Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

About

Team

Engagements are led by Security Inspect practitioners and supported by specialists selected for the agreed scope. The proposal identifies the practitioners assigned to each engagement and their responsibilities.

Credentials belong to people, not to the firm

Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.

Practice leadership

Jason Felps — Security Assurance Lead

Focus areas

  • PCI DSS
  • CMMC
  • ISO/IEC 27001
  • Readiness and assessor independence

Credentials and authorizations: how firm and individual records are kept apart

How to verify a practitioner’s credential

You don’t need to take any firm’s word for a credential. Ask the practitioner for the details the issuer needs, usually their name as registered and a certificate or member number, then check with the issuer directly.

Check that the credential is current, not just that it was earned. Many credentials expire unless they’re renewed.

  • ISACA

    What you can check: CISA, CISM, CRISC, and CMMC individual certifications such as CCP and CCA

    ISACA issues its own certifications. Since December 17, 2025 it has also been the CMMC Assessor and Instructor Certification Organization (CAICO), which certifies CMMC professionals and assessors, so it verifies those individual CMMC certificates too.

    ISACA official website (external site)

  • PCI Security Standards Council (PCI SSC) assessor listings

    What you can check: QSA Companies, ASV companies, and individual professionals such as QSAs, ISAs, and PCIPs

    PCI SSC qualifies QSA Companies first. An individual's QSA qualification depends on employment by a listed QSA Company and covers only assessments performed for that company. PCIP is an individual credential that confers no assessor rights, and an ISA's qualification applies only to the merchant or service provider that sponsors them.

    PCI Security Standards Council official website (external site)

  • The Cyber AB Marketplace

    What you can check: Authorized C3PAOs, Registered Practitioners, and other CMMC ecosystem organizations and practitioners

    C3PAOs assess organizations. They don't issue credentials to individuals: individual CMMC certificates come from the CAICO, which is ISACA.

    The Cyber AB official website (external site)

  • State boards of accountancy and CPAverify

    What you can check: CPA licenses

    CPA licenses are issued by state boards of accountancy. CPAverify, run by the National Association of State Boards of Accountancy, searches license records from participating boards. SOC 2 reports are issued by licensed CPA firms. There's no AICPA-issued or state-recognized individual SOC 2 certification, and no individual credential authorizes anyone to issue a SOC 2 report.

    CPAverify official website (external site)

  • Personnel certification bodies for ISO/IEC 27001

    What you can check: Individual certificates such as ISO/IEC 27001 Lead Implementer or Lead Auditor

    Several bodies issue these certificates, ideally under accreditation to ISO/IEC 17024. Ask which body issued the certificate and check that body's public register. ISO/IEC 27001 certificates for organizations are issued by certification bodies, not by ISO or by personnel certification bodies; an accredited certificate comes from a certification body accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1.