Our methodology
Exactly how we choose firms, what we verify, how we label prices — and what we refuse to do.
Which firms get listed
A firm appears in our directory only if, as of our last check, it meets all three: (1) it is a real, operating cybersecurity practice; (2) its official website returns HTTP 200; (3) it does genuine work against at least one NIST publication (CSF 2.0, SP 800-53, or SP 800-171) — assessor roles (3PAO, C3PAO) are described only as the firms themselves claim them.
What we verify — and what we don't claim
For each firm we record headquarters, firm type, and the frameworks its own public materials say it supports. Directory facts were last verified in September 2026; we aim to re-check quarterly.
How we label every price
Consulting fees are scoped per engagement, so most firms publish no prices at all. Where we show a planning range, it always carries one of three labels:
| Label | Meaning |
|---|---|
| Firm-published | The firm publishes the figure itself. |
| Published planning range | A third-party published planning range (September 2026). Useful for budgeting; not a quote. |
| Directory estimate | Our estimate synthesized from published rate data (September 2026), clearly labeled. Not a quote. |
| Not published | The firm publishes no band. Request a scoped quote — that's what our quote form is for. |
None of these are quotes. Your fee depends on scope, sector, and starting posture. Treat every band as a planning figure and get scope and fee in writing.
What we will never do
- No star ratings or review scores. We have not hired these firms' clients and won't compress fit into a number.
- No testimonials. Every quote-like line on this site would be fabricated — so there are none.
- No pay-for-rank. Ever. Firms cannot pay to be listed, ranked higher, recommended, or have a profile softened.
- No invented statistics. Every number on this site has a clickable source or a visible estimate label.
How we make money
When you request quotes, matched firms may pay us a lead or referral fee. That payment cannot change which firms we list, what our guides say, or which firms we recommend — the firewall is absolute.
Corrections
Wrong price, stale fact, firm missing? Tell us. We check corrections against the firm's own public materials.
Verification log
Row-level log of every firm website and price source check. Append-only: new entries go on top.
| Date checked | Firm / source | URL | HTTP status | Result |
|---|---|---|---|---|
| 2026-09-24 | Summit 7 | summit7.us | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | CyberSheath | cybersheath.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | SecureStrux | securestrux.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Redspin | redspin.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Sera-Brynn | sera-brynn.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Coalfire | coalfire.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Schellman | schellman.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | A-LIGN | a-lign.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | GuidePoint Security | guidepointsecurity.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Optiv | optiv.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Peak InfoSec | peakinfosec.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | CyberSecOp | cybersecop.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | StackArmor | stackarmor.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Pivot Point Security | pivotpointsecurity.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | NIST — the publications themselves (nist.gov) | source link | — | CSF 2.0, SP 800-53, and SP 800-171 are free downloads. There is no NIST certification and |
| 2026-09-24 | NIST SP 800-171 Rev. 3 (2024) | source link | — | The current revision of the CUI-protection requirements for nonfederal systems — 110 requi |
| 2026-09-24 | FedRAMP — about the authorization process (fedramp.gov) | source link | — | FedRAMP authorization requires a 3PAO assessment against the 800-53-based baseline plus PM |
| 2026-09-24 | Directory estimates (September 2026) | source link | — | Advisory and assessment engagement bands synthesized from published consulting-rate data a |
Browse the directory
14 verified firms, grouped by buyer type, with every price labeled by source.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.