Certification
Renewal, suspension and revocation
During a certificate’s validity the holder has duties, SecurityInspect keeps checking, and the verification record always shows the current status.
How long a certificate lasts
A certificate is valid for 12 months from the decision date, unless it is suspended, revoked or withdrawn sooner. There is no grace period after expiry.
Certification is valid only when the linked verification record confirms an Active status.
Surveillance during the year
A formal surveillance review around month 6 retests critical controls, compensating controls, open exceptions and remediation plans, and anything affected by a reported change. SecurityInspect also runs surveillance checks during the year.
What holders must tell us
Holders tell us about material changes to the certified scope within 30 calendar days, and before go-live for planned major changes where practicable, and about serious security incidents affecting the certified scope within 72 hours of confirming that the scope is affected.
These notices are for the certificate’s status only, sent to the address in the certification agreement. SecurityInspect doesn’t provide incident response through this channel.
Renewal
Renewal is a full reassessment against the current SIAS version, with 12 months of evidence. Apply at least 180 days before the expiry date, so that the assessment, any remediation, the independent review and the decision can finish in time. A certificate renewed on time keeps its ID, so its badge keeps working.
Suspension
- A suspended certificate is not valid. SecurityInspect may suspend a certificate while it investigates or while a problem is fixed, for up to 90 days. After that, the certificate is reinstated or revoked.
- Reasons for suspension include an unreported change, a failed or overdue surveillance review, a special review, or badge misuse under review.
- The public record gives only a short neutral reason, never details of any finding or incident.
Revocation
SecurityInspect revokes a certificate for cause, including false or misleading evidence; material misrepresentation of the scope; a significant system change that wasn’t reported; a serious security incident affecting the scope, where the review finds that a certified control was not in place, the incident was not reported to us on time, or the fix was not verified; a critical vulnerability left unresolved; misuse of the badge; failed surveillance; or refusal to cooperate with surveillance or reassessment.
Withdrawal and expiry
A certificate is withdrawn when it ends early without an adverse finding: at the holder’s request, because the scope was retired, because the entity ceased to operate, or because SecurityInspect withdrew the standard version. A holder can’t withdraw a certificate to avoid a revocation that is under way. A certificate expires when its 12 months end without a completed reassessment.
The record keeps the history
Every status change stays on the verification record with its date and a short public reason. Nothing is deleted. Records remain available for at least 6 years after a certificate ends.
Appeals
An applicant or holder can appeal a certification, suspension or revocation decision within 30 days of the decision. An appeals panel of people who took no part in the decision hears it. We acknowledge every appeal in writing and tell you when to expect a decision.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to us about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.