Kobalt.io today announced three strategic partnerships with Forward Security, Johanson Group LLP, and Insight Assurance, signed at the company’s inaugural Partner Summit, held last week in Vancouver, BC. Each agreement makes the two firms each other’s primary go-to-market partner in its domain.
These partnerships come at a moment of growth for Kobalt.io. The company serves more than 1,600 customers, most of them in North America and APAC, and is expanding into EMEA this year.
They also come at a moment of rapid change for the security and compliance industry. Security review has moved from a late-stage formality to an early gate in how software gets bought, with enterprise buyers routinely asking for SOC 2 or ISO 27001 evidence before a contract progresses. AI is helping teams ship more software faster while surfacing vulnerabilities faster than any team can work through them. And in the defense supply chain, certification requirements that were once advisory are now contractual, on both sides of the Canada–US border. The three partnerships are designed to meet that shift, giving Kobalt.io’s clients and prospects a clear route through it.
Forward Security — Managed Application Security
Kobalt.io and Forward Security are now each other’s primary go-to-market partner for managed and recurring application security, covering application-layer managed detection and response, secure SDLC advisory, and continuous application security review, with a focus on AI-native companies across North America, EMEA, and APAC. Beyond a conventional referral arrangement, the agreement commits both leadership teams to quarterly working sessions to align service development and roadmap, with learnings from shared customer engagements feeding both planning cycles.
Johanson Group LLP — Audit and Certification for SaaS and Technology Companies.
Serving SaaS and technology companies across North America, the partnership pairs Kobalt.io, which prepares organizations for audit and operates their security programs on an ongoing basis, with Johanson Group LLP, which performs the audit. Keeping those functions with separate firms preserves the independence that gives an audit its value, and the partnership is designed to make the handoff between them straightforward for the client.
Insight Assurance — Defense and Government Supply Chain Certification.
Focused on standards such as CMMC, CPCSC, and FedRAMP / GovRAMP in North America, the partnership pairs Kobalt.io, a CMMC Registered Provider Organization that works with organizations on readiness, with Insight Assurance, an Authorized C3PAO and FedRAMP 3PAO accredited to conduct official CMMC and FedRAMP assessments. The two roles are deliberately distinct, and assessor independence rules require they stay that way. The partnership is built around that separation rather than despite it, giving clients a clear route from preparation through to assessment without either firm compromising its role.
“The ground is shifting under our clients,” said Michael Argast, CEO and Co-Founder of Kobalt.io. “AI is finding vulnerabilities faster than teams can fix them, and helping those same teams ship more software, so the pile grows from both ends. Enterprise buyers want certification evidence before a deal moves. Defense contractors are staring down deadlines that are real now. Nobody gets ahead of all that working alone. That’s why we brought our closest partners into one room for our first Partner Summit to get specific about who does what, so a client gets one clear path from readiness through audit to ongoing security, with no gaps in the middle.”
“Software is shipping faster than ever, and more of it is being written with AI every month. Testing an application once a year was never really enough, and it certainly isn’t now. Kobalt already has continuous relationships with their clients, which is exactly where application security needs to live. That’s what we’re building together,” said Farshad Abasi, Chief Executive Officer of Forward Security.
“An audit is only as valuable as its independence, which is why this partnership is structured the way it is. Kobalt runs the security program, we render the opinion, and the client gets both a smooth path and a report that enterprise buyers trust. We couldn’t be more excited to build on that together,” said Ryan McBride, VP of Sales at Johanson Group LLP.
“Every defense contractor we speak with is up against the same set of deadlines: requirements that were once advisory and are now written into contracts. Kobalt.io’s readiness work and our accreditation as a C3PAO and FedRAMP 3PAO complement each other precisely because they’re kept apart. That’s not a compromise, it’s rather what gives the certification its value, and it’s why this partnership works for clients on either side of the border.” said Ben Wright, Chief Revenue Officer of Insight Assurance.
Over the next year, clients can expect the partnerships to show up in practical ways: joint research on securing AI-native software, co-hosted sessions on getting audit-ready without stalling the roadmap, joint guidance on preparing for CMMC and CPCSC assessment, customer roundtables, and account teams on all sides who know when to bring a partner in.
About Kobalt.io
Kobalt.io is a Vancouver-headquartered cybersecurity company serving more than 1,600 customers in North America, APAC, and EMEA. Founded on the conviction that everyone deserves great cybersecurity, Kobalt.io delivers managed security and compliance programs that meet enterprise and regulatory expectations without enterprise budgets. The company helps clients adopt AI with confidence, building the security and governance foundations that let them move quickly on it. Learn more at www.kobalt.io.
About Forward Security
Forward Security is an application and cloud security consultancy founded in Vancouver in 2018, with offices in Toronto and Austin. Built by software developers, the firm helps engineering teams find and fix security risk in the applications and cloud environments they build, working to OWASP standards including ASVS, MASVS and SPVS. Forward Security serves clients across financial services, technology, healthcare and eCommerce, and its managed application security service pairs continuous scanning through the Eureka DevSecOps platform with expert triage and remediation guidance. forwardsecurity.com
About Johanson Group LLP
Johanson Group LLP is a licensed CPA firm based in Colorado Springs, Colorado, specializing in security and compliance audits for technology, SaaS, financial services, healthcare, and AI companies. An AICPA peer-reviewed firm and IAS-accredited ISO certification body, Johanson Group has been auditing since 2012 and brings decades of combined experience across attestation and certification engagements, including SOC 2, ISO 27001 and 42001, HIPAA, PCI DSS, and other leading frameworks. Every client is supported by a dedicated Client Success Manager who guides them through the audit process from kickoff to report delivery. Ready to start your audit? Visit www.johansonllp.com to connect with the team.
About Insight Assurance
Insight Assurance is an independent audit and compliance assessment firm serving clients across North America, Europe, and APAC, from fast-growing startups to Fortune 100 enterprises. Led by a team of former Big 4 professionals, the firm has completed more than 3,500 compliance engagements with a 97% client retention rate. Insight Assurance is an Authorized C3PAO for CMMC assessments and a FedRAMP 3PAO, and holds accreditation across SOC 2, ISO 27001, PCI DSS, HITRUST, and other major frameworks. Learn more at www.insightassurance.com.
Media Contact
For Kobalt.io – Jeremy Viault – [email protected]
For Forward Security – Rachel Sun – r.sun at fwdsec.com



