About this firm
Listed in the FedRAMP Marketplace as a recognized third-party assessment organization (3PAO). The firm conducts independent security assessments of cloud services; a federal agency, not the assessor, decides whether to grant an Authorization to Operate (ATO).A QSA company assesses PCI DSS compliance. The PCI Security Standards Council does not endorse or recommend any QSA, and companies in remediation are not listed here.HITRUST issues the certification after quality review; the external assessor performs the validated assessment. Readiness licensees on HITRUST's page are not included.
Locations
Marketplace headquarters
1676 International Drive
McLean, VA, 22012
Source and verification
- FedRAMP 3PAO: FedRAMP Marketplace , as of October 3, 2026
- PCI QSA: PCI SSC Qualified Security Assessors , as of October 3, 2026
- HITRUST assessor: HITRUST external assessor list , as of October 3, 2026
- SOC 2 practice: Firm's service page
- Firm site: https://kpmg.com/us/en.html