cybersecuritycompanies.

Categories · Certification

SOC 2

Companies that list a SOC 2 report (Type I or Type II). As listed — we do not audit the report.

39 companies. Refine by location, capabilities, or team size to find the right fit.

Refine your search

Features

Cloud security

Application security

Endpoint security

Identity

Security operations

Email & messaging

Network security

Data protection

Attack surface

Threat & vulnerability

AI security

Cyber-physical

Human risk

GRC

Team size

Vendor type

Company attestations

Practitioner credentials

39 companiesRecently added · page 2/2
PreviousPage 2 of 2
FAQ
What does SOC 2 mean on this index?

Companies that list SOC 2. Company attestations (ISO 27001, SOC 2) are held by the firm. Practitioner credentials (OSCP, GPEN) are held by people on staff. We do not audit certificates or invigilate exams.

Is the order paid?

No. Organic order is recency. Promoted shelves are labeled and separate. That is the opposite of buying a rank.

How do I get listed under SOC 2?

Submit a company and tick the certifications you actually hold. We review before anything is public. Paid plans buy a labeled shelf, not a silent bump in this list.

Why is a staff exam on a company directory?

Buyers shortlist pentest and training firms by who sits on the engagement. OSCP and GPEN are company filters here, not a people directory.