How this site works

Our methodology

Exactly how we choose firms, what we verify, how we label prices — and what we refuse to do.

Which firms get listed

A firm appears in our directory only if, as of our last check, it meets all three: it operates an active public website offering cybersecurity consulting or assessment services relevant to CISA guidance — verified by a human visit, not a database scrape; it describes real federal, critical-infrastructure, or framework-implementation practices (not just a keyword on a services list); and its service offering is current.

What we verify — and what we don't claim

For each firm we record headquarters, firm type, and the frameworks its own public materials say it supports. Directory facts were last verified in September 2026; we aim to re-check quarterly.

What we don't verify. We do not verify security clearances, FedRAMP 3PAO authorization status, or CMMC C3PAO authorization for each firm, and we won't pretend we did. Check 3PAO and C3PAO status yourself on the FedRAMP Marketplace and the CMMC-AB marketplace before signing.

How we label every price

Consulting fees are scoped per engagement, so most firms publish no prices at all. Where we show a planning range, it always carries one of three labels:

LabelMeaning
Firm-publishedThe firm publishes the figure itself.
Published planning rangeA third-party published planning range (September 2026). Useful for budgeting; not a quote.
Directory estimateOur estimate synthesized from published rate data (September 2026), clearly labeled. Not a quote.
Not publishedThe firm publishes no band. Request a scoped quote — that's what our quote form is for.

None of these are quotes. Your fee depends on scope, sector, and starting posture. Treat every band as a planning figure and get scope and fee in writing.

What we will never do

How we make money

When you request quotes, matched firms may pay us a lead or referral fee. That payment cannot change which firms we list, what our guides say, or which firms we recommend — the firewall is absolute.

Corrections

Wrong price, stale fact, firm missing? Tell us. We check corrections against the firm's own public materials.

Verification log

Row-level log of every firm website and price source check. Append-only: new entries go on top.

Date checkedFirm / sourceURLHTTP statusResult
2026-09-24GuidePoint Securityguidepointsecurity.comHTTP 200Official website loaded successfully
2026-09-24Coalfirecoalfire.comHTTP 200Official website loaded successfully
2026-09-24SecureStruxsecurestrux.comHTTP 200Official website loaded successfully
2026-09-24Summit 7summit7.usHTTP 200Official website loaded successfully
2026-09-24ECSecstech.comHTTP 200Official website loaded successfully
2026-09-24Guidehouseguidehouse.comHTTP 200Official website loaded successfully
2026-09-24Booz Allen Hamiltonboozallen.comHTTP 200Official website loaded successfully
2026-09-24Optivoptiv.comHTTP 200Official website loaded successfully
2026-09-24Krollkroll.comHTTP 200Official website loaded successfully
2026-09-24Schellmanschellman.comHTTP 200Official website loaded successfully
2026-09-24A-LIGNa-lign.comHTTP 200Official website loaded successfully
2026-09-24Presidiopresidio.comHTTP 200Official website loaded successfully
2026-09-24Redspinredspin.comHTTP 200Official website loaded successfully
2026-09-24Sera-Brynnsera-brynn.comHTTP 200Official website loaded successfully
2026-09-24CACIcaci.comHTTP 200Official website loaded successfully
2026-09-24Parsonsparsons.comHTTP 200Official website loaded successfully
2026-09-24CISA — Cybersecurity Performance Goals (cisa.gov, updated 2025)source linkCISA's own baseline: the CPGs are voluntary goals for critical infrastructure — no fee, no
2026-09-24CISA — Binding Operational Directives (cisa.gov)source linkBODs are mandatory for federal agencies (e.g. KEV remediation, asset management) — complia
2026-09-24CISA — Free Cyber Hygiene services (cisa.gov)source linkCISA offers free vulnerability scanning and assessments to federal, SLTT, and critical-inf
2026-09-24Directory estimates (September 2026)source linkAdvisory engagement bands synthesized from published consulting-rate data and firm plannin
This methodology describes an independent directory's research process, not a security standard. It doesn't replace your own diligence: verify credentials, meet the engagement team, and read the engagement letter before you sign anything.

Browse the directory

16 verified firms, grouped by buyer type, with every price labeled by source.

Get a free quote