How this site works

Our methodology

Exactly how we choose firms, what we verify, how we label prices — and what we refuse to do.

Which firms get listed

A firm appears in our directory only if, as of our last check, it meets all three: (1) it is a real, operating cybersecurity practice; (2) its official website returns HTTP 200; (3) it does genuine work against at least one NIST publication (CSF 2.0, SP 800-53, or SP 800-171) — assessor roles (3PAO, C3PAO) are described only as the firms themselves claim them.

What we verify — and what we don't claim

For each firm we record headquarters, firm type, and the frameworks its own public materials say it supports. Directory facts were last verified in September 2026; we aim to re-check quarterly.

What we don't verify. We do not verify individual assessor credentials, FedRAMP 3PAO authorization status, CMMC C3PAO authorization status, audit quality, pricing, or availability. Directory inclusion is not an endorsement, and no firm can pay for placement or a higher rank. Verify authorization claims against the official FedRAMP marketplace and Cyber AB marketplace before engaging an assessor.

How we label every price

Consulting fees are scoped per engagement, so most firms publish no prices at all. Where we show a planning range, it always carries one of three labels:

LabelMeaning
Firm-publishedThe firm publishes the figure itself.
Published planning rangeA third-party published planning range (September 2026). Useful for budgeting; not a quote.
Directory estimateOur estimate synthesized from published rate data (September 2026), clearly labeled. Not a quote.
Not publishedThe firm publishes no band. Request a scoped quote — that's what our quote form is for.

None of these are quotes. Your fee depends on scope, sector, and starting posture. Treat every band as a planning figure and get scope and fee in writing.

What we will never do

How we make money

When you request quotes, matched firms may pay us a lead or referral fee. That payment cannot change which firms we list, what our guides say, or which firms we recommend — the firewall is absolute.

Corrections

Wrong price, stale fact, firm missing? Tell us. We check corrections against the firm's own public materials.

Verification log

Row-level log of every firm website and price source check. Append-only: new entries go on top.

Date checkedFirm / sourceURLHTTP statusResult
2026-09-24Summit 7summit7.usHTTP 200Official website loaded successfully
2026-09-24CyberSheathcybersheath.comHTTP 200Official website loaded successfully
2026-09-24SecureStruxsecurestrux.comHTTP 200Official website loaded successfully
2026-09-24Redspinredspin.comHTTP 200Official website loaded successfully
2026-09-24Sera-Brynnsera-brynn.comHTTP 200Official website loaded successfully
2026-09-24Coalfirecoalfire.comHTTP 200Official website loaded successfully
2026-09-24Schellmanschellman.comHTTP 200Official website loaded successfully
2026-09-24A-LIGNa-lign.comHTTP 200Official website loaded successfully
2026-09-24GuidePoint Securityguidepointsecurity.comHTTP 200Official website loaded successfully
2026-09-24Optivoptiv.comHTTP 200Official website loaded successfully
2026-09-24Peak InfoSecpeakinfosec.comHTTP 200Official website loaded successfully
2026-09-24CyberSecOpcybersecop.comHTTP 200Official website loaded successfully
2026-09-24StackArmorstackarmor.comHTTP 200Official website loaded successfully
2026-09-24Pivot Point Securitypivotpointsecurity.comHTTP 200Official website loaded successfully
2026-09-24NIST — the publications themselves (nist.gov)source linkCSF 2.0, SP 800-53, and SP 800-171 are free downloads. There is no NIST certification and
2026-09-24NIST SP 800-171 Rev. 3 (2024)source linkThe current revision of the CUI-protection requirements for nonfederal systems — 110 requi
2026-09-24FedRAMP — about the authorization process (fedramp.gov)source linkFedRAMP authorization requires a 3PAO assessment against the 800-53-based baseline plus PM
2026-09-24Directory estimates (September 2026)source linkAdvisory and assessment engagement bands synthesized from published consulting-rate data a
This methodology describes an independent directory's research process, not a security standard. It doesn't replace your own diligence: verify credentials, meet the engagement team, and read the engagement letter before you sign anything.

Browse the directory

14 verified firms, grouped by buyer type, with every price labeled by source.

Get a free quote