ISO27K

ISO 27001 firms

Firms in the ISO27K directory that do iso 27001 work, ordered by tier and then alphabetically.

62 firms.

TrazTech Inc. VerifiedOperates this site

The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF, PIPEDA, PHIPA

Johanson Group LLP Verified

A licensed US CPA firm running SOC 1, SOC 2 and SOC 3 examinations and accredited as an ISO 27001 certification body, working mostly with early-stage technology companies.

Colorado Springs, Colorado · SOC 2 audit, ISO 27001

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

MHM Professional Corporation Verified

A licensed Canadian CPA firm that performs SOC attestations and is an SCC-accredited certification body for ISO standards, including the first Canadian accreditation for ISO/IEC 42001 AI governance audits.

Calgary, Alberta · SOC 2 audit, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PIPEDA

360 Advanced Unclaimed

A licensed Florida CPA firm (licence AD67897, PCAOB registered) that performs SOC 2 examinations and signs the attestation opinion, alongside ISO, HIPAA, PCI DSS, NIST and FedRAMP work.

St. Petersburg, Florida · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

A-LIGN Unclaimed

Certification body accredited by ANAB and UKAS to audit and issue ISO/IEC 27001 certificates, and also offering ISO/IEC 42001 certification.

Tampa, FL · SOC 2 audit, ISO 27001, ISO 42001, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

ABM Integrated Solutions Unclaimed

IT firm whose compliance practice prepares clients for SOC 2 and ISO 27001 certification using a compliance automation platform, and does not issue certificates.

Dartmouth, NS · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

ABS Quality Evaluations Unclaimed

Certification body accredited by ANAB that audits and issues ISO/IEC 27001 certificates and states it serves the United States and Canada.

Spring, TX · ISO 27001, Compliance advisory

Frameworks: ISO 27001

ACS Canada Unclaimed

Certification services provider based in North Vancouver that delivers ISO/IEC 27001 certification through an IAF accredited certification body, and also lists ISO/IEC 42001.

North Vancouver, BC · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Auditwerx Unclaimed

Attest and audit services are provided by Auditwerx LLC and Carr Riggs & Ingram LLC as CPA firms, covering SOC 1, SOC 2 and SOC 3 examinations plus PCI DSS, HIPAA, HITRUST, NIST CSF, CMMC and ISO 27001.

Tampa, Florida · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

BALANCED+ Unclaimed

IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.

Mississauga, ON · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA, PHIPA

BARR Advisory Unclaimed

Firm offering virtual CISO and security program management within its advisory and managed services line, oriented to compliance program delivery.

SOC 2 readiness, ISO 27001, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

BD Emerson Unclaimed

Consultancy offering ISO 27001 and ISO 42001 compliance consulting and internal audit services, and does not issue certificates.

Richmond, VA · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Boulay Unclaimed

A CPA firm with 107 CPAs whose risk advisory group delivers SOC 1, SOC 2 and SOC 3 reporting along with ISO 27001 compliance and Microsoft SSPA attestations.

Minneapolis, Minnesota · 320 · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

BSI Group Unclaimed

Management systems certification body that audits and issues ISO/IEC 27001 certificates, with a Canadian portal serving Canadian clients.

London, UK · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Bureau Veritas Unclaimed

Certification body that audits organisations and issues ISO/IEC 27001 information security management system certificates.

Paris, France · ISO 27001, Compliance advisory

Frameworks: ISO 27001

Canadian Cyber Unclaimed

Governance, risk and compliance consultancy that guides clients through ISO 27001 scoping, gap analysis, policy development and implementation ahead of an external certification audit, and does not issue certificates.

Toronto, ON · ISO 27001, ISO 42001, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Certi360 Unclaimed

Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.

Laval, QC · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Clavea Security Unclaimed

Montreal area cybersecurity firm serving small and mid-sized businesses with offensive security testing managed monitoring ISO 27001 work and Quebec Law 25 compliance.

Laval, Quebec · ISO 27001, Penetration testing, Compliance advisory

Frameworks: ISO 27001

Coalfire Certification Unclaimed

Registered certification body accredited by ANAB to audit and issue ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001 management system certificates.

Alpharetta, GA · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Cognisys Unclaimed

UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.

United Kingdom · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Coral eSecure Unclaimed

Consultancy offering ISO 27001 ISMS consulting and ISO 42001 AI management system consulting, with a listed Oakville office, and does not issue certificates.

Oakville, ON · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Corporate Prime Solutions Inc. Unclaimed

Consultancy providing end to end ISO 27001 advisory, assessment and training to prepare clients for external certification audits, and does not issue certificates.

Vancouver, BC · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

CyberCrest Compliance Unclaimed

Licensed CPA firm registered with the AICPA that issues SOC 2 attestation reports and also provides readiness work; states it serves clients in the US, Canada, Europe and APAC.

Encinitas, California · SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Cyberium Group Unclaimed

Vancouver consultancy listing vCISO among its cybersecurity services, focused on compliance program delivery across SOC 2, ISO 27001 and ISO 42001.

Vancouver, British Columbia · ISO 27001, ISO 42001, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

CyberSecOp Unclaimed

US consultancy running a named virtual CISO program providing outsourced security leadership, with ISO 27001 and NIST program work.

Stamford, Connecticut, United States · ISO 27001, vCISO, Compliance advisory

Frameworks: ISO 27001, NIST CSF

DEKRA Unclaimed

Certification body operating a Canadian site that audits and issues ISO/IEC 27001 and ISO/IEC 42001 management system certificates.

ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Digital Fort Unclaimed

Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.

Winnipeg, MB · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

DNV Unclaimed

Accredited management systems certification body with Canadian offices in Toronto, Calgary, Guelph, Halifax, Montreal, St John's and Vancouver that audits and issues ISO/IEC 27001 certificates.

Toronto, ON · ISO 27001, Compliance advisory

Frameworks: ISO 27001

Elastify Unclaimed

Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.

Toronto, ON · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

Elevate Consult Unclaimed

Consultancy offering a standalone ISO 42001 AI management system assessment and a separate ISO 27001 readiness assessment, and does not issue certificates.

Coral Gables, FL · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

GRC Solutions Unclaimed

Consultancy offering ISO 27001 advisory alongside ISO 42001 readiness assessments and AI governance framework design, and does not issue certificates.

London, UK · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Groupe AD Cyberdefense Unclaimed

Boutique consultancy offering ISMS governance, policy and committee work for ISO 27001 plus AI governance under ISO/IEC 42001, delivered as vCISO engagements, and does not issue certificates.

Montreal, QC · ISO 27001, ISO 42001, vCISO, Compliance advisory

Frameworks: ISO 27001, ISO 42001, NIST CSF

GuardsArm Unclaimed

Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.

Edmonton, AB · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Intertek Unclaimed

Certification body offering ISO/IEC 27001 and ISO/IEC 42001 certification audits, serving North America including Canada through its Toronto operation.

Toronto, ON · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

IRM Consulting & Advisory Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.

Toronto, ON · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

IS Partners Unclaimed

Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.

Dresher, Pennsylvania · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

KirkpatrickPrice Unclaimed

A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.

Nashville, Tennessee · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

Kobalt.io Unclaimed

Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

Lazarus Alliance Unclaimed

States it is a fully licensed CPA firm specializing in SOC 1 and SOC 2 audits, with licensed CPAs leading engagements, and also offers gap and readiness assessments and remediation support.

SOC 2 audit, SOC 2 readiness, ISO 27001, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF, PIPEDA

Linford & Company Unclaimed

A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.

Denver, Colorado · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

LRQA Unclaimed

Certification body accredited by UKAS that audits and issues ISO/IEC 27001 and ISO/IEC 42001 certificates, serving the United States and Canada through its regional site.

London, UK · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Mirai Security Unclaimed

Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.

Vancouver, BC · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

My ISO Consultants Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap analysis, documentation and certification preparation, and does not issue certificates.

Crestline, CA · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

NQA Unclaimed

Accredited certification body that audits and issues ISO/IEC 27001 and ISO/IEC 42001 certificates, with a Canadian regional site.

UK · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

OmniCyber Security Unclaimed

Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.

Vancouver, British Columbia · ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 27001, ISO 42001, PCI DSS, PIPEDA

Orion Assessment Services of Canada Inc. Unclaimed

Canadian certification body accredited by the International Accreditation Service that audits and issues ISO/IEC 27001 certificates.

ISO 27001, Compliance advisory

Frameworks: ISO 27001

Perry Johnson Registrars Unclaimed

Certification body accredited by ANAB, UKAS, JAB and ACCREDIA that audits and issues ISO/IEC 27001 certificates.

Troy, MI · ISO 27001, Compliance advisory

Frameworks: ISO 27001

Pivot Point Security Unclaimed

Consultancy offering ISO 27001 ISMS implementation and ISO 42001 AI readiness assessment and implementation, and does not issue certificates.

Hamilton, NJ · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

PricewaterhouseCoopers Canada Unclaimed

Certification body accredited by the Standards Council of Canada under ISO/IEC 27006-1 and ISO/IEC 42006 to audit and issue ISO/IEC 27001 and ISO/IEC 42001 certificates.

Toronto, ON · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Quali-Conseil inc. Unclaimed

Management systems consultancy that assists clients with ISO 27001 implementation, coaching, internal audits and training, and does not issue certificates.

Quebec City, QC · ISO 27001, Compliance advisory

Frameworks: ISO 27001

risk3sixty Unclaimed

GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.

Roswell, Georgia · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, NIST CSF

RSI Security Unclaimed

Consultancy offering ISO 27001 readiness and ISO 42001 gap assessment and AI management system design, then referring clients to a separate auditor, and does not issue certificates.

US · ISO 27001, ISO 42001, Compliance advisory

Frameworks: ISO 27001, ISO 42001

Sagentix Advisors Unclaimed

Ottawa advisory firm whose cyber and AI practice sells ISO 27001 and SOC 2 readiness alongside privacy and AI governance work. Not a CPA firm and does not sign SOC 2 opinions.

Ottawa, ON · SOC 2 readiness, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001

SAV Associates Unclaimed

CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.

Toronto, ON · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA

Schellman Unclaimed

Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.

Tampa, Florida · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Secrecy Evolution Unclaimed

Consultancy that performs ISO 27001 gap assessments mapped to Annex A and delivers remediation roadmaps and vCISO support, and does not issue certificates.

Toronto, ON · ISO 27001, vCISO, Compliance advisory

Frameworks: ISO 27001, NIST CSF

Systemes Securitech Systems inc. Unclaimed

Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.

Montreal, Quebec · ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

Throughline Unclaimed

A registered CPA firm and certification body that performs SOC 1 and SOC 2 audits and signs the report, and also covers ISO 27001 and ISO 42001.

Australia · SOC 2 audit, ISO 27001, ISO 42001

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

Truvo Cyber Unclaimed

Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.

Ottawa, ON · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

TUV Rheinland Unclaimed

Certification body operating a Canadian site that audits and issues ISO/IEC 27001 information security management system certificates.

Germany · ISO 27001, Compliance advisory

Frameworks: ISO 27001

TwelveDot Incorporated Unclaimed

Ottawa firm selling a Virtual CSO service giving companies of any size security leadership guidance on demand, alongside ISO 27001 program work.

Ottawa, Ontario · 7 · ISO 27001, vCISO, Compliance advisory

Frameworks: ISO 27001

Withum Unclaimed

WithumSmith+Brown PC performs SOC 2 Type I and Type II attestations with independent reporting by AICPA licensed CPAs, and also runs SOC 1, SOC for Cybersecurity and ISO 27001 consulting.

Princeton, New Jersey · 3200 · SOC 2 audit, ISO 27001, Compliance advisory

Frameworks: SOC 2, ISO 27001, NIST CSF

Get quotes instead of browsing

Describe what you need once and it reaches the firms on this page that match it.

Get quotes

Back to the full directory

How were these firms chosen?

They were listed from public information or added by the firm itself. Being listed is not a recommendation, and ISO27K does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

How many firms should I approach?

Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.