Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Certification

SIAS badge rules

A SIAS badge is valid only when it links to an Active verification record. These rules keep badges honest. The full policy is part of every holder’s badge license.

Who can display a badge

  • Only SecurityInspect Certified and SecurityInspect Verified lead to a certificate and a badge.
  • A SecurityInspect Verified badge, and any statement about it, always says “limited technical scope”. SecurityInspect Reviewed has no badge.
  • No one may display a badge before a certification decision, or after a certificate stops being Active.

How a badge must look

Only the supplied light and dark versions of the horizontal, seal and compact layouts, at or above the minimum size, with clear space around them. No recoloring, cropping, stretching, animation, added words or effects.

Badge layouts and minimum sizes
LayoutNative size (CSS px)Minimum on screenIntended use
Horizontal352 × 100288 px wideTrust, security and product pages
Seal176 × 176160 px wideWhere a round mark fits; documents
Compact140 × 50 (SecurityInspect Verified: 140 × 62)120 px wideWebsite footers

The alternative text for the SecurityInspect Certified badge is fixed:

SecurityInspect Certified — independently assessed against SIAS v1.0. Select to verify current status.

Specimen badges

These specimens show every supplied layout. Each carries the reserved ID SIAS-0000-0000-0000-0000, which is never issued, and a band that reads “Specimen — not a real certificate”. A real badge carries its own certificate ID and links to its own record.

Where a badge may appear

Where it clearly refers to the certified scope, and on websites only on the domains listed on the verification record. When a page covers more than the scope, the badge carries a line saying what is covered. Badges are never shown in a row of HIPAA, PCI, SOC or ISO logos, and are never combined with any other framework’s name or mark.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

What holders may say

Holders may say that they hold SecurityInspect Certified (or SecurityInspect Verified, with its limited technical scope) for the stated scope, with a link to the record. They may not describe themselves as secure, compliant or guaranteed on the strength of a certificate, or suggest that SIAS is a HIPAA, PCI DSS, SOC 2 or ISO/IEC 27001 outcome.

When a certificate stops being Active

The hosted badge changes to “Not currently active” straight away, but the text that describes the badge in the holder’s own page code does not, so holders remove the embed code as well.

  • Expiry: every badge, embed and certification claim comes down by the end of the expiry date (23:59:59 UTC). Suspension, revocation or an unplanned withdrawal: web and digital uses come down as soon as the holder receives our notice, and printed materials stop being handed out. The certificate is not valid from the moment its status changes.
  • Badge images aren’t used in email signatures, because a sent email can’t be updated. Holders may add a plain text line with the verification link instead.

Misuse

Misuse can lead to suspension or revocation. To report a badge that looks wrong, use the contact form and choose the topic “SIAS certification”. Report a badge that looks wrong

Examples of badge misuse
What was doneWhy it is misuse
Badge image with no linkA visitor can’t check the status; the badge becomes an unverifiable claim
Badge linked to the SecurityInspect home pageIt doesn’t lead to the certificate
A downloaded image on a website instead of the hosted imageIt won’t change when the status changes
Badge recolored to the holder’s brand colorRecoloring is prohibited
Badge in a row with HIPAA, SOC 2 and ISO logos under “Our certifications”It suggests SIAS is part of, or equal to, those programs
“HIPAA compliant” added under the badgeIt adds wording and implies a framework claim
Alternative text changed to “Certified secure”It changes fixed text and makes a prohibited claim
SecurityInspect Verified badge in a site-wide header, with no scope lineIt presents a limited technical scope as organizational certification
Badge still on the website the day after the certificate expiredUse after expiry: the expiry date was known a year ahead
Staff profile headline “SecurityInspect Certified professional”SIAS never certifies a person
Badge on a subsidiary’s website that isn’t listed on the recordIt is outside the certified scope and not a bound domain
Screenshot of the verification page used as proof months laterThe status may have changed; screenshots are not records
A “SIAS in progress” seal during an assessmentNo badge exists before a decision
Link to the verification page through a URL shortenerIt hides the destination
Badge shown for a SecurityInspect Reviewed outcomeReviewed never gets a badge and doesn’t indicate a pass
Hosted badge image in an email signatureSent emails can’t be updated, and blocked images keep showing the alternative text

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.