SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Kobalt.io signs security partnerships across North America

Kobalt.io signs security partnerships across North America

Wed, 2nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Kobalt.io has signed partnerships with Forward Security, Johanson Group and Insight Assurance covering application security, audit and certification, and defence supply chain assessments.

The agreements were signed at Kobalt.io's first Partner Summit in Vancouver and apply to customer work across North America and APAC, where most of its more than 1,600 customers are based. The company is also expanding into EMEA.

Each agreement makes the two parties the other's main go-to-market partner in its area. Kobalt.io said the move responds to tighter security checks in software procurement, wider use of AI in software development, and tougher certification demands in the defence supply chain.

The partnership with Forward Security focuses on managed and recurring application security work, including application-layer managed detection and response, secure software development lifecycle advisory, and continuous application security review. It has an explicit focus on AI-native companies across APAC, North America and EMEA.

Rather than a standard referral arrangement, the companies said their leadership teams will hold quarterly working sessions to align service development and roadmaps. Lessons from shared customer engagements will feed into planning on both sides.

The Johanson Group agreement targets audit and certification work for software and technology companies in North America. Under the arrangement, Kobalt.io will prepare organisations for audit and run their security programmes on an ongoing basis, while Johanson Group will carry out the audit.

Both companies said that separation is intended to preserve auditor independence. The model is designed to give clients a clearer handoff between readiness work and the formal audit process.

Insight Assurance will work with Kobalt.io on defence and government supply chain certification, centred on standards including CMMC, CPCSC, and FedRAMP or GovRAMP in North America.

Under the arrangement, Kobalt.io acts as a CMMC Registered Provider Organisation on readiness, while Insight Assurance conducts official assessments as an Authorised C3PAO and FedRAMP 3PAO. The companies said assessor independence rules require those roles to remain separate.

Michael Argast, Chief Executive Officer and Co-Founder of Kobalt.io, said the partnerships reflect a shift in customer requirements across software security, compliance and government contracting.

"The ground is shifting under our clients. AI is finding vulnerabilities faster than teams can fix them, and helping those same teams ship more software, so the pile grows from both ends. Enterprise buyers want certification evidence before a deal moves. Defence contractors are staring down deadlines that are real now. Nobody gets ahead of all that working alone. That's why we brought our closest partners into one room for our first Partner Summit to get specific about who does what, so a client gets one clear path from readiness through audit to ongoing security, with no gaps in the middle," said Michael Argast, Chief Executive Officer and Co-Founder of Kobalt.io.

Application security

Forward Security said the pace of software development has made periodic testing less effective, particularly as AI tools are used more widely by engineering teams.

"Software is shipping faster than ever, and more of it is being written with AI every month. Testing an application once a year was never really enough, and it certainly isn't now. Kobalt already has continuous relationships with their clients, which is exactly where application security needs to live. That's what we're building together," said Farshad Abasi, Chief Executive Officer of Forward Security.

Kobalt.io said the alliance is aimed in part at companies developing AI-native software, where application security demands are changing as product cycles shorten and code volumes rise. Forward Security, founded in Vancouver, focuses on application and cloud security consulting.

Audit split

The Johanson Group arrangement reflects a long-standing division between advisory work and formal assurance. Kobalt.io will continue to handle security programme operations and audit preparation, while the audit firm issues the opinion.

"An audit is only as valuable as its independence, which is why this partnership is structured the way it is. Kobalt runs the security program, we render the opinion, and the client gets both a smooth path and a report that enterprise buyers trust. We couldn't be more excited to build on that together," said Ryan McBride, Vice President of Sales of Johanson Group LLP.

Johanson Group is a licensed CPA firm based in Colourado Springs. It works on security and compliance audits including SOC 2 and ISO standards for technology, financial services, healthcare and AI companies.

Defence rules

The agreement with Insight Assurance comes as certification requirements in the defence sector become part of contracts rather than optional guidance. The companies said that shift affects suppliers on both sides of the Canada-US border.

"Every defense contractor we speak with is up against the same set of deadlines: requirements that were once advisory and are now written into contracts. Kobalt.io's readiness work and our accreditation as a C3PAO and FedRAMP 3PAO complement each other precisely because they're kept apart. That's not a compromise, it's rather what gives the certification its value, and it's why this partnership works for clients on either side of the border," said Ben Wright, Chief Revenue Officer of Insight Assurance.

Insight Assurance said it has completed more than 3,500 compliance engagements and works with clients in North America, Europe and APAC.