Our methodology
Exactly how we choose firms, what we verify, how we label prices — and what we refuse to do.
Which firms get listed
A firm appears in our directory only if, as of our last check, it meets all three: it operates an active public website offering cybersecurity consulting or assessment services relevant to CISA guidance — verified by a human visit, not a database scrape; it describes real federal, critical-infrastructure, or framework-implementation practices (not just a keyword on a services list); and its service offering is current.
What we verify — and what we don't claim
For each firm we record headquarters, firm type, and the frameworks its own public materials say it supports. Directory facts were last verified in September 2026; we aim to re-check quarterly.
How we label every price
Consulting fees are scoped per engagement, so most firms publish no prices at all. Where we show a planning range, it always carries one of three labels:
| Label | Meaning |
|---|---|
| Firm-published | The firm publishes the figure itself. |
| Published planning range | A third-party published planning range (September 2026). Useful for budgeting; not a quote. |
| Directory estimate | Our estimate synthesized from published rate data (September 2026), clearly labeled. Not a quote. |
| Not published | The firm publishes no band. Request a scoped quote — that's what our quote form is for. |
None of these are quotes. Your fee depends on scope, sector, and starting posture. Treat every band as a planning figure and get scope and fee in writing.
What we will never do
- No star ratings or review scores. We have not hired these firms' clients and won't compress fit into a number.
- No testimonials. Every quote-like line on this site would be fabricated — so there are none.
- No pay-for-rank. Ever. Firms cannot pay to be listed, ranked higher, recommended, or have a profile softened.
- No invented statistics. Every number on this site has a clickable source or a visible estimate label.
How we make money
When you request quotes, matched firms may pay us a lead or referral fee. That payment cannot change which firms we list, what our guides say, or which firms we recommend — the firewall is absolute.
Corrections
Wrong price, stale fact, firm missing? Tell us. We check corrections against the firm's own public materials.
Verification log
Row-level log of every firm website and price source check. Append-only: new entries go on top.
| Date checked | Firm / source | URL | HTTP status | Result |
|---|---|---|---|---|
| 2026-09-24 | GuidePoint Security | guidepointsecurity.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Coalfire | coalfire.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | SecureStrux | securestrux.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Summit 7 | summit7.us | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | ECS | ecstech.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Guidehouse | guidehouse.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Booz Allen Hamilton | boozallen.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Optiv | optiv.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Kroll | kroll.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Schellman | schellman.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | A-LIGN | a-lign.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Presidio | presidio.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Redspin | redspin.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Sera-Brynn | sera-brynn.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | CACI | caci.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | Parsons | parsons.com | HTTP 200 | Official website loaded successfully |
| 2026-09-24 | CISA — Cybersecurity Performance Goals (cisa.gov, updated 2025) | source link | — | CISA's own baseline: the CPGs are voluntary goals for critical infrastructure — no fee, no |
| 2026-09-24 | CISA — Binding Operational Directives (cisa.gov) | source link | — | BODs are mandatory for federal agencies (e.g. KEV remediation, asset management) — complia |
| 2026-09-24 | CISA — Free Cyber Hygiene services (cisa.gov) | source link | — | CISA offers free vulnerability scanning and assessments to federal, SLTT, and critical-inf |
| 2026-09-24 | Directory estimates (September 2026) | source link | — | Advisory engagement bands synthesized from published consulting-rate data and firm plannin |
Browse the directory
16 verified firms, grouped by buyer type, with every price labeled by source.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.