GetPentest

Compliance advisory firms in Canada

Firms in the GetPentest directory that do compliance advisory work, ordered by tier and then alphabetically.

49 firms.

Compliance advisory firms in Canada

TrazTech Inc. VerifiedOperates this site

The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Canadian privacy, Trust center, Cloud compliance, AI-built app QA, AI security, Security questionnaires, Auditor management, Internal audit, Threat and risk assessment, Tabletop and continuity testing, Cyber insurance readiness, Technical due diligence, Outsourced privacy officer

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF, PIPEDA, PHIPA

3Tenets Consulting Unclaimed

Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.

Ontario · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, AI security

Frameworks: SOC 2, NIST CSF, PHIPA

BALANCED+ Unclaimed

IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.

Mississauga, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy, Cloud compliance

Frameworks: SOC 2, ISO 27001, PIPEDA, PHIPA

BreachLock Unclaimed

Pentest as a service provider covering web mobile API network and cloud testing plus red team services with compliance ready reports.

New York, New York, United States · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

Bulletproof Solutions Unclaimed

Canadian managed security provider whose security testing and audit practice includes penetration testing alongside managed detection and compliance services.

New Brunswick · Penetration testing, Compliance advisory

Frameworks: SOC 2

Certi360 Unclaimed

Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.

Laval, Quebec · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Clavea Security Unclaimed

Montreal area cybersecurity firm serving small and mid-sized businesses with offensive security testing managed monitoring ISO 27001 work and Quebec Law 25 compliance.

Laval, Quebec · ISO 27001, Penetration testing, Compliance advisory

Frameworks: ISO 27001

Coalfire Unclaimed

Cybersecurity advisory and assessment firm combining offensive testing with audit services across a large number of compliance frameworks.

ISO 42001, Penetration testing, Compliance advisory

Frameworks: ISO 42001

Cognisys Unclaimed

UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.

United Kingdom · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Compass IT Compliance Unclaimed

Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.

SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, HIPAA, PCI DSS, NIST CSF

Cyber Security Pentesting Inc. Unclaimed

Toronto offensive security firm running red team operations Active Directory attacks cloud and web application testing with compliance aligned reporting.

Toronto, Ontario · Penetration testing, Compliance advisory, AI security

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, PIPEDA

CyberSpective Unclaimed

Montreal cybersecurity consultancy providing penetration testing and compliance advisory work for organisations in Ontario Quebec Alberta and British Columbia.

Montreal, Quebec · Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA

Digital Fort Unclaimed

Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.

Winnipeg, Manitoba · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Elastify Unclaimed

Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

GuardsArm Unclaimed

Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.

Edmonton, Alberta · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

GuidePoint Security Unclaimed

Security consultancy offering penetration testing along with governance risk and compliance services for regulated organisations.

Reston, Virginia, United States · Penetration testing, Compliance advisory

Frameworks: HIPAA, PCI DSS

IRM Consulting & Advisory Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

IS Partners Unclaimed

Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.

Dresher, Pennsylvania, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

KirkpatrickPrice Unclaimed

A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.

Nashville, Tennessee, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

Kobalt.io Unclaimed

Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

LevelBlue Unclaimed

Managed security provider whose CREST certified testing practice covers network application operational technology physical and social engineering penetration testing.

Penetration testing, Compliance advisory

Frameworks: NIST CSF

Linford & Company Unclaimed

A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.

Denver, Colorado, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

Malleum Unclaimed

Ottawa security consultancy offering enterprise penetration testing alongside compliance advisory work for regulated and government adjacent clients.

Ottawa, Ontario · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

Mirai Security Unclaimed

Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001

Neotrust Unclaimed

French firm with a Montreal office listing CISO as a service within its security transformation practice, alongside testing and compliance work.

Puteaux, France · Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 27001, NIST CSF

OmniCyber Security Unclaimed

Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.

Vancouver, British Columbia · ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 27001, ISO 42001, PCI DSS, PIPEDA

Oread Risk & Advisory Unclaimed

Attestation, information security and compliance consulting firm that conducts SOC reporting engagements and IT security reviews; the site names a CPA principal but does not state firm-level CPA licensure for signing SOC 2 opinions.

Kansas, United States · SOC 2 readiness, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Parabellyx Cybersecurity Unclaimed

Ontario firm delivering penetration testing as a service across applications infrastructure AI and operational technology plus compliance advisory work.

Richmond Hill, Ontario · Penetration testing, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001

PlutoSec Unclaimed

Canadian cybersecurity company selling manual penetration testing across web APIs networks cloud mobile and Active Directory plus red team and wireless testing.

Etobicoke, Ontario · Penetration testing, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, PHIPA

Raxis Unclaimed

Manual penetration testing firm covering web APIs cloud internal and external networks mobile IoT operational technology and physical security.

Atlanta, Georgia, United States · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

risk3sixty Unclaimed

GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.

Roswell, Georgia, United States · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, NIST CSF

SAV Associates Unclaimed

CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA

Schellman Unclaimed

Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Secure Ideas Unclaimed

CREST member consultancy offering penetration testing and PCI qualified security assessor services plus security training.

Jacksonville, Florida, United States · Penetration testing, Compliance advisory

Frameworks: PCI DSS

Sherlock Forensics Unclaimed

British Columbia boutique offering penetration testing adversary simulation and digital forensics for small businesses startups SaaS companies and law firms with published pricing.

Burnaby, British Columbia · Penetration testing, Compliance advisory, AI-built app QA, AI security

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF

Sikich Unclaimed

Sikich CPA LLC is a licensed CPA firm providing audit and attest services, and the cybersecurity practice performs service provider reviews covering SOC 1, SOC 2 and SOC 3 plus PCI DSS, HIPAA and penetration testing.

2500 · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA, PCI DSS

Software Secured Unclaimed

Canadian penetration testing firm working mainly with SaaS companies on web API mobile infrastructure cloud and AI testing with compliance ready reporting.

Ottawa, Ontario · Penetration testing, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Sprocket Security Unclaimed

Continuous penetration testing provider covering external internal web application and social engineering testing.

Madison, Wisconsin, United States · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

StreamScan Unclaimed

Montreal cybersecurity company selling penetration testing and managed detection with compliance work aligned to NIST 800-171 and Canadian certification programs.

Montreal, Quebec · Penetration testing, Compliance advisory

Frameworks: NIST CSF

Systemes Securitech Systems inc. Unclaimed

Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.

Montreal, Quebec · ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

Tevora Unclaimed

Firm listing vCISO under resource augmentation, providing executive-level CISO assistance alongside compliance and testing work.

Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 42001, HIPAA, PCI DSS

ThreeShield Information Security Unclaimed

Calgary firm providing penetration testing alongside compliance advisory work mapped to several security and privacy frameworks for Canadian organisations.

Calgary, Alberta · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, PIPEDA

Triaxiom Security Unclaimed

Penetration testing firm offering external internal web application API mobile physical and wireless tests for compliance driven clients.

Penetration testing, Compliance advisory

Frameworks: PCI DSS, NIST CSF

TrustedSec Unclaimed

CREST certified consultancy offering penetration testing red teaming and security program work including CMMC readiness.

Fairlawn, Ohio, United States · Penetration testing, Compliance advisory

Frameworks: NIST CSF

Truvo Cyber Unclaimed

Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

Uzado Inc. Unclaimed

Ontario provider offering a fractional vCISO covering security strategy, board reporting and audit ownership, alongside compliance and testing work.

Richmond Hill, Ontario · Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF

Vumetric Cybersecurity Unclaimed

Canadian penetration testing provider covering network application hardware and cloud testing with reporting aimed at PCI DSS SOC 2 and ISO 27001 requirements.

Toronto, Ontario · Penetration testing, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, PCI DSS

Workstreet Unclaimed

Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.

100+ · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Trust center, Cloud compliance, Security questionnaires

Frameworks: SOC 2, ISO 27001

Zero Day CPA Unclaimed

A CPA-led audit practice that performs SOC 1, SOC 2 Type I and Type II and SOC 3 examinations and signs the report, and also offers penetration testing and HIPAA work.

West Bloomfield, Michigan, United States · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA

Get quotes instead of browsing

Describe what you need once and it reaches the firms on this page that match it.

Get quotes

Back to the full directory

Other ways to narrow the list

Same directory, cut a different way.

How do I know I can trust one of these firms?

Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.

How were these firms chosen?

They were listed from public information or added by the firm itself. Being listed is not a recommendation, and GetPentest does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

How many firms should I approach?

Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.