7 firms name this framework on its website
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Plurilock
Cybersecurity services firm covering adversary simulation, cloud and data protection, identity and compliance readiness, including CPCSC and CMMC readiness for defence suppliers.
- Pen testing
- Red team
- Cloud security
- IAM
- GRC advisory
- +2
- CPCSC
- CMMC
- NIST 800-171
- MITRE ATT&CK
- OWASP
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
Software Secured
Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.
- Pen testing
- Red team
- AppSec
- Cloud security
- Training
- SOC 2
- HIPAA
- ISO 27001
- PCI DSS
- GDPR
- +1
Stingrai
Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.
- Pen testing
- Red team
- AppSec
- Cloud security
- SOC 2
- ISO 27001
- CMMC
- PCI DSS
- HIPAA
- +1
TwelveDot Incorporated
Ottawa technology and security consulting practice offering virtual CSO, ethical hacking, cloud, mobile and IoT assessments, ISO 27001 implementation and audit, breach mitigation and incident response.
- GRC advisory
- Pen testing
- Cloud security
- Audit and certification
- IR and forensics
- +1
- ISO 27001
- OWASP
Vumetric
Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.
- Pen testing
- Red team
- Vulnerability mgmt
- AppSec
- OT and ICS
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
- OWASP
- +1
// more
Other frameworks
- ISO/IEC 27001
- SOC 2
- PCI DSS
- NIST Cybersecurity Framework
- NIST SP 800-171
- CMMC
- CPCSC
- ITSG-33
- CIS Controls
- PIPEDA
A firm appears here only when its own website names the framework. That is not a statement that it is certified, accredited, or qualified for it. Confirm with the firm. How the directory works.