About
Team
Credentials belong to people, not to the firm
Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.
Practice leadership
Jason Felps — Security Assurance Lead
Focus areas
- PCI DSS
- CMMC
- ISO/IEC 27001
- Readiness and assessor independence
Credentials and authorizations: how firm and individual records are kept apart
How to verify a practitioner’s credential
You don’t need to take any firm’s word for a credential. Ask the practitioner for the details the issuer needs, usually their name as registered and a certificate or member number, then check with the issuer directly.
Check that the credential is current, not just that it was earned. Many credentials expire unless they’re renewed.
ISACA
What you can check: CISA, CISM, CRISC, and CMMC individual certifications such as CCP and CCA
ISACA issues its own certifications. Since December 17, 2025 it has also been the CMMC Assessor and Instructor Certification Organization (CAICO), which certifies CMMC professionals and assessors, so it verifies those individual CMMC certificates too.
PCI Security Standards Council (PCI SSC) assessor listings
What you can check: QSA Companies, ASV companies, and individual professionals such as QSAs, ISAs, and PCIPs
PCI SSC qualifies QSA Companies first. An individual's QSA qualification depends on employment by a listed QSA Company and covers only assessments performed for that company. PCIP is an individual credential that confers no assessor rights, and an ISA's qualification applies only to the merchant or service provider that sponsors them.
PCI Security Standards Council official website (external site)
The Cyber AB Marketplace
What you can check: Authorized C3PAOs, Registered Practitioners, and other CMMC ecosystem organizations and practitioners
C3PAOs assess organizations. They don't issue credentials to individuals: individual CMMC certificates come from the CAICO, which is ISACA.
State boards of accountancy and CPAverify
What you can check: CPA licenses
CPA licenses are issued by state boards of accountancy. CPAverify, run by the National Association of State Boards of Accountancy, searches license records from participating boards. SOC 2 reports are issued by licensed CPA firms. There's no AICPA-issued or state-recognized individual SOC 2 certification, and no individual credential authorizes anyone to issue a SOC 2 report.
Personnel certification bodies for ISO/IEC 27001
What you can check: Individual certificates such as ISO/IEC 27001 Lead Implementer or Lead Auditor
Several bodies issue these certificates, ideally under accreditation to ISO/IEC 17024. Ask which body issued the certificate and check that body's public register. ISO/IEC 27001 certificates for organizations are issued by certification bodies, not by ISO or by personnel certification bodies; an accredited certificate comes from a certification body accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1.