Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Questions to ask an incident response provider
Updated
Ask an IR provider about accreditation class (PFI, CREST, FedRAMP CSO), SLA, data handling, jurisdiction, tooling, deliverables, and cost model — then score the answers against good-answer and red-flag signals. Not a ranking. Not legal advice.
Operational guidance, last verified 7 September 2026 against NIST SP 800-61 Revision 3 (Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile) — current final as of April 2025; it superseded SP 800-61r2; it is guidance, not a statute — NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), CREST Incident Response company accreditation as a capability class, the PCI SSC PCI Forensic Investigator (PFI) programme as a cardholder-data investigation class, the FedRAMP Marketplace as a cloud-service-offering authorization roster (not an IR-firm directory), FedRAMP Incident Evaluation and Communication rules for FedRAMP-certified cloud service providers, and generic insurer panel-vendor norms in NAIC cyber-claims materials. This page does not rank DFIR firms, does not name any, does not reprint a roster, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The how-to-select-a-dfir-provider page on this site is the selection decision tree. The when-you-need-dfir page on this site is the retain-or-not tree. The best-digital-forensics-firms page on this site is the inclusion-criteria checklist. The information-to-give-a-dfir-firm page on this site is the intake checklist. The comparing-major-incident-response-providers page on this site is the named-brand criteria table (not a ranking; inclusion is not endorsement). The best-incident-response-firms page on this site is the inclusion-criteria checklist. The breach-investigation-cost page on this site is the cost-driver explainer. Not legal advice. Not coverage advice. Not procurement advice.
This is a question bank, not a ranking
Audience: a CISO, founder, CTO, counsel, or incident commander on a vendor call who needs questions that separate a qualified IR / DFIR provider from a slide deck. The how-to-select-a-dfir-provider page on this site is the selection decision tree (retain-or-not, panel, class, jurisdiction, scope). This page is the script for that call: grouped questions, why each one matters, a good-answer signal, and a red-flag answer. Print this page; the tables are the checklist. The when-you-need-dfir page on this site is the in-house-versus-firm decision. The best-digital-forensics-firms page on this site is the accreditation-class checklist against named public rosters. The incident-response-retainer page on this site is the retainer explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. The chain-of-custody page on this site is the handling record. It does not rank DFIR firms, does not name any, and is not a directory. The information-to-give-a-dfir-firm page on this site is the intake checklist. The comparing-major-incident-response-providers page on this site is the named-brand criteria table (not a ranking; inclusion is not endorsement). The best-incident-response-firms page on this site is the inclusion-criteria checklist.
NIST SP 800-61r3 is the current final incident-response guidance this page cites — a CSF 2.0 community profile, guidance, not a statute. It superseded SP 800-61r2 in April 2025. Preparation is where you establish contact with external parties before you need them; selection under duress is the failure mode that preparation is meant to avoid. NIST SP 800-86 is a guide to integrating forensic techniques into incident response — also guidance, not a statute. It assumes trained people, procedures that preserve integrity, and a reconstructable method, and it tells readers to consult management and legal counsel before applying the practices. CREST Incident Response is a company-level capability class assessed against a published standard. PCI SSC's PFI programme qualifies companies to investigate suspected cardholder-data compromises; the Council tells clients to check the current list each time they engage a PFI. FedRAMP authorizes cloud service offerings listed on the FedRAMP Marketplace; it is not a public roster of IR firms. FedRAMP 3PAO recognition is an assessor class (A2LA Cybersecurity Inspection Body), not an IR retainer class. Expert-witness standing is not a public roster — it is a counsel question on YOUR facts. None of those sources is a ranking of firms. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice.
- A DFIR provider is a retained role, not a trophy vendor. Ask about THIS incident's work class, not a blog's 'top firms' list. This page does not rank DFIR firms and does not name any.
- If you have a cyber policy, the panel or prior-consent clause is a contract constraint. It is not a quality ranking. Notice the carrier before you retain off-panel. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
- Counsel-directed DFIR is common practice so working papers can sit under attorney-client privilege and work-product. That is practice, not a ruling that privilege will attach. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
- Accreditation is a class (PFI, CREST Incident Response, ISO/IEC 17025 forensic-lab scope, regional CIR, FedRAMP CSO authorization if they will store evidence in a listed cloud). Verify the CURRENT listing and the CURRENT scope. A slide-deck logo is marketing.
- Empty answers on class, roster listing, jurisdiction, scope, method, custody, independence, surge, or where evidence will live are unknowns, not a pass.
- This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, is not legal advice, is not coverage advice, and is not procurement advice.
Decision tree — ask these after retain-or-not and panel
Walk top to bottom with the commander and counsel. A 'yes' on an earlier row does not skip the later questions: a panel clause still applies after you decided you need a firm; a matching accreditation class does not replace jurisdiction or scope. Then print the grouped checklists below. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice.
| Question | If the facts point yes | If the facts point no |
|---|---|---|
| Have we decided we need a firm at all — forensic capture we cannot do in-house, regulated data, theft unknown, litigation in view, or an insurer panel? | Continue. The when-you-need-dfir page on this site is the retain-or-not tree. Do not skip this bank because a brand is famous. This page does not rank firms. | Stay with the in-house method if capture is sound and counsel agrees. You can still bring a firm later for analysis. Do not retain a firm as theatre. |
| Does YOUR cyber policy have a panel or prior-consent clause for DFIR, counsel, or restorers? | Notice the carrier (or the broker) before you pick a firm. Use the panel or get written consent. Then ask the bank below of the panel or consented firm. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. That is a contract role, not a ranking. Verify YOUR policy. The contact-cyber-insurance page on this site is that checklist. | The bank still applies. Do not invent a panel. You are not using a carrier list as a substitute for class, jurisdiction, or scope. |
| Will counsel retain and direct the firm, with a SOW that says the work is to assist counsel in giving legal advice? | Common practice. Ask the bank on the out-of-band channel counsel names. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Confirm with counsel before you sign. | Do not assume privilege will attach after the fact. Dual-purpose ordinary-course IT work is a known waiver risk. That is practice, not a ruling. Not legal advice. |
Printable checklist — accreditation and authorization
These questions probe actual authorization, not a logo. Verify the CURRENT public roster for the class of work. PCI SSC: check the PFI list each time you engage. CREST Marketplace / members search: filter Incident Response company accreditation. FedRAMP Marketplace: search the named cloud service offering, not the IR brand. Expert-witness standing is not a roster. Last verified 7 September 2026. Not legal advice. Not procurement advice.
| Question | Why it matters | Good-answer signal | Red-flag answer |
|---|---|---|---|
| Which CURRENT public roster lists you for THIS work class — PFI, CREST Incident Response, ISO/IEC 17025 digital-forensics scope, or a regional CIR scheme — and what is the listing, region, and scope? | Accreditation is a class, independently assessed against that scheme's standard. A neighbouring class is not a pass. The how-to-select-a-dfir-provider page on this site is that tree. The best-digital-forensics-firms page on this site is the roster checklist. | A named roster, a current status, a region, and a scope that matches the sources you actually have. PCI SSC: check the PFI list at each engagement. CREST: company IR accreditation, not membership alone. | 'We are accredited' with no scheme, no listing, or a logo pack. CREST membership without IR accreditation. A 17025 certificate for another discipline. An expired listing. |
| If cardholder data may be in scope: are you a current PCI Forensic Investigator, working for a QSA company with a dedicated forensic practice? | PFI is a PCI SSC class for suspected cardholder-data compromises, not a general forensics licence. The Council tells clients to check the current list each time they engage a PFI. | Yes, with a current PFI listing you can open on pcisecuritystandards.org, QSA company, dedicated forensic practice, and a scope that is cardholder-data investigation. | 'We do PCI work' with no PFI listing. A QSA without a forensic practice. Treating PFI as a global IR licence for OT or cloud identity with no card data. |
| If you claim CREST: is it company Incident Response accreditation, or only membership / a people exam (CPIA / CRIA / CCIM as examples of a competence class)? | CREST Incident Response is a company-level capability class against a published standard. Individual CREST exams are a people competence class. CREST's published accreditation standards do not make individual exams mandatory for company accreditation. | Company IR accreditation on the current CREST Marketplace / members search, plus who will actually staff THIS engagement and whether those people hold a relevant competence-class exam. | 'We are CREST' meaning a person once sat an exam, or membership without IR accreditation. Refusing to say which listing. |
| If you claim 'FedRAMP IR' or FedRAMP authorized: which cloud service offering is on the FedRAMP Marketplace, at what impact level, and does that authorization cover where OUR evidence will live? | FedRAMP authorizes cloud service offerings, not IR firms as IR firms. A FedRAMP Marketplace listing is a CSO authorization. FedRAMP 3PAO recognition is an assessor class (A2LA Cybersecurity Inspection Body), not an IR retainer class. FedRAMP Incident Evaluation and Communication rules apply to FedRAMP-certified CSPs, not as a directory of IR firms. Last verified 7 September 2026. | A named CSO on marketplace.fedramp.gov, impact level, and a clear answer that evidence storage is in that authorized offering — or an honest 'we are not a FedRAMP CSO; evidence will live here instead,' with jurisdiction and DPA. If they are a 3PAO, they say so and do not confuse assessment with IR. | 'We are FedRAMP IR' with no CSO, no Marketplace URL, and no distinction between 3PAO assessment and incident response. Treating FedRAMP as a ranking of IR firms. |
| Have named examiners testified, or are they prepared to testify, in the jurisdiction and on the evidence class that actually applies? | Expert-witness standing is not a public roster. Court-admissibility is a legal question on YOUR facts (for example FRE 702 in US federal court is a rule of evidence, not a vendor list). Treat this as a counsel question, not a score this page can assign. | Named people, the jurisdiction, the evidence class, and whether counsel will qualify them. A 'we have not testified on this class; here is the method another examiner can reconstruct' can still be a good answer. NIST SP 800-86: method should be reconstructable. | 'Our reports are always admissible' or a count of 'wins.' Refusing to name who would take the stand. A marketing CV with no method. |
Printable checklist — SLA, surge, independence, and panel
Response time is a contract term, not a league table. Panel membership is a contract role, not a quality ranking. Independence is a conflict criterion. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice.
| Question | Why it matters | Good-answer signal | Red-flag answer |
|---|---|---|---|
| What is the contractual response-time term — clock start, after-hours staffing, class of work covered, and the remedy if you miss? | A marketing SLA quoted as if it were a ranking is a red flag on the how-to-select-a-dfir-provider page on this site. Surge is a contract term. The incident-response-retainer page on this site is the retainer explainer. This page does not invent hour numbers. | A SOW clause: when the clock starts, who is on the bridge, what work class is covered, and what happens if they miss. Named after-hours staffing, not a hope. | 'We respond in minutes' with no clock, no staffing, no remedy. An SLA used as a ranking. Refusing to put surge in the contract. |
| Who actually pages — a named team, or 'we will staff' — and are those people the ones assessed for the capability class? | Company accreditation is not the same as the people on YOUR engagement. CREST individual exams are a competence class, not a firm ranking. Confirm what YOUR engagement actually staffs. | Names or a named rota, the class those people hold, and whether the named people are the ones who image, analyse, and sign the report. | 'Our global bench' with no names and no class. Bait-and-switch from the accredited entity to an unnamed subcontractor. |
| Are you on OUR carrier's current panel, or do we need written consent to retain you? | If you have a cyber policy, panel or prior consent is often a condition of coverage. NAIC cyber-claims materials describe both designs. That is a contract role, not a ranking. Verify YOUR policy. The contact-cyber-insurance page on this site is that checklist. | Yes, with a way to confirm on the current list, or a written-consent path the broker will run before work starts. An existing retainer your policy already cleared is still a fact, not a ranking. | 'Insurers love us' with no panel check. Pressuring you to skip notice. Treating panel membership as 'we are the best.' |
| Are you independent of the MSP, SOC, or internal team that runs this estate? | Independence is a conflict criterion: the operator is a fact witness, not always the examiner. Common practice, not a statute. An insurer-cleared retainer can still be the right call — ask the carrier and counsel. | A clear yes, or a documented exception counsel and the carrier accept. Who images versus who operates is named. | The estate operator investigating themselves with no conflict note. 'We already have the logs' as a substitute for independence. |
Printable checklist — data handling, jurisdiction, and tooling
Where evidence lives, who can testify, and whether the method is reconstructable are selection criteria, not slogans. NIST SP 800-86: collection should preserve integrity; personnel should be trained for the method they use. Last verified 7 September 2026. Not legal advice.
| Question | Why it matters | Good-answer signal | Red-flag answer |
|---|---|---|---|
| Does the roster listing and the engagement cover the jurisdiction that actually applies — country, legal process, evidence storage, who can testify? | A UK NCSC CIR or UKAS 17025 listing does not, by itself, authorise work everywhere. A US PFI listing is a PCI class, not a global forensics licence. Ask counsel where the work will be done and where the evidence will live. | Match of roster region to THIS incident, plus where images and working papers will sit, and who can take the stand in that forum. | 'We work globally' with no roster region and no data-residency answer. Evidence in a country counsel has not mapped. |
| Where will images, memory, logs, and working papers live — country, cloud tenant, who holds keys — and will you process personal data under a DPA? | Data handling is a selection criterion. A DPA for personal data on the evidence is a counsel question. This page does not draft YOUR DPA. FedRAMP CSO authorization, if claimed, must cover this storage — see the accreditation checklist above. | Named location, named holder, subprocessors you can read, and a DPA path if personal data is on the evidence. Counsel signs the DPA, not the commander alone. | 'In our cloud' with no region, no tenant, no DPA. Mixing customer evidence into a multi-tenant lab with no isolation story. |
| What is the forensic method — working copy, integrity preservation, hashes, chain of custody, documented tools and versions, trained handlers? Can another examiner reconstruct the work? | NIST SP 800-86: acquire while preserving integrity; document the method. Method is guidance, not a guarantee of admissibility. The preserve-evidence page on this site is the order-of-volatility checklist. The chain-of-custody page on this site is the handling record. | A method statement: working copy, hash algorithm, custody fields, tool names and versions, who is trained. A sample (redacted) custody log. Live analysis on a working copy, not the original. | Live analysis on the original, no hashes, no custody record, untrained capture. 'We image in place.' Refusing to name tools. |
| Does assessed scope cover the sources we actually have — host/disk media, cloud identity and logs, mobile, OT? | Cloud API collection is not the same as a write-blocked disk image. OT is not a host-image lab by default. PFI is a cardholder-data investigation class. Scope is a class of assessed work, not a named case study this page will invent. | The schedule (17025 methods and item types; CREST IR environments; PFI if card data) names the sources you have. A no on OT or mobile, with a referral, can still be a good answer. | Force-fit: a host-image lab for a multi-account cloud tenant, or a card-data PFI for OT with no card data. 'We do all environments' with no schedule. |
Printable checklist — deliverables and cost model
A forensic report is not a GDPR Article 33 notice, not a CRA Article 14 filing, and not insurer notice. Cost-model questions are about what draws hours and what is out of scope — not a price this page will invent. The breach-investigation-cost page on this site is the cost-driver explainer. Last verified 7 September 2026. Not legal advice. Not financial advice. Not procurement advice.
| Question | Why it matters | Good-answer signal | Red-flag answer |
|---|---|---|---|
| Will the report say what the evidence supports, what it does not, the methods, who handled what — need-to-know, on the out-of-band channel? | Reporting that states limits is a selection criterion on the when-you-need-dfir and how-to-select-a-dfir-provider pages on this site. Counsel owns what you may say. CISA: do not tip the actor. | A sample table of contents: facts, method, limits, custody, who handled what. Separate working papers under counsel. No press draft as the deliverable. | A 'board-ready narrative' with no method and no limits. A report the firm wants to publish. Mixing notification language into the forensic findings. |
| Who owns the report, who can share it, and will you testify from it if counsel asks? | Work-product and privilege are legal questions on YOUR facts. Common practice is counsel retains DFIR so working papers can sit under privilege. That is practice, not a ruling. | Counsel owns the engagement; the firm will not share without counsel's instruction; named examiners will testify if asked. Dual-purpose ordinary-course IT work is flagged as a waiver risk. | The firm retains publication rights. Sharing with the MSP or the board without counsel. 'Privilege is automatic.' |
| What draws hours (or on-demand fees) — capture, analysis, reporting, meetings, testimony — and what happens at zero of a retainer bank? | Typical retainer terms (hours, SLA, rollover, panel, notice) are generic market design, not YOUR SOW. The incident-response-retainer page on this site is that explainer. This page does not invent hour numbers and does not invent dollar figures. | A written list of what draws the bank, who can open a ticket, and what happens at zero (true-up, stop, on-demand rates the SOW names). Out-of-scope named: ransom, restoration, notification, crisis communications — often separate panel vendors. | A blended rate with no scope. 'Don't worry about hours.' Treating unused hours as an ROI this page will not invent. |
| What is out of scope — ransom negotiation, restoration, customer notification, crisis communications — and which of those sit on a different panel vendor? | One IR engagement is not the whole response bench. CISA's #StopRansomware Guide lists the cyber insurance company as a response stakeholder. Notification is a counsel and, if you have a policy, carrier question. This page does not start a clock. | A named out-of-scope list and, if you have a policy, which of those roles are panel vendors. The who-to-call page on this site is the contact map. | 'We handle everything' with no panel check and no notice to the carrier. A restorer who also wants to be the examiner. |
Red-flag answers — walk away or keep asking
Any one of these is a reason to pause with counsel, not a statute. Empty answers are unknowns, not a pass. Last verified 7 September 2026. Not legal advice. Not procurement advice.
- A logo pack instead of a current public-roster listing for THIS work class (PFI, CREST IR, 17025 digital-forensics scope, regional CIR).
- 'We are FedRAMP IR' with no named cloud service offering on the FedRAMP Marketplace, or a 3PAO claiming that assessor recognition is an IR retainer class.
- 'Our reports are always admissible' or a count of expert-witness 'wins.' Expert-witness standing is not a public roster.
- A marketing SLA with no clock, no staffing, and no remedy — quoted as if it were a ranking.
- 'Insurers love us' while skipping YOUR panel or prior-consent clause. Notice the carrier first. Verify YOUR policy.
- The MSP, SOC, or internal estate operator investigating themselves with no conflict note.
- 'We work globally' with no roster region and no data-residency answer.
- Live analysis on the original, no hashes, no custody record, untrained capture. NIST SP 800-86: preserve integrity.
- Signing before a counsel-directed SOW, then asking counsel to 'wrap privilege around it.'
- A blended rate with no scope, or a promise this page will not price. The breach-investigation-cost page on this site is the cost-driver explainer.
What you need to do now
Order is the failure mode. Shopping a favourite firm from a blog list, then asking counsel to wrap privilege around it, then telling the carrier, is the reverse of common practice. The sequence below is practice, not a statute. Last verified 7 September 2026. Not legal advice. Not coverage advice. Not procurement advice.
- Preserve first. Do not reimage, power down a live host to 'save it,' or rotate logs before capture. The preserve-evidence page on this site is the order-of-volatility checklist. The we've-been-breached page on this site is the first-moves hub.
- Walk the retain-or-not tree with the commander and counsel. The when-you-need-dfir page on this site is that tree. If you do not need a firm, stop. If you do, continue here.
- If you have a cyber policy, notice the carrier before you pick a non-panel firm. Panel is a contract role, not a ranking. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
- Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
- Walk the how-to-select-a-dfir-provider page on this site: accreditation class, panel constraint, jurisdiction, scope. Check the current public roster for the class of work. The best-digital-forensics-firms page on this site is that checklist. Do not trust a logo.
- Print this page. Ask the grouped checklists above: class, roster listing, FedRAMP CSO if they claim it, expert-witness as a counsel question, SLA, named staff, independence, where evidence will live, method, custody fields, deliverables, and what draws hours. Empty answers are unknowns, not a pass.
- The information-to-give-a-dfir-firm page on this site is the intake checklist: assets, logs, access, UTC timeline, architecture. Hand over on the out-of-band channel counsel names. Do not reimage first. ShipReady Passport is a shareable posture snapshot some teams hand a provider during scoping; it is not a DFIR onboarding pack.
- The comparing-major-incident-response-providers page on this site is the named-brand criteria table (not a ranking; inclusion is not endorsement). The best-incident-response-firms page on this site is the inclusion-criteria checklist. This page does not rank firms and does not name any.
Where this shows up in ShipReady Metrics
The signed-in app does not rank forensic vendors, does not retain a DFIR firm, does not keep a PFI, CREST, or FedRAMP roster, does not interpret YOUR policy, does not image hosts, keep a chain of custody, produce a forensic report, notice an insurer, or file with a regulator. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. ShipReady Passport is a shareable posture snapshot some teams hand a provider during scoping; it is not a DFIR onboarding pack and not a substitute for the intake the firm will still run. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.
Primary sources (last verified 7 September 2026)
Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.
NIST SP 800-61 Revision 3 (April 2025), Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, is the current final this page cites — guidance, not a statute; it superseded SP 800-61r2; preparation includes establishing relationships with external parties before an incident. NIST SP 800-86 (August 2006), Guide to Integrating Forensic Techniques into Incident Response, remains the current final guide this page cites for the forensic process, integrity, chain of custody, trained personnel, and the instruction to consult management and legal counsel — guidance, not a statute, last verified still final on 7 September 2026. CREST publishes a company Incident Response accreditation standard (six domains, expert-led assessment) and, as of March 2026, CREST Marketplace as the buyer-facing roster of CREST-accredited providers; individual CREST intrusion-analyst / incident-manager exams are a people competence class. PCI SSC PCI Forensic Investigator directory and programme materials: PFIs investigate suspected cardholder-data compromises; they must work for a QSA company with a dedicated forensic practice; the Council tells clients to check the current list at each engagement. The FedRAMP Marketplace lists authorized cloud service offerings; it is not a roster of IR firms. FedRAMP 3PAO recognition requires A2LA Cybersecurity Inspection Body accreditation; that is an assessor class, not an IR retainer class. FedRAMP Incident Evaluation and Communication rules (Consolidated Rules for 2026) bind FedRAMP-certified CSPs on reportable incidents; they are not an IR-provider ranking. The UK NCSC Cyber Incident Response scheme assures providers at Standard Level and Enhanced Level; CREST is a delivery partner for Standard Level — a regional class, not a global ranking. NAIC cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. CISA's Federal Government Cybersecurity Incident and Vulnerability Response Playbooks are operational procedures for US FCEB systems; CISA notes other organizations may use them to standardize practice. CISA's #StopRansomware Guide lists the cyber insurance company as a response stakeholder. The FTC Data Breach Response guide is US regulator guidance for businesses: a team that can include legal and forensics; do not destroy forensic evidence.
Frequently asked questions
What questions should you ask an incident response provider?
Ask grouped questions: current accreditation class and roster listing for THIS work (PFI, CREST Incident Response, 17025, regional CIR); if they claim FedRAMP, which CSO is on the Marketplace; expert-witness as a counsel question; contractual SLA and named staff; panel or prior consent; independence from the estate operator; jurisdiction and where evidence will live; reconstructable method and custody fields; report limits; what draws hours. Score answers against good-answer and red-flag signals. This page does not rank firms. Not legal advice. Not procurement advice.
Is this a ranking?
No. It is a question bank: grouped, printable checklists with why-it-matters, good-answer, and red-flag columns. This page does not rank DFIR firms, does not name any, and does not reprint a roster. The how-to-select-a-dfir-provider page on this site is the selection tree. The best-digital-forensics-firms page on this site is the inclusion-criteria checklist. Not legal advice.
Is CREST, PFI, or FedRAMP a ranking of IR firms?
No. They are classes. CREST Incident Response is a company accreditation against a published standard. PFI is a PCI SSC class for suspected cardholder-data compromises; check the current directory at engagement. FedRAMP authorizes cloud service offerings on the Marketplace; it is not an IR-firm roster. FedRAMP 3PAO is an assessor class, not an IR retainer class. Accreditation is not 'best firms.' Verify the CURRENT list for YOUR jurisdiction. Last verified 7 September 2026.
How do you probe a 'FedRAMP IR' claim?
Ask which cloud service offering is on the FedRAMP Marketplace, at what impact level, and whether that authorization covers where YOUR evidence will live. FedRAMP authorizes CSOs, not IR firms as IR firms. A 3PAO is an assessor, not an incident-response retainer. 'We are FedRAMP IR' with no CSO is a red flag. Last verified 7 September 2026. Not legal advice.
Is expert-witness standing a public roster?
No. Court-admissibility and expert-witness standing are questions for counsel on YOUR facts (for example FRE 702 in US federal court is a rule of evidence, not a vendor list). Ask who would testify, in which forum, on which evidence class. A reconstructable NIST SP 800-86-class method still matters if they have not testified. This page does not score witnesses. Not legal advice.
Does ShipReady Metrics rank or retain DFIR firms?
No. The product does not rank DFIR firms, does not retain a firm, does not keep a PFI / CREST / FedRAMP roster, and does not produce a forensic report. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a forensic exam. ShipReady Passport is a shareable posture snapshot, not a DFIR onboarding pack. Not legal advice.
Is this legal advice?
No. It is operational guidance distilled from NIST SP 800-61r3, NIST SP 800-86, CREST-style and PCI PFI accreditation classes, FedRAMP Marketplace CSO authorizations, and NAIC panel-vendor norms. Which firm to retain, whether privilege attaches, whether a panel clause is satisfied, and whether a notification duty applies are questions for counsel and YOUR policy. This page does not rank DFIR firms and is not procurement advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.