Certification
Apply for SIAS certification
A SIAS assessment starts with a written scope. Here’s who can apply, what to prepare and what happens next.
Who can apply
Organizations in the United States with a website, product or system they want assessed against SIAS v1.0.
We don’t assess controls that SecurityInspect designed, implemented, configured or operates for the organization. We don’t accept an application for a scope where we did that work in the previous 24 months.
Choose what you’re applying for
| You want | Apply for | Outcome if the criteria aren’t met |
|---|---|---|
| Certification of a complete scope | SecurityInspect Certified | SecurityInspect Reviewed (findings issued; no certificate) |
| A certificate for a limited technical scope | SecurityInspect Verified, with one profile: VP-EXT, VP-APP or VP-CLD | SecurityInspect Reviewed |
| Findings only, without a certificate | A review (SecurityInspect Reviewed) | Not applicable |
An applicant for SecurityInspect Certified that doesn’t meet the criteria isn’t moved to SecurityInspect Verified automatically. SecurityInspect Reviewed means: An assessment was completed and findings were issued. This status does not indicate that the organization passed.
What to prepare
- The legal name of the entity to be certified, and the websites, products or systems in scope.
- Environments, locations and hosting, and the types of data involved (described, not sent).
- The domains the certificate should cover. You’ll prove control of each with a DNS record.
- Network and data-flow diagrams and an asset list.
- A person who can authorize security testing of every asset in scope, and sign for the organization.
- Any past work SecurityInspect has done for you, so we can run the conflict check.
What happens next
- You get in touch
Use the contact form and choose the topic “SIAS certification”. A few sentences about the scope are enough. Don’t send diagrams, evidence or sensitive data through the form.
- You send the application and scope declaration
We agree the exact scope in writing.
- We run the conflict-of-interest check
If it isn’t clear, we tell you and stop.
- We agree the assessment plan and a written fee
Fees are set in a written proposal before the assessment starts. They cover the assessment, not a result, and are payable whatever the outcome.
- The assessment runs
Through the stages described in how SIAS assessments work.
- You can fix findings, and we retest
The organization may fix findings within 90 days of the findings report. SecurityInspect retests each fix. A retest replaces the original result only when the fix is verified.
- An independent review and decision
An independent reviewer checks the file and an independent decision-maker decides.
- If certification is granted
You sign the badge license, prove control of your domains, and the verification record goes live.
The assessment plan sets the schedule. We don’t promise a timeline or an outcome.
Fees
Fees are set in a written proposal before the assessment starts. They cover the assessment, not a result, and are payable whatever the outcome.
SIAS list prices and what the fee covers
Don’t send sensitive information through the form
We don't collect sensitive evidence through this website. Please don't send passwords or other credentials, sensitive incident details, payment card data, health information, or controlled defense information through a website form. When an engagement needs sensitive evidence, we arrange a secure channel with you after initial contact.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Ask about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.