Assurance
How to check credentials and authorizations
An organization authorization and an individual credential are different things. This page explains each one, lists the authorizations we don’t hold, and shows how to check any assessor’s record with the body that issued it.
How to read this page
- Organization authorization
- Belongs to the firm. A program lists the company itself, for a defined scope and territory, and only that listing lets the firm offer the program’s formal assessments.
- Individual credential
- Belongs to the person named. It shows what that practitioner is qualified to do. It isn’t an authorization of the firm.
Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.
Authorizations we don’t hold
Some formal outcomes can only come from an organization that a program has authorized. Security Inspect doesn’t hold the authorizations below and doesn’t offer the formal outcomes they cover.
- Security Inspect is not an authorized CMMC Third-Party Assessment Organization (C3PAO) and doesn't perform CMMC Level 2 certification assessments. Those are performed by C3PAOs authorized by the Cyber AB.
- Security Inspect is not a licensed CPA firm and doesn't issue SOC 2 reports. SOC 2 examinations are performed by licensed CPA firms.
- Security Inspect is not an ISO/IEC 27001 certification body and doesn't issue ISO/IEC 27001 certificates. Accredited certification comes from certification bodies accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1.
- Security Inspect is not a PCI SSC Approved Scanning Vendor (ASV) and doesn't perform ASV scans. We also don't offer services under the PCI SSC PFI, P2PE, SSF, PIN, or 3DS programs.
How to verify a credential or authorization
You don’t need to take anyone’s word for a credential or authorization. Check each record with the body that issued it: the current status, the holder or company name exactly as registered, and the scope and territory.
PCI DSS: PCI Security Standards Council
- QSA Companies list (external site)Whether a QSA Company is listed, in good standing or in remediation, and which regions it serves
- Approved Scanning Vendors list (external site)Whether a scanning vendor is an approved ASV
- Professionals lookup (external site)An individual's qualification, such as QSA, ISA, or PCIP, and its status
Confirm the person is a QSA (not an ISA or PCIP), that the qualification is current, and that the company shown is a listed QSA Company serving the USA region.
CMMC: The Cyber AB and ISACA
- The Cyber AB CMMC Marketplace (external site)Authorized C3PAOs and other CMMC ecosystem organizations and practitioners
- ISACA certification verification (external site)Individual CMMC certificates, such as CCP and CCA, by certificate number and last name
C3PAOs assess organizations. Individual CMMC certificates come from the CAICO, which is ISACA.
ISO/IEC 27001 Lead Auditor: the issuing personnel certification body
- The issuing body's public certificate registerWhether an individual's ISO/IEC 27001 Lead Auditor or Lead Implementer certificate is current. Ask the practitioner which body issued it.
Several bodies issue these certificates, ideally under accreditation to ISO/IEC 17024. Ask which body issued the certificate and check that body's public register. ISO/IEC 27001 certificates for organizations are issued by certification bodies, not by ISO or by personnel certification bodies; an accredited certificate comes from a certification body accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1.