Normalised provider profile

A-LIGN

A-LIGN provides assessment, certification and cybersecurity services. Its portfolio includes SOC 1 and SOC 2 examinations, ISO certifications and assessments for FedRAMP, CMMC, HITRUST and PCI. Penetration testing, red-team services and other technical security assessments complement its compliance programs. Organisations can address several frameworks through a coordinated assessment program and organise evidence using the A-SCEND audit-management platform. Purchasing decisions depend on customer requirements, target markets, data types and the specific assessment scope. The distinction between preparation and independent assessment, the applicable accreditation and responsibilities require particular attention. A-LIGN partners with Drata, which provides software for control monitoring and evidence collection, while A-LIGN performs agreed audit services. They are separate providers with complementary responsibilities; a jointly published resource does not constitute a joint company.

1

Publication

1

Portal

1

Classified

German source titles are translated automatically; titles from English originals remain unchanged. Original publications stay linked directly.

Portfolio focus

SOC 1 and SOC 2ISO 27001 and privacy certificationsISO 42001 and AI governanceFedRAMP and CMMCHITRUST and healthcare assessmentsPCI assessmentsPenetration testing and red teamingCoordinated multi-framework assessment programs

Typical specialist roles

CISO and information securityCompliance and GRC ownersInternal audit and risk managementSaaS and cloud providersHealthcare IT and privacyGovernment and defence suppliers

Official product sources (German)

Provider product pages supporting the portfolio description; observed publications appear separately below.

Curated knowledge items

No curated knowledge items yet.