home / directory / frameworks

// framework

SOC 2 firms in Canada

Independent attestation reports on a service organization’s controls against the AICPA Trust Services Criteria.

20 firms name this framework on its website

Specialist · Montreal, Quebec

Appollon Inc.

Managed detection and response with 24/7 SOC monitoring, behavioural detection, active threat response and forensic investigation and remediation, aimed at gaming and tech companies in Quebec.

  • MDR and SOC
  • IR and forensics
  • SOC 2
  • ISO 27001
  • Law 25
Focused · Ottawa, Ontario

C3SA

Cybersecurity organization offering consulting, systems integration, training and cyber ranges, incident response and threat intelligence, with compliance work for ITSG-33, CMMC, CPCSC and SOC 2.

  • Architecture
  • IR and forensics
  • Threat intel
  • Privacy
  • ITSG-33
  • CMMC
  • CPCSC
  • SOC 2
Specialist · Toronto, Ontario

Canadian Cyber

Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.

  • GRC advisory
  • Audit and certification
  • ISO 27001
  • SOC 2
  • CIS Controls
Focused · Montreal, Quebec

CyberSpective

Montreal-based firm offering virtual CISO, privacy impact assessments, cybersecurity maturity assessments and audits, vendor risk, governance consulting, penetration testing and awareness training across Canada.

  • GRC advisory
  • Privacy
  • Pen testing
  • Training
  • Audit and certification
  • SOC 2
  • PIPEDA
Full service · Concord, Ontario

Cyberwall

Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.

  • MDR and SOC
  • MSSP
  • IR and forensics
  • Pen testing
  • GRC advisory
  • +3
  • SOC 2
  • PIPEDA
  • HIPAA
  • PCI DSS
  • ISO 27001
Focused · Winnipeg, Manitoba

Digital Fort

Winnipeg consultancy offering fractional CISO, SOC 2, ISO 27001 and PCI DSS readiness, risk and maturity assessments, awareness training, and vulnerability and penetration testing.

  • GRC advisory
  • Audit and certification
  • Training
  • Pen testing
  • Vulnerability mgmt
  • SOC 2
Focused · Waterloo, Ontario

eSentire

24/7 managed detection and response and SOC service with digital forensics and incident response, response and remediation, and autonomous penetration testing and continuous threat exposure management.

  • MDR and SOC
  • IR and forensics
  • Pen testing
  • SOC 2
  • ISO 27001
  • MITRE ATT&CK
Full service · Pointe-Claire, Quebec

EthiSecure Services Inc.

Quebec firm offering audit and compliance, security consulting and advising (architecture, vulnerability assessment, risk analysis, policies, virtual CISO and privacy officer roles) and training and certification.

  • Audit and certification
  • GRC advisory
  • Architecture
  • Vulnerability mgmt
  • Privacy
  • ISO 27001
  • PCI DSS
  • HIPAA
  • SOC 2
Full service · Toronto, Ontario

IRM Consulting & Advisory

Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.

  • GRC advisory
  • Audit and certification
  • Privacy
  • Pen testing
  • AppSec
  • +3
  • SOC 2
  • ISO 27001
  • CMMC
  • CIS Controls
  • GDPR
  • +3
Full service · Vancouver, British Columbia

Kobalt.io

Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.

  • GRC advisory
  • Audit and certification
  • Pen testing
  • IR and forensics
  • MDR and SOC
  • +1
  • CPCSC
  • CMMC
  • NIST 800-171
  • SOC 2
  • ISO 27001
  • +6
Full service · Vancouver, British Columbia

Mirai Security

Application security testing, red team and vulnerability assessment, incident response, cloud security, GRC and security awareness training.

  • AppSec
  • Red team
  • Vulnerability mgmt
  • IR and forensics
  • Cloud security
  • +2
  • SOC 2
  • ISO 27001
Specialist · Montreal, Quebec

Noraa Consulting

Montreal consultancy offering Law 25 compliance support, ISO 27001 and 27005 training and certification preparation, Microsoft 365 security configuration and security architecture consulting; French and English.

  • GRC advisory
  • ISO 27001
  • Law 25
  • SOC 2
Full service · Laval, Quebec

OKIOK

Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.

  • Pen testing
  • Vulnerability mgmt
  • IR and forensics
  • GRC advisory
  • IAM
  • +1
  • ISO 27001
  • SOC 2
  • PCI DSS
  • CPCSC
Focused · Ottawa, Ontario

Pilotcore

Cloud and compliance consultancy offering DevSecOps, readiness assessments for CPCSC and CMMC, SOC 2 readiness, zero trust architecture and fractional CTO support.

  • Cloud security
  • GRC advisory
  • Audit and certification
  • Architecture
  • CPCSC
  • CMMC
  • SOC 2
Full service · Etobicoke, Ontario

PlutoSec

Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.

  • Pen testing
  • Red team
  • GRC advisory
  • Audit and certification
  • Cloud security
  • +3
  • ISO 27001
  • SOC 2
  • PCI DSS
  • NIST CSF
  • ITSG-33
  • +2
Full service · Toronto, Ontario

SAV Associates

Toronto CPA firm and ISO certification body offering SOC 1/2/3 attestation, ISO certification, IT audit, GRC consulting, CMMC and CPCSC readiness, and penetration testing and incident response.

  • Audit and certification
  • GRC advisory
  • Pen testing
  • Vulnerability mgmt
  • IR and forensics
  • SOC 2
  • ISO 27001
  • CMMC
  • CPCSC
Specialist · Toronto, Ontario

Secrecy Evolution

Toronto firm providing fractional and virtual CISO retainers: security roadmaps, policies, risk registers, board reporting, vendor risk assessment and compliance oversight for organizations across Canada.

  • GRC advisory
  • ISO 27001
  • SOC 2
  • PIPEDA
Specialist · Ottawa, Ontario

Software Secured

Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.

  • Pen testing
  • Red team
  • AppSec
  • Cloud security
  • Training
  • SOC 2
  • HIPAA
  • ISO 27001
  • PCI DSS
  • GDPR
  • +1
Specialist · Toronto, Ontario

Stingrai

Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.

  • Pen testing
  • Red team
  • AppSec
  • Cloud security
  • SOC 2
  • ISO 27001
  • CMMC
  • PCI DSS
  • HIPAA
  • +1
Focused · Toronto, Ontario

Vumetric

Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.

  • Pen testing
  • Red team
  • Vulnerability mgmt
  • AppSec
  • OT and ICS
  • PCI DSS
  • SOC 2
  • ISO 27001
  • GDPR
  • OWASP
  • +1

// more

Other frameworks