ISO27K

How to vet a security or compliance firm

Before you get on a call, spend ten minutes on the firm's own website. It is the only sample of their work you get for free, and it tells you most of what a first call would.

Last reviewed 2026-09-13Written by Jacob Masse, TrazTech Inc.

Every firm in this directory describes itself well. That is what a website is for. The useful question is not whether the copy is good, it is whether anything behind it can be checked, and that is a question you can answer on your own before you spend an hour on a call.

These four checks apply to any firm, including the one that runs this directory. None of them is proof on its own. Two or more together is a reason to ask direct questions before you sign anything.

1. Can you see any of their past work?

A firm that has done this work has something to show for it: named clients, case studies, a redacted sample report, published research, CVEs, conference talks, a blog that argues with something. Look for output, not description.

A site that explains the service at length and never once shows the result of it is the single biggest warning sign on this list. Reports are confidential, so nobody expects client names on a homepage, but a redacted sample is standard and any firm that does this work has one ready.

Ask for

  • A redacted sample report from an engagement like yours, before you sign.
  • Two references you can actually call, ideally in your country and sector.
  • Anything they have published under their own name in the last two years.

2. Do they have an address in every country they claim?

If a firm says it operates somewhere, it should be able to show a street address there and name the people who work from it. A country page with no address, no named staff and no local clients is a marketing page, not an office. The work will be delivered from wherever the firm actually is.

That is not automatically a problem. Plenty of good firms deliver across borders and say so plainly. It becomes a problem when the page is written to suggest a local presence that does not exist, because the things you were buying with it do not exist either: pricing in your currency, familiarity with the privacy regime you report under, and someone who can be in a room with you.

Ask for

  • The street address, and who works from it.
  • A client in your country who will take your call.
  • Which entity signs the contract, and which country's law governs it.
  • Which currency you are invoiced in, and who carries the exchange rate.

3. Could the writing only be about them?

Swap the firm's name for a competitor's. If every sentence still works, the page commits them to nothing. Boilerplate is not evidence of a bad firm, but it is evidence that nobody senior has looked at the page, and it leaves you with nothing to hold them to.

The same goes for the flat, tireless, faintly enthusiastic prose of an unedited language model. It is cheap to produce and it is now most of the internet. What it tells you is that the firm was willing to publish something nobody read first.

Look for

  • A specific opinion about how the work should be done, and why.
  • Numbers with units: days of testing, size of team, length of engagement.
  • Something they say they will not do, or are not good at.

4. Are the people named?

Testing and audit work is done by individuals, and the difference between a good engagement and a bad one is usually which individual was assigned to it. A firm that will not tell you who leads the work is asking you to buy a logo.

Check that the named people exist outside the firm's own site, and that their background matches what you are buying. Then make sure the person you meet in the sales call is the person doing the work, or ask who is.

Ask for

  • Who will actually run your engagement, by name, and their background.
  • Whether any of it is subcontracted, and to whom.
  • What happens if that person leaves mid-engagement.

Credentials are a floor, not a finish

For audit work specifically, the credential is not optional: a SOC 2 report is only a SOC 2 report if a licensed CPA firm signs it, and ISO 27001 certification only counts if it comes from an accredited certification body. Check the licence number and the accreditation, because both are public and both are occasionally claimed by firms that do not hold them.

Outside that, certifications tell you less than people think. They prove somebody passed an exam. The four checks above tell you whether the firm has done the work.

Compare at least three

Quotes for the same scope routinely differ by a factor of three, and the reason is almost never that one firm is three times better. It is that the firms are quoting different amounts of human time against the same words. Ask each one how many days of tester or consultant time you are buying, and the comparison becomes possible.

Get quotes and compare them yourself

Describe what you need once and it reaches the firms in the directory that match it. There is no charge to you, and you are not handed to one firm.

Get quotes
Does this apply to the firm that runs this directory?

Yes, and it is meant to. The operator is listed here like any other firm, labelled as the operator, and the same four checks apply to it. A standard that exempts the person publishing it is advertising.

What if a firm fails one of these?

One on its own is weak evidence. Small firms and new ones often have thin websites and are perfectly good at the work. Two or more together, especially a missing track record combined with a claimed presence you cannot verify, is when it is worth asking direct questions and seeing how the answers land.

Is a listing here a recommendation?

No. Listings are compiled from public information and a Verified badge is a tier, not an endorsement. Nothing in this directory is a statement that a firm is the right one for you, which is why this page exists.