11 firms name this framework on its website
Castellan Information Security Services Inc.
Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.
- GRC advisory
- Audit and certification
- Pen testing
- IAM
- CPCSC
- CMMC
- PCI DSS
Cyberwall
Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.
- MDR and SOC
- MSSP
- IR and forensics
- Pen testing
- GRC advisory
- +3
- SOC 2
- PIPEDA
- HIPAA
- PCI DSS
- ISO 27001
EthiSecure Services Inc.
Quebec firm offering audit and compliance, security consulting and advising (architecture, vulnerability assessment, risk analysis, policies, virtual CISO and privacy officer roles) and training and certification.
- Audit and certification
- GRC advisory
- Architecture
- Vulnerability mgmt
- Privacy
- ISO 27001
- PCI DSS
- HIPAA
- SOC 2
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
OKIOK
Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.
- Pen testing
- Vulnerability mgmt
- IR and forensics
- GRC advisory
- IAM
- +1
- ISO 27001
- SOC 2
- PCI DSS
- CPCSC
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
Prairie Cyber Security
Winnipeg firm serving small and mid-sized organizations with security assessments, managed detection and response, incident response, virtual CISO consulting and security awareness training.
- GRC advisory
- MDR and SOC
- IR and forensics
- Training
- PIPEDA
- PCI DSS
Software Secured
Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.
- Pen testing
- Red team
- AppSec
- Cloud security
- Training
- SOC 2
- HIPAA
- ISO 27001
- PCI DSS
- GDPR
- +1
Stingrai
Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.
- Pen testing
- Red team
- AppSec
- Cloud security
- SOC 2
- ISO 27001
- CMMC
- PCI DSS
- HIPAA
- +1
Vumetric
Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.
- Pen testing
- Red team
- Vulnerability mgmt
- AppSec
- OT and ICS
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
- OWASP
- +1
Learn more
// more
Other frameworks
- ISO/IEC 27001
- SOC 2
- NIST Cybersecurity Framework
- NIST SP 800-171
- CMMC
- CPCSC
- ITSG-33
- CIS Controls
- PIPEDA
- Quebec Law 25
A firm appears here only when its own website names the framework. That is not a statement that it is certified, accredited, or qualified for it. Confirm with the firm. How the directory works.