Independence
Independence between readiness work and formal assessment
A SOC 2 report, an accredited ISO/IEC 27001 certificate, a PCI DSS Report on Compliance, or a CMMC Level 2 certification assessment can only come from an organization the program authorizes. Each program also keeps the people who designed your controls from judging them. This page explains those rules and how our work stays on the right side of them.
Why it matters
Readiness work (scoping, gap assessment, remediation planning, and evidence preparation) helps you get ready. A formal report, certificate, or assessment result is different: your customers, acquiring bank, or contracting officer rely on it because an authorized, independent assessor issued it.
If the people who prepared you also judge the result, the assessment can breach its own program’s rules. Keeping the two apart protects the outcome you’re paying for.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
How we keep readiness and assessment apart
Readiness work, and who issues the formal outcome
- Our compliance work prepares you for PCI DSS, SOC 2, ISO/IEC 27001, and CMMC. The formal outcome, such as a PCI DSS Report on Compliance, a SOC 2 report, an ISO/IEC 27001 certificate, or a CMMC certification assessment, comes from an organization that the program authorizes to issue it.
- Readiness work doesn't validate your compliance. We don't complete or sign your Self-Assessment Questionnaire or Attestation of Compliance for you; your organization does.
- You choose and engage your assessor, CPA firm, or certification body directly. We don't choose one for you, and if you ask us to suggest options, we tell you about any relationship we have with each one.
- A practitioner of ours who holds an individual CMMC assessor certification doesn't take part in the Level 2 certification assessment of any organization we helped prepare for a CMMC assessment in the previous three years.
Who can issue what, and the rule that binds them
Program rules and versions were last checked on . They bind whoever performs the formal assessment, and careless readiness work can still make an assessor ineligible.
PCI DSS
- Formal outcome
- Report on Compliance (ROC) and Attestation of Compliance; external vulnerability scan reports
- Who can issue it
- A QSA Company listed by the PCI Security Standards Council, for assessments. A PCI SSC-listed Approved Scanning Vendor (ASV), for external scans. An individual's QSA qualification is active only through employment by a listed QSA Company.
Separation of duties: whoever designed a control can't assess it
- QSA Companies must keep separation-of-duties controls so their assessors are independent and free of conflicts of interest, and must collect written conflict-of-interest disclosures from assessors at hire and every year.
- PCI SSC FAQ 1562: a QSA Employee who designed, developed, or implemented controls for a customer may not assess those controls. Another QSA Employee who wasn't involved may, if the company keeps adequate, documented, and defensible separation of duties.
- QSA Companies may not enter into contracts that guarantee a compliant ROC.
CMMC
- Formal outcome
- Certificate of CMMC Status after a Level 2 (C3PAO) certification assessment
- Who can issue it
- A C3PAO authorized by the Cyber AB, whose assessment team uses assessors (CCAs) certified by the CAICO. ISACA has operated the CAICO since December 2025. C3PAOs certify organizations, not people.
A three-year look-back for ecosystem members who consulted
- 32 CFR 170.8(b)(17)(ii)(G) bars CMMC ecosystem members from the Level 2 certification assessment process for an organization they served as a consultant to prepare for any CMMC assessment within three years.
- The rule reaches C3PAOs (170.9(b)(2)), certified assessors (170.11(b)(2)), and CMMC professionals (170.13(b)(2)).
- Level 1 and Level 2 self-assessments are performed by the organization itself and affirmed by its own senior official.
SOC 2
- Formal outcome
- SOC 2 Type 1 or Type 2 report (an attestation report, not a certification)
- Who can issue it
- A licensed CPA firm, performing the examination under AICPA attestation standards. State accountancy laws generally reserve this attest work for licensed CPAs practicing through a permitted CPA firm.
A CPA firm can't examine controls it designed or implemented
- Under the AICPA Code of Professional Conduct (ET 1.295.030), designing, implementing, or maintaining internal control is a management responsibility. A CPA firm that takes it on for an examination client impairs its independence, and no safeguard can fix that.
- The same applies to preparing the system description or deciding which recommendations to implement.
- The Code's relief for attestation engagements (ET 1.297.030) covers only services unrelated to what's examined, and readiness work always relates to it.
ISO/IEC 27001
- Formal outcome
- ISO/IEC 27001 certificate for an information security management system
- Who can issue it
- A certification body. For accredited certification, the body is accredited to ISO/IEC 17021-1 and ISO/IEC 27006-1 by an accreditation body in the Global ACI MRA (formerly the IAF MLA); in the U.S., ANAB is one example. ISO itself doesn't certify anyone.
An accredited certification body can never consult
- ISO/IEC 17021-1, 5.2.5: the certification body, its legal entity, and any entity it controls may not offer or provide management system consultancy at all.
- 5.2.7: consultancy by a body related to the certification body is a significant threat to impartiality. The recognized mitigation is to wait at least two years after the consultancy ends before certifying.
- 5.2.10: people who provided consultancy to a client are kept off that client's audits, with two years after the consultancy as the recognized mitigation.
- ISO/IEC 27006-1:2024, 5.2.2: the certification body must be independent of whoever performs the client's internal ISMS audit.
HIPAA Security Rule
- Formal outcome
- None. There is no official HIPAA certification.
- Who can issue it
- No one. HHS says it doesn't endorse or otherwise recognize private organizations' certifications regarding the Security Rule. Its Office for Civil Rights enforces the rule.
No assessor program, so no assessor independence rule
- The rule requires a periodic technical and nontechnical evaluation (45 CFR 164.308(a)(8)), which may be done internally or by an outside organization.
- A private certificate doesn't absolve an organization of its legal obligations under the rule.
Our commitments
Program rules govern assessors. These commitments apply to all of our work, so neither your assessor nor our own practitioners end up in a conflict.
- Practitioners who worked on your readiness engagement don't take part in your formal assessment, examination, or certification audit, including as a subcontractor or specialist to the assessor.
- If you're considering an assessor, CPA firm, or certification body that we have any business or personal relationship with, we disclose that relationship to you in writing before you decide.
- We don't accept undisclosed referral fees, commissions, or other payments from assessors, CPA firms, or certification bodies.
- Independent and vendor-neutral: no parent company, reseller quota, or pay-to-recommend arrangement.
Individual credentials aren’t firm authorizations
Individual credentials belong to the practitioner who holds them. An individual credential doesn't give Security Inspect any organization-level authorization.
An individual credential doesn't make Security Inspect an assessor for another program. A Certified CMMC Assessor (CCA) credential doesn't make the firm a C3PAO, and an ISO/IEC 27001 Lead Auditor credential doesn't let the firm certify organizations.
An individual qualification is tied to the person and, for some programs, to their employer. A QSA’s qualification is active only while they work for a listed QSA Company, and CMMC assessors are certified individually by the CAICO. Neither lets another firm offer those assessments.
What we are not
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.
How to check an assessor
You don’t need to take anyone’s word for an assessor’s status. Each program publishes a way to check it.
PCI DSS: PCI Security Standards Council
- QSA Companies list (external site)Whether a QSA Company is listed, in good standing or in remediation, and which regions it serves
- Approved Scanning Vendors list (external site)Whether a scanning vendor is an approved ASV
- Professionals lookup (external site)An individual's qualification, such as QSA, ISA, or PCIP, and its status
Confirm the person is a QSA (not an ISA or PCIP), that the qualification is current, and that the company shown is a listed QSA Company serving the USA region.
CMMC: The Cyber AB and ISACA
- The Cyber AB CMMC Marketplace (external site)Authorized C3PAOs and other CMMC ecosystem organizations and practitioners
- ISACA certification verification (external site)Individual CMMC certificates, such as CCP and CCA, by certificate number and last name
C3PAOs assess organizations. Individual CMMC certificates come from the CAICO, which is ISACA.
SOC 2: CPA licensing and peer review
- CPAverify (external site)CPA licenses from participating state boards of accountancy
- State boards of accountancy (external site)The licensing authority for CPAs and CPA firms in each jurisdiction
- AICPA Peer Review Public File (external site)A CPA firm's peer review enrollment and last review date
CPAverify doesn't include Hawaii or New Mexico, so check those boards directly. You can also ask the CPA firm for its latest peer review report.
ISO/IEC 27001: accredited certification
- IAF CertSearch (external site)Accredited management system certificates, with the issuing certification body and its accreditation body
- ANAB (ANSI National Accreditation Board): search its directory on ANAB’s websiteWhether a U.S. certification body is accredited, and for which scope
IAF CertSearch lists only accredited certificates for organizations. It doesn't cover certificates held by individuals, such as lead auditor credentials.
Educational information, not legal advice
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Talk to a practitioner about independence
Tell us which formal outcome you’re working toward and who you’re considering as your assessor. We’ll explain how we’d keep readiness work separate from it.
What happens next
- Tell us about the framework and the assessor you have in mind, if any.
- Talk through scope and independence questions with a practitioner.
- Review the proposal and decide whether to go ahead.