Compass IT Compliance
Compass IT Compliance, LLC is a US-based cybersecurity and compliance consultancy (founded 2010, North Providence, RI) providing SOC audits, penetration testing, vulnerability management, vCISO services, and advisory across PCI DSS, HIPAA, CMMC, NIST, and other frameworks to enterprise and institutional clients across nine vertical industries.
- Company typePrivate
- Founded2010
- HeadquartersNorth Providence, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Compass IT Compliance does
Compass IT Compliance, LLC is a privately held, US-based cybersecurity and compliance consultancy founded in 2010 and headquartered at 2 Asylum Road, North Providence, Rhode Island. The firm delivers a full portfolio of professional services spanning SOC 1/2/3 reporting, penetration testing, vulnerability management (including web application, API, M365, EDR, and wireless assessments), Virtual CISO (vCISO) leadership, and advisory against 11+ frameworks (PCI DSS, HIPAA, CMMC, NIST 800-171, GLBA, CJIS, HECVAT, ISO 27001/27002, GDPR, CIS Critical Security Controls, MA 201 CMR 17). It also offers risk and business resiliency services including the proprietary Managed Risk Operations Center (mROC) and Data Insights, a data classification service powered by the Classify360 platform, plus AI Governance advisory. Two affiliated companies — Compass Cyber Guard (delivery) and Compass Assurance Team (audit) — sit within the broader Compass family of brands.
The firm's customer base spans nine vertical industries (Financial Services, Higher Education, Retail, Healthcare, Technology, Manufacturing, Hospitality, Nonprofit, Government) with named enterprise and institutional customers including loanDepot, WEX, Avidia Bank, Cabot Creamery, the Baltimore Ravens, Talkspace, University of Massachusetts, Ocean State Job Lot, Cooley Group, and Asplundh Tree Expert Co. Revenue is generated primarily through professional services engagements (assessments, audits, advisory, and vCISO retainers), supplemented by a white-label partner channel that delivers Compass services under other brands. Pricing is quote-based and customized per engagement; no standard pricing is published.
The operating model is consultative and expert-led, with distribution primarily through direct enterprise sales and channel partners. Marketing emphasis is on thought leadership — the firm maintains a 600+ article blog, a YouTube channel of educational webinars, downloadable resources, and participation in industry events such as ITEXPO and the EDUCAUSE Cybersecurity Conference. The firm is founder/operator-owned with no disclosed outside funding, no parent company, and operations confined to the United States.
Compass IT Compliance firmographics
Firmographics- Name
- Compass IT Compliance
- Legal name
- Compass IT Compliance, LLC
- Website
- https://compassitc.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Compass IT Compliance, LLC is a US-based cybersecurity and compliance consultancy (founded 2010, North Providence, RI) providing SOC audits, penetration testing, vulnerability management, vCISO services, and advisory across PCI DSS, HIPAA, CMMC, NIST, and other frameworks to enterprise and institutional clients across nine vertical industries.
- Ownership category
- akta.pro rank
Compass IT Compliance industry classification
Industry- Product category
- Cybersecurity Compliance Services
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
Where Compass IT Compliance is headquartered
LocationHeadquarters
- HQ city
- North Providence
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Compass IT Compliance business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Professional Consulting Services: Expert cybersecurity and compliance consulting delivered by security professionals, auditors, and virtual CISO services. Revenue generated through assessment, advisory, and implementation service engagements.
- Compliance Assessment Services: SOC 1, 2, & 3 audits, penetration testing, vulnerability assessments, and compliance certifications (PCI DSS, HIPAA, CMMC, NIST). One-time assessment and ongoing monitoring services.
- White Label Security Services: Security services provided to partners under their brand name, allowing channel partners to expand service offerings while leveraging Compass expertise.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Compass IT Compliance product offering
Product offeringCore offering
Compass IT Compliance delivers cybersecurity, IT audit, and compliance assessment services to organizations across nine verticals. Core deliverable offerings include SOC 1, 2, & 3 attestation reporting, penetration testing and vulnerability management, virtual CISO services, multi-framework compliance advisory (PCI DSS, HIPAA, CMMC, NIST, ISO 27002, GDPR, GLBA, CJIS, CIS Controls, MA 201 CMR 17), risk and business resiliency services (including its managed mROC offering), AI Governance advisory, social engineering and security awareness, cloud security assessments, and white-label security services for partners.
Product overview
Compass IT Compliance is a premier IT security, audit, and compliance assessment firm established in 2010. The company operates as a services-based consultancy rather than a software product company, offering a comprehensive portfolio of cybersecurity and compliance services. The core offerings include SOC 1, 2, & 3 reporting; Penetration Testing; Vulnerability Management (with sub-services including vulnerability assessments, web application scanning, firewall security review, API scanning, Microsoft 365 security assessments, EDR, and wireless network assessments); Virtual CISO (vCISO); Compliance Services (covering PCI DSS, NIST, HIPAA, CMMC, HECVAT, GLBA, CJIS, ISO 27002, GDPR, CIS Controls, and MA 201 CMR 17); Risk & Business Resiliency (including mROC, Data Insights, AI Governance, and vendor management); Social Engineering & Awareness; Cloud Security; and White Label Security Services. Affiliated brands include Compass Cyber Guard and Compass Assurance Team. The company serves industries including Financial Services, Higher Education, Retail, Healthcare, Technology, Manufacturing, Hospitality, Nonprofit, and Government.
Differentiator
Problem solved
Functional benefit
Products and services
- SOC 1, 2, & 3 Reports SOC reporting services that help service organizations achieve and document compliance with Trust Services Criteria, from criteria selection through audit completion, covering SOC 1, SOC 2 Type 1, SOC 2 Type 2, and SOC 3 engagements.
- Penetration Testing Offensive security testing that identifies and attempts to exploit critical vulnerabilities in applications, networks, and infrastructure, providing remediation insights prior to real-world attacks.
- Vulnerability Management Suite of services to detect, categorize, and score vulnerabilities across websites, applications, networks, and devices. Offered as a single bundled vulnerability management engagement that incorporates vulnerability assessments, web application scanning, firewall review, API scanning, Microsoft 365 security assessments, EDR, and wireless network assessments.
- Virtual CISO (vCISO) Engagement model providing veteran security professionals on a full- or part-time basis to identify risks and enhance security programs for organizations without a full-time CISO.
- Compliance Services Advisory and assessment services to achieve and maintain compliance with federal, state, and industry regulations and standards including PCI DSS, NIST, HIPAA, CMMC, HECVAT, GLBA, CJIS, ISO 27002, GDPR, CIS Critical Security Controls, and MA 201 CMR 17.
- CMMC Readiness & Assessment Cybersecurity Maturity Model Certification services guiding defense contractors through the CMMC journey, from initial scoping and gap assessments to POA&M development, SSP alignment, and full C3PAO assessment readiness at Levels 1, 2, and 3.
- PCI DSS Services Payment Card Industry Data Security Standard compliance services including CDE scoping, QSA-led assessments, and Report on Compliance (ROC) for merchants and service organizations handling cardholder data.
- Risk & Business Resiliency Comprehensive risk management and business resiliency services including IT risk assessments, outsourced IT audits, incident response planning, business continuity planning, IT policy templates, Managed Risk Operations Center (mROC), Data Insights, vendor management, business resilience review, AI Governance, and application risk assessments.
- Social Engineering & Awareness Security awareness and testing services including phishing assessments, security awareness training, and social engineering assessments designed to foster security awareness culture and simulate real-world attack scenarios.
- Cloud Security Assessment of organizational cloud infrastructure attack surface, identifying vulnerabilities in cloud controls and configurations across IaaS, PaaS, and SaaS environments.
- White Label Security Services Delivery of Compass IT security services under a partner's own brand name, enabling channel partners, MSPs, and resellers to expand their service offerings by leveraging Compass's assessors and proprietary platforms.
Companies that use Compass IT Compliance
Customer profileNamed customers17 records
Segments9 records
Ideal customer profiles3 records
Compass IT Compliance technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Compass IT Compliance partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Compass Cyber GuardcoreAffiliated company providing extended cybersecurity services. Operating as a separate entity under the Compass corporate umbrella.
- Compass Assurance TeamcoreAffiliated company providing assurance and assessment services. Part of the Compass IT Compliance corporate family of companies.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Compass IT Compliance competitors and assessment
Company assessmentDirect peers
- Schellman & Co: Schellman is a leading IT compliance and attestation firm offering SOC 1/2/3, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments. It is the closest direct competitor to Compass IT Compliance in audit breadth and mid-market/enterprise targeting.
- A-LIGN: A-LIGN provides SOC, ISO, PCI DSS, HITRUST, and FedRAMP audits along with cybersecurity consulting and penetration testing. Comparable in service mix (assessments + advisory) and SMB-to-enterprise target market to Compass IT Compliance.
- KirkpatrickPrice: KirkpatrickPrice specializes in SOC, PCI DSS, HITRUST, and ISO audits for SMB and mid-market clients. Highly comparable to Compass IT Compliance in service catalog and customer profile, with a similar audit-led business model.
- BARR Advisory: BARR Advisory delivers SOC, HIPAA, PCI DSS, ISO, and FedRAMP assessments with a focus on cloud and SaaS providers. Direct competitor in attestation services targeting technology and SaaS customers — a core vertical for Compass.
- Linford & Co: Linford & Co focuses on SOC 1, SOC 2, HITRUST, and ISO audits for SaaS and technology companies. Comparable in size and service mix to Compass, serving similar technology-vertical clients with similar assessment-driven revenue.
- 360 Advanced: 360 Advanced provides SOC, HITRUST, PCI DSS, ISO, and cybersecurity assessments, plus managed compliance services. Closely comparable mid-market compliance consultancy with overlapping service lines and customer base.
- Pivot Point Security: Pivot Point Security is a GRC-focused consultancy offering ISO 27001, SOC 2, PCI DSS, and HITRUST readiness and certification. Direct peer in delivering structured compliance and risk management services to mid-market clients.
- Prescient Security: Prescient Security delivers SOC, PCI DSS, HITRUST, ISO, and FedRAMP audits plus penetration testing and risk assessments. Comparable boutique compliance and cybersecurity firm with similar service breadth.
Broad incumbents
- Coalfire: Coalfire is a larger, well-established cybersecurity advisory and compliance firm with deep cloud (FedRAMP, Azure, AWS) and PCI DSS/QSA capabilities. Overlaps Compass's assessment practice but operates at materially greater scale with broader cyber engineering services.
- Optiv: Optiv is a large cybersecurity solutions integrator and MSSP offering advisory, risk, and compliance services alongside managed security. Much larger scale than Compass; competes on enterprise compliance and risk engagements.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Compass IT Compliance social profiles
Digital presenceCompass IT Compliance compliance and trust
Trust signalCompliance13 records
Compass IT Compliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
Compass IT Compliance leadership team
Management profileNumber of profiles
Profiles1 record
Compass IT Compliance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Compass IT Compliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Compass IT Compliance
What does Compass IT Compliance do?
Compass IT Compliance delivers cybersecurity, IT audit, and compliance assessment services to organizations across nine verticals. Core deliverable offerings include SOC 1, 2, & 3 attestation reporting, penetration testing and vulnerability management, virtual CISO services, multi-framework compliance advisory (PCI DSS, HIPAA, CMMC, NIST, ISO 27002, GDPR, GLBA, CJIS, CIS Controls, MA 201 CMR 17), risk and business resiliency services (including its managed mROC offering), AI Governance advisory, social engineering and security awareness, cloud security assessments, and white-label security services for partners.
Is Compass IT Compliance a public or private company?
Compass IT Compliance is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Compass IT Compliance founded?
Compass IT Compliance was founded in 2010. It employs 11 to 50 people.
Where is Compass IT Compliance based?
Compass IT Compliance is headquartered in North Providence, United States, in the North America region.
How does Compass IT Compliance make money?
Three revenue lines are on record. Professional Consulting Services are the primary driver. The others are compliance Assessment Services and white Label Security Services.
Who are Compass IT Compliance's main competitors?
Direct peers on record are Schellman & Co, A-LIGN, KirkpatrickPrice, BARR Advisory, Linford & Co, 360 Advanced, Pivot Point Security and Prescient Security. Broad incumbents are Coalfire and Optiv.
Does Compass IT Compliance have an API?
No public API is recorded for Compass IT Compliance.
What industry is Compass IT Compliance in?
Compass IT Compliance's product category is Cybersecurity Compliance Services. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 5415 and its SIC code is 7370.