BARR Advisory P.A.
BARR Advisory P.A. is a Kansas City-based cybersecurity and compliance consulting firm serving cloud and technology enterprises, delivering SOC, ISO/IEC, FedRAMP, CMMC, HIPAA/HITRUST, and privacy certifications through coordinated, multi-framework audit engagements.
- Company typePrivate
- Founded2014
- HeadquartersKansas City, United States
- Headcount51–100
- GTM typeB2B
- OfferingServices
What BARR Advisory P.A. does
BARR Advisory P.A. is a privately held cybersecurity and compliance consulting firm headquartered in Kansas City, founded in 2014 by Brad Thies. The firm specializes in helping cloud service providers and technology companies navigate complex, overlapping security and privacy frameworks, with active practices across SOC, ISO/IEC, HIPAA/HITRUST, FedRAMP, StateRAMP, CMMC, PCI DSS, GDPR, CCPA, and GLBA. BARR operates through two aligned entities: the parent professional services firm delivering advisory, managed, and assessment engagements, and BARR Certifications, a wholly-owned subsidiary serving as the accredited certification body for ISO/IEC standards. The company employs 51–100 staff and positions its Integrated Management System methodology as a differentiator for clients pursuing multiple frameworks simultaneously.
The firm's service portfolio is organized into four pillars: certifications and attestations (SOC 1/2/3, ISO/IEC, healthcare and government compliance), advisory and managed services (Virtual CISO, remediation, managed security awareness, continuous monitoring, vulnerability management), security assessments (penetration testing, risk, readiness, and vendor assessments), and GRC engineering (infrastructure and product security). Its coordinated audits approach maps common controls across frameworks, allowing organizations to test shared controls once and apply findings across SOC 2, ISO 27001, ISO 27701, and ISO 42001 — a methodology claimed to reduce audit duplication. Service delivery rests on professional-services economics: quote-based, multi-year engagements sold through enterprise field sales to security and compliance decision-makers.
BARR's go-to-market is sales-led and enterprise-focused, supported by thought-leadership content (Compliance Compass newsletter, blog, webinars, whitepapers, case studies) and named customer references spanning technology (Airtable, Quickbase, Securiti), financial services (C2FO, Sentry), healthcare technology (RxSense, Moazz), and government-adjacent SaaS firms. Pricing is not publicly disclosed. Recent strategic priorities include the March 2026 launch of ISO Trifecta coordinated audits (enabled by ANAB accreditation across all three frameworks), a February 2026 partnership with Drata for a CMMC Compliance Accelerator Program, and the Public Sector Ready initiative with Product Special Forces targeting federal, state, and local government markets.
BARR Advisory P.A. firmographics
Firmographics- Name
- BARR Advisory P.A.
- Legal name
- BARR Advisory, P.A.
- Website
- https://barradvisory.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- BARR Advisory P.A. is a Kansas City-based cybersecurity and compliance consulting firm serving cloud and technology enterprises, delivering SOC, ISO/IEC, FedRAMP, CMMC, HIPAA/HITRUST, and privacy certifications through coordinated, multi-framework audit engagements.
- Ownership category
- akta.pro rank
BARR Advisory P.A. industry classification
Industry- Product category
- Cybersecurity & Compliance Consulting
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
- akta.pro secondary industries
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Privacy, Consent & Data Protection Management (BPAEAPAF)
Keywords
Where BARR Advisory P.A. is headquartered
LocationHeadquarters
- HQ city
- Kansas City
- HQ country
- United States
- HQ region
- North America
Markets served
BARR Advisory P.A. business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Consulting Services: Advisory and managed services including Virtual CISO, program management, remediation and implementation, managed security awareness, continuous monitoring, and vulnerability management.
- Certification and Attestation Services: SOC examinations (SOC 1, SOC 2, SOC 3, SOC for Cybersecurity), ISO certifications, healthcare compliance certifications, and government compliance assessments.
- Security Assessments: Internal audit services, readiness assessments, risk assessments, vendor assessments, vulnerability assessments, penetration testing, and market enablement diligence.
- GRC and Engineering Services: Infrastructure security, product security, and GRC engineering services to help organizations build robust security programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements based on client needs |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels6 records
BARR Advisory P.A. product offering
Product offeringCore offering
BARR Advisory P.A. is a cybersecurity and compliance consulting firm that provides SOC examinations, ISO/IEC certifications, healthcare compliance (HIPAA/HITRUST), government compliance (FedRAMP, StateRAMP, CMMC, DFARS, NIST 800-53), and privacy and data protection services. It also delivers advisory and managed services such as Virtual CISO, continuous monitoring, vulnerability management, penetration testing, risk assessments, and GRC engineering, typically bundled into multi-year, custom-scoped consulting engagements.
Product overview
BARR Advisory P.A. is a cloud-based cybersecurity and compliance consulting firm that offers a comprehensive portfolio of certification, attestation, advisory, and assessment services. The core offerings include SOC examinations (SOC 1, SOC 2, SOC 3, SOC for Cybersecurity) and ISO Certification Services (ISO 27001, 27701, 27017, 27018, 42001). The company differentiates through its Coordinated Audits approach, combining multiple frameworks into single engagements, and its specialized Government Compliance practice covering FedRAMP, StateRAMP, CMMC, DFARS, and NIST 800-53. Additional services include Healthcare Compliance (HIPAA, HITRUST), Privacy & Data Protection (GDPR, CCPA, GLBA, PCI DSS), Advisory & Managed Services (Virtual CISO, remediation, continuous monitoring), Security Assessments (penetration testing, risk assessments), and GRC & Engineering. Strategic programs include the Public Sector Ready initiative (partnered with Product Special Forces) and the Drata-powered CMMC Compliance Accelerator Program.
Differentiator
Problem solved
Functional benefit
Products and services
- SOC Examinations SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity examinations that audit and attest to an organization's security, availability, confidentiality, processing integrity, and privacy controls, sold to enterprises seeking customer-facing trust reports.
- ISO/IEC Certification Services Certification services for ISO/IEC standards including ISO 27001 (information security), ISO 27701 (privacy), ISO 27017 (cloud security), ISO 27018 (cloud privacy), and ISO 42001 (AI management), offered to enterprises pursuing internationally recognized information security and privacy certifications.
- Coordinated Audits Integrated multi-framework audit approach that combines SOC, ISO, HIPAA, HITRUST, FedRAMP, CMMC, and other assessments into a single engagement using an Integrated Management System, reducing duplication and audit fatigue for organizations managing overlapping standards.
- Healthcare Compliance HIPAA and HITRUST certification and advisory services for healthcare organizations including hospitals, insurers, medical device manufacturers, and telehealth providers needing to demonstrate PHI protection and regulatory compliance.
- Government Compliance Federal and government compliance services covering FedRAMP, StateRAMP/GovRAMP, CMMC, DFARS, and NIST 800-53 assessments, delivered to cloud service providers and defense contractors pursuing authorization to serve U.S. public sector customers.
- CMMC Certification Assessments Cybersecurity Maturity Model Certification assessments helping defense contractors and the Defense Industrial Base achieve the certification levels required for Department of Defense contracts.
- Privacy & Data Protection Compliance Advisory and certification services for GDPR, CCPA, GLBA, PCI DSS, CSA STAR, and Microsoft DPR data protection requirements, helping organizations meet global privacy regulations and cloud security standards.
- Advisory & Managed Services Virtual CISO and program management, remediation and program implementation, managed security awareness, continuous monitoring, and vulnerability management services delivered to organizations that need ongoing cybersecurity leadership and operations.
- Security Assessments Internal audit, readiness assessments, risk assessments, vendor assessments, vulnerability assessments, cloud penetration testing, and market enablement diligence services for organizations seeking to validate their security posture.
- GRC & Engineering Infrastructure security, product security, and GRC engineering services that help organizations design, build, and maintain secure systems and compliance programs.
- CMMC Compliance Accelerator Program (CAP) Drata-powered program that combines compliance automation with BARR's federal compliance consulting to help defense contractors achieve CMMC certification faster, including gap analysis, policy review, and control implementation services.
- ISO Trifecta Coordinated Audits Coordinated audit offering covering ISO 27001 (information security), ISO 27701 (privacy), and ISO 42001 (AI management), enabling organizations to combine multi-standard audits into a single engagement via BARR Certifications' Integrated Management System.
- Public Sector Ready End-to-end program developed in partnership with Product Special Forces (PSF) that combines BARR's cybersecurity and compliance expertise with PSF's government sales strategy expertise to help technology firms enter and scale within federal, state, and local government markets.
Quantifiable outcome
- Organizations save more than 60 hours of internal effort through CMMC Compliance Accelerator Program
- +3 more outcomes
Companies that use BARR Advisory P.A.
Customer profileNamed customers11 records
Segments4 records
Ideal customer profiles3 records
BARR Advisory P.A. technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
BARR Advisory P.A. partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- DratacoreBARR Advisory partnered with Drata to launch a Compliance Accelerator Program (CAP) designed to help organizations achieve CMMC (Cybersecurity Maturity Model Certification) faster. The program integrates Drata's compliance automation platform with BARR's federal compliance consulting expertise, offering gap analysis, policy review, and control implementation services. According to BARR, the program saves organizations more than 60 hours of internal effort.
- Product Special Forces (PSF)corePublic Sector Ready is a first-of-its-kind, end-to-end solution combining BARR Advisory's cybersecurity expertise with PSF's government sales strategy expertise. PSF helps organizations align how they build, price, sell, deliver, and grow with how agencies plan, fund, buy, operate, and scale. PSF's portfolio spans $225M+ in ARR and over $1.3B in awarded public sector contract value.
- ANSI National Accreditation BoardcoreBARR Certifications, the certification body of BARR Advisory, is accredited by the ANSI National Accreditation Board (ANAB) to certify organizations against ISO standards including the ISO Trifecta (ISO 27001, ISO 27701, ISO 42001). BARR is among the first 10 U.S. firms with this accreditation for all three standalone frameworks.
Scale indicators4 records
Recent moves5 records
Expansion highlights5 records
BARR Advisory P.A. competitors and assessment
Company assessmentDirect peers
- Linford & Co. Linford & Co. is a cybersecurity audit firm specializing in SOC 2, ISO 27001, HITRUST, and PCI DSS for SaaS and tech startups. Direct peer at the smaller end of the segment with overlapping buyer personas and frameworks.
- 360 Advanced: 360 Advanced is a cybersecurity compliance and attestation firm providing SOC, ISO, HITRUST, FedRAMP, and PCI services. Closely comparable mid-sized peer with overlapping framework coverage.
- KirkpatrickPrice: KirkpatrickPrice provides SOC, ISO, PCI, and HITRUST audits for mid-market technology and healthcare firms. Closely comparable audit-focused service mix and similar SMB/enterprise client profile.
- Coalfire: Coalfire is a large cybersecurity advisory and assessment firm with deep FedRAMP, CMMC, HITRUST, and cloud security expertise. Direct peer particularly in federal/defense compliance, though larger and broader in scope than BARR.
- A-LIGN: A-LIGN is a closely comparable cybersecurity compliance and attestation firm offering SOC examinations, ISO 27001, HITRUST, FedRAMP, CMMC, and PCI assessments. Operates in the same buyer segment (mid-market and enterprise SaaS/healthcare/fintech) with a near-identical coordinated-audit value proposition.
- Schellman & Co. Schellman is a leading independent cybersecurity assessment firm providing SOC, ISO, HITRUST, FedRAMP, CMMC, and PCI services. Direct competitor in the upper-mid-market with a similar tech/cloud-services client mix and accredited certification body structure.
Emerging players
- Drata: Drata is a compliance automation platform that streamlines SOC 2, ISO 27001, HIPAA, and CMMC evidence collection. Currently a BARR partner (CMMC Compliance Accelerator Program), but increasingly competitive as it embeds more audit-readiness functionality that historically required BARR's advisory hours.
- AssuranceLab: AssuranceLab is a tech-focused audit firm delivering SOC 2, ISO 27001, and HITRUST for SaaS and cloud companies. Smaller and emerging, but competes directly for the same SaaS/startup client base as BARR.
Broad incumbents
- Deloitte (Cyber & Strategic Risk): Deloitte's Cyber & Strategic Risk practice offers SOC, ISO, FedRAMP, CMMC, and broader cyber advisory across global enterprises. A scaled incumbent that increasingly competes in BARR's mid-market and federal segments.
- EY (Cyber Security Consulting): EY's cybersecurity practice provides risk, compliance, and managed services including ISO, SOC, and FedRAMP advisory. A Big 4 incumbent that competes for multi-framework enterprise engagements with global delivery scale.
Market position
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
BARR Advisory P.A. social profiles
Digital presenceBARR Advisory P.A. compliance and trust
Trust signalCompliance18 records
BARR Advisory P.A. financial estimates
Financial estimateRevenue estimate
Valuation estimate
BARR Advisory P.A. leadership team
Management profileNumber of profiles
Profiles1 record
BARR Advisory P.A. subsidiaries and ownership
Company hierarchySubsidiaries1 record
BARR Advisory P.A. funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
BARR Advisory P.A. M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about BARR Advisory P.A.
What does BARR Advisory P.A. do?
BARR Advisory P.A. is a cybersecurity and compliance consulting firm that provides SOC examinations, ISO/IEC certifications, healthcare compliance (HIPAA/HITRUST), government compliance (FedRAMP, StateRAMP, CMMC, DFARS, NIST 800-53), and privacy and data protection services. It also delivers advisory and managed services such as Virtual CISO, continuous monitoring, vulnerability management, penetration testing, risk assessments, and GRC engineering, typically bundled into multi-year, custom-scoped consulting engagements.
Is BARR Advisory P.A. a public or private company?
BARR Advisory P.A. is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was BARR Advisory P.A. founded?
BARR Advisory P.A. was founded in 2014. It employs 51 to 100 people.
Where is BARR Advisory P.A. based?
BARR Advisory P.A. is headquartered in Kansas City, United States, in the North America region.
How does BARR Advisory P.A. make money?
Four revenue lines are on record. Cybersecurity Consulting Services are the primary driver. The others are certification and Attestation Services, security Assessments and GRC and Engineering Services.
Who are BARR Advisory P.A.'s main competitors?
Direct peers on record are Linford & Co., 360 Advanced, KirkpatrickPrice, Coalfire, A-LIGN and Schellman & Co.. Emerging players are Drata and AssuranceLab. Broad incumbents are Deloitte (Cyber & Strategic Risk) and EY (Cyber Security Consulting).
Does BARR Advisory P.A. have an API?
No public API is recorded for BARR Advisory P.A..
What industry is BARR Advisory P.A. in?
BARR Advisory P.A.'s product category is Cybersecurity & Compliance Consulting. Its primary akta.pro industry code is BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments, with a secondary code of BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory. Its NAICS code is 5616 and its SIC code is 8700.