Keepgrade and the AI assistant do not accredit, certify, authorize, attest, or audit organizations. A “Verified” listing means the submitted listing information was reviewed against public records at a stated date and within a stated scope. It does not confer 3PAO, C3PAO, ISO certification-body, SOC auditor, or investigator status. Readiness-only providers are advisory and never hold certification authority; official work and outcomes remain a separate engagement between your organization and the professional.
Independent Assessor Marketplace · AI readiness copilot
From compliance confusion to continuous global readiness.
Keepgrade gives global small and midsize organisations a continuous AI readiness copilot between formal engagements — spanning FedRAMP, StateRAMP, SOC, HIPAA, ISO 27001, NIST CSF, NIST 800-171, and CMMC Levels 1–3 — and the marketplace to find the right assessor when you need to attest or certify.
Frameworks we cover
Honesty before hype — every framework classified, never certified on your behalf.
Each row names the kind of authority behind it — Authorisation, Attestation, Certification, Third-party Assessment, Self-attestation, or Voluntary framework. The classification matches the kind of engagement an assessor issues for it.
FedRAMP
AuthorisationAgency ATO after a 3PAO assessment. We run the readiness copilot and surface a 3PAO directory.
StateRAMP
AuthorisationState-level authorisation derived from FedRAMP. We run the readiness copilot and the assessor directory.
SOC 1
Attestation (AICPA)AICPA attestation on service-organisation controls. Readiness copilot plus the SOC auditor directory.
SOC 2
Attestation (AICPA)AICPA attestation on the Trust Services Criteria. Readiness copilot plus the SOC auditor directory.
SOC 3
Attestation (AICPA, public)AICPA public-facing attestation report. Readiness copilot plus the SOC auditor directory.
HIPAA
Voluntary frameworkRegulatory framework rather than certifiable. We run the readiness copilot to close evidence gaps.
ISO 27001
Certification (Stage 1 + Stage 2 audit)Certificate issued by an accredited certification body after Stage 1 and Stage 2 audits.
NIST CSF
Voluntary frameworkVoluntary cybersecurity framework. We run the readiness copilot to surface gaps.
NIST 800-171
Voluntary framework (CUI)Voluntary framework for protecting Controlled Unclassified Information. Readiness copilot only.
CMMC Level 1
Self-attestation (Foundational)Self-assessment against the Foundational controls. Readiness copilot plus an assessor directory.
CMMC Level 2
Third-party assessment (Advanced)C3PAO assessment against the Advanced controls. Readiness copilot plus the assessor directory.
CMMC Level 3
Certification (Expert, DoD-issued)DoD-issued certification after C3PAO assessment of the Expert controls. Copilot + assessor directory.
We do not issue certifications, attestations, or authorisations ourselves — and we do not imply we do. See the assessor marketplace for the authority types that do.
How it works
From a free score to a saved readiness report.
Three steps, no hidden paywalls in step one. Run the free 15-minute score, claim it with an account, then move into the AI-drafted assessment portal when you are ready for a written report.
- 01
Run a free 15-minute readiness score
Pick a framework, answer a 12-question NIST-CSF aligned rubric, and walk away with a per-framework 0–100 score and a gap map — no signup, no card.
- 02
Sign up to claim your score
Save your score, re-run with updated answers, and build a history per framework. Your submissions are scoped to your account only.
- 03
AI-drafted assessment portal
Get a written readiness report: per-NIST 800-171 gap analysis, prioritised remediation, and an evidence pack you can hand to your assessor on day one.
Where we work
Built for global operators — US, UK, and Sub-Saharan Africa first.
Keepgrade runs against the framework mix above from any English-speaking jurisdiction, with the markets below as our initial footprint.
FedRAMP · StateRAMP · SOC · CMMC
Read more →
ISO · SOC · NCSC-aligned evidence
Read more →
ISO · SOC · sector evidence (CBN / NDPR)
Read more →
ISO · SOC · sector evidence (BOG / DPA)
Read more →
Other locales — readiness scoring in any English-speaking jurisdiction.
Read more →
Scope at a glance
What you get before you ever pick an assessor.
12
Frameworks covered
FedRAMP, StateRAMP, SOC 1/2/3, HIPAA, ISO 27001, NIST CSF, NIST 800-171, and CMMC Levels 1–3 — honestly classified.
5
Independent assessor authority types
FedRAMP 3PAO, StateRAMP 3PAO, AICPA SOC auditor, C3PAO/CMMC assessor, ISO certification body — each with distinct accreditation rules.
4+
Markets and growing
United States, United Kingdom, Nigeria, Ghana — plus readiness scoring in any English-speaking jurisdiction.
Five authority types — clearly distinguished
Pick the right assessor for the engagement.
Each assessor in the marketplace belongs to exactly one or more authority types with distinct accreditation rules. A 3PAO does not self-authorise; an ISO CB issues the certificate only after Stage 1 + Stage 2; a SOC 2 auditor issues an attestation, not a certification. The marketplace makes those distinctions unmistakable.
FedRAMP 3PAOs
GSA FedRAMP PMO-accredited third-party assessment organisations for Low, Moderate, and High baselines.
CMMC C3PAOs & assessors
Cyber-AB authorised assessors for CMMC L1/L2/L3 — final L3 certification flows through the DoD after assessment.
AICPA SOC auditors
Licensed CPA firms issuing SOC 1 / SOC 2 / SOC 3 attestations. Third-party attestation, not certification.
Need a readiness copilot too?
Keepgrade drafts SSPs and POA&Ms between formal engagements, scores gaps against the rubric of your framework mix, and hands a tight evidence pack to your assessor on day one.
Keepgrade is a subsidiary of Volkmann Express Inc.