Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What are the best incident response firms?

Updated

What are the best incident response firms? This page is an inclusion-criteria checklist, not a ranking. Inclusion is not endorsement. Verify current public IR offerings, retainers, and accreditation class. Not legal advice.

Operational guidance, last verified 7 September 2026 against each named firm's current official IR page, the PCI SSC PCI Forensic Investigator (PFI) directory (a cardholder-data investigation class — check the current list at engagement; this page does not reprint it), CREST Marketplace company Incident Response accreditation (a company class, not a league table), the FIRST.org teams list (membership, not an accreditation), CISA incident-response materials, and the FedRAMP Marketplace (a cloud-service-offering authorization roster, not an IR-firm directory). This page does not rank firms, does not endorse anyone on it, does not interpret YOUR policy, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The how-to-select-a-dfir-provider page on this site is the decision tree. The questions-to-ask-an-incident-response-provider page on this site is the call script. Not legal advice. Not procurement advice.

This is an inclusion-criteria checklist, not a ranking

Audience: a CISO, founder, CTO, counsel, or incident commander shortlisting IR / DFIR providers against stated criteria. The search query says 'best'; the body of this page is not a ranking of firms. Inclusion on this page is a recognition set of brands the backlog named, refreshed against the live landscape on 7 September 2026 — not a quality ranking and not an endorsement. A missing roster listing is UNKNOWN, not a fail and not a pass. The how-to-select-a-dfir-provider page on this site is the decision tree (retain-or-not, panel, class, jurisdiction, scope). The questions-to-ask-an-incident-response-provider page on this site is the call script. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. The best-digital-forensics-firms page on this site is the forensics accreditation-class checklist against named public rosters. The comparing-major-incident-response-providers page on this site is the side-by-side criteria table. This page does not rank firms.

Rows are alphabetical by current public IR brand. That order is an index, not a score. Do not read the first row as a recommendation. CREST Incident Response is a company capability class. PCI PFI is a cardholder-data investigation class. FIRST.org membership is membership, not an accreditation. FedRAMP authorizes cloud service offerings, not IR firms as IR firms — this page does not treat FedRAMP as an IR-firm roster. Insurer panel is YOUR policy, not a public ranking; this page does not print a panel list. Expert-witness standing is not a public roster. Last verified 7 September 2026. Not legal advice. Not procurement advice.

  • Inclusion is not endorsement. A name on this table is not a recommendation to retain that firm.
  • Accreditation columns claim a listing only when this page opened the current public roster for THAT legal entity. Otherwise the cell says not verified on this page — check the current list. UNKNOWN is not a fail.
  • If you have a cyber policy, the panel or prior-consent clause is a contract constraint, not a quality ranking. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • This page does not rank firms, does not invent hourly rates, does not reprint a panel list, does not start a notification clock, is not legal advice, and is not procurement advice.

Stated inclusion criteria

A firm belongs on YOUR shortlist only when it meets the criteria that apply to THIS incident. The rows below are inclusion criteria. They are not a league table, not an endorsement, and not a directory. Cells in the named-firm table are as of last-verified, 7 September 2026 — check the current page and the current roster. Not legal advice. Not procurement advice.

Inclusion criteria for an incident-response firm (stated criteria — not a ranking, not an endorsement, not legal advice, not procurement advice)
CriterionWhat this page recordsHow to verifyLimit
Public IR offering under the current brandThe company currently sells incident response (or DFIR) on an official page under the current brand. If a named brand no longer sells IR under that name, the current equivalent is the row.Official IR page, last verified 7 September 2026. For M&A, the acquirer's closing announcement plus the current IR page.A public IR page is not assessed scope and not a ranking. A parent is not a quality score.
Accreditation class (CREST IR, PFI)Whether THIS legal entity is listed now for CREST company Incident Response, and whether PFI was verified on the PCI SSC directory for THIS entity.CREST Marketplace (buyer-facing roster; CREST states it replaced the previous member directory) filtered to Incident Response. PCI SSC PFI directory, checked at each engagement — PCI SSC says the list changes and is not guaranteed current at all times.CREST IR is a company class, not a global licence. PFI is a cardholder-data investigation class, not a general IR mark. A missing listing is UNKNOWN, not a fail. This page does not reprint either roster.
FIRST.org membership / national CERT classWhether a named team for that organisation appears on the current FIRST teams list. Membership is membership, not an accreditation. National CERT / ENISA-class rosters are a class to check for YOUR jurisdiction, not a column this page fills for every firm.FIRST.org members/teams list. Match the legal entity and the team name (CSIRT versus commercial IR versus PSIRT are different teams). For a national CERT class, check the current national roster that applies to YOU — not this page.A PSIRT listing is not a listing of the commercial IR engagement team. Absence is UNKNOWN, not a fail. FIRST contact details are for incident response, not solicitation.
Jurisdiction they publicly claimRegions, hotlines, or place-of-business the official page or CREST listing names.Official IR page; CREST Marketplace region fields; PFI region fields if you are in a cardholder-data investigation.A global marketing claim is not a licence in every country. Data residency and who can testify are counsel questions on YOUR facts.
Retainer versus on-demand (as they publicly describe it)Whether the current official page describes a retainer, on-demand / emergency IR, or both. As of last-verified; check the current page.Official IR and retainer pages. YOUR SOW names the actual SLA, hours, and true-up. The incident-response-retainer page on this site is the structure explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree.A public SLA headline is not YOUR contract. This page does not invent hourly rates and does not print a rate card.
FedRAMP (not an IR-firm class)FedRAMP authorizes cloud service offerings on the Marketplace. It is not a roster of IR firms. This criterion is a reminder, not a score.If a provider claims 'FedRAMP IR,' ask which CSO is on marketplace.fedramp.gov and whether that authorization covers where YOUR evidence will live.Do not treat FedRAMP as an IR-firm accreditation. A 3PAO is an assessor class, not an IR retainer class.
Insurer panel / expert witnessNot inclusion checkboxes this page can tick. Panel is YOUR policy. Expert-witness standing is not a public roster.Notice the carrier. Ask counsel who would testify, in which forum. The contact-cyber-insurance and contact-breach-counsel pages on this site are those checklists.This page does not print a panel list and does not score witnesses. Not legal advice. Not coverage advice.

Criteria table

Rows are alphabetical by current public IR brand after landscape verify on 7 September 2026. That order is not a ranking. Inclusion is not endorsement. A missing CREST, PFI, or FIRST cell is UNKNOWN — check the current list — not a fail and not a pass. As of last-verified; check each current page. Caption and cells are not legal or procurement advice. This page does not rank firms.

Major IR providers by stated inclusion criteria (alphabetical — not a ranking, not an endorsement, not legal advice, not procurement advice). Last verified 7 September 2026. Check current pages and current rosters.
Current brandParent / ownershipCREST IR (company class)PFI (PCI SSC)FIRST.org (membership)Scope as they publicly describe itJurisdiction as they publicly claimRetainer vs on-demand as they publicly describe it
CrowdStrike (CrowdStrike Incident Response Services)CrowdStrike Holdings, Inc. (public IR brand CrowdStrike). No 2025–2026 IR-brand replacement found on the official IR page.Not verified on this page — check the current CREST Marketplace listing for the legal entity that would sign YOUR SOW.Not verified on this page — check the current PCI SSC PFI list. PFI is a cardholder-data investigation class, not a general IR mark.CrowdStrike Security Incident Response Team (CSIRT) is listed on the FIRST.org teams list (US). Membership, not an accreditation.Official IR page describes 24/7 incident response, forensic investigation and remediation, adversary eviction, and a Services Retainer; work is described as covering endpoints, identities, and cloud. That is their description, not this page's audit.Official IR page describes global deployment. Check the current page and YOUR SOW for where work and evidence will actually live.Official pages describe both on-demand / emergency IR ('experienced a breach') and a Services Retainer with priority access. Check the current page and YOUR SOW. This page does not invent hourly rates.
Kroll (Kroll Cyber Incident Response)Kroll, LLC (public IR brand Kroll Cyber / Cyber and Data Resilience, as listed on CREST Marketplace). Ultimate parent not verified on this page — check current corporate filings.Listed on CREST Marketplace as Kroll LLC with company Incident Response accreditation (opened 7 September 2026). Verify the CURRENT listing at engagement.Not verified on this page — check the current PCI SSC PFI list. A marketing mention of PCI/PFI work is not a verified directory listing.Not verified on this page — a Kroll team slug was not found on the FIRST.org teams list opened 7 September 2026. Absence is UNKNOWN, not a fail. Check the current FIRST teams list.Official IR page describes 24x7 cyber incident response, digital forensics, and a Cybersecurity Incident Response Retainer; adjacent pages describe breach notification, eDiscovery, and litigation-support services as part of the wider cyber portfolio. That is their description, not this page's audit.CREST Marketplace listing names Asia & Pacific, Europe, and North America. Official IR page describes global IR. Check the current page for where evidence will live.Official pages describe both 24x7 on-demand IR and a Cybersecurity Incident Response Retainer. Check the current page and YOUR SOW. This page does not invent hourly rates.
Mandiant (Google Cloud Mandiant Cybersecurity Consulting)Google Cloud / Alphabet. Google completed the Mandiant acquisition on 12 September 2022; the Mandiant IR brand continues on cloud.google.com as of 7 September 2026.Listed on CREST Marketplace as Mandiant (part of Google Cloud) with company Incident Response accreditation (opened 7 September 2026). Verify the CURRENT listing at engagement.Not verified on this page — check the current PCI SSC PFI list.Mandiant Security is listed on the FIRST.org teams list (US). Membership, not an accreditation.Official consulting page describes incident response (preparedness, technical response, crisis management), a Mandiant Retainer, compromise assessments, and specialised OT/ICS consulting. That is their description, not this page's audit.CREST Marketplace listing names Europe and Middle East as listing regions. Official Google Cloud page is global. Check the current page for where evidence will live.Official pages describe both on-demand incident-response assistance and a Mandiant Retainer with pre-negotiated terms and a published 2-hour response-time headline. Check the current page and YOUR SOW. This page does not invent hourly rates.
Microsoft Defender Experts Cybersecurity Incident Response (DART)Microsoft Corporation. Current public IR brand on microsoft.com is Microsoft Defender Experts Cybersecurity Incident Response. Microsoft Learn still names the Microsoft Incident Response team as formerly DART/CRSP; DART remains the team name in 2026 Security Blog posts.Not verified on this page — check the current CREST Marketplace listing for the legal entity that would sign YOUR SOW.Not verified on this page — check the current PCI SSC PFI list.Microsoft Security PSIRT is listed on the FIRST.org teams list (US). That is a product-security team, not a listing of the commercial IR engagement team. Membership, not an accreditation. Check the current FIRST teams list.Official IR page describes reactive investigation, containment, recovery and eviction, plus proactive planning, assessment, simulation, and advisory services, with published use of Microsoft security telemetry and product-engineering access. That is their description, not this page's audit.Official IR page describes experts in more than 190 countries. Check the current page and YOUR account terms for where work and evidence will live.Official IR page describes reactive engagement with a published two-hour response headline and a suite of proactive services. Retainer language is not the headline on the current marketing page — check the current page, Premier / account terms, and YOUR SOW. This page does not invent hourly rates.
NCC GroupNCC Group plc (public IR brand NCC Group). No 2025–2026 IR-brand replacement found on the official IR pages.Listed on CREST Marketplace as NCC Group with company Incident Response accreditation (opened 7 September 2026). Verify the CURRENT listing at engagement.Not verified on this page — check the current PCI SSC PFI list.Not verified on this page — an NCC Group team slug was not found on the FIRST.org teams list opened 7 September 2026. Absence is UNKNOWN, not a fail. Check the current FIRST teams list.Official DFIR and incident-response pages describe incident readiness, incident-response management, recovery, and digital forensics, including a cyber incident response retainer. That is their description, not this page's audit.UK-headquartered. Official contact pages name UK & Europe, US & Canada, and APAC incident paths. CREST Marketplace listing names Asia & Pacific, Europe, Middle East, and North America. Check the current page for where evidence will live.Official pages describe both emergency IR and a cyber incident response retainer. Check the current page and YOUR SOW. This page does not invent hourly rates.
Sophos (IR successor to Secureworks)Sophos (Sophos Ltd / Sophos group; Sophos's 3 February 2025 closing release states Sophos is backed by Thoma Bravo). Sophos completed its acquisition of Secureworks on 3 February 2025. Current IR is sold as Sophos DFIR / Emergency Incident Response / Security Services Retainer. The Secureworks brand no longer sells IR as a standalone public IR page — sophos.com hosts the Secureworks-joins-Sophos landing. Former name noted once: Secureworks.Listed on CREST Marketplace as Sophos with company Incident Response accreditation (opened 7 September 2026). Verify the CURRENT listing at engagement. Do not assume a historical Secureworks listing still applies to the current legal entity without checking the current roster.Not verified on this page — check the current PCI SSC PFI list for the legal entity that would sign YOUR SOW (Sophos, not a retired Secureworks listing).Sophos CIRT is listed on the FIRST.org teams list (GB). Membership, not an accreditation. A historical Secureworks FIRST listing, if any, is not this row's current team.Official DFIR page describes emergency incident response, digital forensics, compromise assessment, threat hunting, and a Security Services Retainer with guaranteed DFIR. Adjacent Secureworks-joins-Sophos copy describes advisory services including incident response as the Secureworks portfolio is integrated. That is their description, not this page's audit.UK-headquartered. CREST Marketplace listing names Europe. Check the current page for where evidence will live.Official pages describe both Emergency Incident Response (on-demand) and retainer products (Security Services Retainer) with published SLA headlines. Check the current page and YOUR SOW. This page does not invent hourly rates.
Unit 42 (Palo Alto Networks)Palo Alto Networks, Inc. Unit 42 remains the public IR / threat-intelligence brand as of 7 September 2026. No IR-brand replacement found.Listed on CREST Marketplace as Palo Alto Networks (Netherlands) B.V with company Incident Response accreditation; the profile describes Unit 42 (opened 7 September 2026). Verify the CURRENT listing and which legal entity would sign YOUR SOW.Not verified on this page — check the current PCI SSC PFI list.Palo Alto Networks Security Incident Response Team (PAN PSIRT, CSIRT, and Unit42) is listed on the FIRST.org teams list (US). Membership, not an accreditation.Official Unit 42 IR page describes incident response (ransomware, cloud IR, APT, BEC, web-application attacks), forensic evidence collection, and forensically defensible reporting, plus a Unit 42 Retainer. That is their description, not this page's audit.Official IR page names regional incident hotlines for North America, UK, Europe and Middle East, Asia, Japan, and Australia. CREST listing for the Netherlands entity names Europe. Check the current page for where evidence will live.Official pages describe both emergency IR (hotline / under-attack form) and a Unit 42 Retainer. Check the current page and YOUR SOW. This page does not invent hourly rates.

How to use this checklist with the decision tree and question bank

Do not skip retain-or-not, panel, or class because a brand is on this page. Inclusion is a recognition set, not a shortlist you are required to use. Walk the sequence with the commander and counsel. Last verified 7 September 2026. Not legal advice. Not procurement advice. Not coverage advice.

  • Retain-or-not first. The when-you-need-dfir page on this site is that tree. If you do not need a firm, stop. Presence on this table is not a reason to retain.
  • If you have a cyber policy, notice the carrier before you pick a non-panel firm. Panel is a contract role, not a ranking, and is not a column this page can fill. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • Walk class, jurisdiction, and scope on the how-to-select-a-dfir-provider page on this site. Match THIS incident: PFI only if cardholder data may be in scope; CREST IR only if you are using that scheme; FIRST membership is not a substitute for either class.
  • Re-open the current public roster at engagement — CREST Marketplace, PCI SSC PFI directory, FIRST teams list. A cell on this page is last-verified 7 September 2026, not a live feed. UNKNOWN means check the list, not 'fail the firm.'
  • Print the questions-to-ask-an-incident-response-provider page on this site. Ask class, roster listing, jurisdiction, where evidence will live, method, custody fields, independence, SLA as a contract term, and what draws hours. Empty answers are unknowns, not a pass.
  • Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • The information-to-give-a-dfir-firm page on this site is the intake checklist: assets, logs, access, UTC timeline, architecture. Hand over on the out-of-band channel. Do not reimage first.
  • The comparing-major-incident-response-providers page on this site is the side-by-side criteria table. This page does not rank firms.
  • A dedicated incident-reporting-deadlines guide is not on this site yet. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for CRA-in-scope findings; that ladder is not a vendor shortlist and does not start a clock for you.

What changed (M&A and rebrands)

Ownership and brand notes below are taken from official pages and closing announcements this page opened. They are not a ranking. Last verified 7 September 2026.

Ownership and brand notes for named IR rows (sources and dates — not a ranking, not an endorsement)
RowWhat changedSource openedDate
MandiantGoogle completed its acquisition of Mandiant. The IR brand continues as Mandiant Cybersecurity Consulting on Google Cloud as of last-verified. Use the current Google Cloud Mandiant IR pages, not a pre-2022 independent-Mandiant URL, as the official service page.Google Cloud Mandiant consulting page (current brand). Contemporary close coverage of the 12 September 2022 completion.Close: 12 September 2022. Brand still live: 7 September 2026.
Secureworks → SophosSophos completed its acquisition of Secureworks on 3 February 2025. Current public IR is Sophos DFIR / Emergency Incident Response. This table uses Sophos as the current equivalent of the named Secureworks row because Secureworks no longer sells IR under that name as a standalone official IR page. Former name noted once.Sophos closing press release, 3 February 2025. Sophos Secureworks-joins-Sophos landing (opened 7 September 2026). Sophos DFIR / incident-response-services page.Close: 3 February 2025. Current IR brand: 7 September 2026.
MicrosoftThe current public marketing name is Microsoft Defender Experts Cybersecurity Incident Response. Microsoft Learn describes the Microsoft Incident Response team as formerly DART/CRSP. DART remains in use as the team name on 2026 Microsoft Security Blog posts. This row uses the current public name and notes DART once.microsoft.com Defender Experts Cybersecurity Incident Response page. Microsoft Learn ransomware-approach page (formerly DART/CRSP). Microsoft Security Blog, 2026.Current public name verified 7 September 2026.
Unit 42Remains Palo Alto Networks' public IR brand. No IR-brand replacement found on the official Unit 42 IR page.paloaltonetworks.com Unit 42 incident-response page.7 September 2026.
CrowdStrike, Kroll, NCC GroupNo 2025–2026 IR-brand replacement found on the official IR pages opened for this table. Current names used as listed.Each firm's official IR page, as linked in Primary sources.7 September 2026.

Glossary

Short definitions so a CISO, counsel, and founder can read the same table. They are not legal definitions. Last verified 7 September 2026. Not legal advice.

IR inclusion-criteria glossary (operational names — not legal definitions, not a ranking)
TermMeaning on this page
Recognition setThe named brands on this table after landscape verify. Inclusion is not endorsement and not a quality ranking.
Accreditation classIndependently assessed capability against a published scheme (CREST company Incident Response; PCI PFI). A class is not a league table.
CREST Incident ResponseA CREST company accreditation. Verify on CREST Marketplace. Membership without the IR accreditation is not the IR class.
PFIPCI Forensic Investigator. PCI SSC class for suspected cardholder-data compromises. Check the current directory at each engagement. Not a general IR mark.
FIRST membershipA team listed on FIRST.org. Membership, not an accreditation. A PSIRT listing is not a commercial IR listing.
FedRAMP MarketplaceAuthorization roster for cloud service offerings. Not an IR-firm directory. Do not score IR firms on FedRAMP.
UNKNOWN cellThis page did not verify that listing for that legal entity. Check the current roster. UNKNOWN is not a fail and not a pass.
RetainerA pre-breach contract that reserves IR / DFIR surge. Public SLA headlines are not YOUR SOW. The incident-response-retainer page on this site is the explainer.
On-demand / emergency IRScoping and retaining a firm after the incident is already running, as the vendor's current page describes it.
Insurer panelYOUR policy's recognised-vendor or prior-consent clause. Not a public ranking. This page does not print a panel list.

Where this shows up in ShipReady Metrics

The signed-in app does not rank, retain, or recommend IR firms. It does not sell IR, does not keep a PFI, CREST, FIRST, or FedRAMP IR-firm roster, does not interpret YOUR policy, and does not produce a vendor shortlist. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. Compliance surfaces also hold evidence artifacts (control-mapped collection and review for SOC 2 / ISO 27001-style programs — not a forensic exam and not a vendor shortlist). The cyber risk register lives under Security. The obligation map (frameworks you have marked in-scope) is under Compliance. None of those surfaces is a DFIR-firm comparison, a ranking, or a recommendation to retain anyone on this table.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

Official IR pages opened 7 September 2026: Google Cloud Mandiant Cybersecurity Consulting; CrowdStrike Incident Response Services; Kroll Cyber Incident Response Services; Palo Alto Networks Unit 42 Incident Response; Microsoft Defender Experts Cybersecurity Incident Response; NCC Group Incident Response / Digital Forensics and Incident Response; Sophos DFIR / incident-response-services. Ownership: Google-Mandiant close 12 September 2022 (current brand still Mandiant on Google Cloud); Sophos completes Secureworks acquisition, 3 February 2025, and the Sophos Secureworks-joins-Sophos landing. Microsoft Learn ransomware-approach page (Microsoft Incident Response team formerly DART/CRSP). PCI SSC PCI Forensic Investigator directory and programme materials: PFIs investigate suspected cardholder-data compromises; the Council tells clients to check the current list at each engagement; this page did not reprint company names from that directory because the public page is a live search, so every PFI cell is not verified on this page. CREST Marketplace company listings opened 7 September 2026 for Mandiant (part of Google Cloud), Kroll LLC, NCC Group, Sophos, and Palo Alto Networks (Netherlands) B.V — each showing Incident Response company accreditation on that date; CrowdStrike and Microsoft CREST IR listings were not found at the slugs tried, so those cells are not verified on this page. FIRST.org teams list opened 7 September 2026: CrowdStrike CSIRT, Mandiant Security, Palo Alto Networks Security Incident Response Team (including Unit42), Microsoft Security PSIRT, Sophos CIRT; Kroll and NCC Group team slugs were not found. FedRAMP Marketplace is a CSO authorization roster, not an IR-firm directory. CISA incident-response topic page and Incident Response Plan (IRP) Basics are operational US guidance, not a ranking of commercial firms. NIST SP 800-61 Revision 3 and NIST SP 800-86 remain guidance, not statutes, for IR and forensic method this cluster cites.

Frequently asked questions

Is this a ranking?

No. It is a stated-criteria inclusion checklist. Rows are alphabetical by current public IR brand. Inclusion is a recognition set, not a quality ranking, and inclusion is not endorsement. This page does not rank firms and does not assign scores. The how-to-select-a-dfir-provider page on this site is the decision tree. Not legal advice. Not procurement advice.

Is this legal advice?

No. It is operational guidance distilled from official IR pages, CREST Marketplace listings, the PCI SSC PFI directory as a class, the FIRST.org teams list as membership, and CISA incident-response materials. Which firm to retain, whether privilege attaches, whether a panel clause is satisfied, and whether a notification duty applies are questions for counsel and YOUR policy on YOUR facts. This page does not rank firms and is not procurement advice.

Is inclusion on this table an endorsement?

No. Inclusion is not endorsement. The backlog named these brands; this page refreshed ownership and current IR names and filled cells only where a current public roster or official page was opened. A missing CREST, PFI, or FIRST listing is UNKNOWN, not a fail. Do not treat a row as a recommendation.

Did you verify PFI, CREST, and FIRST for every firm?

Only where this page opened the current public roster for that legal entity. CREST Incident Response was verified on CREST Marketplace on 7 September 2026 for Mandiant (part of Google Cloud), Kroll LLC, NCC Group, Sophos, and Palo Alto Networks (Netherlands) B.V / Unit 42. CrowdStrike and Microsoft CREST IR were not verified on this page. No PFI company name was verified on this page — check the current PCI SSC PFI list at engagement. FIRST membership was verified for some teams and not others; a PSIRT listing is not a commercial IR listing. UNKNOWN is not a fail.

What happened to Secureworks?

Sophos completed its acquisition of Secureworks on 3 February 2025. Current public IR is Sophos DFIR / Emergency Incident Response. This table uses Sophos as the current equivalent because Secureworks no longer sells IR under that name as a standalone official IR page. Check the current Sophos legal entity on CREST, PFI, and FIRST — do not rely on a historical Secureworks listing. Not legal advice. Not procurement advice.

Does ShipReady Metrics rank or retain DFIR firms?

No. The signed-in app does not rank, retain, or recommend IR firms and does not sell IR. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a forensic exam and not a vendor shortlist. Evidence review, the obligation map, and the cyber risk register are product surfaces, not a DFIR-firm comparison. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.