8 firms name this framework on its website
C3SA
Cybersecurity organization offering consulting, systems integration, training and cyber ranges, incident response and threat intelligence, with compliance work for ITSG-33, CMMC, CPCSC and SOC 2.
- Architecture
- IR and forensics
- Threat intel
- Privacy
- ITSG-33
- CMMC
- CPCSC
- SOC 2
Castellan Information Security Services Inc.
Governance, risk and compliance services including gap analysis, policy development, audit preparation, CPCSC and CMMC readiness, penetration testing, business continuity, and security staff augmentation.
- GRC advisory
- Audit and certification
- Pen testing
- IAM
- CPCSC
- CMMC
- PCI DSS
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
Pilotcore
Cloud and compliance consultancy offering DevSecOps, readiness assessments for CPCSC and CMMC, SOC 2 readiness, zero trust architecture and fractional CTO support.
- Cloud security
- GRC advisory
- Audit and certification
- Architecture
- CPCSC
- CMMC
- SOC 2
Plurilock
Cybersecurity services firm covering adversary simulation, cloud and data protection, identity and compliance readiness, including CPCSC and CMMC readiness for defence suppliers.
- Pen testing
- Red team
- Cloud security
- IAM
- GRC advisory
- +2
- CPCSC
- CMMC
- NIST 800-171
- MITRE ATT&CK
- OWASP
SAV Associates
Toronto CPA firm and ISO certification body offering SOC 1/2/3 attestation, ISO certification, IT audit, GRC consulting, CMMC and CPCSC readiness, and penetration testing and incident response.
- Audit and certification
- GRC advisory
- Pen testing
- Vulnerability mgmt
- IR and forensics
- SOC 2
- ISO 27001
- CMMC
- CPCSC
Stingrai
Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.
- Pen testing
- Red team
- AppSec
- Cloud security
- SOC 2
- ISO 27001
- CMMC
- PCI DSS
- HIPAA
- +1
// more
Other frameworks
- ISO/IEC 27001
- SOC 2
- PCI DSS
- NIST Cybersecurity Framework
- NIST SP 800-171
- CPCSC
- ITSG-33
- CIS Controls
- PIPEDA
- Quebec Law 25
A firm appears here only when its own website names the framework. That is not a statement that it is certified, accredited, or qualified for it. Confirm with the firm. How the directory works.