Compliance need

ISO 27001-Certified SOC Providers

Datadog Cloud SIEM

Cloud SIEM detection rules, security signals, notifications, cases, dashboards, threat intelligence context and workflow hooks inside Datadog

Cloud WorkloadsContainers & KubernetesIdentity & Access

What they do Monitor and notify SOCaaS
Market EnterpriseMid-Market
Price Published from $5 per 1M analyzed events/month

You still own Triage, investigation and response decisions after Datadog creates a signal

BT Managed Sentinel

24x7 managed Microsoft Sentinel monitoring, rule tuning, SOC investigation, incident reporting and buyer guidance

NetworkCloud WorkloadsIdentity & Access

What they do Investigate and advise MSSP
Market EnterpriseMid-Market
Price Public G-Cloud price from £6,275 per instance

You still own Maintaining Azure, Microsoft Sentinel and required Microsoft licences

24/7/365 Microsoft-managed threat hunting across eligible Defender telemetry, Defender Experts Notifications, Ask Defender Experts credits, reporting and remediation guidance for an existing SOC.

EndpointsCloud WorkloadsIdentity & Access

What they do Investigate and advise XDR
Market Mid-MarketEnterprise
Price Quote-based Microsoft commercial licensing; no public standalone list price found.

You still own Running the SOC workflow after Microsoft sends a notification

Arctic Wolf

24/7 MDR through Arctic Wolf's Aurora platform, Concierge Security Team guidance and supported Active Response containment workflows

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market SMBMid-Market
Price AWS Marketplace public offer plus quote-based tiers

You still own Choosing the MDR bundle, Concierge tier, add-ons, warranty eligibility and retention scope

Bitdefender MDR

24/7 SOC investigation, threat hunting, reporting and pre-approved containment through Bitdefender GravityZone

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market SMBMid-Market
Price Quote-based with no official public MDR list price found

You still own Choosing the MDR or MDR PLUS scope and enabling the required GravityZone coverage

CrowdStrike Falcon Complete

24/7 triage, managed threat hunting and remote containment by CrowdStrike on the Falcon platform

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market EnterpriseMid-Market
Price ~$25-45/endpoint/month*

You still own Deploying and maintaining required Falcon modules

eSentire

24/7 MDR monitoring, threat hunting, alert validation, investigation, multi-signal correlation, containment actions, incident handling and reporting through eSentire Atlas XDR and eSentire's SOC team.

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market SMBMid-Market
Price Quote-based Atlas Essentials, Advanced and Complete MDR packages

You still own Granting and maintaining access to endpoint, identity, cloud, email, SIEM and network tools that eSentire is expected to monitor or use for response

Expel MDR

24/7 SOC monitoring, analyst investigation, Workbench visibility, cross-product correlation, remediation recommendations and pre-approved auto-remediation through supported tools.

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market Mid-MarketEnterprise
Price Quote-based Starter, Select and Premium MDR packages

You still own Maintaining and licensing the endpoint, identity, cloud, email, SaaS, network and SIEM tools in scope

Field Effect MDR

24/7 MDR over Field Effect's endpoint, cloud and network telemetry, with AROs and policy-bound active response

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market SMBMSP/MSSP
Price Quote-based per-user pricing

You still own Choosing the Active Response policy and excluding critical systems where downtime risk matters

24/7 Microsoft-managed triage, investigation, proactive hunting, managed response recommendations and scoped remediation actions for eligible Microsoft Defender XDR incidents.

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats XDR
Market Mid-MarketEnterprise
Price Microsoft sales-led pricing with a Defender Experts Suite 1,500-seat minimum in Product Terms

You still own Licensing and actively deploying the eligible Defender and Entra products that define service coverage

Rapid7 Managed Threat Complete

24/7 SOC monitoring, alert validation, investigation, exposure-informed prioritization, threat hunting, incident-response support, Rapid7 SIEM visibility, unlimited log ingestion in published packages, 13-month retention and configured Active Response containment.

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market EnterpriseMid-Market
Price AWS Marketplace lists Managed Threat Complete Essential at $73,000 for a 12-month contract starting at 300 assets; Rapid7 also supports private offers and custom quotes.

You still own Scoping protected endpoints, servers, networks and third-party event sources

Red Canary

24/7 MDR that investigates supported security telemetry and can run response playbooks through existing tools

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market Mid-MarketEnterprise
Price Quote-based. Public reviews mention roughly $100/device/year*

You still own Approving which response playbooks can run automatically

Sophos MDR

24/7 managed detection, investigation, threat hunting and response through Sophos Central and supported integrations

EndpointsCloud WorkloadsIdentity & Access

What they do Contain threats MDR
Market SMBMid-Market
Price AWS Marketplace: $239.64/user/year and $390.72/server/year*

You still own Selecting Collaborate, Authorize or Notify Only response mode

Adlumin

A co-managed security operations platform that combines SIEM-style log collection, UEBA, SOAR automation, compliance reporting and 24/7 MDR support

EndpointsCloud WorkloadsIdentity & Access

What they do Co-manage the SOC MDR
Market SMBMid-Market
Price Quote-based

You still own Connecting the right data sources and validating what each source is used for

24/7 SOC monitoring of the buyer's Darktrace environment, alert triage, investigations, containment-action escalation, analyst questions, monthly service reports, service-ready checks and optimization reviews.

NetworkCloud WorkloadsOT/ICS

What they do Co-manage the SOC MDR
Market Mid-MarketEnterprise
Price Quote-based; AWS Marketplace supports private offers but does not expose a reliable public service rate.

You still own Deploying and tuning the relevant Darktrace modules and sensors across the environment

Netsurion Managed Open XDR

Co-managed Open XDR with managed SIEM, 24/7 SOC monitoring, workflow automation, threat hunting, log retention, compliance reporting and package-dependent endpoint, vulnerability and incident-support options.

EndpointsCloud WorkloadsIdentity & Access

What they do Co-manage the SOC Co-managed SOC
Market SMBMid-Market
Price Quote-based, with pay-as-you-grow packaging referenced for MSP buyers

You still own Choosing which endpoints, cloud services, identity systems, network tools and SaaS sources are in scope

Proficio ProSOC MDR

24/7 SOC monitoring, analyst investigation, hosted or customer-owned SIEM operations, threat hunting, case management, guided remediation and optional Active Defense containment across supported tools.

EndpointsCloud WorkloadsIdentity & Access

What they do Co-manage the SOC Co-managed SOC
Market Mid-MarketEnterprise
Price Quote-based direct, partner or marketplace private offer

You still own Choosing and licensing the SIEM, EDR, identity, cloud and ticketing tools in scope

ReliaQuest GreyMatter

GreyMatter connects to enterprise security tools, normalizes alerts, supports investigation and hunting, runs approved response playbooks and gives the buyer a shared operating surface with ReliaQuest analysts and engineers.

EndpointsCloud WorkloadsIdentity & Access

What they do Co-manage the SOC Co-managed SOC
Market EnterpriseMid-Market
Price AWS Marketplace lists a 12-month GreyMatter SIEM Integration Plus package at $226,000*

You still own Licensing and administering the SIEM, EDR, cloud, identity, email and network controls in scope

Hybrid or fully outsourced SOC operation with 24/7 monitoring, alert investigation, threat hunting, threat intelligence, SIEM and SOAR enhancement, incident response leadership and detection improvement across agreed environments.

EndpointsCloud WorkloadsIdentity & Access

What they do Run the SOC SOCaaS
Market Mid-MarketEnterprise
Price Public G-Cloud references by user, server and scope

You still own Defining whether the engagement is hybrid, fully outsourced or limited to a specific SOC function

How to use this list

Use it when

  • Use this list when a framework requirement affects your SOC provider shortlist.

Do not assume

  • Compliance support is not the same as audit readiness for your exact environment, evidence needs, or data location.

Ask before shortlisting

  1. Ask for the actual evidence package, not just the compliance logo.
  2. Confirm data processing locations, retention, and audit-ready reporting.
  3. Check whether the provider can support your framework without a custom services project.
Category background

These SOC providers support ISO 27001 compliance — the globally recognized standard for information security management. ISO 27001 certification is increasingly required by enterprise customers, partners, and regulators worldwide, making it a critical consideration when selecting a SOC provider.

ISO 27001 and Security Operations

ISO 27001’s Annex A includes specific controls for security monitoring, incident management, and operational security that map directly to SOC provider capabilities. A provider that understands ISO 27001 can help you demonstrate compliance with controls related to event logging and monitoring, malware protection, network security, vulnerability management, and information security incident management. Compliance-mapped reporting from your SOC provider becomes valuable evidence during ISO 27001 audits and surveillance assessments.

Evaluating ISO 27001 Support

When evaluating SOC providers for ISO 27001 support, look for providers that are themselves ISO 27001 certified, can map their monitoring capabilities to specific Annex A controls, provide compliance-ready reporting for audit evidence, and understand the continuous improvement requirements of the standard. The best providers help you identify gaps in your ISMS through their monitoring data and incident trend analysis.

Questions

What is ISO 27001 and why does it matter for SOC providers?
ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through risk assessment, security controls, and continuous improvement. For SOC providers, ISO 27001 is relevant in two ways — the provider's own operations should be ISO 27001 certified (demonstrating their security maturity), and they should support your organization's ISO 27001 compliance through security monitoring and incident management aligned to Annex A controls.
Which ISO 27001 Annex A controls do SOC providers cover?
SOC providers primarily support Annex A controls related to operations security (A.12), communications security (A.13), and information security incident management (A.16). This includes monitoring of information processing facilities, protection against malware, event logging and monitoring, network security management, and incident response procedures. Some providers also support access control monitoring (A.9) and supplier relationship security (A.15).
Should my SOC provider be ISO 27001 certified?
While not strictly required, choosing an ISO 27001-certified SOC provider gives you assurance that their operations meet international security standards. It also simplifies your own certification or recertification, since auditors will look favorably on suppliers that maintain recognized certifications. Many enterprise-focused SOC providers hold ISO 27001 certification for their SOC operations.