Certification
SIAS certification questions
Short answers to the questions people ask most about SecurityInspect certification and verification.
Questions and answers
What is SecurityInspect certification?
It’s SecurityInspect’s own certification program. We assess a named website, product or system against our published standard, SIAS v1.0, and if it meets the requirements we issue a certificate with a public verification record.
What does “SecurityInspect Certified” mean?
SecurityInspect Certified indicates that the stated scope met the published requirements of SIAS v1.0 at the time of assessment through proprietary software analysis, manual security review and an independent certification decision. “Met the published requirements” means every certification criterion in the published standard was satisfied. Those criteria allow some findings on non-mandatory controls to stay open under a dated plan, and every verification record shows how many.
Does a certificate mean an organization is secure?
No. It means a stated scope met published requirements when it was assessed. No assessment can show that an organization is secure in general or can’t be breached.
Is SIAS certification a SOC 2 report, an ISO/IEC 27001 certificate, a HIPAA certification or PCI DSS validation?
No. SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.
Is SIAS accredited or endorsed by a government agency or standards body?
No. SIAS is SecurityInspect’s own standard. It is not accredited, endorsed or recognized by any government agency, standards body, accreditation body or framework owner, and it is not a substitute for any of their programs.
What’s the difference between SecurityInspect Certified, SecurityInspect Verified and SecurityInspect Reviewed?
SecurityInspect Certified: The complete applicable SIAS scope passed; all mandatory requirements were met; no unresolved critical failures remain; a separate reviewer approved the certification decision. SecurityInspect Verified: A clearly defined, limited technical scope was tested. It must never be presented as full organizational certification. SecurityInspect Reviewed: An assessment was completed and findings were issued. This status does not indicate that the organization passed.
Do Core, Growth, Advanced and Enterprise mean different levels of security?
No. Core, Growth, Advanced and Enterprise describe how broad the assessed scope is. A verification record shows it as Single-product scope, Multi-product scope, Complex-environment scope or Enterprise scope. It is not a security grade: every SecurityInspect Certified certificate met the same published requirements of SIAS v1.0.
How do I check whether a certificate is valid?
Select the badge, or enter the certificate ID on the verification page. Certification is valid only when the linked verification record confirms an Active status. Read the scope and exclusions too.
The verification page says “No certificate found”. What does that mean?
Usually a typing error. Check the ID against the badge or certificate. If it still isn’t found, tell us through the contact form and we’ll look into it.
Can a certificate be issued from a scan or a questionnaire?
No. Certification is never issued from a vulnerability scan, an automated score, self-attestation, a questionnaire or unvalidated evidence alone. A control can be rated Met only when at least one piece of its evidence was obtained or produced by SecurityInspect (a direct test, an observation, or a system extract obtained by SecurityInspect) and corroborated by evidence of a different type. Interviews and supplied documents alone are never enough.
What does the software do, and what do people decide?
The software never rates a control, assigns a level or publishes a record. People set every rating and severity, approve compensating controls and exceptions, and make the decision.
SecurityInspect owns the standard and does the assessment. How is that independent?
SecurityInspect owns the SIAS standard and performs the assessments. “Independently assessed” means that the people who assessed, reviewed and decided this certificate had no advisory, design, implementation or remediation role for the organization, and no financial interest in the outcome, and that the person who made the certification decision did not take part in the assessment. SIAS is not accredited or endorsed by any government agency or standards body. Read the independence page for how these safeguards work.
Can SecurityInspect help us fix problems and then certify us?
Not the same scope within 24 months, and never with the same people. Anyone at SecurityInspect who advised an organization, or helped design, build or fix its systems, never takes any role in its SIAS assessment, review or decision. We don’t assess controls that SecurityInspect designed, implemented, configured or operates for the organization. We don’t accept an application for a scope where we did that work in the previous 24 months. While an assessment is open, and while a certificate is valid, we don’t design, implement or fix the in-scope systems.
Do fees depend on whether we pass?
No. The fee buys the assessment, not a result. It is payable whether the applicant passes, fails or withdraws. There is no “pay only if you pass” option, because tying fees to outcomes would compromise impartiality.
How long does a certificate last?
A certificate is valid for 12 months from the decision date, unless it is suspended, revoked or withdrawn sooner. There is no grace period after expiry. Renewal is a full reassessment against the current SIAS version, with 12 months of evidence. Apply at least 180 days before the expiry date, so that the assessment, any remediation, the independent review and the decision can finish in time. A certificate renewed on time keeps its ID, so its badge keeps working.
What happens if our systems change after certification?
Holders tell us about material changes to the certified scope within 30 calendar days, and before go-live for planned major changes where practicable, and about serious security incidents affecting the certified scope within 72 hours of confirming that the scope is affected.
Why would a certificate be suspended or revoked?
Reasons for suspension include an unreported change, a failed or overdue surveillance review, a special review, or badge misuse under review. SecurityInspect revokes a certificate for cause, including false or misleading evidence; material misrepresentation of the scope; a significant system change that wasn’t reported; a serious security incident affecting the scope, where the review finds that a certified control was not in place, the incident was not reported to us on time, or the fix was not verified; a critical vulnerability left unresolved; misuse of the badge; failed surveillance; or refusal to cooperate with surveillance or reassessment. The public record gives only a short neutral reason, never details of any finding or incident.
How can I tell whether a badge belongs to the site I’m on?
Select it. The record names the certificate holder and the domains the certificate covers, directly under the status. If the site you came from isn’t listed, the certificate doesn’t apply to it, even if the badge looks genuine.
Are scores published?
No. The verification record shows the level, status, scope, exclusions and dates. Scores and findings stay confidential.
Where can a holder display the badge?
Where it clearly refers to the certified scope, and on websites only on the domains listed on the verification record. When a page covers more than the scope, the badge carries a line saying what is covered. Badges are never shown in a row of HIPAA, PCI, SOC or ISO logos, and are never combined with any other framework’s name or mark.
How do we appeal a decision or make a complaint?
An applicant or holder can appeal a certification, suspension or revocation decision within 30 days of the decision. An appeals panel of people who took no part in the decision hears it. We acknowledge every appeal in writing and tell you when to expect a decision. Anyone can complain about a certificate, a holder’s use of a badge, or how SecurityInspect ran an assessment. Complaints are handled by people who were not involved. We acknowledge every complaint in writing and explain how it will be handled.
Can SIAS help with HIPAA, PCI DSS, SOC 2 or ISO/IEC 27001 work?
Each SIAS control lists informative cross-references to those frameworks, which can show where themes overlap. A SIAS certificate doesn’t count toward any of them, and their formal outcomes come from the bodies and firms those programs recognize.
Is the program open?
The SIAS certification program is open to applications. See how to apply.
What framework mappings mean
SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to us about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.