Cybersecurity Companies

Categories · Certification

FedRAMP

Companies that list a FedRAMP authorization. As listed — we do not audit the package.

13 companies. Search a country or city. Tick features, then apply once. Organic order is not for sale.

Indexorganic · newest first
CompanyWhat they sellFocus / ratingStatus

Proofpoint

Sunnyvale, US · Product vendor

Email security, threat protection, and human-risk controls.

Email & messaging · Human risk

Palo Alto Networks

Santa Clara, US · Product vendor

Network, cloud, and SOC platform spanning firewalls to Prisma Cloud.

Network security · Cloud security

Zscaler

San Jose, US · Product vendor

Cloud-delivered ZTNA, SWG, and SSE for the internet-first workplace.

Network security · Identity

Okta

San Francisco, US · Product vendor

Workforce and customer identity for SSO, MFA, and lifecycle.

Identity
Verified

Tenable

Columbia, US · Product vendor

Exposure management and vulnerability scanning across IT, cloud, and OT.

Threat & vulnerability · Cyber-physical

Rapid7

Boston, US · Product vendor

SIEM, vulnerability management, and detection from InsightVM and InsightIDR.

Security operations · Threat & vulnerability

Netskope

Santa Clara, US · Product vendor

SSE, CASB, and data protection delivered from a security cloud.

Network security · Data protection

Cloudflare

San Francisco, US · Product vendor

CDN, WAF, Zero Trust, and bot management on a global edge.

Network security · Application security

Microsoft Security

Redmond, US · Product vendor

Defender, Entra, Sentinel, and Purview across the Microsoft estate.

Endpoint security · Identity

Cisco Security

San Jose, US · Product vendor

Network, email, and SASE security from the campus to the cloud.

Network security · Email & messaging

Qualys

Foster City, US · Product vendor

VMDR, cloud posture, and compliance scanning as a service.

Threat & vulnerability · Cloud security

Splunk

San Francisco, US · Product vendor

SIEM, observability, and security analytics now under Cisco.

Security operations

CrowdStrike

Austin, US · Product vendor

Cloud-native endpoint detection, identity, and threat intel.

Endpoint security · Security operations
4.0(1)
Verified
FAQ
What does FedRAMP mean on this index?

Companies that list FedRAMP. Company attestations (ISO 27001, SOC 2) are held by the firm. Practitioner credentials (OSCP, GPEN) are held by people on staff. We do not audit certificates or invigilate exams.

Is the order paid?

No. Organic order is recency. Promoted shelves are labeled and separate. That is the opposite of buying a rank.

How do I get listed under FedRAMP?

Submit a company and tick the certifications you actually hold. We review before anything is public. Paid plans buy a labeled shelf, not a silent bump in this list.

Why is a staff exam on a company directory?

Buyers shortlist pentest and training firms by who sits on the engagement. OSCP and GPEN are company filters here, not a people directory.