Keepgrade and the AI assistant do not accredit, certify, authorize, attest, or audit organizations. A “Verified” listing means the submitted listing information was reviewed against public records at a stated date and within a stated scope. It does not confer 3PAO, C3PAO, ISO certification-body, SOC auditor, or investigator status. Readiness-only providers are advisory and never hold certification authority; official work and outcomes remain a separate engagement between your organization and the professional.

Independent Assessor Marketplace · AI readiness copilot

From compliance confusion to continuous global readiness.

Keepgrade gives global small and midsize organisations a continuous AI readiness copilot between formal engagements — spanning FedRAMP, StateRAMP, SOC, HIPAA, ISO 27001, NIST CSF, NIST 800-171, and CMMC Levels 1–3 — and the marketplace to find the right assessor when you need to attest or certify.

Frameworks we cover

Honesty before hype — every framework classified, never certified on your behalf.

Each row names the kind of authority behind it — Authorisation, Attestation, Certification, Third-party Assessment, Self-attestation, or Voluntary framework. The classification matches the kind of engagement an assessor issues for it.

  • FedRAMP

    Authorisation

    Agency ATO after a 3PAO assessment. We run the readiness copilot and surface a 3PAO directory.

  • StateRAMP

    Authorisation

    State-level authorisation derived from FedRAMP. We run the readiness copilot and the assessor directory.

  • SOC 1

    Attestation (AICPA)

    AICPA attestation on service-organisation controls. Readiness copilot plus the SOC auditor directory.

  • SOC 2

    Attestation (AICPA)

    AICPA attestation on the Trust Services Criteria. Readiness copilot plus the SOC auditor directory.

  • SOC 3

    Attestation (AICPA, public)

    AICPA public-facing attestation report. Readiness copilot plus the SOC auditor directory.

  • HIPAA

    Voluntary framework

    Regulatory framework rather than certifiable. We run the readiness copilot to close evidence gaps.

  • ISO 27001

    Certification (Stage 1 + Stage 2 audit)

    Certificate issued by an accredited certification body after Stage 1 and Stage 2 audits.

  • NIST CSF

    Voluntary framework

    Voluntary cybersecurity framework. We run the readiness copilot to surface gaps.

  • NIST 800-171

    Voluntary framework (CUI)

    Voluntary framework for protecting Controlled Unclassified Information. Readiness copilot only.

  • CMMC Level 1

    Self-attestation (Foundational)

    Self-assessment against the Foundational controls. Readiness copilot plus an assessor directory.

  • CMMC Level 2

    Third-party assessment (Advanced)

    C3PAO assessment against the Advanced controls. Readiness copilot plus the assessor directory.

  • CMMC Level 3

    Certification (Expert, DoD-issued)

    DoD-issued certification after C3PAO assessment of the Expert controls. Copilot + assessor directory.

We do not issue certifications, attestations, or authorisations ourselves — and we do not imply we do. See the assessor marketplace for the authority types that do.

How it works

From a free score to a saved readiness report.

Three steps, no hidden paywalls in step one. Run the free 15-minute score, claim it with an account, then move into the AI-drafted assessment portal when you are ready for a written report.

  1. 01

    Run a free 15-minute readiness score

    Pick a framework, answer a 12-question NIST-CSF aligned rubric, and walk away with a per-framework 0–100 score and a gap map — no signup, no card.

  2. 02

    Sign up to claim your score

    Save your score, re-run with updated answers, and build a history per framework. Your submissions are scoped to your account only.

  3. 03

    AI-drafted assessment portal

    Get a written readiness report: per-NIST 800-171 gap analysis, prioritised remediation, and an evidence pack you can hand to your assessor on day one.

Where we work

Built for global operators — US, UK, and Sub-Saharan Africa first.

Keepgrade runs against the framework mix above from any English-speaking jurisdiction, with the markets below as our initial footprint.

Scope at a glance

What you get before you ever pick an assessor.

  • 12

    Frameworks covered

    FedRAMP, StateRAMP, SOC 1/2/3, HIPAA, ISO 27001, NIST CSF, NIST 800-171, and CMMC Levels 1–3 — honestly classified.

  • 5

    Independent assessor authority types

    FedRAMP 3PAO, StateRAMP 3PAO, AICPA SOC auditor, C3PAO/CMMC assessor, ISO certification body — each with distinct accreditation rules.

  • 4+

    Markets and growing

    United States, United Kingdom, Nigeria, Ghana — plus readiness scoring in any English-speaking jurisdiction.

Five authority types — clearly distinguished

Pick the right assessor for the engagement.

Each assessor in the marketplace belongs to exactly one or more authority types with distinct accreditation rules. A 3PAO does not self-authorise; an ISO CB issues the certificate only after Stage 1 + Stage 2; a SOC 2 auditor issues an attestation, not a certification. The marketplace makes those distinctions unmistakable.

Need a readiness copilot too?

Keepgrade drafts SSPs and POA&Ms between formal engagements, scores gaps against the rubric of your framework mix, and hands a tight evidence pack to your assessor on day one.

Keepgrade is a subsidiary of Volkmann Express Inc.