Use cases

Find cybersecurity companies and security vendor decision makers

They are already in the databases. What is not in any database is whether their FedRAMP authorisation is live and at which impact level, which of their products carry a Common Criteria or FIPS 140-3 certificate, whether they assign their own CVEs, and when any of that last changed. Search on those, and Causo reads the FedRAMP Marketplace, the CVE Program list of Numbering Authorities, the Common Criteria certified products list and the IASME Cyber Essentials certificate search vendor by vendor, then shows you the evidence behind every match.

Run your first search

$240B forecast worldwide end-user spending on information security in 2026

Raccoon security team tracing a network graph on a wall display beside a printed diagram

How to find cybersecurity companies by authorisation, certification or product

  1. Run

3 results for this search. Pick another above to see what it returns.

Mystic Point Securitymysticpointsecurity.com92

118 staff across Boston and Cambridge, application security posture management sold to enterprise AppSec teams

Company site + Massachusetts corporations registry

Meredith …VP of Engineering Verified
Kendall Runtimekendallruntime.com89

Cambridge developer tooling vendor, 74 staff, container build and SBOM tooling sold to platform engineering teams

Careers page + GitHub release history

Arjun …Head of Product Verified
Neponset Labsneponsetlabs.com85

61 staff in Quincy, secrets scanning for CI pipelines, publishes its own security advisories

Company site + state business registry

Colleen …Co-founder and CTO Verified
Run this search in Causo

Illustrative example. The source types are the ones Causo genuinely reads for this market.

Where the data on cybersecurity companies comes from

  • FedRAMP MarketplaceCertification status, impact level, service model and the sponsoring agency for every US federal cloud service offering
  • CVE Program list of CVE Numbering Authorities, CISA and the NVDWhich vendors assign their own CVEs, the scope they cover and the root they sit under
  • Common Criteria Portal, BSI, ANSSI and NIAPCertified products by vendor, assurance level, protection profile and certificate date
  • NIST Cryptographic Module Validation ProgramFIPS 140-2 and FIPS 140-3 validated modules, the validating lab and the validation date
  • IASME Cyber Essentials certificate search and UKAS accredited ISO 27001 bodiesUK certification status, whether it is Plus level, and the date it was awarded
  • G-Cloud on the Digital Marketplace and SAM.govWhich products a UK or US public body can actually buy, the lot they sit in and awarded contracts
  • Companies House, Handelsregister, INPI, Bolagsverket and SEC filingsLegal entity, group structure, ownership changes and which subsidiary holds the certificate
  • GitHub releases, changelogs and security advisoriesWhether a developer tools vendor still ships, what it supports and who maintains it
  • Crunchbase and PitchBookFunding stage, investors and acquisitions across the security and developer tooling market
  • Plus many moreNo fixed provider list. If the answer lives somewhere else, the agents read that instead.

Ask anything about a cybersecurity or developer tools company

Every result is a starting point, not an endpoint. Ask a follow-up about any vendor on your list in plain English and the agents go back out and read for it, then answer with the sources they used.

Is their FedRAMP authorisation live, and at what impact level?
Answer

Certified at Moderate impact level, sponsored by a single civilian agency. A second offering is listed as Ready rather than Authorised, so it cannot be bought yet.

SourcesFedRAMP Marketplace listing + the vendor’s own trust page
Do they assign their own CVEs?
Answer

Yes. They have been a CVE Numbering Authority since 2023, with a scope limited to their own products, and they publish advisories themselves rather than through a distributor.

SourcesCVE Program partner list + the vendor’s advisory feed
Which of their products are actually certified, and how old is the certificate?
Answer

One appliance is certified at EAL4+ and the certificate was issued two years ago. The software gateway is not certified at all, and the most recent entry against it is a maintenance report.

SourcesCommon Criteria certified products list + national scheme certification reports

Why you can’t filter cybersecurity companies by certification or authorisation

$240Bforecast worldwide end-user spending on information security in 2026Gartner, July 2025
529cloud service offerings certified on the US FedRAMP MarketplaceFedRAMP Marketplace, August 2026
2,603firms active in the UK providing cyber security products and servicesDSIT Cyber Security Sectoral Analysis 2026

Contact databases are assembled from what companies publish about themselves: professional profiles, funding rounds, tech stacks, hiring pages. A security product company or a developer tools vendor produces all of that by default, so unlike a fabricator or a care home it is already in Apollo and ZoomInfo, with a headcount, a location and an industry label. The company is in the database. The thing you need to filter on is not. No contact database carries whether a vendor’s cloud offering is FedRAMP Authorised or merely In Process, which impact level it reached, which agency sponsored it, whether the vendor is a CVE Numbering Authority and what its CNA scope covers, which of its products hold a Common Criteria certificate and at what assurance level, whether a cryptographic module is FIPS 140-3 validated or still on a legacy 140-2 certificate, whether its Cyber Essentials Plus or ISO 27001 certificate is still in date, or which of its products a public body can actually buy through G-Cloud. Those facts live in the FedRAMP Marketplace, the CVE Program partner list, the Common Criteria portal, the NIST Cryptographic Module Validation Program, the IASME certificate search and the Digital Marketplace. None of those are where a profile-derived database looks, so the record you get back says "computer and network security, 90 employees, Boston" and stops exactly where a partner, distributor, auditor or investor starts qualifying.

Figures as of August 2026.

Apollo vs ZoomInfo vs Causo for cybersecurity company leads

Apollo / ZoomInfoBuying a listCauso
Filtering on "FedRAMP Authorised at Moderate impact level"No such fieldNo such fieldRead from the FedRAMP Marketplace listing
Telling a security product vendor apart from a reseller or an MSSPAll three sit under "computer and network security"Not distinguishedRead from product, pricing and documentation pages
Whether the vendor is its own CVE Numbering AuthorityNot trackedNot trackedRead from the CVE Program partner list
Common Criteria assurance level, FIPS validation and certificate dateNot trackedDate the list was compiledRead from the certification register at search time
Reaching the product security, compliance or channel leadUsually a shared sales addressOften bouncedNamed role, verified address

Frequently asked questions.

Because those are not fields in a contact database. Apollo and ZoomInfo cover cybersecurity and developer tools companies well, since the collection method is built on professional profiles, funding rounds, tech stacks and hiring pages, all of which a software vendor produces by default. What they hold is firmographic: headcount, location, industry label. FedRAMP status and impact level, CVE Numbering Authority status and scope, Common Criteria assurance level and certificate date are published elsewhere, in the FedRAMP Marketplace, the CVE Program partner list and the Common Criteria portal, and no filter can reach them.

Read the FedRAMP Marketplace rather than a contact database. It is the US federal government’s public catalogue of cloud service offerings, and for each one it publishes the certification status, the impact level, the service model and the agency that sponsored the authorisation. The distinction that matters when qualifying a vendor is between an offering that is fully authorised and one still listed as In Process or Ready, because only the first can be bought government wide. Causo reads that listing alongside the vendor’s own trust and compliance pages, so status and impact level become searchable criteria.

By reading what the firm sells rather than how it is labelled. All four sit under the same industry code in a contact database. The distinction shows up in whether there is a product with its own documentation and release notes, whether pricing is per seat or per engagement, whether the company publishes its own security advisories, whether it holds certifications in its own name rather than reselling someone else’s, and whether its engineering hiring is for product roles or for service delivery. Causo reads those pages, registers and job posts and reports which of the four a company actually is.

Start from the certification scheme, not the vendor. The Common Criteria Portal publishes every certified product with its assurance level, protection profile and certificate date, and national schemes such as BSI in Germany, ANSSI in France and NIAP in the United States publish their own certification reports underneath it. Separately, the NIST Cryptographic Module Validation Program, run jointly with the Canadian Centre for Cyber Security, publishes FIPS 140-2 and FIPS 140-3 validated modules by vendor with the validating laboratory and the validation date. Causo reads those registers, so assurance level and certificate age become filters rather than something you have to ask about on a call.

A CVE Numbering Authority, or CNA, is an organisation authorised by the CVE Program to assign CVE identifiers to vulnerabilities within an agreed scope, usually its own products. It matters when qualifying a vendor because becoming one requires a working disclosure process and a product security team, so CNA status is a strong signal that a company ships a real security product rather than reselling or wrapping someone else’s. The CVE Program publishes the full partner list, and CISA operates one of the roots, so the status is public and checkable.

The company, why it matched, the evidence behind that with its source, and the decision maker with a verified email address. For a security or developer tools vendor that typically means its FedRAMP status and impact level, whether it is a CVE Numbering Authority and what its scope covers, which products hold a Common Criteria or FIPS validation and when the certificate was issued, its UK certification position, and which legal entity holds each of those. You can then ask follow-up questions about any result and get answers with sources attached.

Yes. The Common Criteria Portal is international and covers schemes in more than twenty countries. The local layer differs: in the United States it is the FedRAMP Marketplace, SAM.gov, NIAP and the NIST Cryptographic Module Validation Program; in the United Kingdom it is the IASME Cyber Essentials certificate search, NCSC assured product listings, G-Cloud on the Digital Marketplace and Companies House; in Germany it is BSI certification reports and the Handelsregister, in France ANSSI and INPI, in Sweden Bolagsverket, and in Australia ASD and the Information Security Registered Assessors Programme. Causo reads whichever set applies to the country you are searching.

One token per researched company, per decision maker found, per question asked and per outreach sequence sent. Plans start at $10 a month, and the first 10 tokens are free with no card required.

Keep reading

Find cybersecurity companies and security vendor decision makers

Run your first search

10 free tokens. No card.