ISO 42001 firms
Firms in the ISO27K directory that do iso 42001 work, ordered by tier and then alphabetically.
32 firms.
TrazTech Inc. VerifiedOperates this site
The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.
MHM Professional Corporation Verified
A licensed Canadian CPA firm that performs SOC attestations and is an SCC-accredited certification body for ISO standards, including the first Canadian accreditation for ISO/IEC 42001 AI governance audits.
A-LIGN Unclaimed
Certification body accredited by ANAB and UKAS to audit and issue ISO/IEC 27001 certificates, and also offering ISO/IEC 42001 certification.
ACS Canada Unclaimed
Certification services provider based in North Vancouver that delivers ISO/IEC 27001 certification through an IAF accredited certification body, and also lists ISO/IEC 42001.
BD Emerson Unclaimed
Consultancy offering ISO 27001 and ISO 42001 compliance consulting and internal audit services, and does not issue certificates.
BSI Group Unclaimed
Management systems certification body that audits and issues ISO/IEC 27001 certificates, with a Canadian portal serving Canadian clients.
Canadian Cyber Unclaimed
Governance, risk and compliance consultancy that guides clients through ISO 27001 scoping, gap analysis, policy development and implementation ahead of an external certification audit, and does not issue certificates.
Coalfire Unclaimed
Cybersecurity advisory and assessment firm combining offensive testing with audit services across a large number of compliance frameworks.
Coalfire Certification Unclaimed
Registered certification body accredited by ANAB to audit and issue ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 42001 management system certificates.
Cognisys Unclaimed
UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.
Coral eSecure Unclaimed
Consultancy offering ISO 27001 ISMS consulting and ISO 42001 AI management system consulting, with a listed Oakville office, and does not issue certificates.
Cyberium Group Unclaimed
Vancouver consultancy listing vCISO among its cybersecurity services, focused on compliance program delivery across SOC 2, ISO 27001 and ISO 42001.
DEKRA Unclaimed
Certification body operating a Canadian site that audits and issues ISO/IEC 27001 and ISO/IEC 42001 management system certificates.
Elevate Consult Unclaimed
Consultancy offering a standalone ISO 42001 AI management system assessment and a separate ISO 27001 readiness assessment, and does not issue certificates.
GRC Solutions Unclaimed
Consultancy offering ISO 27001 advisory alongside ISO 42001 readiness assessments and AI governance framework design, and does not issue certificates.
Groupe AD Cyberdefense Unclaimed
Boutique consultancy offering ISMS governance, policy and committee work for ISO 27001 plus AI governance under ISO/IEC 42001, delivered as vCISO engagements, and does not issue certificates.
Intertek Unclaimed
Certification body offering ISO/IEC 27001 and ISO/IEC 42001 certification audits, serving North America including Canada through its Toronto operation.
IRM Consulting & Advisory Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.
IS Partners Unclaimed
Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.
KirkpatrickPrice Unclaimed
A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.
Linford & Company Unclaimed
A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.
LRQA Unclaimed
Certification body accredited by UKAS that audits and issues ISO/IEC 27001 and ISO/IEC 42001 certificates, serving the United States and Canada through its regional site.
My ISO Consultants Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap analysis, documentation and certification preparation, and does not issue certificates.
NQA Unclaimed
Accredited certification body that audits and issues ISO/IEC 27001 and ISO/IEC 42001 certificates, with a Canadian regional site.
OmniCyber Security Unclaimed
Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.
Pivot Point Security Unclaimed
Consultancy offering ISO 27001 ISMS implementation and ISO 42001 AI readiness assessment and implementation, and does not issue certificates.
PricewaterhouseCoopers Canada Unclaimed
Certification body accredited by the Standards Council of Canada under ISO/IEC 27006-1 and ISO/IEC 42006 to audit and issue ISO/IEC 27001 and ISO/IEC 42001 certificates.
risk3sixty Unclaimed
GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.
RSI Security Unclaimed
Consultancy offering ISO 27001 readiness and ISO 42001 gap assessment and AI management system design, then referring clients to a separate auditor, and does not issue certificates.
Schellman Unclaimed
Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.
Throughline Unclaimed
A registered CPA firm and certification body that performs SOC 1 and SOC 2 audits and signs the report, and also covers ISO 27001 and ISO 42001.
Truvo Cyber Unclaimed
Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.
Get quotes instead of browsing
Describe what you need once and it reaches the firms on this page that match it.
Get quotesHow were these firms chosen?
They were listed from public information or added by the firm itself. Being listed is not a recommendation, and ISO27K does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
How many firms should I approach?
Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.