Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Independence

Independence between readiness work and formal assessment

A SOC 2 report, an accredited ISO/IEC 27001 certificate, a PCI DSS Report on Compliance, or a CMMC Level 2 certification assessment can only come from an organization the program authorizes. Each program also keeps the people who designed your controls from judging them. This page explains those rules and how our work stays on the right side of them.

Why it matters

Readiness work (scoping, gap assessment, remediation planning, and evidence preparation) helps you get ready. A formal report, certificate, or assessment result is different: your customers, acquiring bank, or contracting officer rely on it because an authorized, independent assessor issued it.

If the people who prepared you also judge the result, the assessment can breach its own program’s rules. Keeping the two apart protects the outcome you’re paying for.

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

How we keep readiness and assessment apart

Readiness work, and who issues the formal outcome

  • Our compliance work prepares you for PCI DSS, SOC 2, ISO/IEC 27001, and CMMC. The formal outcome, such as a PCI DSS Report on Compliance, a SOC 2 report, an ISO/IEC 27001 certificate, or a CMMC certification assessment, comes from an organization that the program authorizes to issue it.
  • Readiness work doesn't validate your compliance. We don't complete or sign your Self-Assessment Questionnaire or Attestation of Compliance for you; your organization does.
  • You choose and engage your assessor, CPA firm, or certification body directly. We don't choose one for you, and if you ask us to suggest options, we tell you about any relationship we have with each one.
  • A practitioner of ours who holds an individual CMMC assessor certification doesn't take part in the Level 2 certification assessment of any organization we helped prepare for a CMMC assessment in the previous three years.

Who can issue what, and the rule that binds them

Program rules and versions were last checked on . They bind whoever performs the formal assessment, and careless readiness work can still make an assessor ineligible.

Our commitments

Program rules govern assessors. These commitments apply to all of our work, so neither your assessor nor our own practitioners end up in a conflict.

  • Practitioners who worked on your readiness engagement don't take part in your formal assessment, examination, or certification audit, including as a subcontractor or specialist to the assessor.
  • If you're considering an assessor, CPA firm, or certification body that we have any business or personal relationship with, we disclose that relationship to you in writing before you decide.
  • We don't accept undisclosed referral fees, commissions, or other payments from assessors, CPA firms, or certification bodies.
  • Independent and vendor-neutral: no parent company, reseller quota, or pay-to-recommend arrangement.

Individual credentials aren’t firm authorizations

Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.

An individual credential doesn't make Security Inspect an assessor for another program. A Certified CMMC Assessor (CCA) credential doesn't make the firm a C3PAO, and an ISO/IEC 27001 Lead Auditor credential doesn't let the firm certify organizations.

An individual qualification is tied to the person and, for some programs, to their employer. A QSA’s qualification is active only while they work for a listed QSA Company, and CMMC assessors are certified individually by the CAICO. Neither lets another firm offer those assessments.

Credentials and authorizations, and how to check each one

What we are not

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.

How to check an assessor

You don’t need to take anyone’s word for an assessor’s status. Each program publishes a way to check it.

  • PCI DSS: PCI Security Standards Council

    Confirm the person is a QSA (not an ISA or PCIP), that the qualification is current, and that the company shown is a listed QSA Company serving the USA region.

  • CMMC: The Cyber AB and ISACA

    C3PAOs assess organizations. Individual CMMC certificates come from the CAICO, which is ISACA.

  • SOC 2: CPA licensing and peer review

    CPAverify doesn't include Hawaii or New Mexico, so check those boards directly. You can also ask the CPA firm for its latest peer review report.

  • ISO/IEC 27001: accredited certification

    • IAF CertSearch (external site)Accredited management system certificates, with the issuing certification body and its accreditation body
    • ANAB (ANSI National Accreditation Board): search its directory on ANAB’s websiteWhether a U.S. certification body is accredited, and for which scope

    IAF CertSearch lists only accredited certificates for organizations. It doesn't cover certificates held by individuals, such as lead auditor credentials.

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Primary sources

Talk to a practitioner about independence

Tell us which formal outcome you’re working toward and who you’re considering as your assessor. We’ll explain how we’d keep readiness work separate from it.

What happens next

  1. Tell us about the framework and the assessor you have in mind, if any.
  2. Talk through scope and independence questions with a practitioner.
  3. Review the proposal and decide whether to go ahead.