We are using their services as an external auditor that has been doing PCI audits since 2014 - they have helped us with all aspects related or not directly but indirectly connected (eg QSA). They also provide regular monitoring reports where we can see if our controls meet up standards set by different agencies/regulators such as GDPR etc., which was nice because it gave me peace-of mind knowing my systems were meeting requirements. Their pricing model seems unfair at times when you're talking about small organizations like ours who only need occasional consulting hours from them compared to larger companies needing more frequent engagement timeframes due too high number engagements / projects per year. I would say this could be improved so its easier for clients without making changes to billing structure & processes. Our main challenge right now being audited externally against several regulations including HIPPA data privacy regulation among others.