Identity and access management by certification

IAM Providers With ISO 27001 Certification for Identity and Access Management

The providers below run identity and access management and support ISO 27001 programs. Access control sits at the centre of the standard's Annex A, so what an auditor actually examines is joiner, mover and leaver handling, privileged account governance, and whether an access review produced a recorded decision rather than a spreadsheet nobody signed.

Why an access review is where identity programs fail an audit

Identity work looks tidy in a diagram and messy under examination. Certificates are issued against a stated scope, and that scope frequently excludes the systems where stale entitlements actually accumulate. A reviewer asks who approved a privileged role, when it was last recertified, and what became of the accounts belonging to people who left during the quarter. A supplier who cannot answer those three with evidence is selling tooling rather than governance.

Identity and access management providers supporting ISO 27001

Each profile lists the identity work the provider delivers alongside the compliance programs it supports. Ask which of your systems the engagement covers, because an identity service scoped to a single directory leaves the remainder of the estate untouched.

Accenture Security logo

Accenture Security

Best for: Enterprise orgs, Retail & E-Commerce, Manufacturing

Accenture Security provides managed security services as part of its global consulting and technology practice, serving large enterprises with complex, multi-na...

Dublin, Ireland1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementVulnerability Management+6 more
Serves: Enterprise (1000+)
View provider
Atos Cybersecurity logo

Atos Cybersecurity

Best for: Enterprise orgs, Government & Public Sector, Defense & Aerospace

Atos is a European IT services leader and one of the largest global MSSPs, operating 17 Security Operations Centers and serving 2,000+ enterprise clients with 2...

Bezons, France1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Threat IntelligenceIncident Response+4 more
Serves: Enterprise (1000+)
View provider

Aujas Cybersecurity

Best for: Mid-Market to Enterprise orgs, Technology, Retail & E-Commerce

Aujas Cybersecurity provides managed security operations, identity management, and security advisory services as an Indian cybersecurity firm serving global ent...

Bangalore, India200-500 employeesNot disclosed SLA
Security Operations Center as a Service (SOCaaS)Identity & Access Management (IAM)Cloud SecurityVulnerability Management+1 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
BT Security logo

BT Security

Best for: Enterprise orgs, Government & Public Sector, Telecommunications

BT Security is the cybersecurity division of British Telecom, one of the world's largest telecom operators, delivering managed security services to 6,400+ enter...

London, UK1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementNetwork Security Monitoring+5 more
Serves: Enterprise (1000+)
View provider
CGI Group Cybersecurity logo

CGI Cybersecurity

Best for: Enterprise orgs, Government & Public Sector, Defense & Aerospace

CGI is a global IT services and consulting company founded in 1976 in Montreal with 90,000+ professionals, offering managed security services, cyber defense, an...

Montreal, Quebec, Canada1000+ employees30 minutes SLA
Security Operations Center as a Service (SOCaaS)Threat IntelligenceIdentity & Access Management (IAM)Cloud Security+3 more
Serves: Enterprise (1000+)
View provider
Cognizant Cybersecurity logo

Cognizant Cybersecurity

Best for: Enterprise orgs, Manufacturing, Technology

Cognizant is a Nasdaq-listed global IT services company founded in 1994 with a dedicated cybersecurity practice, delivering managed security, identity managemen...

Teaneck, NJ1000+ employees30 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Identity & Access Management (IAM)Cloud Security+2 more
Serves: Enterprise (1000+)
View provider
CrowdStrike logo

CrowdStrike

Best for: SMB to Enterprise orgs, Retail & E-Commerce, Manufacturing

CrowdStrike provides fully managed endpoint protection and detection services built on the Falcon platform, offering turnkey MDR with their own security experts...

Austin, TX1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Endpoint ProtectionCloud SecurityIncident Response+3 more
Serves: SMB (51-200), Mid-Market (201-1000), Enterprise (1000+)
View provider
CyberCX logo

CyberCX

Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Energy & Utilities

CyberCX is the largest independent cybersecurity company in Australia and New Zealand, formed in 2019 by combining 14 leading firms with 1,400+ security profess...

Melbourne, Australia1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Incident ResponsePenetration Testing+3 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Cyderes logo

Cyderes

Best for: Mid-Market to Enterprise orgs, Manufacturing, Technology

Cyderes is a global MSSP formed from the 2022 merger of Herjavec Group and Fishtech, offering MDR, managed security, identity, and professional services with ne...

Kansas City, MO500-1000 employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementIdentity & Access Management (IAM)+5 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Deloitte Cyber logo

Deloitte Cyber

Best for: Enterprise orgs, Government & Public Sector, Manufacturing

Deloitte is a Big Four professional services firm with one of the world's largest cybersecurity practices, delivering managed security, incident response, and c...

New York, NY1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Incident ResponseCloud Security+4 more
Serves: Enterprise (1000+)
View provider
DXC Technology logo

DXC Technology

Best for: Enterprise orgs, Government & Public Sector, Manufacturing

DXC Technology is a Fortune 500 global IT services provider with a comprehensive MSSP practice, named a Leader in IDC MarketScape for MSSPs and Everest Group PE...

Ashburn, VA1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementVulnerability Management+6 more
Serves: Enterprise (1000+)
View provider

Espresso Labs

Best for: Startups to Mid-Market orgs, Manufacturing, Technology

Espresso Labs is an AI-native managed IT, cybersecurity, and compliance provider delivering 24/7 monitoring, endpoint detection and response, cloud and email se...

Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Vulnerability ManagementEndpoint Protection+7 more
Serves: Startups (1-50), SMB (51-200), Mid-Market (201-1000)
View provider
EY Cybersecurity logo

EY Cybersecurity

Best for: Enterprise orgs, Government & Public Sector, Manufacturing

EY (Ernst & Young) is a Big Four professional services firm with a global managed security practice, delivering threat detection, incident response, and cyber r...

London, UK1000+ employees30 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Incident ResponseCloud Security+2 more
Serves: Enterprise (1000+)
View provider
GuidePoint Security logo

GuidePoint Security

Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Technology

GuidePoint Security is a cybersecurity solutions and services firm founded in 2011 in Reston, VA with 1,200+ security experts, delivering managed security, prof...

Reston, VA1000+ employees30 minutes SLA
Managed Detection & Response (MDR)SIEM ManagementThreat IntelligencePenetration Testing+4 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider

HCLTech

Best for: Enterprise orgs, Manufacturing, Technology

HCLTech is a global technology company with a large-scale MSSP practice, offering AI-powered managed security operations from five global Cyber Defense Centers...

Noida, India1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Cloud SecurityIdentity & Access Management (IAM)+4 more
Serves: Enterprise (1000+)
View provider
IBM Security logo

IBM Security

Best for: Enterprise orgs, Retail & E-Commerce, Manufacturing

IBM Security provides enterprise-grade managed security services backed by the X-Force threat intelligence team and a global network of security operations cent...

Armonk, NY1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)SIEM ManagementVulnerability Management+8 more
Serves: Enterprise (1000+)
View provider

Infosys

Best for: Enterprise orgs, Manufacturing, Retail & E-Commerce

Infosys is a global IT services leader with a comprehensive cybersecurity MSSP practice, operating Security Command Centers worldwide and serving Fortune 500 cl...

Bengaluru, India1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Identity & Access Management (IAM)Cloud Security+4 more
Serves: Enterprise (1000+)
View provider

IQSEC

Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Telecommunications

IQSEC is a Mexican cybersecurity company providing managed security services, digital identity, and compliance solutions across Mexico.

Mexico City, Mexico200-500 employees15 minutes SLA
Security Operations Center as a Service (SOCaaS)Managed Detection & Response (MDR)Identity & Access Management (IAM)Vulnerability Management+3 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
KocSistem logo

KocSistem

Best for: Mid-Market to Enterprise orgs, Manufacturing, Energy & Utilities

KocSistem is Turkey's leading IT services company and MSSP, providing managed security operations, cloud services, and digital transformation solutions backed b...

Istanbul, Turkey1000+ employees15 minutes SLA
Security Operations Center as a Service (SOCaaS)Managed Detection & Response (MDR)Cloud SecuritySIEM Management+4 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Kyndryl logo

Kyndryl

Best for: Enterprise orgs, Government & Public Sector, Manufacturing

Kyndryl is the world's largest IT infrastructure services company, spun off from IBM in 2021, operating a global cybersecurity practice with 4,000+ security pra...

New York, NY1000+ employees15 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Identity & Access Management (IAM)Cloud Security+2 more
Serves: Enterprise (1000+)
View provider

LTIMindtree

Best for: Enterprise orgs, Manufacturing, Technology

LTIMindtree provides managed security operations, SOC services, and cybersecurity consulting as a major Indian IT services firm formed from the merger of L&T In...

Mumbai, India1000+ employeesNot disclosed SLA
Security Operations Center as a Service (SOCaaS)Managed Detection & Response (MDR)Identity & Access Management (IAM)Cloud Security+2 more
Serves: Enterprise (1000+)
View provider

NEC Asia Pacific

Best for: Enterprise orgs, Government & Public Sector, Telecommunications

NEC Asia Pacific provides managed cybersecurity services and digital infrastructure solutions across the Asia-Pacific region, backed by NEC Corporation's global...

Singapore, Singapore1000+ employees15 minutes SLA
Security Operations Center as a Service (SOCaaS)Managed Detection & Response (MDR)Cloud SecurityNetwork Security Monitoring+2 more
Serves: Enterprise (1000+)
View provider
Novacoast logo

Novacoast

Best for: Mid-Market to Enterprise orgs, Government & Public Sector, Education

Novacoast is a cybersecurity services firm founded in 1996 with 350+ employees, operating SOCs in the US, UK, and Guatemala City and delivering 24/7 managed sec...

Wichita, KS200-500 employees30 minutes SLA
Managed Detection & Response (MDR)Security Operations Center as a Service (SOCaaS)Identity & Access Management (IAM)Penetration Testing+3 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider
Ontinue logo

Ontinue

Best for: Mid-Market to Enterprise orgs, Technology, Manufacturing

Ontinue is a Microsoft-native MXDR provider founded in 2023, delivering AI-powered nonstop security operations via a unique Microsoft Teams-integrated collabora...

Redwood City, CA200-500 employees15 minutes SLA
Extended Detection & Response (XDR)Threat IntelligenceIncident ResponseCloud Security+1 more
Serves: Mid-Market (201-1000), Enterprise (1000+)
View provider

How to evaluate an ISO 27001 identity and access provider

Criterion 1

Certificate scope, not certificate presence

Read the statement of applicability and the scope line on the certificate itself. One covering a single delivery centre says little about the team who will run your directory.

Criterion 2

Joiner, mover and leaver handling

Confirm what triggers the provider from your personnel system, how fast access follows, and what happens to entitlements when somebody changes role rather than departing.

Criterion 3

Privileged access governance

Ask how administrative roles are requested, approved, time bound and logged, and whether any standing privilege survives anywhere in the design.

Criterion 4

Access review mechanics

Establish who certifies each review, what a reviewer actually sees on screen, and whether a revocation decision executes automatically or returns as a ticket.

Criterion 5

Evidence a reviewer can read

Request a sample of the artifacts produced across one audit cycle, and check they show decisions and dates rather than only current configuration state.

Platforms commonly paired with this service

Microsoft Entra ID, Okta, CyberArk, SailPoint, Ping Identity

Provider directories for this capability

Managed Security Service Providers

Frequently asked questions

Does ISO 27001 require a specific identity tool?

No. The standard sets control objectives and leaves implementation open. What gets tested is whether access is granted on an approved basis, recertified on a defined cycle, and removed once the basis for it ends.

How often should access recertification run?

Many programs settle on quarterly for privileged roles and annually for standard entitlements, tightened wherever the risk assessment justifies it. Whichever cycle your own documentation commits to becomes the one you are measured against.

Can a provider extend its certification to us?

No. A certificate belongs to the organization named on it and to the scope written into it. A supplier working inside your environment can furnish evidence and follow your controls, but its certificate does not travel to your program.

What separates identity management from access governance?

Management is the plumbing that creates, changes and removes accounts. Governance is the decision layer stating who should hold what, and proving somebody accountable agreed to it. Programs fall down on the second far more often than the first.