Criterion 1
Trust criteria in scope
Check which criteria the report covers. Security by itself is the usual minimum, and availability carries extra weight for a service holding change authority over your perimeter.
Firewall management by attestation
The providers below run firewall management and hold a SOC 2 Type II report. Type II differs from Type I in the single way that counts to a buyer: it tests whether controls operated across a period rather than whether they existed on one chosen day, which is the gap between a design claim and an operating record.
A logo on a website answers none of the questions a reviewer needs answered. Which trust services criteria sat in scope, availability and confidentiality or security by itself? How long did the observation window run? Did the auditor note exceptions, and what did management say in reply? A firewall supplier holds change authority over the boundary of your network, which makes the exceptions section the part to open first.
Each profile lists the firewall work the provider delivers alongside the certifications and attestations it holds. Request the full report under a non-disclosure agreement rather than settling for a summary, and check the observation window covers the period you care about.
Best for: Startups to Enterprise orgs, Retail & E-Commerce, Manufacturing
Sophos MDR delivers managed detection and response built on the Sophos security ecosystem, offering both Sophos-native and multi-vendor environment support for...
Best for: SMB to Mid-Market orgs, Energy & Utilities, Manufacturing
AMSYS Innovative Solutions delivers managed IT and cybersecurity services to businesses in the Houston area, specializing in proactive security monitoring and c...

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing
AT&T Cybersecurity, building on the AlienVault acquisition, delivers managed threat detection and response services powered by the USM Anywhere platform and AT&...
Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing
Check Point Infinity Global Services delivers managed security operations built on the Check Point security architecture, offering prevention-first security man...

Best for: SMB to Mid-Market orgs, Education, Nonprofit
Custom Computer Specialists is a New York-based managed IT and security services provider offering cybersecurity operations, cloud services, and compliance supp...

Best for: SMB to Mid-Market orgs, Manufacturing, Retail & E-Commerce
DataEndure provides managed security and IT infrastructure services with four decades of technology operations experience, serving mid-market organizations that...

Best for: Enterprise orgs, Government & Public Sector, Manufacturing
DXC Technology is a Fortune 500 global IT services provider with a comprehensive MSSP practice, named a Leader in IDC MarketScape for MSSPs and Everest Group PE...
Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Energy & Utilities
Hughes Network Systems provides managed network and cybersecurity services to distributed enterprises, leveraging its satellite and terrestrial network expertis...

Best for: SMB to Mid-Market orgs, Legal, Manufacturing
JLS Technology provides managed cybersecurity and IT services to businesses in the New Jersey/New York metro area, offering 24/7 monitoring, compliance support,...
Best for: SMB to Mid-Market orgs, Manufacturing, Education
Locknet Managed IT provides cybersecurity and managed IT services to businesses across the Midwest, specializing in proactive threat monitoring and compliance s...

Best for: Mid-Market to Enterprise orgs, Telecommunications, Government & Public Sector
Lumen Technologies is a Fortune 500 global network and cloud provider operating a 24/7 MSSP practice backed by Black Lotus Labs threat intelligence and 4 Asia-P...
Best for: SMB to Mid-Market orgs, Manufacturing
MIS Solutions is a family-owned managed IT and cybersecurity provider serving small and mid-sized businesses in the greater Atlanta area for over three decades.
Best for: SMB to Mid-Market orgs, Legal, Manufacturing
NetCov provides managed cybersecurity services to businesses in the New England area, offering threat monitoring, vulnerability management, and compliance suppo...

Best for: SMB to Mid-Market orgs, Retail & E-Commerce, Manufacturing
Netsurion delivers managed threat detection and response with its proprietary EventTracker SIEM platform, serving mid-market and multi-site organizations with c...

Best for: SMB to Enterprise orgs, Government & Public Sector, Technology
Ntirety is a Denver-based MSSP formerly known as HOSTING, founded in 1997, delivering Compliant Security-as-a-Service (CompSaaS) for highly regulated industries...

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing
NTT Security provides managed security services through a global network of SOCs, offering comprehensive threat detection, incident response, and consulting ser...

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing
Nuspire is a Commerce Township, MI-based MSSP founded in 1999 with one of the longest track records in managed security, offering 24/7 SOC services, MDR, and ne...

Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing
Palo Alto Networks delivers managed extended detection and response through its Cortex XMDR service, backed by Unit 42 threat research and incident response exp...
Best for: SMB to Mid-Market orgs, Manufacturing, Legal
Paranet Solutions provides managed cybersecurity and cloud services to mid-market organizations in Texas, offering SOC operations, vulnerability management, and...
Best for: SMB to Enterprise orgs, Retail & E-Commerce, Education
SonicWall delivers managed security services through its network of global partners, leveraging its deep expertise in next-generation firewalls, threat intellig...

Best for: Mid-Market to Enterprise orgs, Telecommunications, Manufacturing
Tata Communications is a Mumbai-based global digital infrastructure company founded in 1986 delivering managed security services across its global network backb...
Best for: Startups to Mid-Market orgs, Technology, Legal
Todyl provides an all-in-one security platform combining SIEM, endpoint protection, network security, and managed services specifically designed for small and m...
Best for: Mid-Market to Enterprise orgs, Retail & E-Commerce, Manufacturing
Verizon delivers managed security services leveraging its global network infrastructure, proprietary threat intelligence from the annual DBIR report, and a larg...

Best for: Mid-Market to Enterprise orgs, Technology, Manufacturing
VirtualArmour provides managed security services and cybersecurity consulting, specializing in firewall management, threat monitoring, and security infrastructu...
Criterion 1
Check which criteria the report covers. Security by itself is the usual minimum, and availability carries extra weight for a service holding change authority over your perimeter.
Criterion 2
Confirm the period the auditor tested and how long ago it closed. Ask for a bridge letter covering the months between that closing date and today.
Criterion 3
Open the exceptions section before anything else. An exception paired with a dated, specific remediation reassures more than a report that lists none at all.
Criterion 4
Establish how a rule change is raised, reviewed, approved and recorded, and whether emergency changes follow a documented shortened path with retrospective sign-off.
Criterion 5
Identify which functions the report carves out to another party, because a carved-out data centre or hosting platform means those controls were never examined here.
Manufacturing, Retail & E-Commerce, Healthcare, Government & Public Sector
Palo Alto Networks, Fortinet, Check Point, Cisco Firepower, SonicWall
MSSP Providers for Small Businesses, Managed Security Service Providers
Type I reports whether controls were suitably designed at a single point in time. Type II tests whether they genuinely operated across a defined period, commonly three to twelve months, which is why buyers ask for the second one.
Reviewers generally want an observation window that closed within the past year, plus a bridge letter covering the months since. An older report with no bridge letter leaves a stretch of time nobody has attested to.
Rarely. Every report carries a system description that bounds what was examined, and functions handled by another party are frequently carved out. Read that description before assuming the service you are buying was inside it.
Usually yes, under a non-disclosure agreement. A supplier willing to share only a logo or a one-page overview is withholding the exact sections, exceptions and carve-outs, that make the document worth requesting.