About this firm
Listed in the FedRAMP Marketplace as a recognized third-party assessment organization (3PAO). The firm conducts independent security assessments of cloud services; a federal agency, not the assessor, decides whether to grant an Authorization to Operate (ATO).GovRAMP does not endorse or recommend any specific 3PAO.A QSA company assesses PCI DSS compliance. The PCI Security Standards Council does not endorse or recommend any QSA, and companies in remediation are not listed here.An ASV runs external vulnerability scans, not a full PCI DSS assessment. The PCI Security Standards Council does not endorse or recommend any ASV, and vendors in remediation are not listed here.A C3PAO conducts CMMC certification assessments for defense contractors. Check the Cyber AB Marketplace for each firm's current authorization status.HITRUST issues the certification after quality review; the external assessor performs the validated assessment. Readiness licensees on HITRUST's page are not included.
Locations
Marketplace headquarters
1 S Wacker Drive Suite 800
Chicago, IL, 60606
Source and verification
- FedRAMP 3PAO: FedRAMP Marketplace , as of October 3, 2026
- GovRAMP 3PAO: GovRAMP program participants , as of October 3, 2026
- PCI QSA: PCI SSC Qualified Security Assessors , as of October 3, 2026
- PCI ASV: PCI SSC Approved Scanning Vendors , as of October 3, 2026
- CMMC C3PAO: Cyber AB CMMC Marketplace , as of October 3, 2026
- HITRUST assessor: HITRUST external assessor list , as of October 3, 2026
- SOC 2 practice: Firm's service page
- Firm site: https://rsmus.com/