Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Certification

Independence in SIAS certification

SecurityInspect writes the standard, performs the assessments and makes the certification decisions. So we separate those jobs, and we publish how.

What “independently assessed” means

SecurityInspect owns the SIAS standard and performs the assessments. “Independently assessed” means that the people who assessed, reviewed and decided this certificate had no advisory, design, implementation or remediation role for the organization, and no financial interest in the outcome, and that the person who made the certification decision did not take part in the assessment. SIAS is not accredited or endorsed by any government agency or standards body.

Different people for different jobs

On every file, the assessment team, the quality reviewer and the certification decision-maker are different people. The decision-maker has never done consulting, readiness or remediation work for the organization.

Advice and certification stay apart

  • Anyone at SecurityInspect who advised an organization, or helped design, build or fix its systems, never takes any role in its SIAS assessment, review or decision.
  • We don’t assess controls that SecurityInspect designed, implemented, configured or operates for the organization. We don’t accept an application for a scope where we did that work in the previous 24 months.
  • While an assessment is open, and while a certificate is valid, we don’t design, implement or fix the in-scope systems.
  • We don’t sell packages that combine advice with certification.
  • The verification record always says whether SecurityInspect provided any other service to the organization in the 24 months before the assessment.
  • We don’t start a SIAS assessment of a scope within 12 months of a SIAS Readiness Review we performed for it.

How we keep advisory work apart from formal assessment in our other services

Fees and sales never decide outcomes

Fees are fixed in writing before an application is accepted. No fee, discount or refund depends on the level, the score, whether certification is granted or how quickly. We don’t sell expedited certification. We set no targets for certificates or pass rates, and no one’s pay depends on outcomes. Sales staff never promise an outcome or a timeline.

Qualified people, second reviews

Assessors, testers, reviewers and decision-makers are authorized for their roles against written competence requirements. High-risk judgments, such as lowering a critical finding or accepting a compensating control for a critical control, need a second independent reviewer.

Conflicts of interest

We check for conflicts before every assessment and whenever the team changes. Everyone on a file signs a declaration. Conflicts are disclosed and recorded.

Complaints and appeals

  • ComplaintsAnyone can complain about a certificate, a holder’s use of a badge, or how SecurityInspect ran an assessment. Complaints are handled by people who were not involved. We acknowledge every complaint in writing and explain how it will be handled.
  • AppealsAn applicant or holder can appeal a certification, suspension or revocation decision within 30 days of the decision. An appeals panel of people who took no part in the decision hears it. We acknowledge every appeal in writing and tell you when to expect a decision.

Use the contact form and choose the topic “SIAS certification”. Raise a concern or complaint about a certificate

When we say “independently assessed”

We say “independently assessed” only for an issued SecurityInspect Certified or SecurityInspect Verified certificate whose file records every safeguard on this page, and whose verification record discloses whether we provided any other service to the organization in the 24 months before the assessment. Never for SecurityInspect Reviewed, never for our advisory or testing services, and never as a slogan for the program as a whole.

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.