Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Assurance

How to check credentials and authorizations

An organization authorization and an individual credential are different things. This page explains each one, lists the authorizations we don’t hold, and shows how to check any assessor’s record with the body that issued it.

How to read this page

Organization authorization
Belongs to the firm. A program lists the company itself, for a defined scope and territory, and only that listing lets the firm offer the program’s formal assessments.
Individual credential
Belongs to the person named. It shows what that practitioner is qualified to do. It isn’t an authorization of the firm.

Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.

Authorizations we don’t hold

Some formal outcomes can only come from an organization that a program has authorized. Security Inspect doesn’t hold the authorizations below and doesn’t offer the formal outcomes they cover.

  • Security Inspect is not an authorized CMMC Third-Party Assessment Organization (C3PAO) and doesn't perform CMMC Level 2 certification assessments. Those are performed by C3PAOs authorized by the Cyber AB.
  • Security Inspect is not a licensed CPA firm and doesn't issue SOC 2 reports. SOC 2 examinations are performed by licensed CPA firms.
  • Security Inspect is not an ISO/IEC 27001 certification body and doesn't issue ISO/IEC 27001 certificates. Accredited certification comes from certification bodies accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1.
  • Security Inspect is not a PCI SSC Approved Scanning Vendor (ASV) and doesn't perform ASV scans. We also don't offer services under the PCI SSC PFI, P2PE, SSF, PIN, or 3DS programs.

Is SOC 2 a certification? Who can issue what

How to verify a credential or authorization

You don’t need to take anyone’s word for a credential or authorization. Check each record with the body that issued it: the current status, the holder or company name exactly as registered, and the scope and territory.

  • PCI DSS: PCI Security Standards Council

    Confirm the person is a QSA (not an ISA or PCIP), that the qualification is current, and that the company shown is a listed QSA Company serving the USA region.

  • CMMC: The Cyber AB and ISACA

    C3PAOs assess organizations. Individual CMMC certificates come from the CAICO, which is ISACA.

  • ISO/IEC 27001 Lead Auditor: the issuing personnel certification body

    • The issuing body's public certificate registerWhether an individual's ISO/IEC 27001 Lead Auditor or Lead Implementer certificate is current. Ask the practitioner which body issued it.

    Several bodies issue these certificates, ideally under accreditation to ISO/IEC 17024. Ask which body issued the certificate and check that body's public register. ISO/IEC 27001 certificates for organizations are issued by certification bodies, not by ISO or by personnel certification bodies; an accredited certificate comes from a certification body accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1.

Meet the team and review our engagement staffing model