Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Best digital forensics firms — criteria, not a ranking

Updated

Evaluate digital-forensics firms by stated criteria — accreditation class (PFI, CREST, ISO/IEC 17025), jurisdiction, and media/cloud/mobile scope — not a ranking. Verify the current public roster. Not legal advice.

Operational guidance, last verified 7 September 2026 against the PCI SSC PCI Forensic Investigator (PFI) directory, CREST Incident Response company accreditation and the CREST Marketplace / member roster, ISO/IEC 17025 laboratory accreditation as listed by ILAC-recognised bodies (UKAS, A2LA, ANAB), NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), and SWGDE published digital-evidence guidelines. This page does not rank DFIR firms, does not name any, does not reprint a roster, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The what-is-dfir page on this site is the DFIR explainer. The when-you-need-dfir page on this site is the retain-or-not tree. Not legal advice.

This is a criteria checklist, not a vendor list

Audience: an engineering leader, founder, CTO, CISO, counsel, or incident commander shortlisting a digital-forensics firm under time pressure. The what-is-dfir page on this site is the explainer (identify, preserve, analyze, report; forensic soundness; chain of custody). The when-you-need-dfir page on this site is the in-house-versus-firm decision tree. The preserve-evidence page on this site is the order-of-volatility checklist. This page is the inclusion-criteria step: which accreditation classes, jurisdictions, and media/cloud/mobile scopes to check against a public roster before you retain anyone. It does not rank DFIR firms, does not name any, and is not a directory. The how-to-select-a-dfir-provider page on this site is the selection decision tree. A dedicated comparing-major-incident-response-providers guide is not on this site yet.

Forensics is P0 evidence-preservation work. A firm you cannot reconstruct later is a broken chain, not a brand. NIST SP 800-86 is a guide to integrating forensic techniques into incident response — guidance, not a statute. SWGDE documents are consensus best-practice / guideline publications for digital and multimedia evidence, not a statute and not a ranking of firms. PCI SSC's PFI programme qualifies companies to investigate suspected cardholder-data compromises; the Council tells clients to check the current list each time they engage a PFI. CREST Incident Response is a company-level capability class assessed against a published standard. ISO/IEC 17025 is a laboratory-competence standard; the scope of accreditation is the claim, not the logo. ASCLD is a professional membership society; the former ASCLD/LAB accreditation programme is now ANAB. None of those sources is a league table. Last verified 7 September 2026. Not legal advice.

  • Inclusion on this page means a criterion you can check on a named public roster, not a brand we like. This page does not rank DFIR firms and does not name any.
  • Accreditation is a class (PFI, CREST Incident Response, ISO/IEC 17025 forensic-lab scope). Verify the CURRENT listing and the CURRENT scope. A slide-deck logo is marketing.
  • Court-admissibility and expert-witness standing are not public rosters. Treat them as questions for counsel on YOUR facts, not a score this page can assign.
  • If you have a cyber policy, the panel or prior-consent clause is a contract constraint, not a quality ranking. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, and is not legal advice.

Stated inclusion criteria

A firm belongs on YOUR shortlist only when it meets the criteria that apply to THIS incident. The rows below are inclusion criteria. They are not a league table, not an endorsement, and not a directory. Last verified 7 September 2026. Not legal advice.

Inclusion criteria for a digital-forensics firm (stated criteria — not a ranking, not a vendor list, not legal advice)
CriterionWhat must be trueHow to verifyLimit
Current accreditation class for the workThe company is listed now for the class of work you need: PFI (cardholder-data compromise), CREST Incident Response (company IR/forensics capability class), or ISO/IEC 17025 with a digital-forensics / computer / mobile scope on an ILAC-recognised body's schedule.Open the public roster named in the accreditation-classes table below. Check the company, the status, the region, and the scope — not a logo on a pitch deck.Accreditation is a capability class, not 'best firms,' not a licence in every country, and not a guarantee of admissibility. Verify the CURRENT list. This page does not reprint one.
Jurisdiction matchThe roster listing and the engagement cover the country, legal process, and data-residency rules that actually apply — including where evidence will be stored and who can testify.Read the roster's region / place-of-business fields (PFI regions; CREST Marketplace filters; 17025 schedule of accreditation). Ask counsel where the work will be done.A UK NCSC CIR or UKAS 17025 listing does not, by itself, authorise work everywhere. A US PFI listing is a PCI class, not a global forensics licence.
Media / cloud / mobile scopeThe firm's assessed scope covers the sources you actually have: host/disk media, cloud identity and logs, mobile devices — not a generic 'we do DFIR' claim.Read the 17025 schedule (methods and item types). For CREST, filter Incident Response and ask which environments the assessed capability covers. For PFI, the class is cardholder-data investigations, not every media type.Scope is a class of assessed work, not a named case study this page will invent. Cloud API collection is not the same as a write-blocked disk image.
Forensic method (NIST SP 800-86 / SWGDE class)Working copy, integrity preservation, hashes, chain of custody, documented tools and versions, trained handlers. Another examiner can reconstruct the work.Ask for the method statement and a sample custody record (fields, not a client file). NIST SP 800-86 and SWGDE best-practice documents describe the class of method. The preserve-evidence page on this site is the order-of-volatility checklist.Method is guidance, not a guarantee of admissibility. NIST SP 800-86 and SWGDE are not statutes. The chain-of-custody page on this site is the handling record.
Insurer panel / prior consentYOUR form either lists this firm or written consent is in hand before DFIR costs are incurred.Notice the carrier (or the broker). Ask which DFIR the policy recognises. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.A contract role, not a quality score. Panel is not 'the best firms.' This page does not interpret YOUR policy and does not rank panel members.
Counsel-directed statement of workCounsel retains and directs the firm, with a SOW that says the work is to assist counsel in giving legal advice — common practice, not a privilege ruling.The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Confirm with counsel before you sign.Common practice, not a ruling that privilege or work-product will attach. Dual-purpose ordinary-course IT work is a known waiver risk.
Independence from the estate operatorThe examiner is independent of the MSP, SOC, or internal team that runs the environment, unless counsel and the insurer have a reason to use the incumbent.Ask who operates the estate and who will image it. Independence is a conflict criterion.Independence is not a preference for boutiques. An insurer-cleared retainer can still be the right firm.
Court-admissibility / expert-witness standingNot an inclusion checkbox this page can tick. Whether a later forum will admit the work, and whether a named examiner can testify, are counsel's questions on YOUR facts.Ask counsel. Ask the firm who would testify, in which jurisdictions they have, and whether the method is reconstructable. There is no public 'expert-witness roster' this page will invent.Track record is not a ranking and not a public list. This page does not score firms on court wins. Not legal advice.

Accreditation classes (not a ranking)

These are classes of independently assessed capability. A class is not a league table. Verify each class on the named public roster at the time you engage — PCI SSC says to check the PFI list each time; CREST and 17025 listings also change. This page does not reprint those lists and does not name firms. Last verified 7 September 2026.

Accreditation classes for digital-forensics work (capability classes — not a ranking, not a vendor list)
ClassWhat it actually isPublic roster to checkWhat this page is not saying
PCI Forensic Investigator (PFI)PCI SSC qualifies PFI companies to investigate suspected cardholder-data compromises. A PFI must work for a Qualified Security Assessor company with a dedicated forensic investigation practice, and requalify. 'In Remediation' is a published status, not a hidden fail.PCI SSC PFI directory (assessors and solutions → PCI Forensic Investigators). PCI SSC: check the list each time you engage a PFI; the Council does not guarantee the list is current at all times.PFI is a payment-card forensics class, not a general 'best digital forensics firms' mark, not a licence for every media type, and not a ranking. A dedicated best-incident-response-firms guide is not on this site yet.
CREST Incident Response (company)CREST company accreditation against a published Incident Response standard (six domains; expert-led assessment of documentation, artefacts, and prior engagements). Individual CREST exams (CPIA / CRIA / CCIM) are a people competence class, not the company class.CREST Marketplace (buyer-facing roster of CREST-accredited providers; CREST states it replaced the previous member directory) and the CREST members search. Filter for Incident Response accreditation. CREST accreditation standards are published separately.CREST IR is a capability class, not 'best firms,' not a global licence, and not this page's vendor list. Membership without the IR accreditation is not the IR class. Verify the CURRENT listing.
ISO/IEC 17025 laboratoryISO/IEC 17025 is the international standard for testing and calibration laboratory competence. For digital forensics, the claim that matters is the schedule of accreditation: which methods, which item types (computer, mobile, cloud-derived media), which location.The accrediting body's directory, not the lab's marketing site: UKAS (search accredited organisations), A2LA (accredited-organisations directory), ANAB (directory of accredited organisations). Read the schedule. ILAC recognition is how bodies recognise each other; it is not a ranking of labs.A 17025 certificate for chemistry or calibration is not a digital-forensics scope. Logo without a current schedule is not verification. 17025 is not a statute of admissibility.
ASCLD-class forensic-lab accreditationASCLD (American Society of Crime Laboratory Directors) is a professional membership society. The former ASCLD/LAB accreditation programme transferred to ANAB (ANSI National Accreditation Board). Today, US forensic-lab ISO/IEC 17025 / 17020 accreditation is offered by ANAB and A2LA — not by ASCLD as a current accreditor.ANAB directory of accredited organisations (forensic testing / inspection programmes) and A2LA's directory. ASCLD's own site is membership and an accreditation toolkit pointing at ANAB and A2LA, not a current lab roster.An old ASCLD/LAB logo is history, not a current listing. ASCLD membership is not ISO/IEC 17025. This page does not treat ASCLD as a ranking of firms.

Comparison by criteria

Use this table to compare candidates you already have — a panel list, a retainer, or a name counsel supplied — against the same criteria. Fill the cells from the public roster and from counsel. Empty cells are unknowns, not a pass. This is not a filled-in vendor comparison and not a ranking. A dedicated comparing-major-incident-response-providers guide is not on this site yet. Last verified 7 September 2026. Not legal advice.

Compare a candidate firm by criteria (worksheet — not a ranking, not a directory, not legal advice)
CriterionWhat a defensible 'yes' looks likeFail / skip signal
PFI class (if cardholder data may be in scope)Named on the current PCI SSC PFI directory for the region; status is not a surprise; company requalification is current.Logo on a website, an expired listing, or 'our people used to be PFI.' PCI SSC: check the list at engagement.
CREST IR class (if you are using that scheme)Company listed on CREST Marketplace / members search with Incident Response accreditation current.CREST membership without IR accreditation; an individual exam quoted as if it were the company class; a screenshot from last year.
ISO/IEC 17025 digital-forensics scopeCurrent schedule from UKAS, A2LA, or ANAB naming the methods and item types you need (computer, mobile, the media you have).A 17025 certificate whose schedule is another discipline; a certificate with no schedule; a body you cannot find on an ILAC-recognised directory.
ASCLD-class (ANAB / A2LA today)Current ANAB or A2LA forensic-lab listing covering the digital-evidence discipline you need.ASCLD membership, a historical ASCLD/LAB mark, or a crime-lab claim with no current ANAB/A2LA schedule.
JurisdictionRoster region and engagement geography match; evidence storage and testimony location are named.'We work globally' with no roster region and no data-residency answer.
Media / cloud / mobileAssessed scope covers the sources in play. Cloud collection method is documented (API, snapshot, legal process), not implied.A host-image lab asked to collect a multi-account cloud tenant with no scope for it — or the reverse.
Method / chain of custodyWorking copy, hashes, custody fields, tool versions. NIST SP 800-86 / SWGDE class. Reconstructable by another examiner.Live analysis on the original with no record; 'we just run the tool'; no custody log. The chain-of-custody page on this site is the handling record.
Panel / counsel / independenceCarrier recognises the firm or has consented; counsel holds the SOW; examiner is not the estate operator unless that is the agreed exception.You signed before notice; privilege assumed after the fact; the MSP is investigating itself with no conflict note.

What you need to do now

Order is the failure mode. Shopping a favourite firm from a blog 'top list,' then asking counsel to wrap privilege around it, then telling the carrier, is the reverse of common practice. The sequence below is practice, not a statute. Last verified 7 September 2026. Not legal advice. Not coverage advice.

  • Preserve first. Do not reimage, power down a live host to 'save it,' or rotate logs before capture. The preserve-evidence page on this site is the order-of-volatility checklist. The we've-been-breached page on this site is the first-moves hub.
  • Walk the retain-or-not tree with the commander and counsel. The when-you-need-dfir page on this site is that tree. In-house capture now does not bar a firm later for analysis.
  • If you have a cyber policy, notice the carrier before you pick a non-panel firm. Panel is a contract role, not a ranking. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • Check the current public roster for the class of work: PFI directory, CREST Marketplace / members search (Incident Response), ISO/IEC 17025 schedule (UKAS / A2LA / ANAB). Do not trust a logo. This page does not reprint those lists.
  • Match jurisdiction and media/cloud/mobile scope to THIS incident. Empty cells on the comparison table are unknowns, not a pass.
  • A dedicated information-to-give-a-dfir-firm guide is not on this site yet. Until it is: hand over the UTC timeline, the evidence-hold list, what you have already imaged, and what you have not — on the out-of-band channel. Do not reimage first.

Where this shows up in ShipReady Metrics

The signed-in app does not image hosts, keep a chain of custody, produce a forensic report, retain a DFIR firm, notice an insurer, or file with a regulator. It does not rank forensic vendors, does not keep a copy of your policy, and does not maintain a PFI, CREST, or ISO/IEC 17025 roster. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

PCI SSC PCI Forensic Investigator directory and programme materials: PFIs investigate suspected cardholder-data compromises; they must work for a QSA company with a dedicated forensic practice; the Council tells clients to check the current list at each engagement; 'In Remediation' is a published status. CREST publishes a company Incident Response accreditation standard and, as of March 2026, CREST Marketplace as the buyer-facing roster of CREST-accredited providers (CREST states it replaced the previous member directory); the members search remains a listing surface; individual CREST intrusion-analyst / incident-manager exams are a people competence class. ISO/IEC 17025:2017 is the laboratory-competence standard; UKAS, A2LA, and ANAB publish searchable directories and schedules of accreditation; ILAC is the recognition arrangement among accreditation bodies, not a ranking. ASCLD is a membership society; ASCLD/LAB accreditation transferred to ANAB; ASCLD's accreditation toolkit names ANAB and A2LA as the US forensic-lab accreditors to ISO/IEC 17025 / 17020. NIST SP 800-86 (August 2006) remains the current final guide this page cites for integrating forensic techniques into IR — guidance, not a statute. SWGDE publishes consensus guidelines and best-practice documents for digital evidence collection, acquisition, and examination; they are not a statute and not a ranking of firms. NIST SP 800-61 Revision 2 remains the current final Computer Security Incident Handling Guide this cluster cites — guidance, not a statute.

Frequently asked questions

Is this a ranking?

No. It is a stated-criteria checklist: accreditation class (PFI, CREST Incident Response, ISO/IEC 17025 forensic-lab scope, ASCLD-class via ANAB/A2LA), jurisdiction, and media/cloud/mobile scope, verified against named public rosters. This page does not rank DFIR firms, does not name any, and does not reprint a roster. Not legal advice.

How do I verify a digital-forensics firm's accreditations?

Open the public roster for the class of work, not the firm's marketing site. PFI: PCI SSC PFI directory, checked at engagement. CREST IR: CREST Marketplace or members search, filtered to Incident Response company accreditation. ISO/IEC 17025: the current schedule on UKAS, A2LA, or ANAB naming methods and item types. ASCLD/LAB is historical; check ANAB or A2LA today. Last verified 7 September 2026.

Does PFI, CREST, or ISO/IEC 17025 mean a firm is the best?

No. Those are accreditation classes — independently assessed capability against a published scheme — not a league table and not a licence in every country. PFI is a cardholder-data investigation class. CREST IR is a company IR class. 17025 is a laboratory-competence standard whose digital-forensics claim lives in the schedule. Verify the CURRENT listing. This page does not rank firms.

Does ShipReady Metrics rank DFIR firms?

No. The product does not rank DFIR firms, does not keep a PFI / CREST / ISO/IEC 17025 roster, does not retain a firm, and does not produce a forensic report. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a forensic exam. Not legal advice.

Is court-admissibility a criterion you score?

No. Whether a later forum admits the work, and whether a named examiner can testify, are counsel's questions on YOUR facts. There is no public expert-witness roster this page will invent. NIST SP 800-86 and SWGDE describe method; they are not a guarantee of admissibility. Not legal advice.

Is this legal advice?

No. It is operational guidance distilled from the PCI SSC PFI directory, CREST accreditation and Marketplace / member roster, ISO/IEC 17025 directories (UKAS, A2LA, ANAB), NIST SP 800-86, and SWGDE published guidelines. Which firm to retain, whether privilege attaches, whether a copy is admissible, and whether a notification duty applies are questions for counsel on YOUR facts. This page does not rank DFIR firms.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.