Skip to content

SecurityMetrics

Longstanding Utah-based provider of PCI compliance, vulnerability scanning, and forensic services purpose-built for small and mid-sized merchants.

Visit Website ↗ + Add to Compare
52/100Incremental Innovator

Overview

SecurityMetrics provides PCI DSS compliance validation, vulnerability scanning, penetration testing, and payment-card forensic investigation services, with a customer base concentrated among small and mid-sized merchants who need to meet payment-card industry security requirements but typically lack in-house security teams. As an Approved Scanning Vendor (ASV) and Qualified Security Assessor (QSA), the company helps merchants complete the compliance validation processes that payment processors and card brands require.

Founded in 2000 and headquartered in Orem, Utah, SecurityMetrics has built a two-decade track record specifically serving the SMB segment of the payments ecosystem, a market often underserved by security vendors that focus on larger enterprise deals. Its forensic investigation practice has also historically been engaged to investigate real-world payment-card breaches, giving the company direct exposure to how card-data compromises actually happen in the field.

At the 2026 Global InfoSec Awards, SecurityMetrics was recognized as The Most Promising in SMB Cybersecurity, reflecting its long-standing focus on making PCI compliance and breach-related forensic services accessible to smaller merchants that larger security vendors often overlook.

Innovation Matrix Assessment

Innovation Velocity 4/10

A long-established compliance and scanning services firm; steady service delivery rather than rapid product innovation is the norm for this category.

Operational Value 6/10

Makes PCI compliance and vulnerability scanning accessible to small and mid-sized merchants who otherwise struggle to meet payment-card security requirements on their own.

Market Momentum 8/10

Over two decades of continuous operation focused on the SMB payments segment, plus 2026 Global InfoSec Award recognition, indicate durable, if not explosive, market presence. Recognized in Cyber Defense Media Group's 2026 Global InfoSec Awards (1 award), independently juried industry validation of market traction.

Category Disruption 3/10

A well-established compliance and scanning services provider in a mature category (PCI ASV/QSA services); valuable but not disruptive to how the underlying problem is solved.

Real-World Efficacy 5/10

Two decades of forensic breach-investigation experience provides real-world exposure to actual compromises, though independently published efficacy metrics were not found.

Enduring Relevance 5/10

PCI compliance requirements are not going away, so demand for accessible SMB-focused compliance and scanning services should remain steady, if unglamorous.

Why CISOs Should Care

Gives resource-constrained merchants and small businesses a practical path to PCI compliance and breach forensics without needing an internal security team.

What Makes It Different

A sustained, two-decade focus specifically on the SMB/merchant segment of PCI compliance, a market larger security and compliance vendors often underserve.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A durable, trusted compliance and scanning services provider for an underserved SMB niche; steady rather than transformative.

Editorial Note: Claims vs. Verified Findings

Award recognition is from the vendor-submission-based Global InfoSec Awards program; company history is drawn from the vendor's own public materials.

Sources