Skip to content
LokalMatch

Cybersecurity Consultants

Cybersecurity Consultants near you

Hiring a cybersecurity consultant in the United States starts with a question most buyers skip: which framework are we being measured against? A general business improving its defences, a defence subcontractor holding controlled unclassified information, a public company writing an annual disclosure and a clinic protecting patient records are all buying security work, but they are being judged by different documents and the engagements look nothing alike.

Tell us what you need and we’ll help you find cybersecurity consultants who serve your area.

Free for homeowners · No obligation to hire

On this page

The market divides roughly into assessment work, testing work and ongoing advisory work. An assessment compares what you do against a named standard and produces a gap list. Testing tries to break in and produces findings with evidence. Advisory work, sometimes sold as a fractional chief information security officer, supplies judgement over months rather than a document.

Nobody licenses this profession. Individual certifications exist and are widely held, but they certify a person, not the firm and not the engagement. The useful due diligence is on the scope statement: what is in scope, what standard is being used, what the deliverable will contain, and who is legally permitted to authorise the testing.

Types of cybersecurity engagement and what each produces

  • A risk assessment maps your controls to a chosen framework and produces a prioritised gap list with owners and target dates.
  • A penetration test attempts real exploitation within agreed limits and produces findings with proof, severity ratings and remediation steps.
  • A vulnerability assessment scans broadly for known weaknesses and produces a longer, shallower list that needs triage.
  • A tabletop exercise walks your leadership through a simulated incident and produces a record of where decision-making broke down.
  • A fractional or virtual chief information security officer supplies recurring hours for policy, vendor review and board reporting.
  • Incident response retainers buy a pre-agreed team, contact path and hourly rate before you need them, which is the point.
  • Compliance readiness work prepares evidence for a specific external assessment rather than improving security generally.

Choosing the standard: NIST CSF 2.0, SP 800-171 and CMMC

For most private businesses the default reference is the NIST Cybersecurity Framework 2.0, published in 2024. NIST describes it as a taxonomy of high-level cybersecurity outcomes usable by any organization regardless of size, sector or maturity, and stresses that it does not prescribe how the outcomes are achieved. It has six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was new in 2.0 and covers how cybersecurity decisions get made, which is where most small-company programs are weakest.

If you hold controlled unclassified information for a federal agency, the reference is NIST SP 800-171. Revision 3 was finalised in May 2024 and organises requirements into seventeen families, from access control and audit to supply chain risk management. It is written for nonfederal systems, which is exactly the position a contractor is in.

Defence work adds the Cybersecurity Maturity Model Certification. As of the Department's July 2026 announcement, Phase II requirements were suspended and a reform task force established, while Phase I self-assessment requirements remain in place; during the pause the Department enforces compliance with NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments. Level 1 covers fifteen requirements from FAR clause 52.204-21 with an annual self-assessment; Level 2 covers the 110 requirements of SP 800-171 Revision 2 required by DFARS clause 252.204-7012, with results entered into the Supplier Performance Risk System. A consultant working in this space should be able to state the current position without hedging.

What a security assessment actually delivers

A real assessment starts with a scope document naming the systems, locations, cloud tenants and business units included, and just as importantly the ones excluded. Vague scope is how two firms produce wildly different quotes for what looks like the same job.

The fieldwork is interviews plus evidence. A consultant asks how accounts are provisioned, then asks to see the last ten accounts created. They ask about backups, then ask for the last restore test record. Anything accepted on assertion alone is an opinion, not a finding, and a good report distinguishes the two.

The deliverable should be a findings register you can work from: each gap tied to a control reference, a severity, a recommended fix, an estimate of effort and a named owner. A plan of action with milestones is the form federal work expects and it is a sensible shape for anyone. Be wary of a report that is mostly scanner output with a cover page, and of one whose every recommendation happens to be a product the consultant resells.

Vulnerability scan, penetration test and red team compared

A vulnerability scan is automated. It compares software versions and configurations against a database of known issues and returns everything it matches. It is cheap, repeatable and noisy, and its output needs a human to separate the real exposure from the theoretical.

A penetration test is manual work on top of that. A tester chains weaknesses together to show what an attacker could actually reach, and documents the path with evidence. The value is in the chain, not the individual findings. Ask how many days of hands-on testing are included, because a one-day test that produces a fifty-page report was mostly a scan.

A red team exercise measures your detection and response rather than your patching. The team works toward a defined objective over a longer period and tries to stay unnoticed, and the interesting result is whether anyone spotted them. It only makes sense once monitoring exists, which is why buying one first is usually money spent proving a gap you already knew about.

Written authorization before anyone tests your systems

Testing involves deliberately attempting unauthorised access, so it needs authorisation in writing from someone with authority to give it. The scope should list the exact addresses, domains and applications in play, the testing window, the techniques excluded and an emergency contact on both sides.

If the systems are hosted, the hosting provider's own terms may govern what testing is permitted and how it must be notified. That is a question to settle before the test starts, not after a provider's abuse team notices traffic.

Social engineering and phishing simulations raise employment questions as well as technical ones, because they involve testing your staff. Decide in advance who is told, what is recorded, and whether individual results are reported to managers. Those decisions belong in the engagement letter, and your own employment counsel is the right person to review them.

Known exploited vulnerabilities and the patching argument

CISA maintains the Known Exploited Vulnerabilities catalog, an authoritative list of vulnerabilities it has confirmed are being exploited in the wild, and recommends organizations build it into how they prioritise remediation. It is a short, evidence-based list rather than the whole universe of published vulnerabilities, which makes it genuinely useful for deciding what to fix this week.

The associated binding operational directive applies to Federal Civilian Executive Branch agencies, not to private companies. BOD 26-04 requires those agencies to remediate on a risk-based schedule, with the shortest timeline reserved for publicly exposed assets carrying automatable exploits that grant total control and appearing in the catalog. Private firms are not bound by it, but the logic of the model, exposure plus confirmed exploitation plus impact, is worth borrowing.

A consultant who hands you every scanner finding sorted by a generic severity score has not done the prioritisation you were paying for. Ask for the internet-facing, actively exploited items first, then everything else.

Incident response, reporting duties and disclosure

Reporting obligations in the United States stack rather than replace each other. CISA is working on the final rule under the Cyber Incident Reporting for Critical Infrastructure Act of 2022, which sets a 72-hour window for covered cyber incidents and 24 hours for ransom payments by covered entities; until that rule is in effect CISA says reporting remains voluntary and encourages it. Confirm the current status rather than assuming.

Public companies have a separate duty. Under the SEC's rules, a registrant discloses a material cybersecurity incident on Form 8-K Item 1.05, generally within four business days of determining the incident is material, and describes its cybersecurity risk management, strategy and governance annually under Regulation S-K Item 106.

Then there is the state layer, which reaches almost everybody: the FTC notes that all states, the District of Columbia, Puerto Rico and the Virgin Islands have breach notification legislation covering personal information. A retainer that includes counsel and forensics is worth more than one that includes only technical cleanup, because the notification decisions are where the cost and the exposure sit.

What drives the price of a security engagement

  • Testing is priced in tester days, so the number of applications, external addresses and internal segments in scope moves it directly.
  • Assessment cost tracks the framework chosen, because a SP 800-171 gap analysis has far more control detail than a short framework review.
  • Evidence-heavy work for a regulated client costs more than an advisory conversation producing the same recommendations.
  • Retesting after remediation is sometimes included for a window and sometimes billed again, and the difference is worth asking about.
  • Retainers are usually a monthly minimum against an hourly rate, with a separate incident rate that may be considerably higher.
  • Remediation is almost never included in an assessment quote, so budget for the work the report creates as well as the report.

Cybersecurity Consultants: frequently asked questions

Which security framework should a US small business use?

For a general business with no sector mandate, the NIST Cybersecurity Framework 2.0 is the usual starting point. NIST describes it as usable by any organization regardless of size, sector or maturity, and it organises outcomes into six Functions: Govern, Identify, Protect, Detect, Respond and Recover. If you hold controlled unclassified information under a federal contract, SP 800-171 is the applicable document, with Revision 3 finalised in May 2024 across seventeen control families. Healthcare and financial services carry their own overlays. Pick one and be consistent, because switching frameworks mid-program mostly generates rework.

Is a penetration test the same as a vulnerability scan?

No. A scan is automated matching of your software and configuration against known issues, and it returns a long list that still needs triage. A penetration test is manual work in which a tester chains weaknesses together to demonstrate what an attacker could actually reach, with evidence for each step. Ask how many hands-on tester days a quoted test includes. If the answer is one or two days for a large environment and the deliverable is fifty pages, you are largely buying scanner output with commentary.

Do defence contractors still need CMMC?

The program's status changed recently, so verify it against the Department's own page before relying on anything. In July 2026 the Department announced an immediate suspension of CMMC Phase II requirements and established a reform task force, while Phase I self-assessment requirements remain in place. During the pause the Department enforces cybersecurity compliance with NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments. Level 1 covers fifteen requirements from FAR clause 52.204-21; Level 2 covers the 110 requirements of SP 800-171 Revision 2 under DFARS clause 252.204-7012, with results recorded in the Supplier Performance Risk System. The underlying duty to protect the information did not go away.

Is there a federal law requiring us to report a cyber incident?

There is no single general one. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 directs CISA to write rules requiring covered entities to report covered cyber incidents within 72 hours and ransom payments within 24 hours, but CISA has said the final rule is still being worked on and that reporting is voluntary until it takes effect. Public companies have a separate SEC duty to disclose material incidents on Form 8-K Item 1.05, generally within four business days of the materiality determination. Meanwhile every state has its own breach notification law covering personal information, which is what catches most private businesses.

How should we prioritise which vulnerabilities to fix?

Start with anything internet-facing that appears in CISA's Known Exploited Vulnerabilities catalog, which lists vulnerabilities confirmed to be exploited in the wild rather than merely published. CISA recommends organizations incorporate the catalog into their prioritisation. The federal directive built on it, BOD 26-04, applies only to Federal Civilian Executive Branch agencies, but its model is a sensible one to copy: weigh whether the asset is publicly exposed, whether the exploit is automatable, how much control it grants, and whether exploitation is confirmed. That ordering beats sorting a scanner report by severity score.

What do we need to sign before a consultant tests our systems?

A written authorisation from someone with authority to grant it, plus a scope document listing the exact addresses, domains and applications included, the testing window, excluded techniques, and named emergency contacts on both sides. If the systems are hosted, check the hosting provider's terms on security testing first. If phishing or social engineering is included, agree in advance who inside the company is informed, what is recorded about individual employees and how results are reported. Have your own counsel review the engagement letter; this guide is not legal advice.

Sources

  1. NIST Cybersecurity Framework
  2. NIST Cybersecurity Framework (CSF) 2.0, CSWP 29
  3. NIST SP 800-171 Rev. 3, Protecting CUI in Nonfederal Systems
  4. Department of War CIO: About CMMC
  5. CISA: Known Exploited Vulnerabilities Catalog
  6. CISA: BOD 26-04, Prioritizing Security Updates Based on Risk
  7. CISA: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
  8. SEC adopts rules on cybersecurity risk management and incident disclosure
  9. FTC: Data Breach Response, a guide for business

Written by the LokalMatch editorial team. Last reviewed September 22, 2026. How we write and check our guides

Find cybersecurity consultants by city

California

Show 186 cities

Florida

Show 82 cities

Texas

Show 79 cities

What affects the fees cybersecurity consultants charge

Fees depend on the work involved and how the professional bills. We only publish fee ranges when they’re backed by real LokalMatch data or reliable sources. Until then, here’s what usually changes the fee:

  • Scope and complexity of the work
  • How the firm bills: hourly, per project or on a monthly retainer
  • Experience of the team
  • Timeline and how urgent the work is
  • Ongoing support after the work is delivered

How to compare cybersecurity consultants before you hire

  • Ask for examples of similar work for clients like you.
  • Read reviews and ask for references you can contact.
  • Make sure the scope, deliverables and timeline are written down before work starts.
  • Ask who will do the work: an in-house team, freelancers or subcontractors.
  • Compare two or three proposals before you decide.

Questions to ask cybersecurity consultants before you hire

  • Have you done work like this before, and can I see examples?
  • Who will work on this, and who is my main contact?
  • How do you charge: hourly, per project or monthly?
  • What is included, and what costs extra?
  • How long is the contract, and how can either side end it?
  • How will you report on progress?
  • Who owns the work, files and accounts you set up for me?

Licences and registration

This kind of work is often limited to licensed or registered professionals, and the rules depend on where you are. Ask which body they’re registered with, and check their status on that body’s public register before you hire.

Ready to contact cybersecurity consultants?

Tell us what you need in a few sentences.