Vendor sourcing for the people who actually have to operate it.

CISO Marketplace · Sourcing Practice

Independent, security-specialist sourcing. Tell us what you're solving. We pre-qualify the brief, surface the right two or three options from a curated catalog, and connect you with certified sales engineers who can actually quote — not generalists pushing the supplier their carrier rep called about this quarter.

01 · The process

Four steps. No discovery theater.

Step 01

You write the brief

Eight fields, about two minutes. Company size, what you're solving for, current stack, contract timing, decision authority, compliance drivers. Enough for an SE to quote intelligently — not enough to feel like a sales form.

Step 02

We pre-qualify

A human reviewer (not a chatbot) reads your brief, validates fit, and selects 2–3 suppliers from our curated catalog. We tell you why each one. If nothing fits, we tell you that too.

Step 03

SE engagement

You meet certified sales engineers who already have your context. No retelling the same story five times. They produce quotes, not pitch decks.

Step 04

You decide

We're paid by the suppliers via standard channel residuals — never by you. Our incentive is fit and stickiness, not closed-this-quarter pressure.

02 · Where we focus

Security categories we actually understand.

Cat 01

MDR & XDR

Managed detection across endpoint, identity, cloud, OT.

Cat 02

SASE & SSE

Unified network + security convergence on a private backbone.

Cat 03

Compliance

SOC 2, ISO 27001, HIPAA, PCI, FedRAMP automation.

Cat 04

Zero Trust

ZTNA replacement for legacy VPN and flat networks.

Cat 05

Edge Security

WAF, bot management, API security, microsegmentation.

03 · Free tools

Run the math before you brief.

Network Security

SASE Readiness Scorer

12-question maturity assessment. Identify your SASE pillar gaps before you talk to a vendor.

Run the tool →
Voice & Collaboration

UCaaS vs On-Prem TCO

7-field 5-year total cost comparison. Includes PBX refresh, SIP trunking, and UCaaS platform costs.

Run the tool →
Network Security

Firewall Throughput Sizing

Calculate required NGFW throughput with SSL inspection and IPS overhead factored in.

Run the tool →
Connectivity

SD-WAN vs MPLS Cost Comparison

Multi-site 3-year cost model. Shows breakeven and savings vs. legacy MPLS.

Run the tool →
Security Operations

SOC Build vs Buy Calculator

Fully-loaded internal SOC cost vs. MDR pricing. Breakeven at ~34K endpoints for most orgs.

Run the tool →
Endpoint Security

Endpoint License Planner

EDR/XDR license cost modeling across Tier 1, 2, and 3 platforms at your scale.

Run the tool →
Cloud Connectivity

Cloud Egress Cost Estimator

AWS, Azure, and GCP egress cost comparison. Shows ZTNA / private connectivity savings.

Run the tool →
Carrier Expense

Mobility & Carrier Expense Audit

Finds waste in wireless, wireline, and Starlink plans. Includes TEM savings estimate.

Run the tool →
OT / IoT Security

IoT / OT Risk Surface Mapper

10-question risk assessment across device inventory, segmentation, and monitoring gaps.

Run the tool →
Identity

IAM / Zero Trust TCO

Entra vs Okta vs Ping cost comparison with consolidation savings over 3 years.

Run the tool →
04 · Curated catalog

The ten suppliers we lead with.

MDR · XDR

eSentire

The Authority in MDR — 15-minute mean time to contain across 2,000+ orgs in 80+ countries.

Sourcing page
MSSP · Enterprise

LevelBlue

Top-10 MSSP (formerly AT&T Cybersecurity), with Trustwave and Cybereason under one roof.

Sourcing page
MDR · Microsoft

Ontinue

The MXDR built for Microsoft — extracts maximum value from M365 E5, Defender, and Sentinel.

Sourcing page
MDR · Mid-market

CyberMaxx

MDR with offensive-informed defense — purple-team thinking applied to managed detection.

Sourcing page
SASE · SSE

Cato Networks

Single-vendor SASE that converges SD-WAN, SSE, and ZTNA on one private backbone.

Sourcing page
SASE · Managed

Aryaka

Unified SASE-as-a-Service. Managed network and security delivered as a single outcome.

Sourcing page
SASE · MDR

Open Systems

Mission-critical SASE and MDR delivered as a co-managed service.

Sourcing page
Zero Trust · ZTNA

Appgate

Zero Trust Network Access purpose-built for hybrid environments. VPN replacement done right.

Sourcing page
Compliance · GRC

Drata

Continuous compliance automation across SOC 2, ISO 27001, HIPAA, PCI, and 20+ frameworks.

Sourcing page
Edge · WAF · Bot · API

Akamai

Edge security — WAF, bot management, API security, and microsegmentation via Guardicore.

Sourcing page
05 · Why this exists

The thing other channels don't say out loud.

01

Most VARs sell what their carrier rep called about this quarter.

We sell what fits. We have no quota on any single supplier. The brief drives the recommendation — not the other way around.

02

Security-specialist sourcing, not connectivity-first.

We don't lead with UCaaS or SD-WAN deals dressed up in security clothing. Our catalog is MDR, SASE, compliance, ZTNA, edge security. That's it.

03

We do the SE pre-flight ourselves.

Backed by a our advisor network and a certified SE bench. We curate, qualify, and translate the brief before anyone gets on a call with you.

04

Membership pricing if you want it.

Free to use as a one-off. CISO Marketplace members get priority routing, recorded SE sessions, and access to category briefings. Learn more.

06 · The architecture call

A CISSP-credentialed engineer joins call two.

Your second call isn't with a vendor account executive. It's with a certified solutions engineer from our advisor network — CISSP, CCIE, CCSP credentialed — who works the architecture conversation on your behalf. They're not paid by any vendor whose product you eventually buy.

They walk architecture options, refine the vendor shortlist, translate your requirements into vendor-quotable RFP specifications, and review proposals when they come back. The buyer-side equivalent of a Fortune 500 procurement architect — without the procurement department.

How our engineers work
CISSP · CCIE · CCSP · CCSK
Credentials held across the advisor network
15–25+ years
Channel engineering experience, average
Vendor-agnostic
Aligned with your outcome, not a vendor's quota
Call 2 every engagement
Not a premium add-on — standard for every brief
Full process walkthrough →

One brief. Two or three quotes.
No discovery theater.

Start a sourcing brief