Home / Certifications / NIST CSF

Find a pentest company with NIST CSF

39 companies have this certification

Origin of the NIST Cybersecurity Framework


The NIST Cybersecurity Framework (CSF) was developed by the National Institute of Standards and Technology, a non-regulatory agency within the U.S. Department of Commerce. It was created in response to Executive Order 13636, signed by President Obama in February 2013, which directed NIST to develop a voluntary framework to help organizations manage cybersecurity risks. The framework was first released in February 2014 after extensive collaboration between government and private sector stakeholders across critical infrastructure sectors. Version 1.1 was released in April 2018, and the most recent version 2.0 was published in February 2024.


Industry Value and Importance


The NIST CSF is highly valued because it provides a flexible, risk-based approach to cybersecurity that organizations of any size or sector can adapt to their needs. Unlike prescriptive standards, it offers a common language for understanding and managing cybersecurity risks across organizational levels, from executives to technical staff. The framework is widely adopted both domestically and internationally because it's technology-neutral, cost-effective to implement, and aligns well with other security standards and regulations. Many organizations use it to assess their cybersecurity posture, communicate about security initiatives, and demonstrate due diligence to stakeholders, partners, and regulators.

RAVUS LLC

RAVUS LLC

Penetration Testing and Vulner...
montgomery, United States 3 employees

Cybersecurity company specializing in penetration testing and vulnerability scanning; veteran-owned small business founded in 2021 with 4 employees; based in Montgomery, Alabama, United States; focuses on safeguarding systems, data, and operations with a mission-driven approach.

Provides Penetration Testing
Vulnerability Assessment
Cybersecurity Consulting Services To Help Organizations Safeguard Their Systems
+2 more
Bishop Fox

Bishop Fox

Comprehensive Penetration Test...
Tempe, United States 389 employees

Bishop Fox is a private cybersecurity firm specializing in offensive security, including continuous penetration testing, red teaming, and attack surface management; 235 employees, founded in 2005, headquartered in Tempe, Arizona; $75M annual revenue, $197.1M total funding, Series B in 2022-11-15; recognized leader in pentesting and security assessments.

Offensive Security Services Including Penetration Testing
Red Teaming
Attack Surface Management
+5 more
Truvantis, Inc.

Truvantis, Inc.

Customized Penetration Testing
San Francisco, United States 13 employees

Cybersecurity consulting firm specializing in security and privacy testing, program implementation, compliance assessments, and outsourcing; provides penetration testing services including network and small-business pentests with an offensive security focus; based in San Francisco, California, with 8 employees and $2.2M annual revenue.

Truvantis
Inc. Offers Comprehensive Security
Privacy
+5 more
eSecurity Solutions

eSecurity Solutions

Network, Application, and Soci...
California 8 employees

Cybersecurity service provider based in Irvine, California; offers GRC, managed security, cyber insurance, and penetration testing services including red team and continuous testing.

The Company Offers Cybersecurity Services Including Governance
Risk
Compliance (grc)
+5 more
Symosis Security

Symosis Security

Cloud and SaaS
San Francsico, United States 5 employees

Symosis Security LLC. is a California-based private cybersecurity company founded in 2004, with 5 employees and $2.3M annual revenue; specializes in penetration testing, vulnerability assessments, security architecture, threat modeling, cloud security, and red teaming, serving clients with comprehensive security services and active in risk & compliance markets.

The Company Offers CISO Advisory And Governance
Penetration Testing And Red Teaming
AI And LLM Risk Assessments
+5 more
One82, LLC.

One82, LLC.

Network
California 6 employees

California-based IT support and cybersecurity firm specializing in penetration testing and vulnerability assessments; headquartered in Los Gatos, CA, with active security testing services.

The Company Offers Outsourced IT Support
Cybersecurity Services
Compliance Services
+5 more
Charles IT

Charles IT

Network and Infrastructure Pen...
Connecticut 85 employees

Connecticut-based IT services provider specializing in cybersecurity solutions such as penetration testing; operates from Middletown, CT, with additional offices in Stamford; offers managed security services and emphasizes security assessments through dedicated pen testing offerings.

Penetration Testing Management
IT Compliance
IT Security
+5 more
Ad

Stop wasting time on security questionnaires

ResponseHub uses AI to automate your security questionnaire responses. 100% confidence, save days, unblock deals.

Learn more
Catalisto

Catalisto

External and Internal Penetrat...
Fort Lauderdale, United States 11 employees

Cybersecurity and IT services company specializing in penetration testing; provides external and internal pentest services to critical infrastructure and corporate clients; 9 employees; Founded 2018; Fort Lauderdale, FL.

Penetration Testing
Continuous Monitoring
Compliance Readiness
+5 more
I.t. Consulting St Petersburg LLC

I.t. Consulting St Petersburg LLC

External Penetration Testing
Florida 5 employees

Cybersecurity firm based in St. Petersburg, Florida; provides penetration testing services including external penetration testing and security assessments; founded in the United States with a focus on SMB cybersecurity needs.

Penetration Testing
Cybersecurity Assessments
Vciso Consulting
+5 more
UncommonX

UncommonX

Web Application Pentesting
Illinois 3 employees

Cybersecurity company headquartered in Chicago, Illinois; specializes in advanced security solutions including penetration testing, vulnerability assessments, and web application security; has achieved zero reportable breaches and offers 24/7 SOC monitoring.

Penetration Testing
Vulnerability Assessment
Web Application Security
+5 more
Pondurance

Pondurance

Application Security and Red T...
Indianapolis, United States 117 employees

Cybersecurity company specializing in Managed Detection and Response (MDR) services; offers penetration testing, application security testing, and red-team exercises; 84 employees, $8M revenue, founded 2008 in Indianapolis, Indiana; ranked #5,711,096 globally and #1,712,205 in the US.

Managed Detection And Response (mdr)
Incident Response
Vulnerability Management
+5 more
Pendragon Security

Pendragon Security

Comprehensive Cybersecurity Pe...
Sulphur, United States 3 employees

Cybersecurity company specializing in penetration testing, risk management, and physical security; 2 employees with +200% YoY growth; founded 2019; headquartered in Sulphur, Louisiana, USA. Offers integrated vCISO services combining cyber, physical, and personal security expertise.

Vciso Services
Penetration Testing
Vulnerability Assessments
+5 more
Tiro Security

Tiro Security

Tiro Security specializes in c...
Henderson, United States 8 employees

Cybersecurity staffing and consulting company specializing in security assessment and penetration testing; 4 employees with 14.3% growth, $3.7M revenue; based in Henderson, Nevada, founded 2012.

Cybersecurity Consulting
Infosec Staffing
GRC Recruitment
+5 more
HIFENCE

HIFENCE

Comprehensive Penetration Test...
New York 2 employees

Cybersecurity firm based in New York, NY; specializes in penetration testing services including network, server, application, and API testing, with a focus on simulating real-world attacks to identify vulnerabilities.

Penetration Testing
Managed IT Services
Managed Detection And Response
+5 more
Ad

Advertise on pentest.fyi

You could be here!

Learn more
Blair Carlisle

Blair Carlisle

Offensive Security & Penetrati...
Ohio 7 employees

Cybersecurity consulting firm specializing in technology risk, compliance, and cybersecurity advisory; headquartered in Columbus, Ohio, with a focus on penetration testing services to evaluate and improve security defenses.

Risk Assessments
Fractional CISO Services
SOC 2 And ISO27001 Readiness & Audits
+3 more
Breach Craft

Breach Craft

Web Application Testing
Havertown, United States 3 employees

Cybersecurity consulting firm specializing in penetration testing, vulnerability assessments, and virtual CISO services; 3 employees with +200% YoY growth; based in Havertown, Pennsylvania, USA; founded by seasoned cybersecurity practitioners, focusing on deep industry knowledge and innovative security solutions.

Penetration Testing
Vulnerability Assessments
Gap Assessments
+3 more
Seiso

Seiso

Human-Led Penetration Testing
Pennsylvania 40 employees

Cybersecurity company based in Gibsonia, Pennsylvania; offers penetration testing services including enterprise and targeted assessments; founded in Pennsylvania, with a focus on GRC, cloud, CMMC, and vCISO solutions.

Penetration Testing
Governance Risk And Compliance (grc)
Cloud Security
+5 more
ZAVIANT

ZAVIANT

External and Internal Network ...
Philadelphia, United States 19 employees

ZAVIANT is a private IT services and consulting company specializing in data privacy, security, and risk management; with 13 employees, headquartered in Philadelphia, Pennsylvania, and offering penetration testing services as part of their cybersecurity offerings. The firm actively engages in privacy and security consulting, with recent growth and regional recognition.

Data Privacy
Third Party Risk Management
Compliance
+4 more
The Oxman Group LLC

The Oxman Group LLC

Web Application Penetration Te...
Fort Worth, United States 10 employees

Computer and Network Security company based in Fort Worth, Texas; provides penetration testing, risk assessments, and executive security services; $1.7M annual revenue, founded 2013, 1-10 employees, -100% YoY growth, specializing in cybersecurity consulting and testing.

Chief Security Officer (cso) As A Service
Chief Information Security Officer (ciso) As A Service
Chief Technology Officer (cto) As A Service
+3 more
Tekzys

Tekzys

Network Penetration Testing
Texas 3 employees

Cybersecurity and managed IT services provider headquartered in Dallas, Texas; offers penetration testing services to identify and mitigate vulnerabilities, supporting nationwide security needs.

Managed IT Services
IT Consulting
Voip Solutions
+4 more
ISSE Services

ISSE Services

Information Systems Penetratio...
Clearfield, United States 35 employees

Defense and space manufacturing company specializing in cybersecurity engineering, monitoring, and compliance; 27 employees (+12.9% YoY growth), founded 2006, headquartered in Clearfield, Utah, United States. Provides penetration testing services to government and commercial clients, with a woman-owned small business status.

Managed Security Services
CMMC Readiness
Penetration Testing
+4 more
Data Pulse Tech

Data Pulse Tech

Network and Application Penetr...
Virginia 2 employees

Cybersecurity firm based in Ashburn, Virginia, specializing in penetration testing and vulnerability research; offers comprehensive security assessments for networks, applications, and systems.

Software Development
System Administration
Vulnerability Research
+4 more
Assured Enterprises, Inc.

Assured Enterprises, Inc.

Network Penetration Testing
Virginia 11 employees

Cybersecurity company based in Vienna, Virginia, specializing in penetration testing services; explicitly lists troubleshooting and pentest operations on its site, confirming active pentest capabilities.

Penetration Testing
Hands-on Project Management
Monitored Cybersecurity Services
+5 more
Benijah Consulting

Benijah Consulting

Internal and External Penetrat...
Belgium 6 employees

Cybersecurity consulting firm headquartered in Brussels, Belgium; specializes in penetration testing services, explicitly offering 'Penetration tests' as part of cybersecurity audits and pentest solutions.

Cybersecurity Solutions Integration
Operational Technology Cybersecurity
Cybersecurity Audits And Pentests
+2 more
ThreatScene

ThreatScene

Comprehensive Penetration Test...
athens, Greece 20 employees

ThreatScene is a private IT Services and IT Consulting firm specializing in cybersecurity solutions, including penetration testing, incident response, threat intelligence, and digital forensics. Founded in 2024 and headquartered in Athens, Greece, it has 15 employees and experienced 100% YoY growth. The company provides top-tier cybersecurity services to public bodies, B2B enterprises, defense, maritime, and critical infrastructure sectors, focusing on protecting organizations from evolving cyber threats.

Penetration Testing
Red Teaming
Vulnerability Assessment
+5 more
AMARU

AMARU

Managed Cybersecurity and Pene...
Auckland, New Zealand 9 employees

IT services and consulting company specializing in cybersecurity; 6 employees with 80% YoY growth; based in Auckland, New Zealand; founded 2019; offers CREST-certified penetration testing, risk assessments, security compliance, and incident response services, serving New Zealand clients.

Penetration Testing
Security Compliance
Security Risk Assessments
+3 more
Cypherleap

Cypherleap

Infrastructure, Web, API, and ...
Australia 8 employees

Australian cybersecurity consultancy based in Pyrmont, NSW; specializes in penetration testing services including infrastructure, web, API, and mobile pentests, with a focus on proactive security and adversarial simulations.

Provides Penetration Testing
Offensive And Defensive Security Services
Cybersecurity Awareness Training
+3 more
Cyberensic

Cyberensic

Ethical Hacking and Penetratio...
Australia 7 employees

Cyberensic is an Australian cybersecurity consultancy headquartered in Barangaroo, NSW; it specializes in tailored cybersecurity solutions and strategic security assessments. The company provides penetration testing (pentest) services, including secure ethical hacking, and is supported by an Australian ABN, with operations confirmed in Sydney, Australia.

Provides Tailored Cybersecurity Solutions
Governance Risk And Compliance Management
Secure Ethical Hacking (penetration Testing)
+2 more
Untapped Group

Untapped Group

Red Team And Web Application P...
Melbourne, Australia 15 employees

Non-profit Human Resources Services organization based in Melbourne, Australia; founded in 2017 with 9 employees, focusing on neurodiversity inclusion, training, cybersecurity, and life skills; actively advocates for neurodiverse employment and ecosystem development.

Provides Advanced Technology Solutions Including AI And Cybersecurity
Workforce Development Programs
Training
+5 more
Ad

Stop wasting time on security questionnaires

ResponseHub uses AI to automate your security questionnaire responses. 100% confidence, save days, unblock deals.

Learn more
GreyDetect

GreyDetect

Penetration Testing for Mobile...
Canada 6 employees

Cybersecurity company specializing in penetration testing services such as mobile, web application, cloud, and API testing; 5 employees with stable staffing; headquartered in Canada; focuses on data privacy, cyber risk, and ISO27001 compliance.

Governance & Privacy
Compliance Services
Technical Assessment
+2 more
Coolidge Solutions

Coolidge Solutions

Cybersecurity Testing
Toronto, Canada 2 employees

Cybersecurity and data analytics company based in Toronto, Canada; specializes in penetration testing, cybersecurity risk management, and compliance (PCI DSS, SOC 2); 2 employees, $3.57M revenue, founded 2013, with a focus on cybersecurity transformation and payment security.

Strategy And Risk Management
Cybersecurity Transformation
Cybersecurity Testing
+2 more
C

Cyberometrics

Penetration Testing and Risk A...
Canada 2 employees

Cyberometrics is a Canada-based cybersecurity firm headquartered in Toronto, Ontario, specializing in end-to-end security solutions including penetration testing, risk assessments, infrastructure hardening, compliance readiness, and 24/7 AI-powered protection; supports standards like ISO27001, SOC2, ISM3, NIST CSF, and employs tools such as Fortinet, Azure Security Center, OWASP ZAP, and Nessus.

Penetration Testing
Risk Assessments
Infrastructure Hardening
+5 more
Coral eSecure Private Limited

Coral eSecure Private Limited

Cybersecurity Consulting and P...
Oakville, Canada 4 employees

Canadian-based cybersecurity consulting firm specializing in penetration testing, privacy, and compliance standards; with 20+ years of experience, $10M annual revenue, and a focus on certification support for standards like SOC, NIST, HIPAA, GDPR, and ISO 27701.

Cybersecurity Consulting
Penetration Testing
Privacy And Data Protection Consulting
+4 more
Cybercontrols.io

Cybercontrols.io

Offensive Security
Morpeth, United Kingdom 8 employees

Cybercontrols.io is a UK-based infosec consultancy providing cybersecurity and compliance services, including penetration testing, internal audits, and endpoint security; founded in 2022, with 4 employees and +300% YoY growth, headquartered in Morpeth, UK.

Compliance Consulting
Penetration Testing
Cybersecurity Strategy
+4 more
CyberFortis Consulting

CyberFortis Consulting

Network and Application Penetr...
Other 6 employees

UK-based IT and cybersecurity consulting firm specializing in penetration testing, threat intelligence, risk assessments, and compliance services; 4 employees; founded 2019; offers explicit pentest services; serves clients across UK, EU, Australia, New Zealand, and USA.

Penetration Testing
Compliance Support
Security Auditing
+3 more
Stefanini Cyber

Stefanini Cyber

Network and System
São Paulo, Brazil 224 employees

Brazil-based IT services and cybersecurity company specializing in managed security services, penetration testing, vulnerability analysis, and threat detection; 179 employees with a 59.9% YoY decline; recognized leader in managed security by ISG Provider Lens; part of Stefanini Group, founded in 2016, headquartered in São Paulo.

Application Security
Devsecops
Squads
+5 more
Delta Protect

Delta Protect

Comprehensive penetration test...
Mexico City, Mexico 44 employees

Cybersecurity company specializing in pentesting, compliance, and digital risk management; 29 employees, founded 2019, headquartered in Mexico City, Mexico; offers penetration testing, vulnerability analysis, and cyber intelligence services, with 41,903 monthly visits and a global rank of #680,565.

Penetration Testing
Ethical Hacking
Compliance And Certifications
+5 more
Hkmx Sc

Hkmx Sc

Network and system penetration...
Mexico 11 employees

Mexico-based cybersecurity firm specializing in risk management, vulnerability assessment, and penetration testing; offers security strategy, compliance, and certification services aligned with ISO 27001, NIST CSF, and ISO 22301; headquartered in Monterrey, Nuevo León, Mexico.

Risk Management
Vulnerability Assessment
Penetration Testing
+5 more
Layer 8 Security

Layer 8 Security

infrastructure and application...
Lima, Peru 12 employees

Cybersecurity company specializing in penetration testing and network security; 9 employees with 9.1% YoY growth, founded in 2015, based in Lima, Peru. Provides services including vulnerability assessments, impact analysis, and remediation recommendations, with a focus on pentesting and cybersecurity solutions.

Ethical Hacking
Penetration Testing
Social Engineering
+5 more