SIAS v1.0 standard
Every domain and control, published in full
Certification
SecurityInspect certification tells you that a named website, product or system met the published requirements of our own standard, the SecurityInspect Assurance Standard (SIAS) v1.0, at the time it was assessed. Every certificate has a public record you can check.
Every certificate carries the same statement, word for word:
SecurityInspect Certified indicates that the stated scope met the published requirements of SIAS v1.0 at the time of assessment through proprietary software analysis, manual security review and an independent certification decision.
“Met the published requirements” means every certification criterion in the published standard was satisfied. Those criteria allow some findings on non-mandatory controls to stay open under a dated plan, and every verification record shows how many.
A certificate names the legal entity and the website, product or system that was assessed, and lists anything excluded. The standard behind it is published in full, control by control.
Every certificate rests on four things. None of them is enough on its own.
Certification is never issued from a vulnerability scan, an automated score, self-attestation, a questionnaire or unvalidated evidence alone.
| Level | What it means |
|---|---|
| SecurityInspect Certified | The complete applicable SIAS scope passed; all mandatory requirements were met; no unresolved critical failures remain; a separate reviewer approved the certification decision. |
| SecurityInspect Verified | A clearly defined, limited technical scope was tested. It must never be presented as full organizational certification. |
| SecurityInspect Reviewed | An assessment was completed and findings were issued. This status does not indicate that the organization passed. |
Only SecurityInspect Certified and SecurityInspect Verified lead to a certificate and a badge.
Core, Growth, Advanced and Enterprise describe how broad the assessed scope is. A verification record shows it as Single-product scope, Multi-product scope, Complex-environment scope or Enterprise scope. It is not a security grade: every SecurityInspect Certified certificate met the same published requirements of SIAS v1.0.
A badge is a picture, and pictures can be copied. Certification is valid only when the linked verification record confirms an Active status. Select any SIAS badge to open its record, or enter a certificate ID on the verification page.
A certificate covers the stated scope, at the time of assessment. It does not mean an organization is secure in general, compliant with any law or framework, or protected against breaches.
A certificate does not mean an organization is secure, that its systems are free of vulnerabilities, or that it can’t be breached. No assessment can establish that. SIAS tests a stated scope against published requirements at a point in time.
Systems, products, entities and locations outside the scope on the verification record are not covered, even if they belong to the same organization. Read the scope, exclusions and limitations before you rely on a certificate.
SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.
SIAS is SecurityInspect’s own standard. It is not accredited, endorsed or recognized by any government agency, standards body, accreditation body or framework owner, and it is not a substitute for any of their programs.
SecurityInspect is not a law firm. A certificate is not a legal opinion and does not determine whether an organization meets any law or contract.
A certificate is valid for 12 months from the decision date, unless it is suspended, revoked or withdrawn sooner. There is no grace period after expiry. Always check the verification record.
Every domain and control, published in full
The 15 stages from scope to decision
How advice, assessment and decisions stay apart
Cross-references by identifier, not equivalence
How holders may display a badge
Who can apply, what to prepare, and what happens next
List prices and what the fee covers
Validity, surveillance and status changes
Common questions about SIAS certification
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Tell us what you want assessed, and we’ll start with the scope.