internationally recognized third-party assurance of security and quality management systems.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "France",
        "United Kingdom",
        "United States",
        "Asia",
        "Latin America",
        "Middle East",
        "Africa"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/bureau+veritas/r/74c27320-702d-4e5a-9003-8fb01fe25a29"
    },
    {
      "name": "Carbide",
      "url": "https://carbidesecure.com",
      "briefSummary": "Canadian security and privacy management platform combining software automation with expert advisory for fast-growing companies.",
      "description": "Carbide makes enterprise-class security and privacy accessible to fast-growing organizations by combining automated compliance software with expert in-house services including fractional CISO support.",
      "serviceType": [
        "Compliance platform",
        "Consultants"
      ],
      "regionCovered": [
        "Canada",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "PCI DSS",
        "NIST CSF",
        "CMMC",
        "CCPA",
        "NIST SP 800-171",
        "NIST SP 800-53",
        "CIS Controls"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Policy Creation",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small",
        "Medium"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/carbide/r/88c42f2f-6126-45e7-98b3-5de12e426fe5"
    },
    {
      "name": "CBIZ Pivot Point Security",
      "url": "https://www.pivotpointsecurity.com",
      "briefSummary": "US information security consultancy specializing in ISO 27001 implementation, SOC 2 readiness, CMMC, and ongoing compliance programs.",
      "description": "CBIZ Pivot Point Security is a long-standing information security consulting practice (now under the CBIZ umbrella) known for ISO 27001 implementation and certification readiness. Services also cover SOC 2 readiness, CMMC, AI governance, and related cybersecurity compliance programs for mid-market and enterprise clients.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "CMMC",
        "NIST CSF",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Gap Analysis",
        "Risk Management",
        "Audit Preparation",
        "Compliance",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cbiz+pivot+point+security/r/e222c5a4-4aed-48e5-8ebe-bf2e8b4afaf4"
    },
    {
      "name": "Certi360: ISO 27001 & Cybersecurity Compliance Consulting",
      "url": "https://certi360.com",
      "briefSummary": "Certi360 helps Quebec SMBs achieve and maintain information security compliance (ISO 27001, Quebec's Law 25) with CISO-as-a-service, so compliance stays with the business, not locked in with a consultant.",
      "description": "Patrick Boucher was a programmer, IT director, and company president (Gardien Virtuel, sold in 2019) before founding Certi360 in 2021. That path gives him a rare ability to translate between technical and strategic language at every level, from developers to the board. Direct, concrete approach, no unnecessary theory. Core belief: compliance should belong to the business, not stay locked with the consultant. 250+ clients since 2021. ISO 27001 first, alongside Quebec's Law 25 (personal information protection). Also covered: SOC 2, PCI DSS, CyberSecure Canada (CAN/DGSI 104), and TGV controls (Quebec's health network, MSSS). CMMC/CP3PP is in development, not yet a complete offering.",
      "serviceType": [
        "Internal audit"
      ],
      "regionCovered": [
        "Canada"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Certification Assistance",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/certi360:+iso+27001+&+cybersecurity+compliance+consulting/r/e7bd6c28-f5be-4e7e-aee1-747f80b4cb9f"
    },
    {
      "name": "CG Business Consulting",
      "url": "https://www.cgbusinessconsulting.com",
      "briefSummary": "Irish consultancy specializing in ISO management systems including ISO 27001, ISO 27701, ISO 22301, and integrated compliance programs.",
      "description": "CG Business Consulting is an Ireland-based consultancy focused on ISO certification support, sustainability compliance, and digital management systems. Information security offerings include ISO 27001 and ISO 27701 implementation support alongside broader schemes such as ISO 22301, quality, and ESG-related reporting frameworks for Irish organizations.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Ireland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 27701",
        "ISO 22301",
        "ISO 9001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Gap Analysis",
        "Compliance",
        "Policy Creation",
        "Risk Management"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cg+business+consulting/r/c2f8d704-6a57-4505-b51a-805acbbf2aee"
    },
    {
      "name": "Circl3.tech",
      "url": "https://circl3.tech",
      "briefSummary": "Circl3.tech is a Cyprus-based cybersecurity advisory firm specialising in vCISO services, information security governance, risk management, and regulatory compliance. Founded by Panos Panayiotou — an ISO/IEC 27001 Lead Implementer (Senior) and seasoned CISO with over 25 years of experience across banking and government sectors — Circl3.tech supports public and private sector organisations in designing and implementing cybersecurity frameworks, ISMS control environments, and strategic security programmes aligned with ISO/IEC 27001 and NIS requirements.",
      "description": "Circl3.tech is led by a practitioner who has actually held CISO roles — not a consultant who has only advised from the outside. Panos Panayiotou served as Group CISO at two major banking groups for over two decades, and as CISO to the Republic of Cyprus government. Clients get Board-level thinking, real implementation experience, and access to active European policy networks (EBF, ENISA).\n\nFrameworks and Standards circl3.tech can provide value: \nISO/IEC 27001 (design, gap analysis, implementation, audit readiness)\nNIS / NIS2 Directive compliance\nDORA (financial sector, given banking background)\nRisk management frameworks (CRISC-aligned)\nSecOps governance and control environments\n\nCommon procing models to choose from:\nFixed retainer (monthly vCISO)\nProject-based (e.g. per ISO 27001 implementation engagement)\nDaily/hourly rate\nTiered packages ",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "NIS2",
        "DORA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Vendor Management",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/circl3.tech/r/c71416bd-4924-484f-aec6-aacdbc3a3ed1"
    },
    {
      "name": "CK Associates",
      "url": "https://ckassociates.biz/",
      "briefSummary": "CK Associates is a leading ISO consulting firm with 20+ years of experience and 450+ successful certification projects. We help organizations implement, audit, and achieve ISO standards, including ISO 27001, ISO 42001, ISO 9001, and other compliance frameworks.",
      "description": "Key Differentiators\n\n20+ years of consulting experience.\n450+ successful certification projects across diverse industries.\nPractical implementation approach focused on business outcomes, not just documentation.\nEnd-to-end support including gap assessment, documentation, implementation, internal audits, training, and certification readiness.\nDedicated consultants with hands-on industry expertise.\n\nFrameworks and Standards Focus\n\nISO 27001 Information Security Management System (ISMS)\nISO 42001 Artificial Intelligence Management System (AIMS)\nISO 9001 Quality Management System\nISO 22301 Business Continuity Management\nISO 20000 IT Service Management\nISO 14001 Environmental Management\nISO 45001 Occupational Health & Safety\nMulti-framework compliance programs\n\nPricing Model\nOur pricing is based on organization size, employee count, business complexity, number of locations, current compliance maturity, and certification scope. We provide transparent project-based proposals with no hidden costs.\n\nCommitment to Quality\nQuality is demonstrated through our proven track record of 450+ successful certification engagements, structured implementation methodologies, experienced consultants, documented project governance, and a strong focus on client success and continual improvement.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "India"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "Multi-framework",
        "ISO 13485",
        "ISO 14001",
        "ISO 22000",
        "ISO 22301",
        "ISO 45001",
        "ISO 9001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries",
        "Construction",
        "Finance",
        "Government",
        "Healthcare",
        "Hospitality",
        "Insurance",
        "Manufacturing",
        "Private Equity",
        "Real Estate",
        "Retail",
        "Technology",
        "Transportation"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/ck+associates/r/1287847f-10b7-4166-991d-cfc20350bc4f"
    },
    {
      "name": "ClearLoop Security",
      "url": "https://clearloopsecurity.com/our-services/",
      "briefSummary": "We provide ISO 27001 consultancy to take you from a standing start to fully certified, with a speciality of working with tech companies with a cloud-first infrastructure. We provide Lead Auditors with great relationships with certification bodies to ensure you pass first time.",
      "description": "We have a 100% record in getting our clients certified to ISO 27001 first time, with zero non-conformities. But we don't just take you through the certification process, we provide ongoing outsourced CISO services to ensure your 27001 ISMS continues to run smoothly, delivering security benefits and successful audits every year.\n\nIn addition, we have a wealth of experience helping companies with their data protection requirements, incorporating this into their ISMS and acting as the outsourced Data Protection Officer.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/clearloop+security/r/3b176967-273e-4f49-8ad0-f7a4a9cfea0d"
    },
    {
      "name": "Cloud360 Technologies",
      "url": "https://www.cloud360grc.com",
      "briefSummary": "Building an AI-native GRC platform that replaces manual, outdated governance processes with agentic frameworks designed for organizations enabling AI.\n\nCloud360 delivers real-time security posture, AI-generated cyber risk profiles, continuous attack surface discovery, and AI pen testing — all built on the principle that compliance does not equal secure.\n\nCore focus areas:\n→ AI governance frameworks for mid-market companies enabling AI across their engineering organizations\n→ Continuous compliance monitoring for SOC 2, ISO 27001, and EU AI Act\n→ Shadow AI detection and observability — if you can't see it, you can't secure it\n→ Agentic GRC workflows that replace analyst headcount with purpose-built AI agents",
      "description": "Custom Affordable Pricing",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Vendor Management",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "Technology"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cloud360+technologies/r/e7cee0a4-be69-4432-8dfd-192ac14134fd"
    },
    {
      "name": "Coalfire",
      "url": "https://www.coalfire.com",
      "briefSummary": "Enterprise cybersecurity and compliance assessment firm for FedRAMP, SOC 2, HITRUST, PCI, ISO 27001, and government frameworks.",
      "description": "Coalfire is a well-known cybersecurity and compliance assessment company serving regulated and enterprise environments. Engagements commonly cover FedRAMP 3PAO assessments, SOC 2, HITRUST, PCI DSS, ISO 27001-related work, and broader cyber risk programs for cloud and government-facing organizations.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "United Kingdom",
        "Canada"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "FedRAMP",
        "HITRUST",
        "PCI DSS",
        "ISO 27001",
        "CMMC",
        "NIST SP 800-53",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Audit Preparation",
        "Compliance",
        "Risk Management",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "Technology",
        "Government",
        "Healthcare",
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/coalfire/r/0ee5e1a7-cd27-46a9-87be-1ee82b6c13a9"
    },
    {
      "name": "Comp AI",
      "url": "https://www.trycomp.ai",
      "briefSummary": "US open-source-friendly compliance automation platform for SOC 2, ISO 27001, and HIPAA evidence.",
      "description": "Comp AI is a US compliance automation product for startups collecting evidence for SOC 2, ISO 27001, and HIPAA. It is a software platform, not an auditor. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform",
        "AI assistant"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "HIPAA",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Automation",
        "Compliance",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "SaaS",
        "Startups",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/comp+ai/r/ac44415c-09e1-4432-bd19-708336d9017d"
    },
    {
      "name": "Compleye",
      "url": "https://compleye.io/",
      "briefSummary": "Compleye provides a user-friendly compliance platform to help companies achieve ISO 27001, SOC 2, ISO 9001, and GDPR compliance quickly and efficiently.",
      "description": "Compleye focuses on startups and small businesses, offering a flexible and affordable compliance solution.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Netherlands"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "SOC 2 Type 2",
        "GDPR",
        "ISO 27701",
        "HIPAA",
        "NIS2"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Certification Assistance",
        "Data Protection"
      ],
      "industrySpecialization": [
        "Technology",
        "Startups"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/compleye/r/rec1icmqYbZfYf20Y"
    },
    {
      "name": "Consulia",
      "url": "https://www.consulia.fr/",
      "briefSummary": "Consulia provides deep consulting related to cybersecurity standards, from gap analysis to certification assistance. \nAs a training center, we provide expertise on the following standards: ISO 27001, ISO 42001, ISO 27701, ISO 22301, HDS, PCI DSS.\nLocated in France, we intervene all over Europe and further, to make compliance easier and business driven.",
      "description": "At Consulia, we deliver tailored expertise and are therefore creating dedicated offers to each customer. We do not aim at telling you you will be certified in 1 month, as we take the time to implement controls and processes the right way and through time.",
      "serviceType": [
        "Internal audit"
      ],
      "regionCovered": [
        "Europe",
        "France"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/consulia/r/e9a10025-2cf6-437a-b873-89b0ae7f29c7"
    },
    {
      "name": "ContrailRisks",
      "url": "https://www.linkedin.com/company/contrailrisks",
      "briefSummary": "ContrailRisks is a Berlin-based strategic advisory firm delivering lean, high-impact cybersecurity & risk management solutions. We help businesses identify vulnerabilities, implement tailored strategies, and enhance operations—minimizing risks, reducing costs, and boosting resilience.",
      "description": "ContrailRisks delivers lean, high-impact cybersecurity services tailored for startups and growing businesses. We prioritize strategic alignment, regulatory readiness, and practical outcomes over checkbox compliance. Our expertise in EU regulations and global standards enables effective, business-focused security support.\n\nWhat frameworks or standards are your services focused on?\nOur services align with ISO/IEC 27001:2022, NIST CSF 2.0, DORA, NIS2, IEC 62443, CMMC, Secure Control Framework (SCF), and CIS Controls. We guide clients in selecting the most appropriate framework based on their sector, maturity, and regulatory needs.\n\nHow does pricing work for your offers?\nWe offer fixed-fee packages for assessments and implementations, monthly subscriptions for vCISO services, and discounted starter packs for early-stage companies. Pricing is transparent and tailored to the client’s size, complexity, and requirements.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Asia",
        "Canada",
        "Europe",
        "Israel",
        "United Kingdom",
        "Spain"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "GDPR",
        "DORA",
        "NIS2",
        "CMMC"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Security Awareness",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "Spanish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/contrailrisks/r/reca12cCMCc71V9ks"
    },
    {
      "name": "ControlCase",
      "url": "https://www.controlcase.com",
      "briefSummary": "US QSA and assessor for PCI DSS, SOC 2, ISO 27001, and related payment-security programs.",
      "description": "ControlCase is a US assessment firm known for PCI DSS QSA work plus SOC 2 and ISO 27001. Payment and technology companies use it as an assessor. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "PCI DSS",
        "SOC 2",
        "ISO 27001",
        "HITRUST",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Compliance",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Finance",
        "Technology"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/controlcase/r/b19b371e-02e8-474b-892d-a6f829cde9ff"
    },
    {
      "name": "Conveyor",
      "url": "https://www.conveyor.com",
      "briefSummary": "San Francisco AI trust-center and questionnaire platform for customer security reviews.",
      "description": "Conveyor is a US platform for customer trust centers and AI-assisted security questionnaires. SaaS teams use it to answer buyer reviews without a dedicated questionnaire staff. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Vendor Management",
        "Automation",
        "Compliance"
      ],
      "industrySpecialization": [
        "SaaS",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/conveyor/r/ef2dbb70-bbf2-4f2a-97f4-c822e56ef3cc"
    },
    {
      "name": "Corelink",
      "url": "https://corelink.ai/",
      "briefSummary": "ISO/IEC 27001 internal audit, ISMS readiness, and ISMS documentation services to support certification and continual improvement.",
      "description": "Corelink.ai provides ISO/IEC 27001-focused services using proprietary AI-assisted tooling to accelerate traditionally manual activities such as document review, control mapping, and evidence analysis. This reduces effort and turnaround time while maintaining audit quality.\n\nAll outputs are reviewed and validated by experienced consultants and auditors, with professional judgement applied to final conclusions and recommendations. Services are aligned to ISO/IEC 27001 and ISO/IEC 27002, supporting certification readiness, internal audit, and continual improvement.\n\nPricing is typically fixed-fee based on organization size, scope, and complexity, with clear engagement boundaries defined upfront.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Canada",
        "Europe",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "PCI DSS",
        "HIPAA",
        "HITRUST"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/corelink/r/reciYzfu8yNzBg5qS"
    },
    {
      "name": "Cyberbits Consulting",
      "url": "https://cyberbitsconsulting.com",
      "briefSummary": "\nSpecializing in Governance, Risk, and Compliance, we help businesses navigate the complex landscape of regulatory requirements and risk management.\nWhether you are navigating new regulations, enhancing internal controls, or preparing for an audit, we are here to help you turn GRC challenges into opportunities!",
      "description": "A proven track record in ISO 27001 ISMS implementation, combined with experience as an external auditor for a certification body, gives me a distinct advantage in both implementing and auditing information security management systems. Implementation & Auditing services can be done in English and French",
      "serviceType": [
        "Consulting",
        "Internal audit"
      ],
      "regionCovered": [
        "Europe",
        "Middle East",
        "United Kingdom",
        "France"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cyberbits+consulting/r/recGl2QQ0qdyVPprz"
    },
    {
      "name": "CyberHeed",
      "url": "https://www.cyberheed.com",
      "briefSummary": "CyberHeed is an AI-powered GRC platform that helps organisations build, manage, and maintain compliance across 9+ frameworks. From guided discovery and document generation to evidence collection, risk management, and continuous monitoring - all in one place.  ",
      "description": "CyberHeed combines AI-guided discovery with a multi-framework compliance engine. Organisations complete guided sessions that capture their actual context, and the platform generates tailored documentation, maps controls across frameworks simultaneously, and automates evidence management. \nFor consultancies, we provide real-time compliance visibility across multiple organisations.\n\nHow does pricing work?\nPricing is sized per organisation based on scope, framework coverage, and complexity. \n                                                                                                                      \nHow can we know you care about quality?                                                                           \nCyberHeed is built by practitioners with over 20 years in information security and compliance. We don't compromise on principles - every document, every control mapping, and every assessment output reflects how compliance actually works in practice, not how it looks on paper. CyberHeed has been recognised as a finalist in both the Australian AI \n  Awards and the Australian Cyber Awards.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Australia",
        "Middle East",
        "New Zealand",
        "UAE"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cyberheed/r/1640c470-76c6-4280-af5a-8ae5926be1d3"
    },
    {
      "name": "CyberPulse",
      "url": "https://www.cyberpulse.com.au/",
      "briefSummary": "CyberPulse is an Australian cybersecurity and GRC consultancy specialising in audit and compliance. We deliver ISO 27001, Essential Eight, and NIST CSF audits, GRC advisory, vCISO, and managed compliance—helping you achieve and maintain certification with penetration testing and continuous assurance.",
      "description": "CyberPulse pairs ISO Lead Auditor credentials with hands-on technical delivery, so audits are grounded in real security testing rather than checklists. We work fluently across ISO 27001:2022, NIST CSF 2.0, Essential Eight, CPS 234/230, and SOCI, including regulated critical-infrastructure environments, and use platforms like Vanta and Drata to move clients from point-in-time audits to continuous assurance. Because penetration testing and MDR sit under the same roof, findings flow straight into remediation and managed detection instead of stopping at a report. Add deep third-party and supply-chain risk capability—FOCI assessments, sub-processor and DPA analysis—and Australian-based sovereign data handling, and you have an audit partner built for high-assurance, APRA-regulated, and government-adjacent organisations.",
      "serviceType": [
        "Internal audit"
      ],
      "regionCovered": [
        "Australia"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "NIST"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "Hindi"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cyberpulse/r/4ad707e7-a35b-4a3f-9fcd-0e237d7c9e5a"
    },
    {
      "name": "CyberSaint",
      "url": "https://www.cybersaint.io",
      "briefSummary": "Boston cyber GRC platform (CyberStrong) for NIST-oriented risk, control testing, and vendor risk.",
      "description": "CyberSaint CyberStrong is a US cyber GRC platform used for NIST-oriented risk scoring, control testing, and vendor risk. It is closer to federal and enterprise cyber risk than to startup SOC 2 automation. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "NIST CSF",
        "NIST SP 800-53",
        "CMMC",
        "FedRAMP",
        "Multi-framework",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Continuous Monitoring",
        "Automation"
      ],
      "industrySpecialization": [
        "Government",
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/cybersaint/r/383d9eb6-d47c-4593-83c6-9fb3070942e1"
    },
    {
      "name": "Digimojo",
      "url": "https://digimojo.de/",
      "briefSummary": "Externer Datenschutz- und Informationssicherheitsbeauftragter für den Mittelstand, plus die ISMS-Plattform DigimojoCOMPLY. TÜV-zertifiziert. Bringt KMU strukturiert zu ISO 27001, TISAX, NIS-2 und DORA.",
      "description": "Ein fester, zertifizierter Beauftragter begleitet das Mandat durchgängig, vom Erstgespräch bis zur Zertifizierung.\nFrameworks: ISO 27001, TISAX, NIS-2, DORA, VdS 10000, DSGVO. Zwei eigene Produkte ergänzen die Beratung: DigimojoCOMPLY (ISMS- und Compliance-Plattform) und DigimojoSECURE (Awareness und Human Risk).\nPreise: Externer Datenschutz- und Informationssicherheitsbeauftragter im monatlichen Retainer, gestaffelt nach Unternehmensgröße. ISO 27001, TISAX und VdS 10000 als Festpreis-Projekt nach Scope-Klärung. DigimojoCOMPLY und DigimojoSECURE als monatliches Abo.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Austria",
        "Europe",
        "Germany",
        "Switzerland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/digimojo/r/57ab6d91-f512-4a5e-8448-e6f8a09dc567"
    },
    {
      "name": "Diligent",
      "url": "https://www.diligent.com",
      "briefSummary": "New York governance platform covering board, audit, risk, and compliance workflows for enterprises.",
      "description": "Diligent is a US governance platform that now includes audit, risk, and compliance products alongside board software. Enterprise teams use it when governance and GRC sit in one vendor. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "SOX",
        "ISO 27001",
        "Multi-framework",
        "CMMC",
        "FedRAMP",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "All industries",
        "Finance"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/diligent/r/14e4a237-499a-42fa-87fa-65251add8d27"
    },
    {
      "name": "DNV",
      "url": "https://www.dnv.com",
      "briefSummary": "Global assurance provider offering ISO 27001 certification and risk-based management system audits, with deep Nordic and critical-infrastructure roots.",
      "description": "DNV is a worldwide assurance and risk management company. Its business assurance services include ISO/IEC 27001 certification and related management system audits. Through its cyber security practice (including the former Nixu business), DNV also supports organizations across the Nordics and Europe on security and compliance programs.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "Norway",
        "Sweden",
        "Denmark",
        "Finland",
        "Netherlands",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 22301",
        "ISO 9001",
        "Multi-framework",
        "SOC 2"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Risk Management",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/dnv/r/8720b4ac-b6fc-4528-8e03-2bfff1618d15"
    },
    {
      "name": "DQS",
      "url": "https://www.dqsglobal.com",
      "briefSummary": "Independent global certification body specializing in management system audits including ISO 27001 information security.",
      "description": "DQS is an established independent certification body operating in 60+ countries. It focuses on management system audits and assessments, including ISO/IEC 27001 information security certification, with dedicated ISMS auditors and international accreditations.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "Germany",
        "United States",
        "Asia"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "Multi-framework",
        "ISO 42001"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/dqs/r/6aa299d2-69e1-4ea3-8247-0493af59922f"
    },
    {
      "name": "Drata",
      "url": "https://www.drata.com/",
      "briefSummary": "Continuous compliance automation platform for ISO 27001, SOC 2, and other standards.",
      "description": "Drata streamlines compliance through automation, reducing the workload for businesses aiming for ISO 27001 certification.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/drata/r/recKPGSmEipIvCIcv"
    },
    {
      "name": "EasyAudit",
      "url": "http://easyaudit.ai/",
      "briefSummary": "We help you achieve SOC 2 compliance for half the cost (using AI).",
      "description": "EasyAudit stands out with its AI-driven automation that simplifies SOC 2 compliance, reducing both time and costs by up to 50%. We offer customized compliance solutions that cater to your specific needs, ensuring efficiency and relevance. Our platform provides continuous monitoring with real-time alerts and risk assessments, keeping your data secure and compliant. We focus primarily on SOC 2 compliance and have plans to expand to other standards like ISO 27001. Our services are offered at a competitive rate of $5,000 per year, providing an all-inclusive compliance solution without hidden fees. EasyAudit makes compliance hassle-free and cost-effective, allowing you to concentrate on growing your business while ensuring data security and client trust.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Canada",
        "Europe",
        "Latin America",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2 Type 2",
        "ISO 27001",
        "ISO 42001",
        "HIPAA",
        "GDPR",
        "NIST CSF",
        "CCPA"
      ],
      "problemsTheySolve": [
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/easyaudit/r/rectDSvw6jiJYB2Kv"
    },
    {
      "name": "Experta",
      "url": "https://experta.com/login",
      "briefSummary": "Experta is an AI-powered knowledge base providing expert answers on ISO 27001, 9001, 14001, and other standards, offering guidance throughout your compliance journey.",
      "description": "Specializes in accurate, expert-validated responses on ISO standards, designed for professionals at all levels.",
      "serviceType": [
        "Compliance platform",
        "AI assistant"
      ],
      "regionCovered": [
        "United States",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 14001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Certification Assistance",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/experta/r/rec7cdlInDiKrvDXZ"
    },
    {
      "name": "FEHA",
      "url": "https://feha.io",
      "briefSummary": "FEHA is an AI and Human powered platform supporting businesses to comply with various frameworks and regulations, and prepare for certification, seamlessly.",
      "description": "Our USP is we bundle GRC technology and human consultant as one package. Other than Global and Western Countries frameworks (ISO 27001, SOC 2, etc), we also support security and privacy laws from MENA and APAC countries (Singapore CSA, UAE PDPL, etc). \nPricing is determined by size of the organization, the numbers of frameworks or regulations to be activated, and location. We don’t price USA companies the same way as companies in Asia.",
      "serviceType": [
        "Consulting",
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "Multi-framework",
        "ISO 27001",
        "ISO 9001",
        "ISO 42001",
        "SOC 2",
        "CIS Controls",
        "GDPR",
        "NIS2",
        "DORA",
        "ISO 27701"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/feha/r/recaLkOlT4joiQ2Ys"
    },
    {
      "name": "FullyInControl",
      "url": "https://fullyincontrol.com/",
      "briefSummary": "One Platform. Total Control.\nFullyInControl is a modular Integrated Management Platform that unifies GRC, ISMS, PIMS, QHSE, ESG, BCM & audit in one workspace. Plug-and-play standards, shared data core and smart workflows give you real-time oversight, faster audits and continuous improvement.",
      "description": "•\tAll-in-One & Pick-and-Choose\nActivate only the domain you need—GRC, Risk, ISMS & Privacy, QHSE, ESG, BCM, Audit and more—then expand any time.\n•\tStandards-Ready, Future-Proof\nISO, NIST, DORA, NIS2, GDPR, CSRD… every framework is pre-loaded or easily added. Map controls once and reuse them everywhere—no double data entry, no blind spots.\n•\tSeamless, Shared Data Core\nRisks, controls, tasks and evidence live in one system, so insights flow automatically across teams, dashboards stay up-to-date and audits become a breeze.\n•\tBuilt for Continuous Improvement\nSmart workflows, KPI tracking and automated reminders keep every process moving—and surface opportunities to enhance quality, security and sustainability.\n•\tLimitless Flexibility\nFrom modules, fields and forms to reports and roles and workflows, tune the platform around your terminology, approval routes and information needs. It’s software that works exactly the way you want.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "United Kingdom",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "DORA",
        "NIS2"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "German",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/fullyincontrol/r/reclxKgEWCjsRtTLO"
    },
    {
      "name": "GCAI Certification",
      "url": "https://gcaicert.com/",
      "briefSummary": "Global Certification & Accreditation Institute (GCAI) delivers IAS-accredited ISO 27001 certifications and compliance audits across SOC 2, GDPR, HIPAA, NIST & AI standards. Built for startups and SMBs — rigorous audits, faster timelines, globally recognized results.",
      "description": "GCAI is purpose-built for startups and SMBs — combining IAS accreditation with a digital-first delivery model that compresses audit timelines without compromising rigor. \n\nOur auditor team operates across security, privacy, and AI governance, giving clients a single trusted partner for their entire compliance journey rather than juggling multiple vendors.\n\nWe cover the full compliance spectrum — ISO/IEC 27001, SOC 2 Type 2, ISO 42001 (AI Governance), ISO 27701 (Privacy), ISO 22301, GDPR, DPDP, HIPAA, CCPA, PIPEDA, NIST CSF, NIST AI RMF, PCI DSS, CMMC, DORA, NIS2, FedRAMP, and EU AI Act, among others. We also offer readiness assessments, regulatory audits, and Exemplar Global-accredited personnel certifications.\"\n\nOur competitive pricing is scope-based and tailored to the size and complexity of the client's environment — making it accessible for lean startups while scaling appropriately for larger SMBs.  \n\nOur quality is backed by IAS accreditation under the IAF Multilateral Recognition Arrangement — meaning our certificates are independently validated to global standards, not self-declared. With 100+ certified clients, 1,500+ audit days delivered, and 200+ assessment reports completed across 20+ industries, our track record speaks for itself.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "Hindi"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/gcai+certification/r/ab73e9a0-a63c-47bf-8c79-2f97c21094c3"
    },
    {
      "name": "Genius GRC",
      "url": "https://www.geniusgrc.com/",
      "briefSummary": "We offer cybersecurity and compliance consulting that focuses on delivering high quality service at a reasonable price. ISO 27001, SOC 2, ISO 42001, GDPR",
      "description": "Our customers appreciate our consistently high quality and personal human touch. Auditors find that we help build truly robust programs that build real trust. We help you reduce risk year over year while increasing your maturity and capabilities.\n\nWe manage ISO 27001, ISO 42001, SOC 2, HIPAA, PCI, GDPR and others on behalf of our customers. This includes working with the auditor on your behalf so you don't have to. We also offer short term engagements for completing ISO 27001 and ISO 42001 internal audits.\n\nWe perform our managed service with flat fee billing that covers everything including completing your inbound security questionnaires. We completely reject the idea of \"loss leader\" services just to make it easier to upsell to more profitable services. Our pricing tends to be middle of the road. Not the most expensive but definitely not the cheapest. ",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Canada",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "PCI DSS",
        "HIPAA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "Finance",
        "Healthcare",
        "Insurance",
        "Private Equity",
        "Real Estate",
        "Technology",
        "Transportation"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/genius+grc/r/recTi9j02BekhXty2"
    },
    {
      "name": "GRASP - ISMS",
      "url": "https://eu1.hubs.ly/H0lLlC70",
      "briefSummary": "GRASP compliance platform helps organizations build and operate a structured ISMS. The platform enables centralized management of risks, actions, and evidence, ensures transparency and traceability, and supports full compliance with ISO 27001 requirements.",
      "description": "Key Differentiators of GRASP (provided by DextraData)\n\n1. Built specifically for GRC\nGRASP isn’t a generic project tool or a repurposed spreadsheet. It’s a compliance platform purpose-built to manage Governance, Risk, and Compliance processes with the depth and structure they require.\n\n2. Modular and focused\nInstead of bloated suites, GRASP offers dedicated apps like ISMS, Audit, and BCM – each tailored to its purpose and aligned with industry best practices.\n\n3. End-to-end traceability\nFrom risk identification to corrective actions, GRASP keeps a complete and verifiable record. Every change, responsibility, and deadline is traceable and audit-ready.\n\n4. Built for teams, not individuals\nGRASP supports distributed teams with workflows, assignments, and alerts. It’s easy to collaborate across departments, locations, or external auditors.\n\n5. Fast setup and real results\nGRASP includes prebuilt templates, role structures, and best practices – so you can start immediately without long onboarding phases.\n\n⸻\n\nFrameworks and Standards Supported by the compliance platform\n\t•\tISO/IEC 27001 (incl. 2022 controls)\n\t•\tNIS2 Directive\n\t•\tGDPR (supporting risk and measure integration)\n\t•\tOptional integrations across ISMS, Audit, BCM, and Risk\n\n⸻\n\nPricing Model\n\t•\tModular and usage-based\nYou only pay for the apps and number of users you need – scalable as your needs grow.\n\t•\tTransparent tiers\nFeatures like on-premise deployment, advanced integrations, or white-labeling are available as premium options.\n\t•\tNo hidden fees\nCloud hosting, updates, and standard support are included.\n\t•\tFree 30-day trial\nTry GRASP risk-free for 30 days – no commitment, no payment details required.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Global",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "NIS2"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring",
        "Certification Assistance",
        "Data Protection",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/grasp+-+isms/r/recMOgdwuJOJqb43J"
    },
    {
      "name": "GRC Advisory",
      "url": "https://grcadvisory.com",
      "briefSummary": "Polish GRC and SAP security consultancy with 15+ years of enterprise access governance, SoD, and risk-compliance implementations.",
      "description": "GRC Advisory Sp. z o.o. is a Wrocław and Kraków-based consulting firm specializing in governance, risk, and compliance for enterprise systems. The practice delivers SAP Security and authorizations, SAP GRC Access Control, RSA Archer implementations, SoD workshops, and GDPR-related compliance support. It is ISO 27001 certified and has delivered multi-year programs for major Polish and international enterprises.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Poland",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "SOX",
        "NIS2",
        "DORA",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Vendor Management",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "Manufacturing",
        "Finance",
        "Technology",
        "Retail",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "Polish",
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/grc+advisory/r/830f661e-a08e-404e-a7f7-8c6367d2b3ef"
    },
    {
      "name": "GRC Lab",
      "url": "https://grclab.com",
      "briefSummary": "GRC Lab provides resources, courses, and toolkits to help organizations implement ISO 27001-compliant ISMS in a practical way.",
      "description": "Offers starter kits, project plans, document templates, video courses, and hands-on guidance for ISO 27001 and other GRC standards.",
      "serviceType": [
        "Toolkit"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "ISO 42001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/grc+lab/r/recl8FfroAQNZ7rmt"
    },
    {
      "name": "GRC Solutions",
      "url": "https://grcsolutions.io",
      "briefSummary": "UK cyber security and compliance group (formerly IT Governance) for ISO 27001 consultancy, training, toolkits, and multi-framework programs.",
      "description": "GRC Solutions is the rebranded home of IT Governance Ltd and related compliance brands. For more than two decades the group has been known for ISO 27001 consultancy, documentation toolkits, training, and broader cyber security and compliance services covering SOC 2, Cyber Essentials, PCI DSS, GDPR, and AI governance. It remains a primary reference brand for structured ISO 27001 programs in the UK and internationally.",
      "serviceType": [
        "Consulting",
        "Training",
        "Toolkit"
      ],
      "regionCovered": [
        "United Kingdom",
        "Europe",
        "Global",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "PCI DSS",
        "Cyber Essentials",
        "ISO 42001",
        "Multi-framework",
        "ISO 22301",
        "NIS2"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Gap Analysis",
        "Policy Creation",
        "Lead Implementer Training",
        "Compliance",
        "Risk Management",
        "Security Awareness Training"
      ],
      "industrySpecialization": [
        "All industries",
        "Technology",
        "SaaS"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/grc+solutions/r/0e23b872-2cce-4b35-820a-60ef633b94f3"
    },
    {
      "name": "GRCC Jahn",
      "url": "https://www.grc.consulting/",
      "briefSummary": "Governance, Risk & Compliance consulting by Viktor Jahn. One point of contact from start to finish. Audits, advisory, and training across NIS2, BISG, TISAX, DORA, GDPR, and ISO 27001. Pragmatic, hands-on and built for practice.",
      "description": "GRCC is an independent GRC consultancy run by Viktor Jahn, focused on governance, risk management, and compliance. Services cover advisory, audits, and training across ISO 27001, ISO 22301, ISO 9001, ISO 37301, TISAX® VDA-ISA, C5, NIS2/BSIG, DORA, IT-Grundschutz and GDPR.\n\nWhat sets GRCC apart from larger firms is a simple promise: Viktor Jahn personally leads every engagement from start to finish. There is no rotating team, no junior handoff, and no gap between who sells and who delivers. Commitments are binding, communication is transparent, and solutions are built for how a business actually operates.\n\nEngagements are available on a project or day-rate basis. A free initial consultation can be booked directly through the website.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Austria",
        "Belgium",
        "Denmark",
        "Europe",
        "France",
        "Germany",
        "Sweden",
        "Switzerland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "GDPR",
        "Multi-framework",
        "NIS2",
        "DORA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Certification Assistance",
        "Data Protection",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "Construction",
        "Finance",
        "Government",
        "Healthcare",
        "Hospitality",
        "Manufacturing",
        "Private Equity",
        "Real Estate",
        "Retail",
        "Technology",
        "Transportation"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/grcc+jahn/r/97c4d0ee-17c6-45c9-97e1-5c3c154f986e"
    },
    {
      "name": "Gritera",
      "url": "https://gritera.com/en",
      "briefSummary": "Gritera specializes in information security management services, including advisory for ISO 27001 implementation and risk management.",
      "description": "Gritera is a leading consulting provider focused on ISO 27001 compliance, cybersecurity, and secure system architecture, helping organizations maintain ISMS.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe",
        "Norway"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "ISO 27701",
        "ISO 42001",
        "DORA",
        "NIS2",
        "ISO 22301"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Certification Assistance",
        "Data Protection",
        "GDPR Compliance",
        "Security Awareness"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Norwegian"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/gritera/r/reci0kPFByi1LtaRB"
    },
    {
      "name": "HALOCK",
      "url": "https://www.halock.com",
      "briefSummary": "Chicago information-security consultancy for risk assessments, SOC 2 readiness, and compliance programs.",
      "description": "HALOCK is a US information-security consultancy based in the Chicago area. Teams hire it for risk assessments and compliance readiness, not as a software platform. This listing is not a certification claim.",
      "serviceType": [
        "Consultants"
      ],
      "regionCovered": [
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "HIPAA",
        "PCI DSS",
        "Multi-framework",
        "CCPA"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Gap Analysis"
      ],
      "industrySpecialization": [
        "Technology",
        "Healthcare",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/halock/r/850ded9b-3ca5-406e-b315-6a1154dba948"
    },
    {
      "name": "Hard2bit",
      "url": "https://hard2bit.com",
      "briefSummary": "Madrid cybersecurity firm offering GRC consulting for ISO 27001, NIS2, DORA, and ENS alongside technical security services.",
      "description": "Hard2bit is a Spanish cybersecurity company founded in 2013 and based in Madrid. Its Compliance and GRC practice helps organizations implement and operate controls for ISO 27001, NIS2, DORA, and Spain's ENS framework with audit-ready evidence. Hard2bit holds multiple ISO certifications and ENS High for its own systems, and also delivers SOC/MDR and technical testing for regulated clients.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Spain",
        "Europe",
        "Latin America"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "NIS2",
        "DORA",
        "ISO 22301",
        "ISO 9001",
        "Multi-framework",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Gap Analysis",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring",
        "Incident Response"
      ],
      "industrySpecialization": [
        "All industries",
        "Finance",
        "Technology",
        "Government"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "Spanish",
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/hard2bit/r/4ccc4676-dd44-4181-a074-6a5b2c4f0336"
    },
    {
      "name": "heygrc",
      "url": "https://heygrc.com",
      "briefSummary": "GitHub App that reviews every pull request against your compliance frameworks, flags changes that put a control at risk, and says exactly what to fix.",
      "description": "heygrc is a GitHub App that brings compliance into the developer workflow. It reviews every pull request the moment it opens, catches the changes that put a control at risk (whether a person or an AI agent wrote the code), and says exactly what to fix, citing the actual control clause (for example ISO 27001:2022 A.8.15, SOC 2 CC6.1). It posts a review, inline comments, and a check status, with no CI config or YAML to maintain. It covers 76 frameworks including ISO 27001, SOC 2, GDPR, DORA, NIS 2, ISO 42001, EU AI Act, PCI DSS, and HIPAA. By ISMS Copilot.",
      "serviceType": [
        "SaaS",
        "Compliance platform",
        "AI assistant"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "EU AI ACT",
        "DORA",
        "NIS2",
        "ISO 42001",
        "PCI DSS",
        "HIPAA",
        "ISO 27701",
        "NIST CSF",
        "CMMC",
        "FedRAMP",
        "CCPA",
        "Cyber Essentials",
        "TISAX",
        "ISO 22301",
        "SOX",
        "CIS Controls",
        "SOC 1",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Automation",
        "Continuous Monitoring",
        "Audit Preparation",
        "Risk Management"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/heygrc/r/b1a7073d-5d19-47f9-8af7-8151c43d5116"
    },
    {
      "name": "Hollanders Consultancy",
      "url": "https://www.hollanders-consultancy.nl/",
      "briefSummary": "Hollanders Consultancy helps organizations strengthen information security and IT governance through pragmatic advisory, architecture, and compliance support, including ISO 27001, NIS2, risk management, and secure cloud solutions.",
      "description": "Key differentiators\nPragmatic, hands-on consulting with deep technical expertise. I combine governance, risk, and compliance with real-world IT architecture and operations, focusing on what actually works.\n\nFrameworks & standards\nPrimarily ISO/IEC 27001, NIS2, DORA, and related frameworks (e.g. risk management, BCM/DR, supplier assurance), aligned with Microsoft 365, Azure, and modern cloud environments.\n\nPricing model\nTransparent hourly or fixed-price engagements, scoped upfront. No long-term lock-ins; clients pay for measurable progress and concrete deliverables.\n\nCommitment to quality\nQuality is ensured through structured documentation, evidence-based controls, clear ownership, and audit-ready outputs. I work to auditor standards and take accountability for results.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe",
        "Netherlands"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "NIS2",
        "DORA",
        "ISO 42001"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Incident Response"
      ],
      "industrySpecialization": [
        "Finance",
        "Healthcare",
        "Manufacturing",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/hollanders+consultancy/r/recmKR9pbAUWweP6E"
    },
    {
      "name": "Hyperproof",
      "url": "https://hyperproof.io",
      "briefSummary": "Intelligent GRC platform that transforms compliance from a cost center into a competitive advantage with AI-powered automation.",
      "description": "Hyperproof streamlines compliance operations by automating control mapping, eliminating duplicative work, and turning real-time risk data into actionable insights. The FedRAMP Moderate authorized platform is trusted by organizations like Reddit, Fortinet, and Thales.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "PCI DSS",
        "NIST CSF",
        "NIS2",
        "DORA",
        "CMMC",
        "FedRAMP",
        "NIST SP 800-53",
        "HITRUST"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Continuous Monitoring",
        "Risk Management",
        "Audit Preparation",
        "Gap Analysis"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Medium",
        "Enterprise"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/hyperproof/r/75b292eb-008e-412f-81e7-a4c187cddcc1"
    },
    {
      "name": "I.S. Partners",
      "url": "https://www.ispartnersllc.com",
      "briefSummary": "Philadelphia CPA and compliance firm for SOC, HIPAA, HITRUST, PCI, and ISO 27001 assessments.",
      "description": "I.S. Partners is a US CPA firm based in Philadelphia that performs SOC, HIPAA, HITRUST, PCI, and ISO 27001 work. It is an assessor, not a software platform. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "HIPAA",
        "HITRUST",
        "PCI DSS",
        "ISO 27001",
        "Multi-framework",
        "CMMC",
        "CSA STAR",
        "GDPR",
        "SOX"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "Healthcare",
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/i.s.+partners/r/660af82c-5e36-4047-9571-e972b16e541c"
    },
    {
      "name": "i.s.c. Group",
      "url": "http://www.iscgroup.co.at",
      "briefSummary": "ISMS implementations, OneCompliance(tm) program to implement multiple standards at once.",
      "description": "Founder is a member of the author group of ISO27001, did first ISMS in 2004",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "India",
        "Israel",
        "Middle East",
        "United Kingdom",
        "United States",
        "Austria",
        "Germany",
        "France"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "PCI DSS",
        "TISAX"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "French",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/i.s.c.+group/r/recmK2eBWryoWsk4j"
    },
    {
      "name": "Insight Assurance",
      "url": "https://insightassurance.com",
      "briefSummary": "Florida CPA firm providing SOC 2, ISO 27001, and HIPAA attestation for mid-market technology companies.",
      "description": "Insight Assurance is a US CPA firm that issues SOC 2 and related reports for technology companies. It is an auditor, not a compliance automation product. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "HIPAA",
        "PCI DSS",
        "Multi-framework",
        "CMMC",
        "CSA STAR",
        "FedRAMP",
        "HITRUST",
        "ISO 27701",
        "ISO 42001",
        "NIST CSF",
        "NIST SP 800-171"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "SaaS",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/insight+assurance/r/734f87c2-5fff-4a53-bdc0-cb54ea2dff5c"
    },
    {
      "name": "Instant 27001",
      "url": "https://instant27001.com/",
      "briefSummary": "Instant 27001 is a ready-to-run ISMS, that contains all you need to implement ISO 27001 and get yourself ready for certification in a matter of weeks. You will start the implementation with 80% of the work already done, no prior experience or training necessary.",
      "description": "Instant 27001 is a lean-and-mean approach towards ISO 27001. We have included the stuff that works and left out the rest. Instant 27001 is available for Confluence or Microsoft 365 (ISOPlanner). Prices starting at € 2495 (one time fee!). Add-ons are available for ISO 9001, ISO 42001, SOC 2, TISAX, C5 and many more.",
      "serviceType": [
        "Toolkit"
      ],
      "regionCovered": [
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "United Kingdom",
        "United States",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "ISO 27701",
        "ISO 9001",
        "TISAX",
        "NIS2",
        "DORA",
        "HIPAA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "German",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/instant+27001/r/recm7iWGWVZVwve5A"
    },
    {
      "name": "Intercert",
      "url": "https://www.intercert.com",
      "briefSummary": "Intercert provides internationally accredited auditing, certification, and training services across various management systems and standards.",
      "description": "Intercert offers a wide range of certifications, including ISO 9001, ISO 27001, ISO 14001, and more. They are accredited by the Standard Council of Canada (SCC) and provide professional training accredited by Exemplar Global.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 14001",
        "ISO 45001",
        "ISO 50001",
        "ISO 22000",
        "ISO 21001",
        "ISO 13485",
        "ISO 27701",
        "ISO 22301",
        "SOC 2",
        "PCI-DSS",
        "GDPR",
        "HIPAA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Certification Assistance",
        "Incident Response",
        "Data Protection",
        "Certification Body Services",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/intercert/r/recR3LipkKqhhvROe"
    },
    {
      "name": "IRM Consulting",
      "url": "https://irmcon.com/",
      "briefSummary": "Delivering tailored Fortune 500-level Virtual CISO (vCISO) Services.and solutions that ensure robust Cybersecurity, AI Risk Management & Data Governance for SaaS businesses at a fraction of the cost of an in-house team or full-time CISO. We help SaaS Companies, Startups & SMBs achieve SOC2, ISO42001, CMMC, ISO27001/2 Compliance 40% Cheaper & Faster.",
      "description": "SOC2, ISO42001, CMMC, ISO27001/2, PCI-DSS, HIPAA, PIPEDA",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Canada",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "HIPAA",
        "NIST CSF",
        "CMMC",
        "CCPA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/irm+consulting/r/355e49e8-05c1-4ed7-a8b5-e2c61be120ca"
    },
    {
      "name": "ISMS Copilot",
      "url": "https://www.ismscopilot.com/products",
      "briefSummary": "Compliance AI engine for 75+ frameworks including ISO 27001, SOC 2, GDPR, NIS2, DORA, and ISO 42001. Chat for practitioners. OpenAI-compatible API and embed for products and partners.",
      "description": "ISMS Copilot is a compliance AI engine for information security and privacy work. Practitioners use the chat assistant to draft policies, prepare audits, and work across 75+ frameworks including ISO 27001, ISO 42001, SOC 2, GDPR, NIS2, DORA, NIST, HIPAA, and the EU AI Act. Product and platform teams use the same engine through an OpenAI-compatible API and an embeddable assistant, so compliance AI can sit inside other GRC tools and workflows. ISMS Copilot is not a continuous-control-monitoring or evidence-vault GRC suite: it does not replace a compliance platform for those jobs. It is a specialized alternative to general-purpose AI for people and products that already know the compliance job. Built for GRC consultants, lead implementers, auditors, and teams embedding compliance AI into their own software.",
      "serviceType": [
        "AI assistant",
        "SaaS"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "ISO 27701",
        "ISO 22301",
        "ISO 9001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "CCPA",
        "NIST CSF",
        "NIST SP 800-171",
        "NIST SP 800-53",
        "NIS2",
        "DORA",
        "TISAX",
        "CMMC",
        "FedRAMP",
        "Cyber Essentials",
        "EU AI ACT",
        "NIST AI Risk Management Framework",
        "Multi-framework",
        "NEN7510",
        "BIO",
        "NIS2 CyberFundamentals"
      ],
      "problemsTheySolve": [
        "Policy Creation",
        "Compliance",
        "Audit Preparation",
        "Automation",
        "Risk Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German",
        "Spanish",
        "French",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/isms+copilot/r/recqbO6TBTkQueDHo"
    },
    {
      "name": "ISMS.online",
      "url": "https://www.isms.online",
      "briefSummary": "Cloud-based ISMS platform that guides organizations to first-time ISO 27001 certification and compliance across 100+ frameworks.",
      "description": "ISMS.online provides a pre-built bank of tools, frameworks, policies, and controls where up to 81% of compliance work is already done, empowering over 65,000 users globally. The platform uses the Assured Results Method with dedicated Customer Success Managers to simplify certification.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 27701",
        "ISO 42001",
        "ISO 9001",
        "ISO 22301",
        "SOC 2",
        "GDPR",
        "NIS2",
        "DORA",
        "PCI DSS",
        "ISO 45001",
        "ISO 14001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Policy Creation",
        "Audit Preparation",
        "Risk Management",
        "Continuous Monitoring",
        "Gap Analysis"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/isms.online/r/a7457d65-c196-4fa7-8bea-bdc3122d751d"
    },
    {
      "name": "ISO 27001 Lead Implementer Course",
      "url": "https://grclab.com/courses/iso-27001-lead-implementer",
      "briefSummary": "Deep knowledge and toolkits to implement ISO 27001.",
      "description": "Comprehensive ISO 27001 Lead Implementer course offering deep knowledge and practical toolkits for effective implementation of ISO 27001.",
      "serviceType": [
        "Lead implementer course"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001"
      ],
      "problemsTheySolve": [
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso+27001+lead+implementer+course/r/recaUj5GkhPb4MeMw"
    },
    {
      "name": "ISO 27001:2002 Audit prep",
      "url": "Www.Multiplai.de",
      "briefSummary": "ISO 27k and Cyber GRC suite of offerings encompassing NIS2 and other frameworks \n",
      "description": "Cost effect posture visibility based on business goals with broad framework support. ",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Africa",
        "Europe",
        "United Kingdom",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "Multi-framework",
        "NIS2",
        "DORA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso+27001:2002+audit+prep/r/recmh0nj32VJTone3"
    },
    {
      "name": "ISO Certification Provider",
      "url": "https://sqccertification.com/",
      "briefSummary": "SQC Certification Services Pvt. Ltd., we pride ourselves not only on certifying organizations but also on fostering a culture of continuous improvement with our training programs like Internal Auditor, Lead Auditor, Workplace Management System etc. Our journey has been marked by a commitment to quality & reliability.",
      "description": "Accredited Certification Body: We are accredited by UAF and operate with strict compliance to international requirements.\n\nIndustry-Experienced Auditors: Our auditors come with strong domain expertise across IT, manufacturing, education, healthcare, and services.\n\nEnd-to-End Support: From gap assessment to certification, surveillance, and continual improvement support.\n\nFast Turnaround Time: We ensure quick scheduling, timely reporting, and smooth audit closure.\n\nTransparent Communication: Clear processes, milestone-based engagement, and no hidden charges.\n\nStrong Global Network: We work with trusted business associates and clients across multiple countries.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "Africa",
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "India",
        "Latin America",
        "Middle East",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "ISO 9001",
        "ISO 14001",
        "ISO 45001",
        "ISO 13485",
        "ISO 22301",
        "ISO 50001",
        "ISO 22000"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Security Awareness",
        "Certification Assistance",
        "Data Protection",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries",
        "Construction",
        "Cryptocurrency",
        "Finance",
        "Government",
        "Healthcare",
        "Hospitality",
        "Insurance",
        "Manufacturing",
        "Private Equity",
        "Real Estate",
        "Retail",
        "Technology",
        "Transportation"
      ],
      "targetClientsSize": [
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "Hindi"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso+certification+provider/r/recqscq4hys182gRE"
    },
    {
      "name": "ISO Serious",
      "url": "https://www.isoserious.com",
      "briefSummary": "Pragmatic ISO 27001 implementation and maintenance for startups.",
      "description": "Specialized in pragmatic ISO 27001 implementation and ongoing maintenance services tailored specifically for startups.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "United Kingdom",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Policy Creation",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso+serious/r/recLXV7FtdB93pGg1"
    },
    {
      "name": "ISO27001 Implementation",
      "url": "https://grc-hub.co.uk/services/iso27001/",
      "briefSummary": "At GRC Hub, we help businesses strengthen their governance, risk, and compliance frameworks through a blend of expert consultancy and smart automation. Our approach reduces unnecessary manual effort, enabling teams to focus on what matters most.\nOur ISO27001 services include:\n\nStatement of Applicability and Scope Identification\nGap Analysis and Implementation Support\nMock Audits and Readiness Assessments\nGuidance throughout Stage 1 and Stage 2 Certification Audits\n\nWe combine deep industry expertise with technology-driven solutions to deliver efficiency, clarity, and confidence in compliance.",
      "description": "GRC Hub focuses purely on outcomes and results. Unlike firms that prolong engagements unnecessarily, we deliver efficient, value-driven solutions tailored to your business needs. Our approach combines expert consultancy with automation tools, reducing manual effort and accelerating compliance without compromising quality.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "United Kingdom"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Certification Assistance",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries",
        "Real Estate",
        "Retail",
        "Technology"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso27001+implementation/r/recFCwlUmHiuqLQGB"
    },
    {
      "name": "ISO27001.zip",
      "url": "https://iso27001.zip/",
      "briefSummary": "A free-to-use site ran by the Technical Director of ADAS Ltd, providing resources related to ISO 27001, such as clause explainers, workshops, historical timelines and more. It's designed to provide Implementors and Auditors actionable insights into the standard, and provide terms of reference for thinking in systems. It's an excellent tool to add to the toolbox of any consultant or team member working in, on, or around ISO 27001.",
      "description": "Completely free to use and non-commercial, this is one of the few tools in the landscape that is a pure passion project centred around a love for the utility that ISO 27001 provides. ",
      "serviceType": [
        "Lead implementer course"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Data Protection",
        "Secure AI Deployment",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso27001.zip/r/rectqt6H97ouJJ2PB"
    },
    {
      "name": "ISO27001security",
      "url": "https://www.iso27001security.com/",
      "briefSummary": "Info on 100 \"ISO27k\" standards, plus a user community, FAQ and toolkit - all free",
      "description": "Free information and support for ISMS implementers",
      "serviceType": [
        "Toolkit"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/iso27001security/r/recZ9ZCHnSk9SuH7Q"
    },
    {
      "name": "ISOPlanner",
      "url": "https://isoplanner.app",
      "briefSummary": "ISOPlanner is a Microsoft 365-integrated platform that simplifies ISO compliance and information security management. It helps organizations implement, monitor, and improve frameworks like ISO 27001, NIS2, and BIO 2.0 efficiently and collaboratively.",
      "description": "Key differentiators:\nISOPlanner seamlessly integrates with Microsoft 365 (Teams, SharePoint, Power Automate), offering an intuitive, collaborative ISMS environment. It combines compliance management, risk control, and audit workflows in one secure EU-hosted platform.\n\nFrameworks and standards:\nFocused on ISO 27001, ISO 27701, NEN 7510, BIO 2.0, NIS2, ISO 14001, and ISO 45001 — with structured mappings and templates for each.\n\nPricing model:\nTiered SaaS pricing per active user: Management users (full access) and Light users (limited access). Plans available as monthly or annual subscriptions (Basic, Business, Premium tiers).",
      "serviceType": [
        "SaaS"
      ],
      "regionCovered": [
        "Europe",
        "Global",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/isoplanner/r/recaznMsaFzHxuULd"
    },
    {
      "name": "Johanson Group LLP",
      "url": "https://www.johansonllp.com",
      "briefSummary": "Boutique US CPA firm specializing in SOC 1/2/3 examinations and related security and compliance audits for growing companies.",
      "description": "Johanson Group LLP is a Colorado-based CPA firm focused on security and compliance attestation. It provides SOC 1, SOC 2, and SOC 3 examinations plus ISO 27001 and HIPAA-related audit services, with a boutique model emphasizing partner access and efficient report delivery for technology companies.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "HIPAA",
        "Multi-framework",
        "CCPA",
        "GDPR",
        "ISO 42001",
        "NIST",
        "PCI DSS",
        "SOC 2 Type 2"
      ],
      "problemsTheySolve": [
        "Audit Preparation",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/johanson+group+llp/r/68b5c6eb-895e-4d73-8508-28a7865b839c"
    },
    {
      "name": "Kertos",
      "url": "www.kertos.io",
      "briefSummary": "Kertos is the modern backbone of every company’s privacy and compliance operations. Providing support in Data & Process Discovery, Data Subject Requests (e.g. customer data deletion), Access Management, Compliance Documentation and various Certification Frameworks such as ISO27001, SOC2, TISAX® and similar. Our no-code SaaS solution connects to the entire IT infrastructure, identifies compliance relevant assets and processes, related data and automates compliance workflows to get an organization certification ready within weeks.\n",
      "description": "Kertos provides essential support for your company's privacy and compliance operations with a no-code SaaS platform. Our solution integrates with your IT infrastructure to handle Data & Process Discovery, Data Subject Requests, Access Management, and Compliance Documentation. We support frameworks like ISO27001, SOC2, and TISAX®, automating workflows to help your organization achieve certification quickly. Our pricing is based on monthly fees, scaled to the size of your company.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Global",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "GDPR",
        "NIS2",
        "DORA",
        "ISO 42001",
        "ISO 27701",
        "TISAX"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Automation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/kertos/r/recLE2fifAMBmrHZk"
    },
    {
      "name": "KirkpatrickPrice",
      "url": "https://kirkpatrickprice.com",
      "briefSummary": "Nashville licensed CPA firm for SOC 2, PCI, HIPAA, and ISO 27001 audits across US offices.",
      "description": "KirkpatrickPrice is a US CPA firm that performs SOC 2, PCI, HIPAA, and ISO 27001 audits. It has offices in several US cities. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "PCI DSS",
        "HIPAA",
        "ISO 27001",
        "Multi-framework",
        "CMMC",
        "HITRUST",
        "ISO 42001"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "Healthcare",
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/kirkpatrickprice/r/242890d0-c431-4520-99e2-c7f8855d7bf9"
    },
    {
      "name": "Kiwa",
      "url": "https://www.kiwa.com",
      "briefSummary": "Dutch-rooted testing, inspection, and certification group offering RvA-accredited ISO 27001 certification across Europe.",
      "description": "Kiwa is an international testing, inspection, and certification organization with strong presence in the Netherlands and Europe. Kiwa provides ISO/IEC 27001 certification under national accreditation (including RvA in the Netherlands) and related management system schemes for organizations that need independent third-party assurance of information security.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Netherlands",
        "Europe",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "Multi-framework",
        "GDPR",
        "ISO 20000-1",
        "ISO 27701",
        "ISO 42001"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/kiwa/r/52e1f00c-b9f2-44d6-be18-06ae9aae670b"
    },
    {
      "name": "Kopexa",
      "url": "https://kopexa.com",
      "briefSummary": "Kopexa is a compliance platform for building and maintaining ISO 27001–ready management systems. It helps organizations structure assets, risks, controls and evidence, enabling continuous compliance instead of one-time audits.",
      "description": "Kopexa is a compliance and GRC platform focused on building sustainable, auditable management systems instead of “audit-only” checklists. We support organizations in structuring assets, risks, controls, evidence and responsibilities in a way that aligns with ISO 27001 and related frameworks.\n\nOur focus is long-term compliance maturity rather than fast certification promises. We support multi-framework setups (ISO 27001, GDPR, NIS2, DORA) and help teams move from static documentation to continuous control validation.\n\nPricing is transparent and subscription-based, depending on organization size and usage. We deliberately avoid “guaranteed certification” or shortcut approaches — quality, traceability and real operational security come first.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Global",
        "Germany",
        "Spain",
        "France"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "NIS2",
        "ISO 9001",
        "TISAX",
        "DORA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Spanish",
        "French",
        "German",
        "Catalan"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/kopexa/r/receqecRnJH0xONCA"
    },
    {
      "name": "Kordon",
      "url": "https://kordon.app/",
      "briefSummary": "Kordon is a straightforward GRC (Governance, Risk, and Compliance) platform designed to simplify compliance processes for companies by offering a comprehensive suite of tools for risk management and regulatory adherence.",
      "description": "Kordon streamlines GRC management with a user-friendly platform that integrates various compliance frameworks and risk management tools, helping businesses efficiently manage their compliance obligations.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "Multi-framework",
        "ISO 27001",
        "GDPR",
        "SOC 2 Type 2",
        "SOC 2",
        "PCI DSS",
        "NIS2",
        "DORA",
        "ISO 42001",
        "E-ITS"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Continuous Monitoring",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Estonian",
        "Ukrainian"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/kordon/r/receirRXJPJrpZe97"
    },
    {
      "name": "Lazarus Alliance",
      "url": "https://lazarusalliance.com",
      "briefSummary": "US assessor for SOC 2, FedRAMP, CMMC, and related federal-adjacent security audits.",
      "description": "Lazarus Alliance is a US assessment firm for SOC 2 and federal-adjacent frameworks including FedRAMP and CMMC. Listing them does not mean they are a FedRAMP PMO or that they authorize systems. This listing is not a certification claim.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "FedRAMP",
        "CMMC",
        "ISO 27001",
        "NIST SP 800-53",
        "Multi-framework",
        "CCPA",
        "GDPR",
        "HIPAA",
        "ISO 27701",
        "ISO 42001",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "Government"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/lazarus+alliance/r/4dbd1219-a19a-4776-ae41-141a348e719e"
    },
    {
      "name": "Linford & Company",
      "url": "https://linfordco.com",
      "briefSummary": "Denver CPA firm of former Big Four auditors specializing in SOC 2, HIPAA, FedRAMP, and HITRUST assessments.",
      "description": "Linford & Company is a US CPA firm built around IT compliance and attestation. The practice is widely known for SOC 2 examinations, with additional capability across HIPAA, FedRAMP, and HITRUST assessments. Teams often come from large-firm audit backgrounds with a boutique delivery model.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "HIPAA",
        "FedRAMP",
        "HITRUST",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Audit Preparation",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "Healthcare",
        "Finance"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/linford+&+company/r/f04b2af3-e2a8-489f-9659-f9af3105dfe6"
    },
    {
      "name": "LogicGate",
      "url": "https://www.logicgate.com",
      "briefSummary": "Chicago no-code GRC platform (Risk Cloud) for enterprise risk, compliance, and audit workflows.",
      "description": "LogicGate Risk Cloud is a US GRC platform that lets teams build risk, compliance, and audit applications without custom code. It is aimed at enterprise GRC teams that want configurable workflows. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "Multi-framework",
        "DORA",
        "GDPR",
        "HIPAA",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Automation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/logicgate/r/00e9264f-d29a-4a2e-8076-953a87dc1807"
    },
    {
      "name": "LogicManager",
      "url": "https://www.logicmanager.com",
      "briefSummary": "Boston ERM and GRC software for enterprise risk, compliance, and audit alignment.",
      "description": "LogicManager is a US ERM and GRC platform from Boston. Mid-market and enterprise risk teams use it to connect risk registers, compliance, and audit follow-up. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/logicmanager/r/b3f3547f-96e6-4afb-8df5-f40302ac75cc"
    },
    {
      "name": "LowerPlane",
      "url": "https://lowerplane.com/",
      "briefSummary": "LowerPlane is a compliance automation platform that helps growing companies achieve SOC 2, ISO 27001, GDPR, and HIPAA faster — with continuous monitoring, policy automation, and custom review workflows.",
      "description": "LowerPlane differentiates through custom access review workflows, transparent pricing, and a design built for companies just starting their compliance journey — not enterprise-only. Supports SOC 2, ISO 27001, GDPR, HIPAA, and PCI-DSS. Priced more efficiently compared to Vanta/Drata with no per-integration fees.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Asia",
        "Europe",
        "Middle East",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "HIPAA",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/lowerplane/r/75799d4e-4432-4ebd-b5b3-303cf70b5c1b"
    },
    {
      "name": "Maor Compliance",
      "url": "www.maorcompliance.com",
      "briefSummary": "\n\nWe provide a process-based ISO/IEC 27001:2022 compliance platform that helps organisations build and maintain a reliable ISMS at a practical, sustainable pace. Our approach focuses on clarity, structure, and doing things correctly rather than rushing to certification.\n\nThe platform guides users through each clause and control with step-by-step instructions, evidence management, task ownership, risk handling, and document control. It is designed to support real audit readiness—not shortcut implementations.\n\nMAOR Compliance is based in Ireland, and our team has hands-on expertise in ISO/IEC 27001 implementation and audit preparation, gained from supporting organisations of different sizes and maturity levels. We aim to provide a tool grounded in real-world experience, not generic checklists.\n\nWe primarily support small and mid-size companies that want a structured, methodical platform to manage their ISMS without heavy consulting overhead. We don’t replace auditors or consultants; instead, we provide a system that helps teams understand the standard, stay organised, and maintain ongoing compliance.\n\nIf you’re looking for a platform built by practitioners who understand how ISO/IEC 27001 works in real organisations, and who value robustness over shortcuts, our solution may be a good fit.\n\n-\n",
      "description": "Key differentiators:\nOur platform takes a process-based approach rather than relying on generic templates. It guides organisations through ISO 27001:2022 step by step so they understand what they are doing. The product is built by practitioners with real audit-preparation experience, and it reflects how ISO 27001 actually works in practice. We are focused on small and mid-size organisations that need a clear, structured ISMS workflow without enterprise-level complexity. We do not make unrealistic promises about fast certifications; instead, we help teams build an ISMS that is genuinely audit-ready. The platform brings risk management, evidence tracking, document control, task management, and readiness indicators into one integrated system.\n\nFrameworks and standards we focus on:\nOur primary focus is ISO 27001:2022. The platform incorporates guidance aligned with ISO 27002:2022 and risk management principles from ISO 31000. We are also preparing optional support for ISO 27701 as an extension for organisations that already have a stable ISMS.\n\nHow pricing works:\nWe use a simple subscription model. Pricing is based on the number of users and the size of the organisation. There are no hidden fees, and consulting is optional. Customers get a predictable annual cost that fits SMEs. Optional services like expert review hours or audit-preparation guidance are available separately when needed.\n\nHow you can know we care about quality:\nWe do not overpromise or offer shortcuts. Our content and workflows follow the real requirements of the standard, clause by clause. We encourage teams to build proper ISMS maturity rather than rushing. The platform’s guidance is shaped by real-world experience with external audit processes. We also continuously improve the product based on feedback from customers and auditors. As a small company, we rely on doing things well rather than doing them at volume, and every customer matters to us.\n\n-",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "United Kingdom",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "NIS2",
        "DORA",
        "TISAX"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/maor+compliance/r/recNbvJXYxPipVf3b"
    },
    {
      "name": "Mastermind Assurance",
      "url": "https://mastermindassurance.com/",
      "briefSummary": "Mastermind Assurance specializes in ISO and CSA STAR certification audits, focusing exclusively on these areas to provide expert assessments and straightforward project management.\n",
      "description": "Mastermind Assurance offers comprehensive certification audits, backed by experience in over 500 certification audits. They emphasize simplicity and expertise in their approach to ISO and CSA STAR certifications.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "Global",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "CSA STAR",
        "ISO 42001",
        "ISO 27701"
      ],
      "problemsTheySolve": [
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/mastermind+assurance/r/recyGzipgPCVEBGSF"
    },
    {
      "name": "MatrixGard",
      "url": "https://matrixgard.com",
      "briefSummary": "Fractional DevSecOps for pre-seed and seed startups: SOC 2, ISO 27001 and DPDP Act readiness, cloud security and AWS hardening, delivered by the engineer who does the work. Readiness and remediation, not attestation. Remote, worldwide.",
      "description": "Differentiators: founder-led and single-operator, so the person scoping the work is the person doing it, with roughly ten years across cloud, DevOps and security rather than one of the three. Frameworks: SOC 2, ISO 27001, India DPDP Act, RBI cyber security guidelines for fintech. Scope honesty is the quality bar: readiness and remediation only, never attestation, and clients engage a CPA or certification body for the audit itself. Pricing: monthly retainer, tiered by hours. Free public tooling as proof of work: a no-signup domain security scan at matrixgard.com/scan and Ghost-hunter, an open-source AI investigator for cloud billing. Website: https://matrixgard.com\n\n[tally:WJ1aO0v]",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Canada",
        "India",
        "Singapore",
        "UAE",
        "United Kingdom",
        "United States",
        "Global",
        "Switzerland",
        "New Zealand",
        "Netherlands",
        "Middle East",
        "Australia",
        "Asia"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "PCI DSS",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Certification Assistance",
        "Incident Response",
        "Data Protection",
        "Security Awareness",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "Finance",
        "Healthcare",
        "Technology",
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/matrixgard/r/94ebbc22-f933-4294-bbfa-b862f16afef1"
    },
    {
      "name": "MeasurementPros - Implementation and Assurance",
      "url": "https://www.measurementpros.io",
      "briefSummary": "MeasurementPros brings hands-on implementation experience across security (ISO 27001, SOC 2) and governance (DORA, NIS2, CRA, EU AI Act, AIUC-1, GDPR, vCISO), serving clients in the EU as well as North American companies exposed to EU law.",
      "description": "MeasurementPros combines cybersecurity, GRC and AI governance to help organizations manage an increasingly overlapping set of security and regulatory obligations.\n\nOur work is grounded in established security and assurance frameworks including ISO 27001 and SOC 2, while extending into ISO 42001, the EU AI Act, DORA, NIS2, the Cyber Resilience Act (CRA) and GDPR. \n\nWe also provide vCISO services for organizations that need experienced security leadership without a full-time CISO.\n\nWe focus on the practical work behind compliance: risk and gap assessments, governance and management systems, policies and controls, audit preparation, technical and regulatory documentation, vendor and third-party risk, AI governance, and ongoing compliance. \n\nFor organizations deploying or providing AI systems, we help connect AI-specific obligations to the security, risk and governance structures they already have rather than creating another isolated compliance program.\n\nMeasurementPros is particularly focused on the convergence of cybersecurity, AI governance and European technology regulation. As requirements increasingly overlap, our objective is to identify what can be shared across frameworks, what remains regulation-specific, and what organizations actually need to implement and maintain in practice.\n\nEngagements can range from focused readiness and gap assessments to implementation support, ongoing advisory and fractional security leadership. Our approach is practical and evidence-based: build what is needed, reuse what already works, document it clearly, and leave organizations with systems they can operate rather than compliance paperwork they cannot maintain.\n\n[tally:LD6jYol]",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "United States",
        "United Kingdom",
        "UAE",
        "Switzerland",
        "Sweden",
        "Spain",
        "Portugal",
        "Poland",
        "Norway",
        "Netherlands",
        "Italy",
        "Austria",
        "Belgium",
        "Canada",
        "Denmark",
        "Finland",
        "France",
        "Germany",
        "Ireland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "ISO 27701",
        "SOC 2 Type 2",
        "GDPR",
        "DORA",
        "NIS2",
        "HIPAA",
        "PCI DSS",
        "NIST CSF",
        "EU AI Act",
        "AIUC-1",
        "CMMC",
        "EU AI ACT"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "Construction",
        "Cryptocurrency",
        "Finance",
        "Government",
        "Healthcare",
        "Hospitality",
        "Insurance",
        "Manufacturing",
        "Transportation",
        "Technology",
        "Real Estate",
        "Private Equity",
        "Retail"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "French",
        "German",
        "Polish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/measurementpros+-+implementation+and+assurance/r/0b659f86-4cab-4ec9-a931-da61849f759a"
    },
    {
      "name": "MetricStream",
      "url": "https://www.metricstream.com",
      "briefSummary": "Enterprise GRC suite for operational risk, compliance, audit, and third-party risk at large institutions.",
      "description": "MetricStream is a US enterprise GRC suite used by large financial and regulated firms for operational risk, compliance, audit, and vendor risk. It is a full-suite product, not a startup SOC 2 automation tool. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Asia"
      ],
      "complianceFrameworkExpertise": [
        "SOX",
        "ISO 27001",
        "NIST CSF",
        "Multi-framework",
        "CCPA",
        "COBIT",
        "DORA",
        "GDPR",
        "HIPAA",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Vendor Management",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/metricstream/r/4785583e-5f43-461b-b616-fc75a1c9e466"
    },
    {
      "name": "NAVEX",
      "url": "https://www.navex.com",
      "briefSummary": "Oregon ethics, compliance, and GRC platform for policy, hotline, and risk programs.",
      "description": "NAVEX is a US ethics and compliance platform used for policy, speak-up, and related GRC processes. It is stronger on corporate compliance than on SOC 2 evidence collection. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "SOX",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/navex/r/14cb7bc9-407c-4cbd-91fc-f06327751d31"
    },
    {
      "name": "Nexus Advisory",
      "url": "Www.nexusadvisory.org",
      "briefSummary": "ISO 27001 Consulting, auditing, gap analysis",
      "description": "ISO 27001 - I build engineer and implement information security management systems for close to 10 years, and worked in security and compliance for well over 20. My approach to consulting is about building a client centric approach that gives the client ownership over their system and positions them from the beginning to rely more on themselves and less on the auditor so that they can have a self-sufficient and properly functioning ISMS. ",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/nexus+advisory/r/a48500e2-109b-4517-aab7-25c504ece9b9"
    },
    {
      "name": "Oneleet",
      "url": "https://www.oneleet.com",
      "briefSummary": "Security-first compliance platform that consolidates penetration testing, code scanning, and compliance into one integrated solution.",
      "description": "Oneleet takes a security-first approach to compliance, combining automated tools with human expertise including a dedicated vCISO for each client. The platform consolidates penetration testing, code scanning, cloud security, and attack surface monitoring.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "PCI DSS",
        "DORA",
        "HITRUST",
        "NIST",
        "FedRAMP",
        "ISO 42001",
        "Cyber Essentials"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Continuous Monitoring",
        "Audit Preparation",
        "Security Awareness Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small",
        "Medium"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/oneleet/r/0abd7eb5-b20b-44e2-9ccb-8283e6e9798f"
    },
    {
      "name": "OneTrust",
      "url": "https://www.onetrust.com",
      "briefSummary": "Atlanta GRC and privacy platform for privacy, third-party risk, and compliance programs at enterprise scale.",
      "description": "OneTrust is a US GRC and privacy platform used to run privacy, risk, audit, and third-party programs in one system. It is built for large organizations that need policy, assessment, and evidence workflows across GDPR, CCPA, and security frameworks. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "GDPR",
        "CCPA",
        "ISO 27001",
        "SOC 2",
        "EU AI ACT",
        "HIPAA",
        "Multi-framework",
        "CMMC",
        "NIST"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Data Protection",
        "Vendor Management",
        "Automation"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/onetrust/r/0025aa71-9b23-4298-99ed-3bb251825a23"
    },
    {
      "name": "Onspring",
      "url": "https://onspring.com",
      "briefSummary": "Kansas City no-code GRC platform for risk, compliance, audit, policy, and third-party workflows.",
      "description": "Onspring is a US no-code GRC platform from Kansas City. Teams use it to connect risk, compliance, audit, policy, and vendor processes in one configurable system. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "Multi-framework",
        "CMMC"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Automation",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/onspring/r/6b3b74ff-a818-4bb1-9492-ec123ab87fcc"
    },
    {
      "name": "Ostendio",
      "url": "https://www.ostendio.com",
      "briefSummary": "Washington DC security and compliance platform for assessments, vendor risk, and control programs.",
      "description": "Ostendio is a US security and compliance platform used for assessments, vendor risk, and control management. It is often used by healthcare and government-adjacent teams. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "HIPAA",
        "SOC 2",
        "NIST CSF",
        "CMMC",
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Vendor Management",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Healthcare",
        "Government",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/ostendio/r/c9d4d241-01d8-4876-974e-f8c88c5f3531"
    },
    {
      "name": "Pakuła Consulting",
      "url": "https://pakulaconsulting.pl",
      "briefSummary": "Polish ISO 27001 implementation consultancy focused on ISMS design, training, and certification preparation for SMEs and IT companies.",
      "description": "Pakuła Consulting specializes in implementing information security management systems to ISO/IEC 27001 in Poland. Services include gap analysis, full ISMS implementation, employee training, and preparation for certification audits. The firm positions itself for SMEs and technology companies, with lead auditors on staff and a published track record of numerous successful certifications.",
      "serviceType": [
        "Consulting",
        "Training"
      ],
      "regionCovered": [
        "Poland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Gap Analysis",
        "Policy Creation",
        "Security Awareness Training",
        "Compliance",
        "Risk Management"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "All industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "Polish",
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/pakuła+consulting/r/30d43eff-84ca-4fca-ba17-6017d0e46ee5"
    },
    {
      "name": "Perium B.V.",
      "url": "https://perium.uk",
      "briefSummary": "With Perium, you manage risks intuitively and efficiently and comply with important standards such as ISO9001, ISO27001, NEN7510, BIO, CRSD, RI&E and many others. The platform adapts effortlessly to your specific sector.",
      "description": "Ready to use within hours, low consultancy, very user-friendly, powerful management function including PDCA cycle, competitively priced. Price depends on use and size of organisation. Price starts at €199 per month. Always fits the customer's ambitions. Scalable to full ERM. Own frameworks possible. References overlap different frameworks. ISO27001, DORA, NIS2, NIST, CIS, PCI-DSS, NEN7510, BIO, CIP Privacy baseline, Cloud Control Matrix, ISAE 3402, SOC, DigiD, Horizontaal toezicht, NEN7512, NEN7513, NTA7516, BC5701, BIC, CSRD/ESRS, MVO Prestatieladder, RI&E (arbo), VCA, IBP Onderwijs, E-Health Toetsingskader IGJ, DNB Good Practice IB, ICT Beveiligingsrichtlijnen voor web applicaties, ISO 27036, ISO 27701, ISO42001, ISQM Kwaliteit assurance diensten, NCSC Handreiking Cybersecurity maatregelen, NEN 4400-1, NIST AI Riskmanagement Framework, NOREA Privacy Control framework, NVZ Gedragslijn, SBCA, Suwinet, Wet Politie Gegevens, ZKN Keurmerk and many more.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global",
        "Netherlands"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "ISO 27701",
        "ISO 9001",
        "ISO 50001",
        "PCI DSS",
        "NIS2",
        "DORA",
        "NIST CSF"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring",
        "Security Awareness",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/perium+b.v./r/reczeT212uDou8jjh"
    },
    {
      "name": "Prescient Assurance",
      "url": "https://www.prescientassurance.com",
      "briefSummary": "US CPA firm focused on SOC 2, ISO 27001, and related assurance for technology companies.",
      "description": "Prescient Assurance is a US CPA firm that performs SOC 2 and related technology assurance. Startups and mid-market SaaS teams use it as an auditor, not as a GRC platform. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "HIPAA",
        "HITRUST",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "SaaS",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/prescient+assurance/r/b1c55309-1b3e-4d0e-92db-c380db09f24c"
    },
    {
      "name": "Prevalent",
      "url": "https://www.prevalent.net",
      "briefSummary": "US third-party risk platform for vendor assessments, scoring, and continuous monitoring.",
      "description": "Prevalent is a US third-party risk platform for onboarding, assessing, and monitoring vendors. Security and procurement teams use it when vendor reviews are a standing program. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Vendor Management",
        "Risk Management",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/prevalent/r/9bb4b3e0-c5fe-422d-a534-72251ea538d2"
    },
    {
      "name": "Probo",
      "url": "https://getprobo.com",
      "briefSummary": "Probo is the open-source solution helping small businesses achieve compliance without the usual mental-load. No fluff, only what founders truly need (based on their risks), tailored to their own processes. ",
      "description": "Open-source, free is self-hosted. Hosted version & support free if less than 5. From 5 to 50 employees,  250€ per month, no commitment.\nWe can also help out with audits",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/probo/r/recUAsOUrHKN5Qidy"
    },
    {
      "name": "PROCESS 360",
      "url": "www.process360.com",
      "briefSummary": "At PROCESS 360, we build systems using innovative, effective processes to deliver successful outcomes. The company specializes in a range of ISO management systems, providing our clients with audit, consulting, and training services. ",
      "description": "PROCESS 360 is a member of several ISO Committees, where we help shape, revise, and publish a number of ISO standards. We are certified and experts with the following ISO management system standards: 9001 | 13485 | 20000 | 22301 | 27001 | 27701 | 37301 | 42001. The company is especially gifted at implementing integrated management systems, and several of our staff members qualified as certification auditors.  ",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Global",
        "Germany",
        "Switzerland",
        "Austria"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "ISO 27701",
        "ISO 22301",
        "ISO 9001",
        "ISO 13485"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Certification Assistance",
        "Data Protection",
        "Secure AI Deployment",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/process+360/r/rec5hfphu0fhiaJxm"
    },
    {
      "name": "ProcessUnity",
      "url": "https://www.processunity.com",
      "briefSummary": "US third-party risk platform for assessments, continuous monitoring, and vendor lifecycle programs.",
      "description": "ProcessUnity is a US third-party risk platform used by enterprises to assess and monitor vendors. It is a TPRM system, not a startup SOC 2 evidence collector. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "Multi-framework",
        "DORA"
      ],
      "problemsTheySolve": [
        "Vendor Management",
        "Risk Management",
        "Compliance"
      ],
      "industrySpecialization": [
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/processunity/r/4aa31b6a-84f9-4844-85af-2eadf0ce4fd9"
    },
    {
      "name": "ProvePrivacy",
      "url": "https://www.proveprivacy.com",
      "briefSummary": "Comprehensive privacy and data protection solutions.",
      "description": "ProvePrivacy offers a wide range of services aimed at ensuring compliance with global privacy laws and regulations, providing data protection solutions, and enhancing overall security posture. Our single integrated platform, is designed by industry experts and simplifies compliance, providing an efficient and collaborative solution for information governance professionals to manage data.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "United Kingdom",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "Multi-framework",
        "ISO 27701",
        "NIST 2.0"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/proveprivacy/r/recn23PiRDKYwEEhO"
    },
    {
      "name": "QALogger.com",
      "url": "https://www.qalogger.com",
      "briefSummary": "QALogger is a \"vending machine\" style digital logbook platform designed to replace paper and messy spreadsheets. It helps businesses automate record-keeping and stay audit-ready with zero maintenance. All data is kept in-browser for speed and total privacy.",
      "description": "QALogger differentiates through \"Vending Machine\" simplicity. Unlike complex enterprise QMS suites, our platform requires zero implementation time and no specialized training. Key technical advantages include in-browser data processing for maximum privacy and speed, an intuitive interface that replaces paper logbooks instantly, and a lightweight footprint that doesn't require IT department oversight. We focus on the \"last mile\" of compliance: the actual logs.  Our primary focus is (Quality Management Systems), specifically helping small manufacturers meet the requirements for \"Control of Documented Information\" and \"Operational Planning and Control.\" Our digital logbooks are designed to satisfy auditor requirements for data integrity, traceability, and retrievability, providing a clear digital twin for physical processes.   We offer a transparent, subscription-based pricing model designed for small to mid-sized manufacturers. To ensure the tool is a perfect fit before any financial commitment, we provide a 14-day free trial with no commitment or obligation required. This allow businesses to try the application against their specific manufacturing workflows and audit requirements with zero risk.   Quality is the core of our origin. QALogger was founded by a software developer specifically to solve the \"compliance gap\" where small manufacturers struggle with manual paper records. Every feature is built with the end-user in mind—ensuring that data entry is error-proof and audit preparation is automated. We treat our own code with the same rigor we expect from a manufacturing shop floor: simple, functional, and reliable.",
      "serviceType": [
        "Toolkit"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Continuous Monitoring",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "Construction",
        "Healthcare",
        "Hospitality",
        "Manufacturing",
        "Transportation"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/qalogger.com/r/b86d098f-3709-4a56-8407-c4a767760916"
    },
    {
      "name": "ReadySecGo",
      "url": "https://readysecgo.com",
      "briefSummary": "ReadySecGo provides practical, end-to-end information security and compliance services designed for startups and growing organizations. We specialize in ISO 27001, SOC 2, and BSI C5 implementation, readiness, and auditing — helping teams build trust through structured, scalable, and cost-effective security programs.\n\nOur services include Gap Assessments, Internal & External Audits, Audit Readiness, and vCISO (Virtual CISO) support. With a hands-on, no-nonsense approach, ReadySecGo bridges the gap between frameworks and real-world execution — enabling companies to achieve compliance maturity without the complexity.",
      "description": "Our pricing approach is transparent and outcome-oriented. Engagements are scoped according to organizational maturity, complexity, and objectives, ensuring a fair balance between value and cost. Whether through defined project deliverables or structured compliance partnerships, clients receive predictable, results-based pricing tailored to their specific needs.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe",
        "United Kingdom",
        "United States",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "NIS2",
        "DORA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Certification Assistance",
        "Certification Body Services",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "Cryptocurrency",
        "Finance",
        "Government",
        "Healthcare",
        "Insurance",
        "Private Equity",
        "Retail",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/readysecgo/r/recLFhWKRUCkVPrcG"
    },
    {
      "name": "Reisender",
      "url": "www.reisender.us",
      "briefSummary": "Reisender helps your organization stay protected while driving performance and growth by assessing risks, implementing ISMS requirements, identifying opportunities, and implementing tailored solutions aligned with business goals.",
      "description": "We have helped over a dozen clients reach certification against ISO frameworks including 27001/27701/9001, as well audit readiness for other frameworks such as  SOC 2, GDPR, and NIST CSF. Our specialty is aligning the ISMS to your organizational objectives to reduce friction when implementing or maturing your security program. Additionally, Reisender provides tailored consulting services such as: Fractional CISO/vCISO services, M&A due diligence, threat assessments, security program maturity assessments, and board and executive reporting.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Canada",
        "Europe",
        "Latin America",
        "United Kingdom",
        "United States",
        "Brazil",
        "Portugal"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "Finance",
        "Healthcare",
        "Hospitality",
        "Manufacturing",
        "Private Equity",
        "Retail",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "Portuguese"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/reisender/r/recuqV2u09Uh3l2vO"
    },
    {
      "name": "Resolver",
      "url": "https://www.resolver.com",
      "briefSummary": "Risk and incident platform used by US enterprises for investigations, risk, and compliance cases.",
      "description": "Resolver is a risk and incident platform used by US and Canadian enterprises. Teams use it for investigations, risk, and case management rather than SOC 2 evidence collection. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Canada",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Incident Response",
        "Compliance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/resolver/r/c7449318-4246-4cc8-9dc9-c27c3e9720cf"
    },
    {
      "name": "Responsum",
      "url": "responsum.eu",
      "briefSummary": "Got it! Here's a brief service description for Responsum.eu:\n\nResponsum offers personalized, GDPR-compliant data protection and privacy management solutions. Simplify compliance, enhance security, and protect your business with our expert-driven, user-friendly tools.",
      "description": "Key Differentiators\n\n\n1. Privacy Culture: Engage coworkers with tailored messages and training.\n\n2. Transparency: Showcase privacy efforts through comprehensive reports.\n\n3. Automation: Simplify tasks with automated actions based on data.\n\n4. Executive Buy-In: Present clear insights into risks and mitigations.\n\n5. Responsibility Allocation: Collaborate effectively with Privacy Champions.\n\n6. EU-Based Compliance: Use entirely EU-based, GDPR-compliant tools.\n\n\n Frameworks and Standards\n\n- Compliance: Aligns with EU data protection laws and international regulations.\n\n- Personal Data Lifecycle Management: Covers data mapping, risk assessment, risk treatment, and reporting.\n\n\nPricing\n\nLight Plan:\n\n- 1 power user, 5 promoted users\n- Register of Processing Activities\n- Dashboards & reports\n- Data Protection Impact Assessment\n- eLearnings\n\n\nPro Plan:\n\n- All Light features plus:\n- 2 power users, 10 promoted users\n- Customizable reports\n- Transfer Impact Assessment\n- Data Subject Rights Management\n- Incident & Breach Management\n- Vendor/Stakeholder Management\n- Risk Management\n\n\nPremium Plan:\n\n- All Pro features plus:\n- 5 power users, 25 promoted users\n- Unlimited customizable reports\n- Expandable team options\n\n",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "GDPR",
        "Multi-framework",
        "ISO 27001",
        "NIS2",
        "DORA",
        "NIST"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "Dutch",
        "French",
        "Swedish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/responsum/r/recMYqFkW7Untndv5"
    },
    {
      "name": "Risk3sixty",
      "url": "https://www.risk3sixty.com/",
      "briefSummary": "Comprehensive security and compliance platform offering ISO 27001 preparation, SOC 2, and other risk management services.",
      "description": "Risk3sixty provides a suite of tools and services designed to simplify risk management and compliance processes. They offer services not just around ISO 27001 but have been one of the premier consulting firms supporting the new ISO 42001 standard, and consult (or conduct internal audits) against ISO 27701, 22301 and 9001.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework",
        "ISO 9001",
        "ISO 42001",
        "ISO 27701",
        "ISO 22301"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/risk3sixty/r/recBzAIBEog38N2Ox"
    },
    {
      "name": "Riskonnect",
      "url": "https://riskonnect.com",
      "briefSummary": "Atlanta integrated risk management platform for enterprise risk, insurance, and compliance programs.",
      "description": "Riskonnect is a US integrated risk platform used for enterprise risk, insurance, and related compliance processes. It sits closer to IRM and insurance risk than to startup SOC 2 automation. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Incident Response",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Insurance",
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/riskonnect/r/be365f7e-3d27-4209-8231-741f07adaaad"
    },
    {
      "name": "Sage Audits LLP",
      "url": "https://sageaudits.com/",
      "briefSummary": "Denver-based CPA firm specializing exclusively in SOC 1 and SOC 2 examinations for SaaS and tech companies. Partner-led engagements, independent control testing against Trust Services Criteria, and Big Four IT audit experience. No junior auditors. CPA, CISSP, CISA, CRISC, CISM, CITP.",
      "description": "Our team collectively holds CPA, CISSP, CISA, CRISC, CISM, and CITP credentials with Big Four IT audit backgrounds. Every engagement is partner-led from scoping through report delivery, no junior auditors. We speak SaaS. We have been on both sides of the table: designing and implementing controls in-house, then auditing them externally. That means we understand your environment before we ask the first question. We perform independent control testing and bring real infrastructure and security experience to every engagement.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2 Type 2",
        "SOC 1",
        "SOC 2 Type I",
        "SOX"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "For all industries",
        "Construction",
        "Finance",
        "Hospitality",
        "Insurance",
        "Manufacturing",
        "Private Equity",
        "Real Estate",
        "Retail",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sage+audits+llp/r/953094a3-367a-47f8-80db-4874857a3001"
    },
    {
      "name": "SAI360",
      "url": "https://www.sai360.com",
      "briefSummary": "Enterprise GRC, risk, and compliance platform for policy, ethics, and operational risk programs.",
      "description": "SAI360 is a GRC platform used by large organizations for risk, compliance, ethics, and policy. US enterprises are a core market. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOX",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Compliance",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sai360/r/dff7bd36-dcbf-4f54-a4be-6af9c0e4e917"
    },
    {
      "name": "Sancert",
      "url": "www.sancert.global",
      "briefSummary": "Sancert, accredited by SANAS and UKAS, provides ISO/IEC 27001 certification services. We assess and certify Information Security Management Systems to help organisations reduce risk, protect data, and build trust.",
      "description": "Dual Accreditation: One of the few certification bodies accredited by both SANAS and UKAS, ensuring global recognition and local credibility.\n\nMarket Leader: Issued more ISO/IEC 27001 certifications in Africa than any other certification body.\n\nFast Turnaround: Certificates issued within 10 working days once deviations are closed out.\n\nEfficient Reporting: Full audit reports delivered within 7 days of the last audit day.\n\nBlended Audits: Combination of on-site and remote auditing for cost-effective and flexible certification.\n\nClient-Focused Approach: Auditors adopt a partnership mindset, helping clients improve rather than just \"tick-box\" auditing.\n\nCompetitive Pricing: Transparent, fair, and highly competitive rates without compromising quality.\n\nPaperless System: End-to-end digital auditing process, reducing delays and admin burden.\n\nRapid Quotations: Certification quotations delivered within 1 working day.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Africa",
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "Middle East",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "Multi-framework",
        "ISO 9001",
        "ISO 14001",
        "ISO 45001",
        "ISO 13485",
        "ISO 27701"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Continuous Monitoring",
        "Certification Assistance",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sancert/r/recQhRsNaZDo3mxms"
    },
    {
      "name": "Schellman",
      "url": "https://www.schellman.com",
      "briefSummary": "Leading US IT compliance attestation firm for SOC 1/2/3, PCI, and ANAB-accredited ISO certifications including ISO 27001 and ISO 42001.",
      "description": "Schellman is a specialist IT compliance and attestation firm known for high-volume SOC examinations and multi-framework assessments. It is an ANAB-accredited certification body for ISO standards including ISO 27001 and was among the first for ISO 42001 AI management systems. Schellman serves startups through Fortune 500 buyers seeking widely recognized audit reports.",
      "serviceType": [
        "External audit",
        "Certification body"
      ],
      "regionCovered": [
        "United States",
        "Global",
        "Europe",
        "Canada"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "ISO 42001",
        "ISO 27701",
        "ISO 22301",
        "PCI DSS",
        "Multi-framework",
        "CMMC",
        "FedRAMP",
        "GDPR",
        "HIPAA",
        "HITRUST",
        "NIST SP 800-171",
        "NIST SP 800-53",
        "SOX"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Audit Preparation",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS",
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/schellman/r/80f1ba9b-8d76-4eb2-af6b-b6feb7c43a2f"
    },
    {
      "name": "Schneider Downs",
      "url": "https://www.schneiderdowns.com",
      "briefSummary": "Pittsburgh CPA firm with SOC 2 and technology assurance services for mid-market companies.",
      "description": "Schneider Downs is a US CPA firm based in Pittsburgh with a technology assurance practice. Regional mid-market companies use it for SOC 2 and related work. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "Multi-framework",
        "SOX"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/schneider+downs/r/4286ce9e-5a1d-4ca4-96ba-448a131cf3b8"
    },
    {
      "name": "Scrut Automation",
      "url": "https://www.scrut.io",
      "briefSummary": "Scrut Automation simplifies continuous compliance automation for cloud-native companies.",
      "description": "Scrut offers a unified platform for managing risk, compliance, and security, integrating with various cloud services and providing automated workflows to streamline GRC processes.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "PCI DSS",
        "ISO 27701",
        "ISO 22301",
        "NIST SP 800-53",
        "NIST SP 800-171",
        "CMMC",
        "FedRAMP",
        "CCPA",
        "SOX",
        "Microsoft SSPA",
        "CIS Critical Security Controls",
        "COPPA",
        "FERPA",
        "DORA",
        "NIS2",
        "NIST CSF",
        "CSA STAR",
        "ISO 9001",
        "TISAX",
        "Cyber Essentials",
        "COBIT",
        "ISO 42001",
        "ISO 13485"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation",
        "Continuous Monitoring",
        "Secure AI Deployment",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/scrut+automation/r/rec1Zcj5K5cX8Wpgs"
    },
    {
      "name": "Scytale",
      "url": "https://scytale.ai",
      "briefSummary": "AI-powered compliance automation platform with dedicated human experts, supporting 60+ security and privacy frameworks.",
      "description": "Scytale combines AI-powered automation with dedicated compliance experts to manage every stage of the compliance journey, reducing compliance workload by 70%. The platform supports 60+ frameworks.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 27701",
        "ISO 42001",
        "ISO 9001",
        "ISO 22301",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "PCI DSS",
        "NIST CSF",
        "NIS2",
        "DORA",
        "TISAX",
        "Cyber Essentials",
        "CMMC",
        "CCPA",
        "SOX",
        "SOC 1",
        "NIST SP 800-53",
        "NIST SP 800-171",
        "CIS Controls",
        "CSA STAR"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Continuous Monitoring",
        "Risk Management",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/scytale/r/3225549e-5ad4-401b-9461-1d8662128ac4"
    },
    {
      "name": "SecAware",
      "url": "https://www.secaware.com/",
      "briefSummary": "ISO27k ISMS templates and awareness content",
      "description": "Pragmatic, fully customisable information risk and security management, training and awareness materials written for workers in general, for managers and for technologists.  ",
      "serviceType": [
        "Toolkit"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Policy Creation",
        "Security Awareness"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/secaware/r/rec6S4TyQvt6MVid3"
    },
    {
      "name": "Seconize DeRisk Center",
      "url": "https://seconize.co",
      "briefSummary": "Seconize DeRisk Centre is an AI-driven compliance audit solution collects evidence artifacts from variety of IT Systems both Onpremise and Cloud. It integrates machine learning to analyze vast datasets of, identify compliance gaps, and predict future risks. It automates routine tasks, ensuring consistent and accurate audits. Benefits include reduced audit time, lower operational costs, enhanced accuracy, real-time monitoring, and proactive issue resolution, all of which bolster regulatory adherence and operational efficiency.",
      "description": "Seconize DeRisk Centre stands out with its AI-driven automation that reduces manual effort and enhances audit accuracy. Its real-time monitoring capabilities offer continuous compliance checks and proactive issue resolution through real-time alerts. The platform seamlessly integrates with existing IT infrastructure, financial systems, and security tools, providing a holistic compliance management solution. Its customizable framework ensures alignment with specific regulatory requirements and internal policies. User-friendly dashboards and reporting tools facilitate easy navigation, while the system's scalability accommodates growing enterprise needs. Seconize DeRisk Centre also features risk-based assessment to prioritize compliance issues and regular updates to keep pace with regulatory changes. Data-driven insights enable informed decision-making, and the overall cost efficiency of the platform leads to significant savings through automation and optimized resource allocation.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Africa",
        "India",
        "United States",
        "Middle East",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "Multi-framework",
        "ISO 27001",
        "SOC 2 Type 2",
        "ISO 42001",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Vendor Management",
        "Audit Preparation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Construction",
        "Finance",
        "Insurance",
        "Technology"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/seconize+derisk+center/r/recWB9hTUsA6mrI89"
    },
    {
      "name": "Secureframe",
      "url": "https://secureframe.com",
      "briefSummary": "AI-powered GRC platform that automates compliance, mitigates risk, and builds customer trust through expert-backed automation.",
      "description": "Secureframe automates evidence collection, continuous security monitoring, and policy management across 200+ integrations, serving 6,000+ customers. The platform supports frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC 2.0, FedRAMP, and NIST.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "PCI DSS",
        "ISO 42001",
        "NIST CSF",
        "CMMC",
        "FedRAMP",
        "CCPA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Continuous Monitoring",
        "Vendor Management",
        "Audit Preparation",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/secureframe/r/f9319d4a-b47a-4e74-ac67-40d85603f351"
    },
    {
      "name": "SecurityScorecard",
      "url": "https://securityscorecard.com",
      "briefSummary": "New York security-ratings and third-party cyber risk platform for vendor monitoring.",
      "description": "SecurityScorecard is a US security-ratings and vendor-monitoring platform. Teams use it to watch outside-in cyber risk across a vendor population. It is complementary to questionnaires and audits, not a substitute. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "NIST CSF",
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Vendor Management",
        "Continuous Monitoring",
        "Risk Management"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/securityscorecard/r/95f4de38-966e-4313-8591-ff7bcde694f2"
    },
    {
      "name": "Sensiba",
      "url": "https://sensiba.com",
      "briefSummary": "Bay Area CPA firm with a technology assurance practice for SOC 2 and related reports.",
      "description": "Sensiba is a US CPA firm with a technology assurance practice that issues SOC 2 and related reports. It is an auditor, not a GRC platform. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "Multi-framework",
        "CMMC",
        "CSA STAR",
        "HIPAA",
        "HITRUST"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "SaaS"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sensiba/r/3c461cc8-fdfd-4655-a891-a3e71ea27a85"
    },
    {
      "name": "SEQURA",
      "url": "https://sequra.se/",
      "briefSummary": "GRC-platform (Governance, Risk, Compliance) that speaks the human language. User experiences is at focus. ISO27001, NIS2, GDPR, risk and vendor management. You get it all. ",
      "description": "All inclusive plans. Fixed prices for small, medium and large companies. We support frameworks, legislations and custom requirements. Eg ISO27001, TISAX, GDPR, NIS2, and we can include more when needed - at no extra cost. \n\n100% Swedish company: ownership, development, support, hosting, suppliers and backup. ",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Sweden"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Incident Response",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "Swedish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sequra/r/recXCM1gjUykdL1Us"
    },
    {
      "name": "SGS",
      "url": "https://www.sgs.com",
      "briefSummary": "World-leading inspection, verification, and certification company offering ISO 27001 and multi-standard management system certification.",
      "description": "SGS is one of the largest inspection, testing, and certification companies globally. Its management system certification services include ISO/IEC 27001 for information security, enabling organizations to demonstrate independent third-party verification of their ISMS.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "Asia",
        "United States",
        "Latin America",
        "Africa",
        "Middle East"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sgs/r/3220e3b2-cf04-462d-b19c-954e8dcdf20d"
    },
    {
      "name": "smartGRC",
      "url": "https://smartgrc.eu",
      "briefSummary": "Polish AI-native SAP access governance and GRC platform for SoD analysis, access workflows, and audit-defensible compliance.",
      "description": "smartGRC is a European SAP access governance and GRC platform from GRC Solutions Sp. z o.o., productized from the sister consulting practice GRC Advisory. Modules cover SoD analysis, access workflows, role architecture, and related compliance automation, with long-running production deployments at large Polish and international organizations. Hosting and design emphasize EU data residency and audit defensibility.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Poland",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "SOX",
        "EU AI ACT",
        "Multi-framework",
        "DORA",
        "NIS2"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Automation",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "Manufacturing",
        "Finance",
        "Retail",
        "Technology",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "Polish",
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/smartgrc/r/506f8028-3628-4192-990a-9782b4676f49"
    },
    {
      "name": "SolidInfoSec",
      "url": "https://solidinfosec.nl/",
      "briefSummary": "Information security consulting focused on strengthening governance, risk and compliance practices. We help organizations structure and implement practical security processes, support audit readiness and build sustainable frameworks that remain workable over time.",
      "description": "SolidInfoSec supports organizations in designing and implementing pragmatic information security governance. Our work focuses on strengthening governance, risk management and compliance structures so organizations can manage security in a structured and sustainable way.\n\nWe typically work with organizations that want a structured approach to information security without unnecessary complexity. Our approach combines governance, risk management and operational security practices so that security frameworks remain usable in daily operations.\n\nFrameworks and standards we work with include ISO 27001, NIS2 and GDPR-related governance practices. Services usually include gap assessments, ISMS design, risk assessment support, policy development, audit preparation and advisory support during certification.\n\nWe do not promise fast-track certifications or “guaranteed passes”. The focus is on building an ISMS that is understandable for management and workable for teams.\n\nIn addition, we developed ISMS Wizard, a lightweight product designed to help smaller organizations take their first structured steps in information security. It offers a practical starting point for companies that want guidance without being overwhelmed by complex frameworks or forced into long-term commitments.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Austria",
        "Belgium",
        "Denmark",
        "Europe",
        "Finland",
        "France",
        "Germany",
        "India",
        "Ireland",
        "Israel",
        "Italy",
        "Middle East",
        "Netherlands",
        "Norway",
        "Poland",
        "Portugal",
        "Singapore",
        "South Africa",
        "Sweden",
        "Switzerland",
        "UAE",
        "United Kingdom",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection"
      ],
      "industrySpecialization": [
        "Finance",
        "Government",
        "Healthcare",
        "Insurance",
        "Private Equity",
        "Retail",
        "Technology"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/solidinfosec/r/546bebb7-9c79-41a5-b785-1ab65a51e3c8"
    },
    {
      "name": "SOTENAC IT RISK",
      "url": "https://www.linkedin.com/company/sotenac-it-risk",
      "briefSummary": "Expert IT Risk & GRC (ex-BNP Paribas), j'aide les DSI/RSSI à sortir de la conformité \"papier\". Mon focus : la sécurité opérationnelle et la priorisation des risques réels. Accompagnement flexible ou missions \"One Shot\" pour transformer la GRC en levier de pilotage simple.",
      "description": "Après plus de 20 ans à piloter les risques IT et la résilience au sein du groupe BNP Paribas, j’accompagne aujourd’hui les DSI et RSSI européens dans leurs missions IT Risk et GRC. Missions courtes ou accompagnement flexible — quelques heures par semaine suffisent.\n\nMa conviction : La gestion des risques IT (avec ou sans outils de GRC) n'est pas là pour cocher des cases, elle est là pour cartographier vos actifs et prioriser les arbitrages réels. \n\nMon approche est pragmatique : Sortir de la conformité \"papier\" pour viser la sécurité opérationnelle. Je ne me contente pas de vérifier les extincteurs, je m'assure qu'on ne stocke pas de bidons d'essence à côté de la cheminée.\n\nMes zones d'impact :\n🛡️ IT Risk Management : Passer de l'inventaire technique à la gestion par l'Asset.\n\n⚙️ ServiceNow GRC : Transformer un outil complexe en levier de pilotage simple et efficace.\n\n📉 Optimisation Cyber : Prioriser les investissements là où se trouvent les vrais risques vitaux.\n\nDisponible pour des missions de niche en \"One Shot\" : audits GRC, IT Risk Reviews, conseil, accompagnement, dossiers complexes.\n\nISO 27005, CRISC (ISACA)\n\n📍 Basé à Bordeaux | 🌍 Intervention Europe",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Belgium",
        "Europe",
        "France",
        "Switzerland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Data Protection"
      ],
      "industrySpecialization": [
        "Finance",
        "Insurance"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "French"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sotenac+it+risk/r/05d257e4-4bfb-424a-afdb-c6b1bf3098a5"
    },
    {
      "name": "Spire",
      "url": "https://spire.synov8studio.com",
      "briefSummary": "AI-powered SOC 2 and EU AI Act compliance. Connect your stack, collect evidence continuously, and auto-fill security questionnaires. From £200/mo.",
      "description": "Key differentiators: AI agent that audits controls and produces pass/fail verdicts with evidence citations, not just evidence collection. Native EU AI Act coverage alongside SOC 2 from day one. AI-powered security questionnaire automation included at every tier, not a paid add-on. 60-second setup with 9 read-only integrations. Transparent pricing with no sales call.\n\nFrameworks/standards: SOC 2 Type II (all five trust service criteria), EU AI Act (Articles 4, 50, high-risk classification, GPAI Code of Practice), ISO 42001 alignment.\n\nPricing: Starter £200/mo (3 integrations, 5 questionnaire auto-fills), Growth £1,200/mo (10 integrations, unlimited questionnaires, team invites), Enterprise £3,000/mo (unlimited everything, dedicated support). All published on the website — no \"contact us\" gates.\n\nQuality: We use Spire internally to monitor our own infrastructure and generate compliance reports. Our infrastructure runs on Cloudflare Workers and Neon PostgreSQL (both SOC 2 certified). All data encrypted at rest (AES-256) and in transit (TLS 1.3). DPA and subprocessor list available on request.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2 Type 2"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring",
        "Certification Assistance",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "Finance",
        "Technology"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/spire/r/d83488cf-65ef-4bc9-92d5-7c7f5711912a"
    },
    {
      "name": "Sprinto",
      "url": "https://sprinto.com/",
      "briefSummary": "Sprinto helps fast-moving cloud companies achieve and scale compliance. The platform automates more than 90% tasks, monitors controls in real-time and ensures continuous audit readiness without manual work or spreadsheet chaos.",
      "description": "Key Differentiators:\nSprinto offers the right tools and support for security-posture visibility, faster audits, and always-on compliance.\n\n- End-to-End Automation with Real-Time Monitoring:\nAutomates the full compliance lifecycle and offers real-time visibility into control status, with tiered alerts before anything slips.\n\n- Prebuilt, Audit-Ready Programs:\nOffers fast out-of-the-box, auditor-approved templates and programs to cut down audit prep time and minimize consulting dependencies.\n\n- Seamless Integrations Across the Stack:\nConnects with 300+ cloud services, HR systems, and dev tools to map risks and monitor assets for zero blindspots.\n\n- Scalable, Multi-Framework Support:\nSupports multiple frameworks in one place with shared controls, so each new audit takes less effort.\n\n- Compliance Experts on Demand:\nProvides hands-on support from certified auditors and compliance leads who guide you through setup, remediation, and every audit.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Africa",
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "India",
        "Israel",
        "Latin America",
        "Middle East",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Certification Assistance",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/sprinto/r/reccD3Mb021rWQGOc"
    },
    {
      "name": "SrivelEnterprise",
      "url": "https://www.linkedin.com/in/rajeshbommaan/",
      "briefSummary": "A seasoned professional with 17+ years of fruitful experience with expertise in ISO Certification, SSAE18 (SOC1 and SOC2), GDPR, Quality Management System (ISO 9001), Information Security Management System (ISO 27001), Information Technology Service Management System (ISO 20001), Asset Management System (ISO 55001), HIPAA, Certified Data Protection Officer, Business Continuity, VAPT, Risk Management, Secure Coding, Data Privacy, Processing Integrity, E-learning, Training and Mentoring, Design Thinking, Operations, Strategy, People Management, Technocommercial Acumen.\n\nManagement Systems: Effectively implemented, maintained, audited ISO 9001 (QMS), ISO 27001 (ISMS), ISO 23001 (BCMS), ISO 20001 (ITSM), ISO 27701 (PMS), ISO 42301 (AIMS), CMMI, SSAE18 (SOC1, SOC2), HIPAA, HITRUST, HITECH, CCPA, GDPR, FedRAMP standards in various organizations across industries. Strong understanding of business best practices w.r.t. quality, information security, continuous process improvements.",
      "description": "We are price-sensitive, flexible, startup friendly, accessible, available on short notice, have 30-odd regular clients for whom we manage  ISO, SOC, PCI-DSS, HIPAA, GDPR, VAPT, CMMI, CCPA, HITRUST, AIMS, Cyber Security.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Africa",
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "India",
        "Israel",
        "Latin America",
        "Middle East",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment",
        "Certification Body Services",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries",
        "Construction",
        "Cryptocurrency",
        "Finance",
        "Government",
        "Healthcare",
        "Hospitality",
        "Insurance",
        "Manufacturing",
        "Private Equity",
        "Real Estate",
        "Retail",
        "Technology",
        "Transportation"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)",
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Hindi"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/srivelenterprise/r/recYgZ3M8cGbFkJqm"
    },
    {
      "name": "StackAware",
      "url": "https://stackaware.com",
      "briefSummary": "StackAware specializes in managing cybersecurity, privacy, and compliance risks associated with AI.",
      "description": "They offer AI risk assessments, penetration testing, and AI governance solutions to ensure secure and compliant AI deployments. Their tools include ISMS Policy Generator and proprietary AI Risk Scoring System.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 42001"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/stackaware/r/recM0ULGROU4Smlds"
    },
    {
      "name": "Strike Graph",
      "url": "https://www.strikegraph.com",
      "briefSummary": "AI-native compliance management platform that accelerates audits and eliminates redundant work across 5,000+ data source integrations.",
      "description": "Strike Graph automates 86% of prior compliance efforts through AI-powered evidence collection, continuous control monitoring, and cross-framework mapping across 5,000+ data sources.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 27701",
        "ISO 42001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "HITRUST",
        "PCI DSS",
        "NIST CSF",
        "CMMC",
        "TISAX",
        "DORA",
        "CCPA",
        "FedRAMP",
        "NIST SP 800-171"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Continuous Monitoring",
        "Risk Management",
        "Gap Analysis"
      ],
      "industrySpecialization": [
        "Healthcare",
        "Manufacturing",
        "Technology"
      ],
      "targetClientsSize": [
        "Medium",
        "Enterprise"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/strike+graph/r/8080df81-bc0a-46f3-ae94-eb352d132771"
    },
    {
      "name": "Tempo Audits",
      "url": "https://www.tempoaudits.com",
      "briefSummary": "ISO 27001 certification body, fast and collaborative.",
      "description": "A collaborative and efficient ISO 27001 certification body known for its fast and thorough audit processes.",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "United Kingdom",
        "Europe"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001"
      ],
      "problemsTheySolve": [
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/tempo+audits/r/recH3pkM7gP9ZWJbx"
    },
    {
      "name": "Tevora",
      "url": "https://www.tevora.com",
      "briefSummary": "Irvine cybersecurity and compliance firm for PCI, SOC 2, ISO 27001, HITRUST, CMMC, and FedRAMP.",
      "description": "Tevora is a US cybersecurity and compliance firm based in Irvine. Teams hire it for PCI, SOC 2, ISO 27001, HITRUST, CMMC, and FedRAMP advisory and assessment work. This listing is not a FedRAMP authorization claim for Tevora itself.",
      "serviceType": [
        "Consultants",
        "External audit"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "PCI DSS",
        "SOC 2",
        "ISO 27001",
        "HITRUST",
        "CMMC",
        "FedRAMP",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Certification Assistance",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "Technology",
        "Finance",
        "Healthcare"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/tevora/r/a12e18f4-b774-4f2e-9076-49b9ad44b4bc"
    },
    {
      "name": "The ISO Guys 27001, 27701 , 42001",
      "url": "www.cybercontrols.io",
      "briefSummary": "At Cybercontrols we understand the ever-growing threat landscape of the digital world. Our mission is to provide comprehensive cyber security services that protect your digital frontiers.",
      "description": "Cybercontrols.io: Your Trusted Partner in Compliance and Risk Management\n\nKey Differentiators\nWe combine deep technical expertise with globally recognized certifications (ISO 27001, ISO 27701, ISO 9001, ISO 42001, GDPR, and more). Our unique edge lies in a tailored, no-nonsense approach, delivering implementation, auditing, and training with real-world impact  not just paperwork.\n\nFrameworks We Focus On\n\nISO/IEC 27001: Information Security\n\nISO/IEC 27701: Privacy Information Management\n\nISO/IEC 42001: AI Management Systems\n\nISO 9001: Quality Management\n\nGDPR: EU Data Protection Compliance\n\nISO 45001 & ISO 14001 (on request)\n\nPricing Model\nFlexible and transparent. We offer fixed-fee packages, time-based consulting, and custom solutions , all scoped to fit your maturity level, risk appetite, and resource constraints.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Africa",
        "Asia",
        "Australia",
        "Canada",
        "Europe",
        "Middle East",
        "United Kingdom",
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "NIST CSF"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment",
        "Certification Body Services",
        "Lead Implementer Training"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/the+iso+guys+27001,+27701+,+42001/r/recEeJnfXGQIai3Vz"
    },
    {
      "name": "The Rybec Group",
      "url": "www.rybec.co.uk",
      "briefSummary": "The Rybec Group: Practical, People‑Focused Cyber Security\n\nThe Rybec Group is a cyber security partner built by former law‑enforcement investigators. We help organisations with limited time or resources achieve IASME Cyber Essentials, ISO 27001, and long‑term compliance with confidence.\n\nOur approach is simple: clear guidance, measurable outcomes, and people‑centred support. No jargon. No complexity. Just practical cyber resilience that helps you build trust, meet client demands, and protect your future.\n\nWhat We Deliver\n\nGovernance, Risk & Compliance\n\nExpert support across ISO 27001, ISO 42001, CAF, NIST, and the Cyber Resilience Act — including full implementation, documentation, and ongoing ISMS management.\n\nCompliance‑as‑a‑Service\n\nA fully managed service that keeps your organisation compliant year‑round. We handle internal audits, ISMS maintenance, evidence collection, policy updates, and continuous improvement so you stay audit‑ready at all times.\n\nCyber Security Assessments\n\nClear identification of vulnerabilities with tailored, actionable recommendations.\n\nCyber Awareness Training\n\nNCSC‑aligned training that empowers your people to recognise and respond to threats.\n\nIASME Cyber Essentials & Cyber Assurance\n\nCertification and consultancy to help you achieve and maintain compliance with ease.\n\nAudit Readiness Support\n\nHands‑on preparation for external audits, ensuring your evidence, processes, and documentation meet the required standards.\n\nFlexible Payment Plans\n\nAccessible support for organisations of all sizes, with payment options that fit your budget and project timelines.\n\n\nTrusted experts. Real‑world experience. Unbeatable support.\nSecure your organisation with The Rybec Group.\n\ncontact@rybec.co.uk\n01482 765251\n",
      "description": "What are your key differentiators?\n\nThe Rybec Group brings together real investigative experience, deep technical expertise, and a people‑first approach. Built by former law‑enforcement cyber investigators, we understand how threats unfold in the real world and how to protect organisations in a practical, achievable way.\n\nWe are also an official IASME Cyber Essentials Certification Body, giving clients direct access to accredited assessors rather than third‑party intermediaries.\n\nQuality and governance are at the heart of our business. We hold our own UKAS‑accredited ISO 9001 (Quality Management) and ISO 27001 (Information Security Management) certifications, demonstrating that we operate to the same high standards we help our clients achieve.\n\nEvery member of our team is fully qualified, vetted, and experienced, ensuring you receive expert guidance you can trust.\n\nOur differentiators are simple: real‑world expertise, accredited capability, clear communication, and long‑term partnership.\n\nWhat frameworks or standards are your services focused on?\n\nWe support organisations across a wide range of recognised cyber security and governance frameworks, including:\n\n• ISO 27001 – Information Security Management Systems\n• ISO 42001 – Artificial Intelligence Management Systems\n• IASME Cyber Essentials & Cyber Assurance (as an official Certification Body)\n• Cyber Assessment Framework (CAF)\n• NIST Cybersecurity Framework\n• Cyber Resilience Act readiness\n• General governance, risk, and compliance best practice\n\nWe deliver full implementation, documentation, certification readiness, and ongoing ISMS management after certification.\n\nHow does pricing work for your offers?\n\nWe keep pricing transparent, predictable, and flexible. Our models include:\n\n• Fixed‑price project packages for ISO implementation, Cyber Essentials, assessments, and training\n• Monthly subscription options for Compliance‑as‑a‑Service and ongoing ISMS management\n• Flexible payment plans to support cash flow and make compliance accessible for organisations of all sizes\n• Clear scopes and deliverables so you always know exactly what you’re paying for\n\nNo hidden fees. No surprises. Just value‑driven support aligned to your needs.\n\nHow can we know you care about quality?\n\nQuality is embedded in everything we do — and independently verified.\n\n• We hold UKAS‑accredited ISO 9001 and ISO 27001 certifications, proving our commitment to quality and information security.\n• As an IASME Certification Body, our work is regularly assessed to ensure accuracy, integrity, and consistency.\n• All staff are qualified, vetted, and trained to deliver high‑quality, audit‑ready outcomes.\n• Every deliverable goes through internal quality checks before it reaches you.\n• We prioritise clear documentation, structured processes, and transparent communication.\n• Our Compliance‑as‑a‑Service model ensures continuous improvement, not one‑off compliance.\n\nWe don’t just talk about quality — we evidence it through our accreditations, our processes, and the results we deliver.\n",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "United Kingdom"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "GDPR"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Security Awareness",
        "Certification Assistance",
        "Incident Response",
        "Vendor Management",
        "Data Protection",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/the+rybec+group/r/recdh7ecfSQPFi83F"
    },
    {
      "name": "Thoropass",
      "url": "https://www.thoropass.com",
      "briefSummary": "End-to-end compliance platform combining AI-powered automation with in-house audit services from Big 4 trained experts.",
      "description": "Thoropass uniquely combines compliance software with an AICPA peer-reviewed CPA firm and PCI-accredited assessor, providing audit prep, continuous monitoring, and security audit services through a single platform. Supporting 30+ frameworks.",
      "serviceType": [
        "Compliance platform",
        "Consultants"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "HITRUST",
        "PCI DSS",
        "NIST CSF",
        "Cyber Essentials",
        "CMMC",
        "SOC 1"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Continuous Monitoring",
        "Risk Management",
        "Vendor Management"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/thoropass/r/dfa5726a-991a-4c36-af12-4fab19af0eb2"
    },
    {
      "name": "Tidal Control",
      "url": "https://tidalcontrol.com ",
      "briefSummary": "Automate compliance work, reduce audit burdens, and build trust by setting up controls, collecting evidence, and preparing for audits with Tidal Control.",
      "description": "Tidal Control simplifies and automates compliance for frameworks like ISO27001, SOC2, GDPR, and more. It integrates with over 60 cloud tools, providing up-to-date insights and a robust audit trail.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Netherlands"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC2",
        "GDPR",
        "NIST CSF",
        "NIST SP800-53",
        "CIS Controls",
        "EBA ICT Guidelines",
        "DORA",
        "ISO 9001",
        "NEN7510",
        "BIO",
        "ABDO",
        "DNB ICT Guidelines",
        "NIS2 CyberFundamentals",
        "RVIT"
      ],
      "problemsTheySolve": [
        "Automation",
        "Compliance",
        "Audit Preparation",
        "Continuous Monitoring"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)",
        "Large (251-1000)"
      ],
      "supportedLanguages": [
        "English",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/tidal+control/r/recGbO8wpuQnacJGs"
    },
    {
      "name": "trail",
      "url": "https://www.trail-ml.com/",
      "briefSummary": "trail offers a software solution for AI governance, helping to comply with e.g. the EU AI Act, to manage AI-specific risks, and to set up an AI management system under the ISO/IEC 42001. It connects GRC capabilities with AI use case management and MLOps to both allow for responsible AI development and usage.",
      "description": "Focused on smart automations of AI governance tasks, curation of AI governance best practices and integration to AI development environments, next to common GRC functionalities. Trail has enabled one of the first ISO/IEC 42001 certifications in Europe.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Australia",
        "Canada",
        "Europe",
        "India",
        "United Kingdom",
        "United States",
        "Germany"
      ],
      "complianceFrameworkExpertise": [
        "ISO 42001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Certification Assistance",
        "Secure AI Deployment"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/trail/r/recZAGCJ7NkbVkmQV"
    },
    {
      "name": "Transpacific Certifications",
      "url": "https://www.tcspl.com.my/",
      "briefSummary": "Transpacific Certifications Services (TCS) aims to provide quality oriented and value-based services in the field of third-party auditing and certification/registration. TCS carries out its certification and auditing activities in an impartial manner and exercises utmost care in managing conflict of interest and ensuring objectivity in certification and auditing process and decision making. TCS endeavour to maintain independence in certification and auditing activities without influence of any commercial, financial or other interests.",
      "description": "ISO9001/ISO45001/ISO14001/ISO13485/ISO22000/ISO27001/ Accreditation SAC/JASANZ/UKAS / certification body company since 2014 ",
      "serviceType": [
        "External audit"
      ],
      "regionCovered": [
        "Singapore"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Security Awareness",
        "Certification Assistance",
        "Data Protection",
        "Certification Body Services"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Malay",
        "Mandarin Chinese"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/transpacific+certifications/r/cacbe423-7c19-4d96-9b5d-571dea756f37"
    },
    {
      "name": "Truesec",
      "url": "https://www.truesec.com",
      "briefSummary": "Nordic cybersecurity company with a dedicated GRC practice for ISO 27001, NIS2, DORA, and NIST-aligned security programs.",
      "description": "Truesec is a major Nordic cybersecurity firm headquartered in Sweden. Beyond technical security services, Truesec offers governance, risk, and compliance engagements that help organizations design and implement programs aligned with ISO 27001, NIS2, DORA, NIST, and related frameworks. The company itself maintains ISO 27001 certification for its management system.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Sweden",
        "Europe",
        "Denmark",
        "Norway",
        "Finland"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "NIS2",
        "DORA",
        "NIST CSF",
        "GDPR",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Gap Analysis",
        "Incident Response",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "All industries",
        "Finance",
        "Technology",
        "Government"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English",
        "Swedish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/truesec/r/0fb69a73-7c63-4e1f-a5da-e0359ac2819d"
    },
    {
      "name": "TrustArc",
      "url": "https://trustarc.com",
      "briefSummary": "San Francisco privacy compliance platform for assessments, records of processing, and cross-border transfer programs.",
      "description": "TrustArc is a US privacy platform for running assessments, processing records, and transfer impact work. Teams use it when privacy operations need a dedicated system rather than a general GRC suite. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "GDPR",
        "CCPA",
        "ISO 27701",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Data Protection",
        "GDPR Compliance",
        "Compliance",
        "Risk Management"
      ],
      "industrySpecialization": [
        "All industries",
        "Technology"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/trustarc/r/fd2519d6-8a24-4f31-b9d0-1e3f989f4531"
    },
    {
      "name": "TrustBound GRC",
      "url": "https://www.trustbound.com/nl",
      "briefSummary": "TrustBound GRC is an intuitive platform for information management, privacy, and audit. With smart automation and mappings, it helps organizations gradually improve their compliance. First-line employees receive manageable tasks, while the second line gains oversight and generates clear reports.",
      "description": "We set ourselves apart from other GRC software providers in that our platform is so well thought out (thanks to automations and interconnections) and works so intuitively (clear dahsboards and use of color) that it makes major compliance challenges manageable and clear. Moving forward step by step motivates.  \nWe can make all desired standards frameworks (privacy, information security, AI) available in the platform (global, European and national) within a short time. This also applies to proprietary internal frameworks. Within TrustBound, we work with standardization as much as possible so that every organization is up and running quickly, but we also offer flexibility on all sorts of fronts so that the platform can be customized for each organization. SMEs can get started with our Professional subscription for as little as 289 euros per month (including 5 users).  TrustBound is a Dutch company. Software is in Dutch and English. ",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Europe",
        "Netherlands"
      ],
      "complianceFrameworkExpertise": [
        "Multi-framework",
        "ISO 27001",
        "ISO 42001",
        "DORA",
        "GDPR",
        "ISO 27701",
        "ISO 9001",
        "ISO 14001",
        "ISO 22301",
        "ISO 45001",
        "NIST CSF",
        "CIS Controls",
        "NIS2",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Continuous Monitoring",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Dutch"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/trustbound+grc/r/reclLmp4SFT55hK8R"
    },
    {
      "name": "Tugboat Logic",
      "url": "https://www.tugboatlogic.com/",
      "briefSummary": "Security assurance platform that simplifies ISO 27001 preparation and certification processes.",
      "description": "Tugboat Logic provides an end-to-end solution for security assurance, making ISO 27001 certification straightforward and manageable.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/tugboat+logic/r/recvtm9TJtSx7Ihy2"
    },
    {
      "name": "TÜV Rheinland",
      "url": "https://www.tuv.com",
      "briefSummary": "Global testing and certification group providing ISO 27001 and broader management system certification services.",
      "description": "TÜV Rheinland is a major international certification and inspection body. It offers ISO/IEC 27001 certification among a wide management systems portfolio, supporting organizations that need independent third-party assurance of their information security management system.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "Germany",
        "Asia",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/tüv+rheinland/r/566a446a-7ce7-44c9-bf5e-73479cbe9e50"
    },
    {
      "name": "TÜV SÜD",
      "url": "https://www.tuvsud.com",
      "briefSummary": "International technical certification body offering ISO 27001 and management system certification with strong European accreditation pedigree.",
      "description": "TÜV SÜD is a global technical services and certification organization. Its management system certification portfolio includes ISO/IEC 27001 information security and related standards, delivered under recognized national accreditation. Buyers often choose TÜV SÜD for technical rigor and multi-country certificate recognition.",
      "serviceType": [
        "Certification body"
      ],
      "regionCovered": [
        "Global",
        "Europe",
        "Germany",
        "Asia",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 9001",
        "ISO 22301",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Body Services",
        "Compliance",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "German"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/tüv+süd/r/b00eb6ac-0ab0-42ef-943c-66fd2485b984"
    },
    {
      "name": "URM Consulting",
      "url": "https://www.urmconsulting.com",
      "briefSummary": "UK information security consultancy for ISO 27001 implementation, internal audit, and certification support with a large public track record.",
      "description": "URM Consulting is a UK-based information security and compliance consultancy. Core services include ISO 27001 gap analysis, ISMS implementation, internal audit, and certification support. The firm is frequently shortlisted for organizations pursuing ISO 27001 certification and related security management programs.",
      "serviceType": [
        "Consulting",
        "Internal audit"
      ],
      "regionCovered": [
        "United Kingdom",
        "Europe",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "GDPR",
        "ISO 22301",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Gap Analysis",
        "Audit Preparation",
        "Risk Management",
        "Policy Creation",
        "Compliance"
      ],
      "industrySpecialization": [
        "All industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/urm+consulting/r/b4670581-7a0c-49a3-b94c-c4636ba9cc37"
    },
    {
      "name": "Use AI Securely",
      "url": "https://www.useaisecurely.com",
      "briefSummary": "Free one-hour AI literacy course for the workplace: no accounts, quiz-gated, verifiable PDF completion record. One ready-made EU AI Act Article 4 measure.",
      "description": "Use AI Securely is a free, fully self-service AI literacy course for the workplace by Better ISMS. Six text chapters (about one hour) cover what AI is, its strengths and failure modes, data-leak and shadow-AI risks, the rules that apply (GDPR, EU AI Act), and practical safe-use habits. A 12-question knowledge check gates a signed PDF completion record that anyone can verify online; no accounts, no seats, no sales contact. Teams roll it out by sharing a link and collecting records. It is one ready-made measure supporting the EU AI Act Article 4 AI literacy obligation; organisations remain responsible for measures fitting their own context.",
      "serviceType": [
        "Training"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "GDPR",
        "CCPA",
        "NIST AI Risk Management Framework",
        "HIPAA",
        "EU AI ACT"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Data Protection",
        "Security Awareness"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/use+ai+securely/r/recIl8JbD14bGCQ0E"
    },
    {
      "name": "Vanta",
      "url": "https://www.vanta.com",
      "briefSummary": "AI-powered trust management platform that automates compliance, manages risk, and builds customer trust across 35+ frameworks.",
      "description": "Vanta automates evidence collection, continuous monitoring, and security reviews across 400+ integrations, serving 15,000+ customers from startups to enterprises. The platform supports 35+ compliance frameworks and uses AI agents to coordinate compliance tasks, collect evidence, surface risks, and accelerate resolution.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "SOC 2",
        "GDPR",
        "HIPAA",
        "HITRUST",
        "ISO 42001",
        "CMMC",
        "NIS2",
        "DORA",
        "Cyber Essentials",
        "FedRAMP",
        "NIST CSF",
        "CCPA",
        "PCI DSS",
        "EU AI ACT"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Continuous Monitoring",
        "Vendor Management",
        "Audit Preparation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/vanta/r/5555ce7e-ce1a-4fa3-9a14-72f46726cffa"
    },
    {
      "name": "vCISO",
      "url": "https://vciso.dk",
      "briefSummary": "Virtual CISO is a service that provides Cyber- and information security advisory to danish companies in need of an experienced advisor with more than 20 years of experience in areas covering private enterprise, government, defense and academia.",
      "description": "I have broad experience in it operations, architecture, leadership and know more than just theory. I have a solid technical and architectural background understanding if controls are adequate within ISO27001/2, ISAE3000/3402, GDPR, CIS18, etc.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe",
        "Denmark"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "NIS2",
        "CIS Controls"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English",
        "Danish"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/vciso/r/recLS3dKYDfCSaK3h"
    },
    {
      "name": "Visionary Point",
      "url": "https://www.visionarypoint.com",
      "briefSummary": "Modern GRC consulting services for based in New York and Paris.",
      "description": "Modern GRC consulting services with expertise in both New York and Paris, providing tailored ISO 27001 implementation services.",
      "serviceType": [
        "Consulting"
      ],
      "regionCovered": [
        "Europe",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Policy Creation"
      ],
      "industrySpecialization": [
        "For all industries"
      ],
      "targetClientsSize": [
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/visionary+point/r/recpfP6RxFiNRzobv"
    },
    {
      "name": "Whistic",
      "url": "https://www.whistic.com",
      "briefSummary": "Utah third-party risk and trust-center platform for assessments, monitoring, and vendor response.",
      "description": "Whistic is a US third-party risk platform with trust centers and assessment workflows. Security teams use it to assess vendors and to publish their own evidence to customers. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "ISO 27001",
        "NIST CSF",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Vendor Management",
        "Continuous Monitoring",
        "Compliance",
        "Automation"
      ],
      "industrySpecialization": [
        "All industries",
        "Technology"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "All"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/whistic/r/a80043d5-9911-4209-8e2e-919921c067fa"
    },
    {
      "name": "Withum",
      "url": "https://www.withum.com",
      "briefSummary": "US CPA firm with a technology attestation practice frequently used for SOC 2 by SaaS companies.",
      "description": "Withum is a US CPA firm whose technology attestation practice issues SOC 2 and related reports. It is an auditor, not a GRC platform. This listing is not an endorsement of any specific report.",
      "serviceType": [
        "External audit",
        "Consultants"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOC 2",
        "SOC 1",
        "ISO 27001",
        "HITRUST",
        "Multi-framework",
        "CMMC",
        "NIST",
        "PCI DSS"
      ],
      "problemsTheySolve": [
        "Certification Assistance",
        "Audit Preparation",
        "Compliance"
      ],
      "industrySpecialization": [
        "Technology",
        "All industries"
      ],
      "targetClientsSize": [
        "Medium (51-250)",
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/withum/r/72903dce-af4c-489f-a426-dfa30f5f6093"
    },
    {
      "name": "Workiva",
      "url": "https://www.workiva.com",
      "briefSummary": "Iowa connected reporting and GRC platform for SOX, audit, risk, and ESG narrative work.",
      "description": "Workiva is a US platform for connected reporting, SOX, audit, and GRC documentation. Finance and compliance teams use it when filings and control narratives need one controlled workspace. This listing describes the public product. It is not a certification claim.",
      "serviceType": [
        "SaaS",
        "Compliance platform"
      ],
      "regionCovered": [
        "United States",
        "Global"
      ],
      "complianceFrameworkExpertise": [
        "SOX",
        "SOC 2",
        "ISO 27001",
        "Multi-framework"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Audit Preparation",
        "Risk Management",
        "Automation"
      ],
      "industrySpecialization": [
        "Finance",
        "All industries"
      ],
      "targetClientsSize": [
        "Large (251-1000)",
        "Enterprise (1001+)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/workiva/r/3b182cbc-2df7-4037-93c7-59e1e954217a"
    },
    {
      "name": "Zerberus.ai",
      "url": "https://www.zerberus.ai",
      "briefSummary": "Zerberus.ai helps SaaS companies fast-track ISO 27001 & SOC 2 compliance in just 10 days using AI-driven automation, one-click remediation, and real-time risk mapping tailored to your tech stack.",
      "description": "We’re not just another compliance tracker. Zerberus.ai builds enforceable controls and remediation workflows directly into your stack. Key differentiators include:\n\nAI-assisted SoA & policy mapping\n\nOne-click remediation inside your cloud/VPC\n\nJust-in-time control provisioning\n\nPrebuilt integrations (AWS, GCP, Azure, GitHub, Jira, GSuite, Okta, etc.)\n\nWe focus on ISO 27001, SOC 2, NIST CSF, and PCI DSS.\n\nPricing is modular, flat monthly fee for platform + optional expert-led audit-readiness support.",
      "serviceType": [
        "Compliance platform"
      ],
      "regionCovered": [
        "Asia",
        "Europe",
        "India",
        "Israel",
        "United Kingdom",
        "United States"
      ],
      "complianceFrameworkExpertise": [
        "ISO 27001",
        "ISO 42001",
        "SOC 2 Type 2",
        "GDPR",
        "Multi-framework",
        "HIPAA"
      ],
      "problemsTheySolve": [
        "Compliance",
        "Risk Management",
        "Audit Preparation",
        "Policy Creation",
        "Continuous Monitoring",
        "Certification Assistance"
      ],
      "industrySpecialization": [
        "Finance",
        "Healthcare",
        "Insurance",
        "Retail",
        "Technology",
        "Transportation"
      ],
      "targetClientsSize": [
        "Small (1-50)",
        "Medium (51-250)"
      ],
      "supportedLanguages": [
        "English"
      ],
      "detailsPage": "https://ismsdirectory.com/service-details/zerberus.ai/r/recNlCSmt2008ofZf"
    }
  ]
}