Cybersecurity Companies

Categories · Certification

SOC 2

Companies that list a SOC 2 report (Type I or Type II). As listed — we do not audit the report.

39 companies. Search a country or city. Tick features, then apply once. Organic order is not for sale.

Indexorganic · newest first · page 2/2
CompanyWhat they sellFocus / ratingStatus

Wiz

New York, US · Product vendor

Cloud security graph for code-to-cloud risk.

Cloud security · Application security
Promoted

Censys

Ann Arbor, US · Research / intel

Internet-wide attack surface and exposure intelligence.

Attack surface · Threat & vulnerability

Aqua Security

Boston, US · Product vendor

Cloud-native application protection from code to runtime.

Cloud security · Application security

Cloudflare

San Francisco, US · Product vendor

CDN, WAF, Zero Trust, and bot management on a global edge.

Network security · Application security

Microsoft Security

Redmond, US · Product vendor

Defender, Entra, Sentinel, and Purview across the Microsoft estate.

Endpoint security · Identity

Qualys

Foster City, US · Product vendor

VMDR, cloud posture, and compliance scanning as a service.

Threat & vulnerability · Cloud security

Splunk

San Francisco, US · Product vendor

SIEM, observability, and security analytics now under Cisco.

Security operations

Mimecast

London, GB · Product vendor

Email security, continuity, and human-risk training.

Email & messaging · Human risk

Orca Security

Portland, US · Product vendor

Agentless CNAPP for AWS, Azure, and GCP.

Cloud security · Threat & vulnerability
5.0(1)
Promoted

SailPoint

Austin, US · Product vendor

Identity governance and administration for large directories.

Identity · GRC

BeyondTrust

Johns Creek, US · Product vendor

Privileged access, remote support, and endpoint privilege.

Identity

Sophos

Oxford, GB · Product vendor

Endpoint, firewall, and managed detection for mid-market.

Endpoint security · Network security

Rubrik

Palo Alto, US · Product vendor

Cyber-recovery, backup, and data security posture.

Data protection · Security operations

HashiCorp

San Francisco, US · Product vendor

Vault secrets, Terraform, and identity-based security for infrastructure.

Identity · Cloud security

CrowdStrike

Austin, US · Product vendor

Cloud-native endpoint detection, identity, and threat intel.

Endpoint security · Security operations
4.0(1)
Verified
PreviousPage 2 of 2
FAQ
What does SOC 2 mean on this index?

Companies that list SOC 2. Company attestations (ISO 27001, SOC 2) are held by the firm. Practitioner credentials (OSCP, GPEN) are held by people on staff. We do not audit certificates or invigilate exams.

Is the order paid?

No. Organic order is recency. Promoted shelves are labeled and separate. That is the opposite of buying a rank.

How do I get listed under SOC 2?

Submit a company and tick the certifications you actually hold. We review before anything is public. Paid plans buy a labeled shelf, not a silent bump in this list.

Why is a staff exam on a company directory?

Buyers shortlist pentest and training firms by who sits on the engagement. OSCP and GPEN are company filters here, not a people directory.