Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Certification

SecurityInspect certification

SecurityInspect certification tells you that a named website, product or system met the published requirements of our own standard, the SecurityInspect Assurance Standard (SIAS) v1.0, at the time it was assessed. Every certificate has a public record you can check.

What a certificate means

Every certificate carries the same statement, word for word:

SecurityInspect Certified indicates that the stated scope met the published requirements of SIAS v1.0 at the time of assessment through proprietary software analysis, manual security review and an independent certification decision.

“Met the published requirements” means every certification criterion in the published standard was satisfied. Those criteria allow some findings on non-mandatory controls to stay open under a dated plan, and every verification record shows how many.

A certificate names the legal entity and the website, product or system that was assessed, and lists anything excluded. The standard behind it is published in full, control by control.

How a certificate is earned

Every certificate rests on four things. None of them is enough on its own.

  • Software analysisAutomated technical tests collect evidence, with timestamps and integrity checks.
  • Manual review by qualified security professionalsTechnical testing, a review of policies and processes, interviews and observation.
  • Independent quality reviewA reviewer who was not on the assessment team checks the whole file.
  • An independent certification decisionThe person who decides did not assess the organization and has never advised it or helped fix its systems.

Certification is never issued from a vulnerability scan, an automated score, self-attestation, a questionnaire or unvalidated evidence alone.

The 15 stages of a SIAS assessment

Three possible outcomes

SIAS levels and what each one means
LevelWhat it means
SecurityInspect CertifiedThe complete applicable SIAS scope passed; all mandatory requirements were met; no unresolved critical failures remain; a separate reviewer approved the certification decision.
SecurityInspect VerifiedA clearly defined, limited technical scope was tested. It must never be presented as full organizational certification.
SecurityInspect ReviewedAn assessment was completed and findings were issued. This status does not indicate that the organization passed.

Only SecurityInspect Certified and SecurityInspect Verified lead to a certificate and a badge.

Scope tiers describe breadth, not a grade

Core, Growth, Advanced and Enterprise describe how broad the assessed scope is. A verification record shows it as Single-product scope, Multi-product scope, Complex-environment scope or Enterprise scope. It is not a security grade: every SecurityInspect Certified certificate met the same published requirements of SIAS v1.0.

What each tier covers, with list prices

Check before you rely on a badge

A badge is a picture, and pictures can be copied. Certification is valid only when the linked verification record confirms an Active status. Select any SIAS badge to open its record, or enter a certificate ID on the verification page.

What certification does not mean

A certificate covers the stated scope, at the time of assessment. It does not mean an organization is secure in general, compliant with any law or framework, or protected against breaches.

It is not a general security verdict

A certificate does not mean an organization is secure, that its systems are free of vulnerabilities, or that it can’t be breached. No assessment can establish that. SIAS tests a stated scope against published requirements at a point in time.

It covers only the stated scope

Systems, products, entities and locations outside the scope on the verification record are not covered, even if they belong to the same organization. Read the scope, exclusions and limitations before you rely on a certificate.

It is not a HIPAA, PCI DSS, SOC 2 or ISO/IEC 27001 outcome

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

  • HIPAAHHS has said it does not endorse or recognize private organizations’ certifications regarding the HIPAA Security Rule. A SIAS certificate does not change any HIPAA obligation.
  • PCI DSSPCI DSS compliance is validated in the way a merchant’s or service provider’s acquirer or the payment brands require, using the PCI Security Standards Council’s assessment programs and forms. A SIAS certificate is not PCI DSS validation.
  • SOC 2SOC 2 examinations and reports are performed and issued by licensed CPA firms. SecurityInspect is not a CPA firm, and a SIAS certificate is not a SOC 2 report.
  • ISO/IEC 27001Accredited ISO/IEC 27001 certification is issued by accredited certification bodies. SecurityInspect is not one, and a SIAS certificate is not ISO/IEC 27001 certification.

It is not accredited or endorsed by anyone else

SIAS is SecurityInspect’s own standard. It is not accredited, endorsed or recognized by any government agency, standards body, accreditation body or framework owner, and it is not a substitute for any of their programs.

It is not legal advice or a legal determination

SecurityInspect is not a law firm. A certificate is not a legal opinion and does not determine whether an organization meets any law or contract.

It is not permanent

A certificate is valid for 12 months from the decision date, unless it is suspended, revoked or withdrawn sooner. There is no grace period after expiry. Always check the verification record.

Read the rules

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.