RiskWatch
RiskWatch International · Founded 1993 · Sarasota, FL, USA
SOC 2 CC6.4 + ISO 27001 A.7 physical security assessment software with co-lo cage and remote-asset coverage.
Summary
RiskWatch ships a physical security risk assessment platform built around pre-mapped libraries for SOC 2 Trust Services Criteria 2017 Common Criteria CC6.4 plus CC6.5 and CC6.7, ISO/IEC 27001:2022 Annex A.7.1 through A.7.14, NIST 800-53 PE, NIST 800-171 3.10, CSA Cloud Controls Matrix Domain DCS (Datacenter Security), PCI DSS v4 Requirement 9, HIPAA Administrative Simplification physical safeguards, and FedRAMP Moderate physical-control families. The platform models the HQ floor, the regional office, the co-located data-centre cage at Equinix or Digital Realty or CoreSite, the hybrid-RTO seasonal floor, and the remote-employee equipment register as discrete assessable assets with their own control sets. Browser-based mobile site walks work offline at the cage where cellular is weak. Customers include SaaS companies, cloud-native infrastructure providers, and IT services firms. The product has been in the field since 1993 and is the only platform in this ranking that pre-maps every SOC 2 and ISO 27001 physical-control requirement a SaaS company owes its Type II auditor in one tenant.
Strengths
- SOC 2 Trust Services Criteria 2017 CC6.4 + CC6.5 + CC6.7 + ISO/IEC 27001:2022 Annex A.7.1 through A.7.14 + NIST 800-53 PE + NIST 800-171 3.10 + CSA CCM Domain DCS + PCI DSS v4 Requirement 9 + HIPAA Administrative Simplification physical safeguards + FedRAMP Moderate physical families pre-mapped on day one in one tenant
- Discrete asset models for HQ floor, regional office, co-located data-centre cage, hybrid-RTO seasonal floor, and remote-employee equipment so the same SaaS customer can score the cage at Equinix DC11 and the HQ floor in San Francisco from the same workspace
- Browser-based mobile TVRA works offline inside a co-located cage where cellular and Wi-Fi are weak; syncs when connectivity returns and the auditor never loses a finding from the cage walk
- Cross-mapping engine that auto-detects shared controls across SOC 2, ISO 27001, NIST 800-53 PE, and CSA CCM so one piece of cage-access evidence satisfies multiple Type II audits and the ISO 27001 surveillance visit
- Site Risk Cycle with ISO 31000 and NIST 800-30 semi-quantitative scoring; findings convert to tracked remediation tasks with owners and proof-of-close defensible to SOC 2 reviewers from Big 4 firms and ISO 27001 registrars
- Single-tenant deployment with customer-owned data residency for SaaS companies that need US-only or EU-only data locality for sub-processor due diligence
- 30-day free trial with no credit card and full platform access; the only TVRA-first vendor on this list offering it for a SaaS physical security owner to evaluate during Type II prep
- Vendor risk management module covers the colo operator and the managed-security-service provider so SOC 2 sub-processor evidence lives in the same tenant as the cage TVRA
Weaknesses
- Pricing is quote-only across all tiers, scaled by framework count, office count, and cage count; there is no published list price for a SaaS buyer to read off the page before requesting a quote
- No native employee laptop or remote-asset GPS tracking; the remote-employee equipment register tracks asset assignment, condition, and return rather than real-time location, so SaaS companies needing Find-My-Device or Apple Business Manager geofencing pair with Jamf or Kandji
- No native insider-threat behavioural analytics on physical-badge events; pair with Resolver or AlertEnterprise for departing-engineer behavioural triggers tied to badge patterns
IT services firms, cloud-native SaaS companies, and software vendors running SOC 2 Type II plus ISO 27001 plus a co-located data-centre cage at Equinix, Digital Realty, CoreSite, Iron Mountain, or QTS, with HQ plus regional plus remote-employee asset scope in one tenant.
Single-office sub-50-employee SaaS startups that only need a Verkada or Brivo bundle for one door and have no SOC 2 audit yet and no co-located cage; the multi-framework engine is over-built for that brief.
Key features
- Pre-built libraries for SOC 2 Trust Services Criteria 2017 (CC6.4, CC6.5, CC6.7), ISO/IEC 27001:2022 Annex A.7.1 through A.7.14, NIST 800-53 PE, NIST 800-171 3.10, CSA Cloud Controls Matrix Domain DCS, PCI DSS v4 Requirement 9, HIPAA Administrative Simplification physical safeguards, FedRAMP Moderate physical families
- Discrete asset models for HQ floor, regional office, co-located data-centre cage, hybrid-RTO seasonal floor, and remote-employee equipment
- Cross-mapping engine for shared controls across SOC 2 + ISO 27001 + NIST 800-53 PE + CSA CCM
- Offline mobile site-walk app for cage walk-throughs with sync-on-reconnect
- Vendor risk management module covering colo operator and MSSP sub-processors
- Site Risk Cycle with ISO 31000 and NIST 800-30 semi-quantitative scoring
- Remote-employee equipment register for ISO 27001 A.7.9 off-premises asset control
- Single-tenant deployment with US-only or EU-only data residency
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU