Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Certification

How SIAS assessments work

Every SIAS assessment follows the same 15 stages, and every certificate rests on evidence that SecurityInspect obtained or tested itself.

Before any testing

  1. Application and scope

    The organization declares the exact scope in a signed form: legal entity, websites, products or systems, environments, locations, data types and domains. It authorizes testing of every asset.

  2. Conflict-of-interest check

    SecurityInspect checks for any relationship that could affect impartiality, including past advisory work. Nothing else starts until this check is clear.

  3. Assets and systems

    The assessment team identifies every asset in scope and compares the declared inventory with what it discovers.

  4. Evidence request

    The team asks for the specific evidence each control requires.

Testing and review

  1. Automated analysis

    Automated technical tests run against the declared assets, and a technical tester confirms or rejects every result that could affect a rating.

  2. Manual technical testing

    Technical testers test what software can’t judge well: access control, business logic, and weaknesses that combine.

  3. Policy and process review

    Assessors check that policies exist and that practice matches them.

  4. Interviews and observation

    Assessors talk to the people who run the controls and watch key processes.

Findings and remediation

  1. Findings

    Each finding gets a severity. The organization can check the report for factual accuracy.

  2. Remediation and retesting

    The organization may fix findings within 90 days of the findings report. SecurityInspect retests each fix. A retest replaces the original result only when the fix is verified.

Review and decision

  1. Independent quality review

    A reviewer who was not on the assessment team reviews the whole file: evidence, severity calls, not-applicable decisions and compensating controls. High-risk judgments need a second independent reviewer.

  2. Certification decision

    A separate decision-maker applies the published checks and records a signed, timestamped decision with reasons.

  3. Certificate and record

    If certification is granted, the certificate, the public verification record and the badge are issued together.

After certification

  1. Surveillance

    A formal surveillance review around month 6 retests critical controls, compensating controls, open exceptions and remediation plans, and anything affected by a reported change. SecurityInspect also runs surveillance checks during the year.

  2. Renewal or status change

    A full reassessment before expiry, or suspension, revocation, withdrawal or expiry when the rules require it.

What software does and what people decide

The software never rates a control, assigns a level or publishes a record. People set every rating and severity, approve compensating controls and exceptions, and make the decision.

On every file, people:

  • Decide whether the scope is meaningful and exclusions are acceptable
  • Test access control, business logic and chained weaknesses
  • Judge whether policies are adequate and actually followed
  • Confirm or reject every automated result that affects a rating
  • Set every rating and severity, approve compensating controls and exceptions, and make the decision

Evidence you can trust

Every evidence item is hashed (SHA-256) and timestamped in UTC when it is received, and linked to the test that used it. False, altered, misleading or withheld evidence ends the assessment without an outcome.

Assessors keep notes for every procedure. A second person reviews high-risk judgments.

What never leads to certification on its own

Certification is never issued from a vulnerability scan, an automated score, self-attestation, a questionnaire or unvalidated evidence alone.

The checks every certification decision must pass

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.