Certification
Independence in SIAS certification
SecurityInspect writes the standard, performs the assessments and makes the certification decisions. So we separate those jobs, and we publish how.
What “independently assessed” means
SecurityInspect owns the SIAS standard and performs the assessments. “Independently assessed” means that the people who assessed, reviewed and decided this certificate had no advisory, design, implementation or remediation role for the organization, and no financial interest in the outcome, and that the person who made the certification decision did not take part in the assessment. SIAS is not accredited or endorsed by any government agency or standards body.
Different people for different jobs
On every file, the assessment team, the quality reviewer and the certification decision-maker are different people. The decision-maker has never done consulting, readiness or remediation work for the organization.
Advice and certification stay apart
- Anyone at SecurityInspect who advised an organization, or helped design, build or fix its systems, never takes any role in its SIAS assessment, review or decision.
- We don’t assess controls that SecurityInspect designed, implemented, configured or operates for the organization. We don’t accept an application for a scope where we did that work in the previous 24 months.
- While an assessment is open, and while a certificate is valid, we don’t design, implement or fix the in-scope systems.
- We don’t sell packages that combine advice with certification.
- The verification record always says whether SecurityInspect provided any other service to the organization in the 24 months before the assessment.
- We don’t start a SIAS assessment of a scope within 12 months of a SIAS Readiness Review we performed for it.
How we keep advisory work apart from formal assessment in our other services
Fees and sales never decide outcomes
Fees are fixed in writing before an application is accepted. No fee, discount or refund depends on the level, the score, whether certification is granted or how quickly. We don’t sell expedited certification. We set no targets for certificates or pass rates, and no one’s pay depends on outcomes. Sales staff never promise an outcome or a timeline.
Qualified people, second reviews
Assessors, testers, reviewers and decision-makers are authorized for their roles against written competence requirements. High-risk judgments, such as lowering a critical finding or accepting a compensating control for a critical control, need a second independent reviewer.
Conflicts of interest
We check for conflicts before every assessment and whenever the team changes. Everyone on a file signs a declaration. Conflicts are disclosed and recorded.
Complaints and appeals
- ComplaintsAnyone can complain about a certificate, a holder’s use of a badge, or how SecurityInspect ran an assessment. Complaints are handled by people who were not involved. We acknowledge every complaint in writing and explain how it will be handled.
- AppealsAn applicant or holder can appeal a certification, suspension or revocation decision within 30 days of the decision. An appeals panel of people who took no part in the decision hears it. We acknowledge every appeal in writing and tell you when to expect a decision.
Use the contact form and choose the topic “SIAS certification”. Raise a concern or complaint about a certificate
When we say “independently assessed”
We say “independently assessed” only for an issued SecurityInspect Certified or SecurityInspect Verified certificate whose file records every safeguard on this page, and whose verification record discloses whether we provided any other service to the organization in the 24 months before the assessment. Never for SecurityInspect Reviewed, never for our advisory or testing services, and never as a slogan for the program as a whole.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to us about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.