Firewall management by attestation

Firewall Providers With a SOC 2 Type II Attestation Report

The providers below run firewall management and hold a SOC 2 Type II report. Type II differs from Type I in the single way that counts to a buyer: it tests whether controls operated across a period rather than whether they existed on one chosen day, which is the gap between a design claim and an operating record.

Why the report matters more than the badge

A logo on a website answers none of the questions a reviewer needs answered. Which trust services criteria sat in scope, availability and confidentiality or security by itself? How long did the observation window run? Did the auditor note exceptions, and what did management say in reply? A firewall supplier holds change authority over the boundary of your network, which makes the exceptions section the part to open first.

Firewall management providers holding SOC 2 Type II

Each profile lists the firewall work the provider delivers alongside the certifications and attestations it holds. Request the full report under a non-disclosure agreement rather than settling for a summary, and check the observation window covers the period you care about.

Sophos

Verified

Best for: Startups to Enterprise orgs, Retail & E-Commerce, Manufacturing

Sophos MDR delivers managed detection and response built on the Sophos security ecosystem, offering both Sophos-native and multi-vendor environment support for...

Abingdon, UK1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Endpoint ProtectionCloud SecurityIncident Response+8 more
Serves: Startups (1-50), SMB (51-200), Mid-Market (201-1000), Enterprise (1000+)
View provider

AMSYS Innovative Solutions

Best for: SMB to Mid-Market orgs, Energy & Utilities, Manufacturing

AMSYS Innovative Solutions delivers managed IT and cybersecurity services to businesses in the Houston area, specializing in proactive security monitoring and c...

Houston, TX51-200 employees1 hour SLA
Managed Detection & Response (MDR)Endpoint ProtectionNetwork Security MonitoringVulnerability Management+4 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
AT&T Cybersecurity logo

AT&T Cybersecurity

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing

AT&T Cybersecurity, building on the AlienVault acquisition, delivers managed threat detection and response services powered by the USM Anywhere platform and AT&...

San Antonio, TX1000+ employees30 minutes SLA
Managed Detection & Response (MDR)SIEM ManagementVulnerability ManagementEndpoint Protection+5 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Check Point Infinity Global Services logo

Check Point Infinity Global Services

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing

Check Point Infinity Global Services delivers managed security operations built on the Check Point security architecture, offering prevention-first security man...

Tel Aviv, Israel1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Endpoint ProtectionCloud SecurityIncident Response+5 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Custom Computer Specialists logo

Custom Computer Specialists

Best for: SMB to Mid-Market orgs, Education, Nonprofit

Custom Computer Specialists is a New York-based managed IT and security services provider offering cybersecurity operations, cloud services, and compliance supp...

Hauppauge, NY51-200 employees1 hour SLA
Managed Detection & Response (MDR)Endpoint ProtectionNetwork Security MonitoringVulnerability Management+4 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
DataEndure logo

DataEndure

Best for: SMB to Mid-Market orgs, Manufacturing, Retail & E-Commerce

DataEndure provides managed security and IT infrastructure services with four decades of technology operations experience, serving mid-market organizations that...

San Jose, CA51-200 employees30 minutes SLA
Managed Detection & Response (MDR)SIEM ManagementVulnerability ManagementCloud Security+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
DXC Technology logo

DXC Technology

Best for: Enterprise orgs, Government & Public Sector, Manufacturing

DXC Technology is a Fortune 500 global IT services provider with a comprehensive MSSP practice, named a Leader in IDC MarketScape for MSSPs and Everest Group PE...

Ashburn, VA1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementVulnerability Management+6 more
Serves: Enterprise (1000+)
View provider

Hughes Network Systems

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Energy & Utilities

Hughes Network Systems provides managed network and cybersecurity services to distributed enterprises, leveraging its satellite and terrestrial network expertis...

Germantown, MD1000+ employees30 minutes SLA
Firewall ManagementNetwork Security MonitoringManaged Detection & Response (MDR)Vulnerability Management+2 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
JLS Technology USA logo

JLS Technology USA

Best for: SMB to Mid-Market orgs, Legal, Manufacturing

JLS Technology provides managed cybersecurity and IT services to businesses in the New Jersey/New York metro area, offering 24/7 monitoring, compliance support,...

Newark, NJ51-200 employees1 hour SLA
Managed Detection & Response (MDR)Endpoint ProtectionCloud SecurityVulnerability Management+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
Locknet Managed IT logo

Locknet Managed IT

Best for: SMB to Mid-Market orgs, Manufacturing, Education

Locknet Managed IT provides cybersecurity and managed IT services to businesses across the Midwest, specializing in proactive threat monitoring and compliance s...

Wausau, WI51-200 employees1 hour SLA
Managed Detection & Response (MDR)Endpoint ProtectionNetwork Security MonitoringSecurity Awareness Training+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
Lumen Technologies Security logo

Lumen Technologies Security

Best for: Mid-Market to Enterprise orgs, Telecommunications, Government & Public Sector

Lumen Technologies is a Fortune 500 global network and cloud provider operating a 24/7 MSSP practice backed by Black Lotus Labs threat intelligence and 4 Asia-P...

Monroe, LA1000+ employees30 minutes SLA
Managed Detection & Response (MDR)Firewall ManagementSIEM ManagementThreat Intelligence+4 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
MIS Solutions logo

MIS Solutions

Best for: SMB to Mid-Market orgs, Manufacturing

MIS Solutions is a family-owned managed IT and cybersecurity provider serving small and mid-sized businesses in the greater Atlanta area for over three decades.

Suwanee, GA51-200 employeesNot disclosed SLA
Managed Detection & Response (MDR)Endpoint ProtectionNetwork Security MonitoringCompliance Management+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
NetCov logo

NetCov

Best for: SMB to Mid-Market orgs, Legal, Manufacturing

NetCov provides managed cybersecurity services to businesses in the New England area, offering threat monitoring, vulnerability management, and compliance suppo...

Danvers, MA51-200 employees1 hour SLA
Managed Detection & Response (MDR)Endpoint ProtectionVulnerability ManagementNetwork Security Monitoring+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
Netsurion logo

Netsurion

Best for: SMB to Mid-Market orgs, Retail & E-Commerce, Manufacturing

Netsurion delivers managed threat detection and response with its proprietary EventTracker SIEM platform, serving mid-market and multi-site organizations with c...

Fort Lauderdale, FL200-500 employees30 minutes SLA
Managed Detection & Response (MDR)SIEM ManagementVulnerability ManagementEndpoint Protection+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider
Ntirety logo

Ntirety

Best for: SMB to Enterprise orgs, Government & Public Sector, Technology

Ntirety is a Denver-based MSSP formerly known as HOSTING, founded in 1997, delivering Compliant Security-as-a-Service (CompSaaS) for highly regulated industries...

Denver, CO200-500 employees30 minutes SLA
Managed Detection & Response (MDR)SIEM ManagementCloud SecurityVulnerability Management+3 more
Serves: SMB (51-200), Mid-Market (201-1000), Enterprise (1000+)
View provider
NTT Security logo

NTT Security

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing

NTT Security provides managed security services through a global network of SOCs, offering comprehensive threat detection, incident response, and consulting ser...

London, UK1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementVulnerability Management+7 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Nuspire logo

Nuspire

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing

Nuspire is a Commerce Township, MI-based MSSP founded in 1999 with one of the longest track records in managed security, offering 24/7 SOC services, MDR, and ne...

Commerce Township, MI200-500 employees30 minutes SLA
Managed Detection & Response (MDR)Network Security MonitoringFirewall ManagementSIEM Management+5 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Palo Alto Networks Unit 42 logo

Palo Alto Networks Unit 42

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing

Palo Alto Networks delivers managed extended detection and response through its Cortex XMDR service, backed by Unit 42 threat research and incident response exp...

Santa Clara, CA1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Cloud SecurityIncident ResponsePenetration Testing+4 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider

Paranet Solutions

Best for: SMB to Mid-Market orgs, Manufacturing, Legal

Paranet Solutions provides managed cybersecurity and cloud services to mid-market organizations in Texas, offering SOC operations, vulnerability management, and...

Carrollton, TX51-200 employees30 minutes SLA
Security Operations Center as a Service (SOCaaS)Managed Detection & Response (MDR)Cloud SecurityVulnerability Management+3 more
Serves: SMB (51-200), Mid-Market (201-1000)
View provider

SonicWALL

Best for: SMB to Enterprise orgs, Retail & E-Commerce, Education

SonicWall delivers managed security services through its network of global partners, leveraging its deep expertise in next-generation firewalls, threat intellig...

Milpitas, CA1000+ employees30 minutes SLA
Managed Detection & Response (MDR)Firewall ManagementEndpoint ProtectionCloud Security+4 more
Serves: SMB (51-200), Mid-Market (201-1000), Enterprise (1000+)
View provider
Tata Communications Cybersecurity logo

Tata Communications Cybersecurity

Best for: Mid-Market to Enterprise orgs, Telecommunications, Manufacturing

Tata Communications is a Mumbai-based global digital infrastructure company founded in 1986 delivering managed security services across its global network backb...

Mumbai, India1000+ employees30 minutes SLA
Firewall ManagementCloud SecurityManaged Detection & Response (MDR)Vulnerability Management+3 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Todyl logo

Todyl

Best for: Startups to Mid-Market orgs, Technology, Legal

Todyl provides an all-in-one security platform combining SIEM, endpoint protection, network security, and managed services specifically designed for small and m...

New York, NY51-200 employees30 minutes SLA
Managed Detection & Response (MDR)SIEM ManagementEndpoint ProtectionNetwork Security Monitoring+2 more
Serves: Startups (1-50), SMB (51-200), Mid-Market (201-1000)
View provider

Verizon

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing

Verizon delivers managed security services leveraging its global network infrastructure, proprietary threat intelligence from the annual DBIR report, and a larg...

Basking Ridge, NJ1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementVulnerability Management+5 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
VirtualArmour logo

VirtualArmour

Best for: Mid-Market to Enterprise orgs, Technology, Manufacturing

VirtualArmour provides managed security services and cybersecurity consulting, specializing in firewall management, threat monitoring, and security infrastructu...

Englewood, CO51-200 employees30 minutes SLA
Firewall ManagementManaged Detection & Response (MDR)Network Security MonitoringVulnerability Management+3 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider

How to read a firewall provider's SOC 2 Type II report

Criterion 1

Trust criteria in scope

Check which criteria the report covers. Security by itself is the usual minimum, and availability carries extra weight for a service holding change authority over your perimeter.

Criterion 2

Observation window and bridge letters

Confirm the period the auditor tested and how long ago it closed. Ask for a bridge letter covering the months between that closing date and today.

Criterion 3

Exceptions and management response

Open the exceptions section before anything else. An exception paired with a dated, specific remediation reassures more than a report that lists none at all.

Criterion 4

Change control over rule sets

Establish how a rule change is raised, reviewed, approved and recorded, and whether emergency changes follow a documented shortened path with retrospective sign-off.

Criterion 5

Subservice organizations

Identify which functions the report carves out to another party, because a carved-out data centre or hosting platform means those controls were never examined here.

Frequently asked questions

What separates SOC 2 Type I from Type II?

Type I reports whether controls were suitably designed at a single point in time. Type II tests whether they genuinely operated across a defined period, commonly three to twelve months, which is why buyers ask for the second one.

How current does the report need to be?

Reviewers generally want an observation window that closed within the past year, plus a bridge letter covering the months since. An older report with no bridge letter leaves a stretch of time nobody has attested to.

Does the report cover the whole company?

Rarely. Every report carries a system description that bounds what was examined, and functions handled by another party are frequently carved out. Read that description before assuming the service you are buying was inside it.

Can I see the full report rather than a summary?

Usually yes, under a non-disclosure agreement. A supplier willing to share only a logo or a one-page overview is withholding the exact sections, exceptions and carve-outs, that make the document worth requesting.