Certification
How SIAS assessments work
Every SIAS assessment follows the same 15 stages, and every certificate rests on evidence that SecurityInspect obtained or tested itself.
Before any testing
- Application and scope
The organization declares the exact scope in a signed form: legal entity, websites, products or systems, environments, locations, data types and domains. It authorizes testing of every asset.
- Conflict-of-interest check
SecurityInspect checks for any relationship that could affect impartiality, including past advisory work. Nothing else starts until this check is clear.
- Assets and systems
The assessment team identifies every asset in scope and compares the declared inventory with what it discovers.
- Evidence request
The team asks for the specific evidence each control requires.
Testing and review
- Automated analysis
Automated technical tests run against the declared assets, and a technical tester confirms or rejects every result that could affect a rating.
- Manual technical testing
Technical testers test what software can’t judge well: access control, business logic, and weaknesses that combine.
- Policy and process review
Assessors check that policies exist and that practice matches them.
- Interviews and observation
Assessors talk to the people who run the controls and watch key processes.
Findings and remediation
- Findings
Each finding gets a severity. The organization can check the report for factual accuracy.
- Remediation and retesting
The organization may fix findings within 90 days of the findings report. SecurityInspect retests each fix. A retest replaces the original result only when the fix is verified.
Review and decision
- Independent quality review
A reviewer who was not on the assessment team reviews the whole file: evidence, severity calls, not-applicable decisions and compensating controls. High-risk judgments need a second independent reviewer.
- Certification decision
A separate decision-maker applies the published checks and records a signed, timestamped decision with reasons.
- Certificate and record
If certification is granted, the certificate, the public verification record and the badge are issued together.
After certification
- Surveillance
A formal surveillance review around month 6 retests critical controls, compensating controls, open exceptions and remediation plans, and anything affected by a reported change. SecurityInspect also runs surveillance checks during the year.
- Renewal or status change
A full reassessment before expiry, or suspension, revocation, withdrawal or expiry when the rules require it.
What software does and what people decide
The software never rates a control, assigns a level or publishes a record. People set every rating and severity, approve compensating controls and exceptions, and make the decision.
On every file, people:
- Decide whether the scope is meaningful and exclusions are acceptable
- Test access control, business logic and chained weaknesses
- Judge whether policies are adequate and actually followed
- Confirm or reject every automated result that affects a rating
- Set every rating and severity, approve compensating controls and exceptions, and make the decision
Evidence you can trust
Every evidence item is hashed (SHA-256) and timestamped in UTC when it is received, and linked to the test that used it. False, altered, misleading or withheld evidence ends the assessment without an outcome.
Assessors keep notes for every procedure. A second person reviews high-risk judgments.
What never leads to certification on its own
Certification is never issued from a vulnerability scan, an automated score, self-attestation, a questionnaire or unvalidated evidence alone.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to us about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.