Criterion 1
Certificate scope, not certificate presence
Read the statement of applicability and the scope line on the certificate itself. One covering a single delivery centre says little about the team who will run your directory.
Identity and access management by certification
The providers below run identity and access management and support ISO 27001 programs. Access control sits at the centre of the standard's Annex A, so what an auditor actually examines is joiner, mover and leaver handling, privileged account governance, and whether an access review produced a recorded decision rather than a spreadsheet nobody signed.
Identity work looks tidy in a diagram and messy under examination. Certificates are issued against a stated scope, and that scope frequently excludes the systems where stale entitlements actually accumulate. A reviewer asks who approved a privileged role, when it was last recertified, and what became of the accounts belonging to people who left during the quarter. A supplier who cannot answer those three with evidence is selling tooling rather than governance.
Each profile lists the identity work the provider delivers alongside the compliance programs it supports. Ask which of your systems the engagement covers, because an identity service scoped to a single directory leaves the remainder of the estate untouched.

Best for: Enterprise orgs, Retail & E-Commerce, Manufacturing
Accenture Security provides managed security services as part of its global consulting and technology practice, serving large enterprises with complex, multi-na...

Best for: Enterprise orgs, Government & Public Sector, Defense & Aerospace
Atos is a European IT services leader and one of the largest global MSSPs, operating 17 Security Operations Centers and serving 2,000+ enterprise clients with 2...
Best for: Mid-Market to Enterprise orgs, Technology, Retail & E-Commerce
Aujas Cybersecurity provides managed security operations, identity management, and security advisory services as an Indian cybersecurity firm serving global ent...

Best for: Enterprise orgs, Government & Public Sector, Telecommunications
BT Security is the cybersecurity division of British Telecom, one of the world's largest telecom operators, delivering managed security services to 6,400+ enter...

Best for: Enterprise orgs, Government & Public Sector, Defense & Aerospace
CGI is a global IT services and consulting company founded in 1976 in Montreal with 90,000+ professionals, offering managed security services, cyber defense, an...

Best for: Enterprise orgs, Manufacturing, Technology
Cognizant is a Nasdaq-listed global IT services company founded in 1994 with a dedicated cybersecurity practice, delivering managed security, identity managemen...

Best for: SMB to Enterprise orgs, Retail & E-Commerce, Manufacturing
CrowdStrike provides fully managed endpoint protection and detection services built on the Falcon platform, offering turnkey MDR with their own security experts...

Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Energy & Utilities
CyberCX is the largest independent cybersecurity company in Australia and New Zealand, formed in 2019 by combining 14 leading firms with 1,400+ security profess...

Best for: Mid-Market to Enterprise orgs, Manufacturing, Technology
Cyderes is a global MSSP formed from the 2022 merger of Herjavec Group and Fishtech, offering MDR, managed security, identity, and professional services with ne...

Best for: Enterprise orgs, Government & Public Sector, Manufacturing
Deloitte is a Big Four professional services firm with one of the world's largest cybersecurity practices, delivering managed security, incident response, and c...

Best for: Enterprise orgs, Government & Public Sector, Manufacturing
DXC Technology is a Fortune 500 global IT services provider with a comprehensive MSSP practice, named a Leader in IDC MarketScape for MSSPs and Everest Group PE...
Best for: Startups to Mid-Market orgs, Manufacturing, Technology
Espresso Labs is an AI-native managed IT, cybersecurity, and compliance provider delivering 24/7 monitoring, endpoint detection and response, cloud and email se...

Best for: Enterprise orgs, Government & Public Sector, Manufacturing
EY (Ernst & Young) is a Big Four professional services firm with a global managed security practice, delivering threat detection, incident response, and cyber r...
Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Technology
GuidePoint Security is a cybersecurity solutions and services firm founded in 2011 in Reston, VA with 1,200+ security experts, delivering managed security, prof...
Best for: Enterprise orgs, Manufacturing, Technology
HCLTech is a global technology company with a large-scale MSSP practice, offering AI-powered managed security operations from five global Cyber Defense Centers...

Best for: Enterprise orgs, Retail & E-Commerce, Manufacturing
IBM Security provides enterprise-grade managed security services backed by the X-Force threat intelligence team and a global network of security operations cent...
Best for: Enterprise orgs, Manufacturing, Retail & E-Commerce
Infosys is a global IT services leader with a comprehensive cybersecurity MSSP practice, operating Security Command Centers worldwide and serving Fortune 500 cl...
Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Telecommunications
IQSEC is a Mexican cybersecurity company providing managed security services, digital identity, and compliance solutions across Mexico.

Best for: Mid-Market to Enterprise orgs, Manufacturing, Energy & Utilities
KocSistem is Turkey's leading IT services company and MSSP, providing managed security operations, cloud services, and digital transformation solutions backed b...

Best for: Enterprise orgs, Government & Public Sector, Manufacturing
Kyndryl is the world's largest IT infrastructure services company, spun off from IBM in 2021, operating a global cybersecurity practice with 4,000+ security pra...
Best for: Enterprise orgs, Manufacturing, Technology
LTIMindtree provides managed security operations, SOC services, and cybersecurity consulting as a major Indian IT services firm formed from the merger of L&T In...
Best for: Enterprise orgs, Government & Public Sector, Telecommunications
NEC Asia Pacific provides managed cybersecurity services and digital infrastructure solutions across the Asia-Pacific region, backed by NEC Corporation's global...
Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Education
Novacoast is a cybersecurity services firm founded in 1996 with 350+ employees, operating SOCs in the US, UK, and Guatemala City and delivering 24/7 managed sec...

Best for: Mid-Market to Enterprise orgs, Technology, Manufacturing
Ontinue is a Microsoft-native MXDR provider founded in 2023, delivering AI-powered nonstop security operations via a unique Microsoft Teams-integrated collabora...
Criterion 1
Read the statement of applicability and the scope line on the certificate itself. One covering a single delivery centre says little about the team who will run your directory.
Criterion 2
Confirm what triggers the provider from your personnel system, how fast access follows, and what happens to entitlements when somebody changes role rather than departing.
Criterion 3
Ask how administrative roles are requested, approved, time bound and logged, and whether any standing privilege survives anywhere in the design.
Criterion 4
Establish who certifies each review, what a reviewer actually sees on screen, and whether a revocation decision executes automatically or returns as a ticket.
Criterion 5
Request a sample of the artifacts produced across one audit cycle, and check they show decisions and dates rather than only current configuration state.
Financial Services, Healthcare, Technology, Government & Public Sector
Microsoft Entra ID, Okta, CyberArk, SailPoint, Ping Identity
No. The standard sets control objectives and leaves implementation open. What gets tested is whether access is granted on an approved basis, recertified on a defined cycle, and removed once the basis for it ends.
Many programs settle on quarterly for privileged roles and annually for standard entitlements, tightened wherever the risk assessment justifies it. Whichever cycle your own documentation commits to becomes the one you are measured against.
No. A certificate belongs to the organization named on it and to the scope written into it. A supplier working inside your environment can furnish evidence and follow your controls, but its certificate does not travel to your program.
Management is the plumbing that creates, changes and removes accounts. Governance is the decision layer stating who should hold what, and proving somebody accountable agreed to it. Programs fall down on the second far more often than the first.