Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How to select a DFIR provider

Updated

Select a DFIR provider with a decision tree and stated criteria — accreditation class, insurer-panel constraint, jurisdiction, and scope — not a ranking. Red flags are listed. Not legal advice.

Operational guidance, last verified 7 September 2026 against NIST SP 800-61 Revision 2 (Computer Security Incident Handling Guide), NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), CREST Incident Response company accreditation as a capability class, the PCI SSC PCI Forensic Investigator (PFI) programme as a cardholder-data investigation class, and generic insurer panel-vendor norms in NAIC cyber-claims materials. This page does not rank DFIR firms, does not name any, does not reprint a roster, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The when-you-need-dfir page on this site is the retain-or-not tree. The what-is-dfir page on this site is the DFIR explainer. The best-digital-forensics-firms page on this site is the inclusion-criteria checklist. Not legal advice. Not procurement advice.

This is a selection tree, not a vendor list

Audience: a CISO, founder, CTO, counsel, or incident commander choosing which DFIR provider to retain — before an incident if you can, under time pressure if you cannot. The when-you-need-dfir page on this site is the in-house-versus-firm decision. This page is the next step: how to select, using criteria you can defend, a decision tree, and a red-flag list. The what-is-dfir page on this site is the explainer (identify, preserve, analyze, report; forensic soundness; chain of custody). The best-digital-forensics-firms page on this site is the accreditation-class checklist against named public rosters. It does not rank DFIR firms, does not name any, and is not a directory. The incident-response-retainer page on this site is the retainer explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait decision tree. The questions-to-ask-an-incident-response-provider page on this site is the question bank. A dedicated best-incident-response-firms guide is not on this site yet.

NIST SP 800-61r2 is the Computer Security Incident Handling Guide this cluster cites — guidance, not a statute. Its preparation phase is where you establish contact with external parties (IR teams, law enforcement, and other stakeholders) before you need them; selection under duress is the failure mode that preparation is meant to avoid. NIST SP 800-86 is a guide to integrating forensic techniques into incident response — also guidance, not a statute. It assumes trained people, procedures that preserve integrity, and a reconstructable method, and it tells readers to consult management and legal counsel before applying the practices. CREST Incident Response is a company-level capability class assessed against a published standard. PCI SSC's PFI programme qualifies companies to investigate suspected cardholder-data compromises; the Council tells clients to check the current list each time they engage a PFI. None of those sources is a ranking of firms. Last verified 7 September 2026. Not legal advice. Not procurement advice.

  • A DFIR provider is a retained role, not a trophy vendor. Select against THIS incident's work class, not a blog's 'top firms' list. This page does not rank DFIR firms and does not name any.
  • If you have a cyber policy, the panel or prior-consent clause is a contract constraint. It is not a quality ranking. Notice the carrier before you retain off-panel. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • Counsel-directed DFIR is common practice so working papers can sit under attorney-client privilege and work-product. That is practice, not a ruling that privilege will attach. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • Accreditation is a class (PFI, CREST Incident Response, ISO/IEC 17025 forensic-lab scope, regional CIR). Verify the CURRENT listing and the CURRENT scope. A slide-deck logo is marketing.
  • This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, is not legal advice, and is not procurement advice.

Decision tree — how to select

Walk top to bottom with the commander and counsel. A 'yes' on an earlier row does not skip the later questions: a panel clause still applies after you decided you need a firm; a matching accreditation class does not replace jurisdiction or scope. Last verified 7 September 2026. Not legal advice. Not procurement advice.

How to select a DFIR provider (questions for the commander and counsel — not a determination, not a ranking, not legal advice, not procurement advice)
QuestionIf the facts point yesIf the facts point no
Have we decided we need a firm at all — forensic capture we cannot do in-house, regulated data, theft unknown, litigation in view, or an insurer panel?Continue this tree. The when-you-need-dfir page on this site is the retain-or-not decision. Do not skip panel, class, jurisdiction, or scope because a brand is famous. This page does not rank firms.Stay with the in-house method if capture is sound and counsel agrees. You can still bring a firm later for analysis. Do not retain a firm as theatre.
Does YOUR cyber policy have a panel or prior-consent clause for DFIR, counsel, or restorers?Notice the carrier (or the broker) before you pick a firm. Use the panel or get written consent. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. That is a contract role, not a ranking. Verify YOUR policy. The contact-cyber-insurance page on this site is the notice-and-panel checklist.The tree still applies. Do not invent a panel. Select on the criteria below; you are not using a carrier list as a substitute for class, jurisdiction, or scope.
What accreditation class matches THIS work — PFI (cardholder-data compromise), CREST Incident Response (company IR/forensics class), ISO/IEC 17025 digital-forensics lab scope, or a regional CIR scheme?Open the named public roster for that class and check the company, status, region, and scope — not a logo. PCI SSC: check the PFI list each time you engage. CREST Marketplace / members search: filter Incident Response company accreditation. The best-digital-forensics-firms page on this site is that checklist.Do not treat a neighbouring class as a pass. PFI is not a general forensics licence. CREST membership without IR accreditation is not the IR class. A 17025 certificate for another discipline is not a digital-forensics scope.
Does the roster listing and the engagement cover the jurisdiction that actually applies — country, legal process, evidence storage, who can testify?Match region and engagement geography. Ask counsel where the work will be done and where the evidence will live. A UK NCSC CIR or UKAS 17025 listing does not, by itself, authorise work everywhere. A US PFI listing is a PCI class, not a global forensics licence.Do not select a firm whose only listing is in another country with no data-residency answer. 'We work globally' with no roster region is a red flag, not a criterion.
Does the assessed scope cover the sources you actually have — host/disk media, cloud identity and logs, mobile, OT?Read the schedule (17025 methods and item types; CREST IR environments; PFI is cardholder-data investigations). Cloud API collection is not the same as a write-blocked disk image. OT is not a host-image lab by default.Do not force-fit. A host-image lab asked to collect a multi-account cloud tenant with no scope for it is a miss — or the reverse. Scope is a class of assessed work, not a named case study this page will invent.
Will counsel retain and direct the firm, with a SOW that says the work is to assist counsel in giving legal advice?Common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Confirm with counsel before you sign.Do not assume privilege will attach after the fact. Dual-purpose ordinary-course IT work is a known waiver risk. That is practice, not a ruling. Not legal advice.
Is the examiner independent of the MSP, SOC, or internal team that runs the environment — unless counsel and the insurer have a reason to use the incumbent?Independence is a conflict criterion, not a preference for boutiques. An insurer-cleared retainer can still be the right firm.The operator of the estate is a fact witness, not always the examiner. Document the conflict if you proceed with the incumbent. Common practice, not a statute.
Can another examiner reconstruct the method — working copy, hashes, chain of custody, documented tools and versions, trained handlers (NIST SP 800-86 class)?Ask for the method statement and a sample custody record (fields, not a client file). The preserve-evidence page on this site is the order-of-volatility checklist. The chain-of-custody page on this site is the handling record.Live analysis on the original with no record, or 'we just run the tool,' is a red flag. Method is guidance, not a guarantee of admissibility. NIST SP 800-86 is not a statute.

Stated selection criteria, not a ranking

If the tree says retain, use criteria you can defend. The rows below are selection criteria. They are not a league table, not an endorsement, and not a directory. This page does not rank DFIR firms and does not name any. Last verified 7 September 2026. Not legal advice. Not procurement advice.

Stated criteria for selecting a DFIR provider (not a ranking, not a vendor list, not legal advice, not procurement advice)
CriterionWhat to askLimit
Accreditation classIs the company listed now for the class of work you need: PFI (cardholder-data compromise), CREST Incident Response (company IR/forensics capability class), ISO/IEC 17025 with a digital-forensics / computer / mobile scope, or a regional CIR scheme (for example UK NCSC CIR Standard or Enhanced)?Accreditation is a capability class, independently assessed against that scheme's standard. It is not a league table, not a licence in every country, and not 'these are the best firms.' Verify the CURRENT published list for YOUR jurisdiction; this page does not reprint one.
Insurer-panel constraintDoes YOUR form require this firm, or written consent to this firm, before DFIR costs are incurred?A contract role, not a quality score. NAIC cyber-claims materials describe panel and prior-agreement designs. Panel is not 'the best firms.' Verify YOUR policy. This page does not interpret it.
JurisdictionDo the roster listing and the engagement cover the country, legal process, evidence-storage location, and testimony location that actually apply?A UK NCSC CIR or UKAS 17025 listing does not, by itself, authorise work everywhere. A US PFI listing is a PCI class, not a global forensics licence. Counsel maps process.
Scope (cloud / OT / media / mobile)Does the assessed scope cover the sources in play: host/disk, cloud identity and logs, mobile devices, OT — not a generic 'we do DFIR' claim?Scope is a class of assessed work, not a named case study this page will invent. Cloud API collection is not a write-blocked disk image. PFI is a cardholder-data class, not every media type.
Counsel-directed statement of workWill counsel retain and direct the firm, with a SOW that says the work is to assist counsel in giving legal advice?Common practice, not a ruling that privilege or work-product will attach. Dual-purpose ordinary-course IT work is a known waiver risk. Confirm with counsel.
Forensic method (NIST SP 800-86 class)Working copy, integrity preservation, hashes, chain of custody, documented tools and versions, trained handlers? Can another examiner reconstruct the work?Method is guidance, not a guarantee of admissibility. NIST SP 800-86 is not a statute. The chain-of-custody page on this site is the handling record. The preserve-evidence page on this site is the order-of-volatility checklist.
Independence from the estate operatorIs the examiner independent of the MSP, SOC, or internal team that runs the environment, unless counsel and the insurer have a reason to use the incumbent?Independence is a conflict criterion, not a preference for boutiques. An insurer-cleared retainer can still be the right firm.
Surge / response-time as a contract termWhat surge do they actually staff for THIS class of work, on the clock YOUR incident needs? What does the SOW say happens if they cannot?A marketing SLA is not a ranking and not a statute. This page does not invent hour numbers. The incident-response-retainer page on this site is the retainer explainer.
Data-handling / DPAWhere will images, logs, and working papers live? Who can access them? What is the data-processing agreement for personal data on the evidence?A contract and privacy question for counsel, not a score this page can assign. This page does not draft YOUR DPA. Not legal advice.
Reporting that states limitsWill the report say what the evidence supports, what it does not, the methods, and who handled what — need-to-know, on the out-of-band channel?A forensic report is not a GDPR Article 33 notice, not a CRA Article 14 filing, and not insurer notice. Counsel owns what you may say. NIST SP 800-61r2: share information on a need-to-know basis.

Red flags

Any one of these is a reason to stop and ask counsel (and, if you have a policy, the carrier) before you sign. They are operational warnings, not a statute and not a scoring model. Last verified 7 September 2026. Not legal advice. Not procurement advice.

Red flags when selecting a DFIR provider (operational warnings — not a ranking, not legal advice, not procurement advice)
Red flagWhy it mattersWhat to do instead
Selecting from a blog 'top-N' brand listA ranking without stated criteria is marketing. This page does not rank DFIR firms and does not name any. Accreditation class, panel, jurisdiction, and scope are the criteria.Walk the decision tree. Check the current public roster for the class of work. The best-digital-forensics-firms page on this site is that checklist.
Retaining a favourite firm before insurer notice when the form has a panel or prior-consent clauseNAIC cyber-claims materials: some policies require a preapproved list; others require prior mutual agreement. A unilateral engagement is a coverage argument.Notice the carrier (or the broker) first. Use the panel or get written consent. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
Logo as accreditation — expired listing, membership quoted as the IR class, 17025 for another disciplinePCI SSC tells clients to check the PFI list at each engagement. CREST membership without Incident Response company accreditation is not the IR class. A chemistry 17025 schedule is not a digital-forensics scope.Open the named roster. Read status, region, and scope. The best-digital-forensics-firms page on this site names the directories.
'We work globally' with no roster region and no data-residency answerJurisdiction is a selection criterion. Evidence storage and testimony location are part of the engagement, not a slogan.Match the roster region to THIS incident. Ask counsel where the work will be done. A regional CIR listing is a regional class, not a global licence.
Scope mismatch — host-image lab for a multi-account cloud tenant, or a card-data PFI for OT with no card dataAssessed scope is the claim. PFI is a cardholder-data investigation class. Cloud API collection is not a write-blocked disk image.Read the schedule. If the sources you have are not in scope, keep walking the tree. Do not force-fit.
Signing before a counsel-directed SOW, then asking counsel to 'wrap privilege around it'Privilege is a legal question on YOUR facts. Dual-purpose ordinary-course IT work is a known waiver risk. Common practice is counsel retains DFIR.The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Confirm with counsel before you sign.
The MSP, SOC, or internal estate operator investigating themselves with no conflict noteIndependence is a conflict criterion. The operator is a fact witness, not always the examiner.Ask who images and who operates. An insurer-cleared retainer can still be the right call — ask the carrier and counsel. Document the exception.
No reconstructable method — live analysis on the original, no hashes, no custody record, untrained captureNIST SP 800-86: collection should preserve integrity; personnel should be trained for the method they use. A broken chain is how a later examiner cannot tell the copy in the report is the copy that was taken.Ask for the method statement and custody fields. The preserve-evidence page on this site is the capture list. The chain-of-custody page on this site is the handling record.
A marketing SLA quoted as if it were a ranking, or a retainer pitched as the only way to be 'best'Response time is a contract term, not a league table. The incident-response-retainer page on this site is the retainer explainer. This page does not invent hour numbers and does not rank retainers.Read the SOW. Ask what surge they actually staff. Panel and class still apply. Not procurement advice.

What you need to do now

Order is the failure mode. Shopping a favourite firm from a blog list, then asking counsel to wrap privilege around it, then telling the carrier, is the reverse of common practice. The sequence below is practice, not a statute. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice.

  • Preserve first. Do not reimage, power down a live host to 'save it,' or rotate logs before capture. The preserve-evidence page on this site is the order-of-volatility checklist. The we've-been-breached page on this site is the first-moves hub.
  • Walk the retain-or-not tree with the commander and counsel. The when-you-need-dfir page on this site is that tree. If you do not need a firm, stop. If you do, continue here.
  • If you have a cyber policy, notice the carrier before you pick a non-panel firm. Panel is a contract role, not a ranking. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • Walk this page's decision tree: accreditation class, panel constraint, jurisdiction, scope. Check the current public roster for the class of work. The best-digital-forensics-firms page on this site is that checklist. Do not trust a logo. This page does not reprint those lists and does not name firms.
  • Reject the red flags above. Empty answers on class, jurisdiction, or scope are unknowns, not a pass.
  • The questions-to-ask-an-incident-response-provider page on this site is the question bank: class, roster listing, jurisdiction, scope, method, custody fields, independence, surge as a contract term, and where evidence will live.
  • A dedicated information-to-give-a-dfir-firm guide is not on this site yet. Until it is: hand over the UTC timeline, the evidence-hold list, what you have already imaged, and what you have not — on the out-of-band channel. Do not reimage first.

Where this shows up in ShipReady Metrics

The signed-in app does not image hosts, keep a chain of custody, produce a forensic report, notice an insurer, or file with a regulator. It does not rank forensic vendors, does not retain a DFIR firm, does not keep a copy of your policy, and does not maintain a PFI, CREST, or ISO/IEC 17025 roster. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

NIST SP 800-61 Revision 2 (August 2012) remains the current final Computer Security Incident Handling Guide this cluster cites — guidance, not a statute; four IR phases; preparation includes establishing relationships with external parties before an incident. NIST SP 800-86 (August 2006), Guide to Integrating Forensic Techniques into Incident Response, remains the current final guide this page cites for the forensic process, integrity, chain of custody, trained personnel, and the instruction to consult management and legal counsel — guidance, not a statute, last verified still final on 7 September 2026. CREST publishes a company Incident Response accreditation standard (six domains, expert-led assessment) and, as of March 2026, CREST Marketplace as the buyer-facing roster of CREST-accredited providers; individual CREST intrusion-analyst / incident-manager exams are a people competence class. PCI SSC PCI Forensic Investigator directory and programme materials: PFIs investigate suspected cardholder-data compromises; they must work for a QSA company with a dedicated forensic practice; the Council tells clients to check the current list at each engagement. The UK NCSC Cyber Incident Response scheme assures providers at Standard Level and Enhanced Level; CREST is a delivery partner for Standard Level — a regional class, not a global ranking. NAIC cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. CISA's Federal Government Cybersecurity Incident and Vulnerability Response Playbooks are operational procedures for US FCEB systems; CISA notes other organizations may use them to standardize practice.

Frequently asked questions

How do you select a DFIR provider?

Walk a decision tree with counsel: retain-or-not first, then insurer-panel constraint, accreditation class for THIS work, jurisdiction, and scope (cloud / OT / media / mobile). Check the current public roster, not a logo. Use stated criteria, not a ranking. This page does not name firms. Not legal advice. Not procurement advice.

Is this a ranking?

No. It is a selection guide: a decision tree, stated criteria (accreditation class, panel constraint, jurisdiction, scope), and red flags. This page does not rank DFIR firms, does not name any, and does not reprint a roster. The best-digital-forensics-firms page on this site is the inclusion-criteria checklist. Not legal advice.

Does the insurer panel pick the firm for us?

Often it constrains the shortlist, but only YOUR form answers it. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. Notice the carrier before you retain off-panel. Panel is a contract role, not a ranking. Verify YOUR policy. Not coverage advice. Not legal advice.

Is CREST or PFI a ranking of DFIR firms?

No. They are capability classes. CREST Incident Response is a company accreditation against a published standard. PFI is a PCI SSC class for suspected cardholder-data compromises; check the current directory at engagement. Accreditation is not 'best firms,' not a global licence, and not this page's vendor list. Verify the CURRENT list for YOUR jurisdiction. Last verified 7 September 2026.

Does ShipReady Metrics rank or retain DFIR firms?

No. The product does not rank DFIR firms, does not retain a firm, does not keep a PFI / CREST roster, and does not produce a forensic report. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a forensic exam. Not legal advice.

Is this legal advice?

No. It is operational guidance distilled from NIST SP 800-61r2, NIST SP 800-86, CREST-style and PCI PFI accreditation classes, and NAIC panel-vendor norms. Which firm to retain, whether privilege attaches, whether a panel clause is satisfied, and whether a notification duty applies are questions for counsel and YOUR policy. This page does not rank DFIR firms and is not procurement advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.