20 firms name this framework on its website
Appollon Inc.
Managed detection and response with 24/7 SOC monitoring, behavioural detection, active threat response and forensic investigation and remediation, aimed at gaming and tech companies in Quebec.
- MDR and SOC
- IR and forensics
- SOC 2
- ISO 27001
- Law 25
C3SA
Cybersecurity organization offering consulting, systems integration, training and cyber ranges, incident response and threat intelligence, with compliance work for ITSG-33, CMMC, CPCSC and SOC 2.
- Architecture
- IR and forensics
- Threat intel
- Privacy
- ITSG-33
- CMMC
- CPCSC
- SOC 2
Canadian Cyber
Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.
- GRC advisory
- Audit and certification
- ISO 27001
- SOC 2
- CIS Controls
CyberSpective
Montreal-based firm offering virtual CISO, privacy impact assessments, cybersecurity maturity assessments and audits, vendor risk, governance consulting, penetration testing and awareness training across Canada.
- GRC advisory
- Privacy
- Pen testing
- Training
- Audit and certification
- SOC 2
- PIPEDA
Cyberwall
Ten managed security services including 24/7 managed SOC, MDR, SIEM as a service, endpoint, identity and cloud security, plus consulting in incident response, penetration testing, compliance and privacy.
- MDR and SOC
- MSSP
- IR and forensics
- Pen testing
- GRC advisory
- +3
- SOC 2
- PIPEDA
- HIPAA
- PCI DSS
- ISO 27001
Digital Fort
Winnipeg consultancy offering fractional CISO, SOC 2, ISO 27001 and PCI DSS readiness, risk and maturity assessments, awareness training, and vulnerability and penetration testing.
- GRC advisory
- Audit and certification
- Training
- Pen testing
- Vulnerability mgmt
- SOC 2
eSentire
24/7 managed detection and response and SOC service with digital forensics and incident response, response and remediation, and autonomous penetration testing and continuous threat exposure management.
- MDR and SOC
- IR and forensics
- Pen testing
- SOC 2
- ISO 27001
- MITRE ATT&CK
EthiSecure Services Inc.
Quebec firm offering audit and compliance, security consulting and advising (architecture, vulnerability assessment, risk analysis, policies, virtual CISO and privacy officer roles) and training and certification.
- Audit and certification
- GRC advisory
- Architecture
- Vulnerability mgmt
- Privacy
- ISO 27001
- PCI DSS
- HIPAA
- SOC 2
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
Mirai Security
Application security testing, red team and vulnerability assessment, incident response, cloud security, GRC and security awareness training.
- AppSec
- Red team
- Vulnerability mgmt
- IR and forensics
- Cloud security
- +2
- SOC 2
- ISO 27001
Noraa Consulting
Montreal consultancy offering Law 25 compliance support, ISO 27001 and 27005 training and certification preparation, Microsoft 365 security configuration and security architecture consulting; French and English.
- GRC advisory
- ISO 27001
- Law 25
- SOC 2
OKIOK
Offensive security (penetration testing, vulnerability assessment), incident response, digital forensics, cybersecurity consulting, compliance and governance, and identity compliance as a service.
- Pen testing
- Vulnerability mgmt
- IR and forensics
- GRC advisory
- IAM
- +1
- ISO 27001
- SOC 2
- PCI DSS
- CPCSC
Pilotcore
Cloud and compliance consultancy offering DevSecOps, readiness assessments for CPCSC and CMMC, SOC 2 readiness, zero trust architecture and fractional CTO support.
- Cloud security
- GRC advisory
- Audit and certification
- Architecture
- CPCSC
- CMMC
- SOC 2
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
SAV Associates
Toronto CPA firm and ISO certification body offering SOC 1/2/3 attestation, ISO certification, IT audit, GRC consulting, CMMC and CPCSC readiness, and penetration testing and incident response.
- Audit and certification
- GRC advisory
- Pen testing
- Vulnerability mgmt
- IR and forensics
- SOC 2
- ISO 27001
- CMMC
- CPCSC
Secrecy Evolution
Toronto firm providing fractional and virtual CISO retainers: security roadmaps, policies, risk registers, board reporting, vendor risk assessment and compliance oversight for organizations across Canada.
- GRC advisory
- ISO 27001
- SOC 2
- PIPEDA
Software Secured
Manual penetration testing for web, API, mobile, cloud, infrastructure, AI and IoT; secure code review, red teaming, threat modeling, PTaaS and developer training on the OWASP Top 10.
- Pen testing
- Red team
- AppSec
- Cloud security
- Training
- SOC 2
- HIPAA
- ISO 27001
- PCI DSS
- GDPR
- +1
Stingrai
Penetration testing for applications, networks and cloud, social engineering, and red/purple team exercises, delivered with a PTaaS platform and retesting.
- Pen testing
- Red team
- AppSec
- Cloud security
- SOC 2
- ISO 27001
- CMMC
- PCI DSS
- HIPAA
- +1
Vumetric
Penetration testing and security assessment provider covering network, application, API, specialized (medical device, IoT, SCADA/ICS), red team and social engineering testing, plus vulnerability assessment.
- Pen testing
- Red team
- Vulnerability mgmt
- AppSec
- OT and ICS
- PCI DSS
- SOC 2
- ISO 27001
- GDPR
- OWASP
- +1
Learn more
// more
Other frameworks
- ISO/IEC 27001
- PCI DSS
- NIST Cybersecurity Framework
- NIST SP 800-171
- CMMC
- CPCSC
- ITSG-33
- CIS Controls
- PIPEDA
- Quebec Law 25
A firm appears here only when its own website names the framework. That is not a statement that it is certified, accredited, or qualified for it. Confirm with the firm. How the directory works.