In June the directory added 29 listings, compared with 2 in May. The total at the end of the month was 183, spread across 11 categories.
Pricing is not published for 25 of the 29. Two listings are open source, one has a free tier plus paid plans, and one has published pricing.
The month in numbers
- 29 listings added in June 2026, against 2 in May 2026. The directory held 183 tools and companies at the end of the month.
- Categories: 11, led by Cyber Resilience Act Compliance (6), Penetration Testing Firms (6), Managed Security Service Providers (5), PCI PTS Compliance Testing Companies (5), Network Detection & Response (NDR) (4).
- Pricing: 25 not published, 2 open source, 1 free tier plus paid plans, 1 published pricing. 4 of 29 let a buyer see a price or a free tier without asking.
- Deployment: 17 cloud-hosted, 8 with a self-hosted option, 2 open source.
- Founded: of the 25 with a sourced founding year, 1 were founded in 2024 or later; the oldest dates from 1828.
- Most common capabilities (fixed-vocabulary tags, 29 of 29 tagged): certification audit services (9), penetration testing (9), eu cyber resilience act (6), red teaming (6), managed detection response (5), network detection response (5).
What was added in June 2026
| Listing | Category | Pricing | What it does |
|---|---|---|---|
| Acronis Cyber Protect | Endpoint & EDR | Not published | Integrated backup, disaster recovery, and AI-based endpoint security (anti-ransomware, EDR) in one platform. |
| Arista NDR | Network Detection & Response (NDR) | Not published | Agentless, AI-assisted network detection and response for campus, data center and cloud |
| Bishop Fox | Penetration Testing Firms | Not published | Offensive security firm pairing high-end penetration testing with Cosmos, a continuous attack-surface management platform. |
| Bureau Veritas | Cyber Resilience Act Compliance | Not published | Global TIC group whose cybersecurity unit delivers end-to-end CRA compliance, RED testing, penetration testing, and conformity assessment for connected products. |
| Corelight | Network Detection & Response (NDR) | Open source | Open NDR platform built on the open-source Zeek network monitoring framework |
| Critical Start | Managed Security Service Providers | Not published | MDR provider built around its Trusted Behavior Registry and MOBILESOC app, delivering managed detection across multiple EDR, XDR, and SIEM platforms. |
| DEKRA | Cyber Resilience Act Compliance | Not published | Major TIC organization offering CRA readiness, security evaluation, and certification, with EUCC accreditation and CRA notified-body status from June 2026. |
| eSentire | Managed Security Service Providers | Not published | Canadian MDR pioneer delivering 24/7 SOC services on the Atlas security operations platform, with strong financial-services and legal-vertical specialisation. |
| Expel | Managed Security Service Providers | Not published | Vendor-neutral MDR founded by former Mandiant leaders, known for transparent operations and an API-only bring-your-own-tech model. |
| Fidelis Network | Network Detection & Response (NDR) | Not published | Network detection and response component of the Fidelis Elevate XDR platform |
| IOActive, Inc. | Penetration Testing Firms | Not published | Independent global research-driven security consultancy specialising in full-stack, hardware, embedded, and critical-infrastructure testing. |
| Lepide Data Security Platform | Data Security & Governance | Published pricing | Unstructured data security, access governance, auditing, threat detection and DSPM across AD, M365 and file servers. |
| Mandiant (part of Google Cloud) | Penetration Testing Firms | Not published | Elite incident response and offensive security consultancy operating as the threat-intelligence arm of Google Cloud Security. |
| NCC Group | Penetration Testing Firms | Not published | FTSE 250 global cybersecurity and software resilience firm offering technical assurance, managed detection, and incident response. |
| ONEKEY | Cyber Resilience Act Compliance, SBOM Analysis | Not published | European product-cybersecurity platform automating SBOM generation, vulnerability management, and CRA compliance for connected-device makers. |
| PCA Cyber Security | Automotive Cybersecurity, PCI PTS Compliance Testing Companies, Product Threat Intelligence Providers, SBOM Analysis | Not published | Offensive security and threat intelligence for payment devices, vehicles and embedded systems |
| pi3g | Cyber Resilience Act Compliance | Not published | German embedded-Linux and IoT specialist helping SME manufacturers make connected products compliant with the EU Cyber Resilience Act. |
| Praetorian | Penetration Testing Firms | Not published | Offensive security firm delivering continuous penetration testing and attack-surface management through its Chariot platform. |
| Red Canary (a Zscaler company) | Managed Security Service Providers | Not published | MDR provider known for deep Microsoft Defender expertise and high-fidelity detection engineering, acquired by Zscaler in 2025. |
| Sawmills | Observability Pipelines | Free tier plus paid plans | AI telemetry pipeline that filters and optimises logs, metrics and traces pre-ingestion to cut observability cost. |
| Secureworks (a Sophos company) | Managed Security Service Providers | Not published | Long-established MDR and XDR provider built around the Taegis platform, now operating as part of Sophos. |
| SERMA Safety & Security | PCI PTS Compliance Testing Companies | Not published | French security evaluation lab (ITSEF); PCI Recognized for PTS, plus EMVCo and Common Criteria. |
| SGS | Cyber Resilience Act Compliance | Not published | World-leading testing and certification company that, through SGS Brightsight, provides CRA and RED security evaluation, conformity assessment, and notified-body services. |
| SGS Brightsight | PCI PTS Compliance Testing Companies | Not published | Major PCI Recognized security evaluation lab for payment devices, EMVCo and Common Criteria. |
| SRC Security Research & Consulting | PCI PTS Compliance Testing Companies | Not published | German PCI Recognized lab for PCI PTS device evaluation and German payment terminal schemes. |
| Stamus Networks | Network Detection & Response (NDR) | Open source | Suricata-based network detection and response with an open-source community edition |
| Trail of Bits | Penetration Testing Firms | Not published | High-end security research and engineering firm known for deep code audits, cryptography reviews, and smart-contract security work. |
| TUV SUD | Cyber Resilience Act Compliance | Not published | Global testing and certification body offering CRA readiness assessment, vulnerability-management support, third-party conformity assessment, and training. |
| UL Solutions | PCI PTS Compliance Testing Companies | Not published | Global TIC firm and PCI Recognized lab for payment terminal (PTS POI/HSM) and EMVCo testing. |
What they have in common
The additions are concentrated in compliance and testing. Cyber Resilience Act Compliance and Penetration Testing Firms each gained 6 listings, while Managed Security Service Providers and PCI PTS Compliance Testing Companies each gained 5. The most common tags are certification audit services and penetration testing, each on 9 listings.
Founding years are known for 25 of the 29. The oldest addition is Bureau Veritas, founded in 1828, and the most recent is Sawmills, founded in 2024. Pricing is not published for 25 of the 29. Corelight and Stamus Networks are open source, and Lepide Data Security Platform has published pricing.
How this is counted
Listings are counted by the date they were added to the directory, which is not a launch date: some were founded years earlier and some were listed within weeks of appearing. Every listing cites its sources on its own page, and free listings are placed in the one category guide that genuinely fits, so the category counts reflect editorial placement rather than vendor self-description. Pricing is read from each listing's published pricing: a listing counts as published if a figure or a free tier is visible without contacting sales. Capability tags are assigned from a fixed vocabulary of 60 terms and checked by an editor; the figures above come from the directory database and none are estimated.
All editions
Every month's additions are listed at New cybersecurity tools, month by month. Vendors can submit a tool for a free listing; Featured listings are the paid product.