ISO consultant and certification body directory
What each listing means, how the tiers differ, and what to check before you sign with any of the firms below.
Filtering happens in your browser. Nothing is sent anywhere and the order never changes.
69 firms listed on ISO27K.
Nothing matches those filters. to see every firm again.
Our offerings
TrazTech Inc. VerifiedOperates this site
The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.
Verified firms
Verified means the firm exists as a registered business, does the work its listing claims, and holds the credentials it states. It is normally a paid tier, though not every Verified listing was paid for. The order inside the tier is fixed either way and is not for sale. See how listings work.
Johanson Group LLP Verified
A licensed US CPA firm running SOC 1, SOC 2 and SOC 3 examinations and accredited as an ISO 27001 certification body, working mostly with early-stage technology companies.
MHM Professional Corporation Verified
A licensed Canadian CPA firm that performs SOC attestations and is an SCC-accredited certification body for ISO standards, including the first Canadian accreditation for ISO/IEC 42001 AI governance audits.
Everyone else
Listed from public information and not yet claimed by the firm, so the details here are ours rather than theirs. If this is your firm, claim it and it becomes yours to edit.
13 Security Unclaimed
Information security consultancy that works through GRC platforms to get clients through SOC 2 Type 1 and Type 2 audits carried out by an independent auditor.
360 Advanced Unclaimed
A licensed Florida CPA firm (licence AD67897, PCAOB registered) that performs SOC 2 examinations and signs the attestation opinion, alongside ISO, HIPAA, PCI DSS, NIST and FedRAMP work.
7 River Systems Unclaimed
Runs internal audits and readiness assessments across SOC 2 and other frameworks and builds compliance programs for clients ahead of an external audit.
A-LIGN Unclaimed
Certification body accredited by ANAB and UKAS to audit and issue ISO/IEC 27001 certificates, and also offering ISO/IEC 42001 certification.
ABM Integrated Solutions Unclaimed
IT firm whose compliance practice prepares clients for SOC 2 and ISO 27001 certification using a compliance automation platform, and does not issue certificates.
ABS Quality Evaluations Unclaimed
Certification body accredited by ANAB that audits and issues ISO/IEC 27001 certificates and states it serves the United States and Canada.
ACS Canada Unclaimed
Certification services provider based in North Vancouver that delivers ISO/IEC 27001 certification through an IAF accredited certification body, and also lists ISO/IEC 42001.
Amomitto Security Unclaimed
Runs SOC 2, ISO 27001 and HIPAA engagements covering readiness and post-audit maintenance, coordinating the audit rather than issuing the report.
Atoro Unclaimed
Compliance consultancy that builds the controls and evidence behind the SOC 2 report North American buyers ask for, and runs internal audits rather than signing opinions.
Auditwerx Unclaimed
Attest and audit services are provided by Auditwerx LLC and Carr Riggs & Ingram LLC as CPA firms, covering SOC 1, SOC 2 and SOC 3 examinations plus PCI DSS, HIPAA, HITRUST, NIST CSF, CMMC and ISO 27001.
BALANCED+ Unclaimed
IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.
BARR Advisory Unclaimed
Firm offering virtual CISO and security program management within its advisory and managed services line, oriented to compliance program delivery.
BD Emerson Unclaimed
Consultancy offering ISO 27001 and ISO 42001 compliance consulting and internal audit services, and does not issue certificates.
Boulay Unclaimed
A CPA firm with 107 CPAs whose risk advisory group delivers SOC 1, SOC 2 and SOC 3 reporting along with ISO 27001 compliance and Microsoft SSPA attestations.
BSI Group Unclaimed
Management systems certification body that audits and issues ISO/IEC 27001 certificates, with a Canadian portal serving Canadian clients.
Bureau Veritas Unclaimed
Certification body that audits organisations and issues ISO/IEC 27001 information security management system certificates.
Canadian Cyber Unclaimed
Governance, risk and compliance consultancy that guides clients through ISO 27001 scoping, gap analysis, policy development and implementation ahead of an external certification audit, and does not issue certificates.
Certi360 Unclaimed
Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.
Clavea Security Unclaimed
Montreal area cybersecurity firm serving small and mid-sized businesses with offensive security testing managed monitoring ISO 27001 work and Quebec Law 25 compliance.
Coalfire Unclaimed
Cybersecurity advisory and assessment firm combining offensive testing with audit services across a large number of compliance frameworks.
Coalfire Certification Unclaimed
Registered certification body accredited by ANAB to audit and issue ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001 management system certificates.
Cognisys Unclaimed
UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.
Coral eSecure Unclaimed
Consultancy offering ISO 27001 ISMS consulting and ISO 42001 AI management system consulting, with a listed Oakville office, and does not issue certificates.
Corporate Prime Solutions Inc. Unclaimed
Consultancy providing end to end ISO 27001 advisory, assessment and training to prepare clients for external certification audits, and does not issue certificates.
CyberCrest Compliance Unclaimed
Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.
Cyberium Group Unclaimed
Vancouver consultancy listing vCISO among its cybersecurity services, focused on compliance program delivery across SOC 2, ISO 27001 and ISO 42001.
CyberSecOp Unclaimed
US consultancy running a named virtual CISO program providing outsourced security leadership, with ISO 27001 and NIST program work.
Cycore Unclaimed
Compliance services firm that guides clients through the whole SOC 2, ISO 27001 and HIPAA process from initial assessment to certification, with the audit done by others.
DEKRA Unclaimed
Certification body operating a Canadian site that audits and issues ISO/IEC 27001 and ISO/IEC 42001 management system certificates.
Digital Fort Unclaimed
Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.
DNV Unclaimed
Accredited management systems certification body with Canadian offices in Toronto, Calgary, Guelph, Halifax, Montreal, St John's and Vancouver that audits and issues ISO/IEC 27001 certificates.
Elastify Unclaimed
Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.
Elevate Consult Unclaimed
Consultancy offering a standalone ISO 42001 AI management system assessment and a separate ISO 27001 readiness assessment, and does not issue certificates.
GRC Solutions Unclaimed
Consultancy offering ISO 27001 advisory alongside ISO 42001 readiness assessments and AI governance framework design, and does not issue certificates.
Groupe AD Cyberdefense Unclaimed
Boutique consultancy offering ISMS governance, policy and committee work for ISO 27001 plus AI governance under ISO/IEC 42001, delivered as vCISO engagements, and does not issue certificates.
GuardsArm Unclaimed
Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.
Intertek Unclaimed
Certification body offering ISO/IEC 27001 and ISO/IEC 42001 certification audits, serving North America including Canada through its Toronto operation.
IRM Consulting & Advisory Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.
IS Partners Unclaimed
Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.
KirkpatrickPrice Unclaimed
A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.
Kobalt.io Unclaimed
Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.
Lazarus Alliance Unclaimed
States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.
Linford & Company Unclaimed
A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.
LRQA Unclaimed
Certification body accredited by UKAS that audits and issues ISO/IEC 27001 and ISO/IEC 42001 certificates, serving the United States and Canada through its regional site.
Mirai Security Unclaimed
Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.
My ISO Consultants Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap analysis, documentation and certification preparation, and does not issue certificates.
NQA Unclaimed
Accredited certification body that audits and issues ISO/IEC 27001 and ISO/IEC 42001 certificates, with a Canadian regional site.
OmniCyber Security Unclaimed
Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.
Orion Assessment Services of Canada Inc. Unclaimed
Canadian certification body accredited by the International Accreditation Service that audits and issues ISO/IEC 27001 certificates.
Perry Johnson Registrars Unclaimed
Certification body accredited by ANAB, UKAS, JAB and ACCREDIA that audits and issues ISO/IEC 27001 certificates.
Pivot Point Security Unclaimed
Consultancy offering ISO 27001 ISMS implementation and ISO 42001 AI readiness assessment and implementation, and does not issue certificates.
PricewaterhouseCoopers Canada Unclaimed
Certification body accredited by the Standards Council of Canada under ISO/IEC 27006-1 and ISO/IEC 42006 to audit and issue ISO/IEC 27001 and ISO/IEC 42001 certificates.
Quali-Conseil inc. Unclaimed
Management systems consultancy that assists clients with ISO 27001 implementation, coaching, internal audits and training, and does not issue certificates.
risk3sixty Unclaimed
GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.
RSI Security Unclaimed
Consultancy offering ISO 27001 readiness and ISO 42001 gap assessment and AI management system design, then referring clients to a separate auditor, and does not issue certificates.
Sagentix Advisors Unclaimed
Ottawa advisory firm whose cyber and AI practice sells ISO 27001 and SOC 2 readiness alongside privacy and AI governance work. Not a CPA firm and does not sign SOC 2 opinions.
SAV Associates Unclaimed
CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.
Schellman Unclaimed
Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.
Secrecy Evolution Unclaimed
Consultancy that performs ISO 27001 gap assessments mapped to Annex A and delivers remediation roadmaps and vCISO support, and does not issue certificates.
Systemes Securitech Systems inc. Unclaimed
Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.
Throughline Unclaimed
A registered CPA firm and certification body that performs SOC 1 and SOC 2 audits and signs the report, and also covers ISO 27001 and ISO 42001.
Truvo Cyber Unclaimed
Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.
TUV Rheinland Unclaimed
Certification body operating a Canadian site that audits and issues ISO/IEC 27001 information security management system certificates.
TwelveDot Incorporated Unclaimed
Ottawa firm selling a Virtual CSO service giving companies of any size security leadership guidance on demand, alongside ISO 27001 program work.
URM Consulting Services Unclaimed
Provides SOC 2 gap analysis, remediation and consultancy for organizations preparing for a Type 1 or Type 2 report rather than producing the report.
Withum Unclaimed
WithumSmith+Brown PC performs SOC 2 Type I and Type II attestations with independent reporting by AICPA licensed CPAs, and also runs SOC 1, SOC for Cybersecurity and ISO 27001 consulting.
Browse a shorter list
The whole directory is above. These are the same firms cut down to one service or one province, which is usually the faster way in.
- Cloud compliance firms in Canada, 5 firms
- Compliance advisory firms in Canada, 67 firms
- ISO 27001 firms in Canada, 68 firms
- ISO 42001 firms in Canada, 33 firms
- Penetration testing firms in Canada, 21 firms
- Canadian privacy firms in Canada, 4 firms
- Security questionnaires firms in Canada, 5 firms
- SOC 2 audit firms in Canada, 14 firms
- SOC 2 readiness firms in Canada, 25 firms
- Trust center firms in Canada, 5 firms
- vCISO firms in Canada, 18 firms
- ISO 27001 firms in British Columbia, 6 firms
- ISO 27001 firms in Florida, 5 firms
- ISO 27001 firms in Ontario, 14 firms
- ISO 27001 firms in Quebec, 5 firms
- ISO 27001 firms in United Kingdom, 6 firms
How do I know I can trust one of these firms?
Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.
Is a listing here a recommendation?
No. Firms are listed from public information or added by the firm itself, and a Verified badge is a tier rather than an endorsement. Nothing on this page says a firm is the right one for you. Compare at least three.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
The rest of this page is the part that will still be useful when the directory is full: which of the two kinds of organization you are actually shopping for, and how to check the one claim that matters.
Certification body or consultant
This is the distinction ISO buyers get wrong most often, and unlike most compliance nuance it is not a matter of judgement. ISO/IEC 17021-1, the standard certification bodies are themselves accredited against, prohibits a body from providing management system consultancy, and prohibits it from certifying an organization that received such consultancy from the body or a related body within the preceding two years. One firm cannot legitimately do both jobs for you.
| Question | Certification body | Consultant or readiness firm |
|---|---|---|
| Can it issue the certificate? | Yes, that is the whole job | No, and a firm implying otherwise should be dropped |
| Who grants it standing? | An accreditation body. In Canada the Standards Council of Canada, and its international peers are accepted here too | Nobody. There is no accreditation for consultants and none is required |
| Can it write your policies or run your risk workshop? | No. That is consultancy and it is prohibited | Yes, that is the work |
| Can it run your internal audit? | No, for the same reason | Yes, though not the same firm that built the system if you can avoid it |
| When you engage it | Once the management system has been running long enough to produce records | At the start, before the scope statement is written |
| How it prices | Audit days, per visit, across a three-year cycle | Fixed project fee, day rate, or a monthly retainer |
| Typical Canadian range | $15,000 to $40,000 CAD, first year | $25,000 to $70,000 CAD for a first certification |
| How many exist in Canada | A small number, national and global businesses | Many, from single practitioners to national firms |
The one question that sorts them
Ask any firm you speak to, in writing: are you quoting to help us get ready, or to audit and certify us. A firm that gives a straight answer is one of the two. A firm that says both is either not accredited, or is describing two legally separate organizations and hoping you will not notice, or is going to hand you an unaccredited certificate. An unaccredited certificate costs less because it is worth less, and a European buyer who asked for ISO 27001 will spot it. How to verify accreditation in five minutes is on certification bodies in Canada.
Language is on that list because of Quebec. A certification body that cannot field a French-speaking lead auditor for three years of audits is not a candidate for a company whose engineers work in French, which is set out on certifying with Quebec in scope.
What a listing shows
The three rows below are examples, not real firms. The names are invented and the details are placeholders, shown to make the difference between the listing states legible before there is anything real to look at.
Sample Registrar Canada (example, not a real firm) Verified
Example of a Verified certification body row. Verified here means one specific thing was checked: the accreditation was confirmed on the accreditation body's own public register, for that standard, on that date. It is not a recommendation.
Example Security Partners (example, not a real firm) Verified
Example of a Verified consultant row on the paid tier: a full profile, written by the firm, above the free listings. Verification for a consultant means the business is registered, the credentials on the listing are real, and the firm performs the work it claims rather than reselling somebody else's.
Sample Readiness Co (example, not a real firm) Unclaimed
Example of an unclaimed row, built from public information that nobody at the firm has confirmed. Treat everything in an unclaimed row as a starting point for your own check. Claiming it is free and is done from a company email address.
What a listing costs
Two tiers, and we would rather print the price here than make you write in and ask.
| Free listing | Verified | |
|---|---|---|
| In the directory, on every network site your services match | Yes | Yes |
| You edit your own listing, permanently | Yes | Yes |
| Description | One line, 300 characters | Full profile |
| Verified badge | No | Yes |
| Placement | Below the Verified tier | Above the free tier |
| Higher-intent enquiries | Offered at $150 or $350 CAD depending on how ready the buyer is | Sent in full, no charge |
| Cost | $0 | $300 CAD/month or $3,000 CAD/year |
So: a claimed listing is free and stays free, and the Verified tier is paid. What paying does not buy is order within a tier, what we write about a firm, or a mention in any guide, cost page or comparison on this site. The full terms, including what verification actually checks and what happens if we cannot confirm a claim, are on list your firm.
How this site makes money, said plainly
TrazTech sells the Verified tier, charges for higher-intent enquiries on the free tier, and takes a fee when a quote request turns into an engagement. TrazTech is also itself a firm that does this work, and will appear in the directory alongside everyone else. Read anything here with that in mind. It does not change what a page says about a standard, an auditor or a price, and the editorial pages are not for sale at any tier.
How to choose from a shortlist
A directory is a way to build a shortlist and a bad way to make a decision. Four things separate firms and none of them fit in a listing row.
Ask who does the work. The person in the sales meeting is frequently not the person in your risk workshops. Ask for the name and background of the assigned consultant, and how many ISO 27001 or ISO 42001 engagements they personally took to certificate.
Ask what the deliverable is. A fixed-fee readiness quote can mean a policy template pack emailed to you, or six months of somebody sitting with your engineers. Both are sold with the same words. Get the deliverable list and the hours in writing, and ask specifically who writes the Statement of Applicability and who runs the internal audit.
Check the accreditation yourself. Do not take a body's word for it and do not take ours. Ask which accreditation body granted it and for which standard, then look it up on that accreditation body's public register. Accreditation is per standard, so a body accredited for ISO 27001 is not automatically accredited for ISO 42001, and the ISO 42001 pool is small and still changing.
Ask what scope they will propose. A firm that proposes certifying the whole organization before asking what your customers demanded is selling audit days. A narrow first scope covering the product buyers ask about is usually the right first certificate, and the certification process page explains how scope drives the audit.
If you run one of these firms
A listing is one channel and usually not the biggest. What we would tell a consultant who asked is written down: where ISO 27001 work actually comes from, including the certification body referral that most firms never ask for, how to price an ISMS build so a fixed fee survives contact with a slow client, whether to be a consultancy or an accredited certification body, and which credentials buyers actually check. None of those pages is about this directory.
Run a firm that should be in here
Claiming a listing is free. The Verified tier, what it checks and what it costs are all set out on one page.
List your firmCommon questions
How did firms get into this directory?
Most were researched from public information: registration records, the firm's own site, and the credentials it publishes. Those listings are ours rather than the firm's until someone there claims it. A claimed listing is free and becomes the firm's to edit. Verified means we checked the firm is real and is what it says it is.
Does it cost anything to be listed?
A basic claimed listing is free and stays free. There is a paid tier, Verified, at $300 CAD a month or $3,000 CAD a year, which adds the badge, a full profile, placement above the free tier and higher-intent enquiries at no extra charge. Order within a tier is not for sale, and neither is anything written on the guides.
What does the Verified badge mean?
That a specific claim was checked against a source. For a certification body, that its accreditation was confirmed on the accreditation body's public register for the standard named. For a consultant, that the business is registered, the credentials cited are real, and it performs the work it claims. It is not a quality rating and it is not an endorsement.
Can the same firm be my consultant and my certification body?
No, not if you want an accredited certificate. ISO/IEC 17021-1 prohibits a certification body from providing management system consultancy, and from certifying an organization that received it from the body or a related body within the previous two years. Use one firm to get ready and a separate accredited body to certify.
How do I check a certification body's accreditation?
Ask which accreditation body accredited them and for which standard, then check that accreditation body's own public register rather than the certification body's website. Accreditation is granted per standard and it can be suspended, so check the register on the day you shortlist rather than relying on a logo.
How do I get quotes before the directory fills up?
Use the quote form. Describe your scope, headcount, which standard you were asked for and your deadline, and it goes to Canadian firms that quote this work. That route does not depend on the directory having entries.