Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Certification

Renewal, suspension and revocation

During a certificate’s validity the holder has duties, SecurityInspect keeps checking, and the verification record always shows the current status.

How long a certificate lasts

A certificate is valid for 12 months from the decision date, unless it is suspended, revoked or withdrawn sooner. There is no grace period after expiry.

Certification is valid only when the linked verification record confirms an Active status.

Surveillance during the year

A formal surveillance review around month 6 retests critical controls, compensating controls, open exceptions and remediation plans, and anything affected by a reported change. SecurityInspect also runs surveillance checks during the year.

What holders must tell us

Holders tell us about material changes to the certified scope within 30 calendar days, and before go-live for planned major changes where practicable, and about serious security incidents affecting the certified scope within 72 hours of confirming that the scope is affected.

These notices are for the certificate’s status only, sent to the address in the certification agreement. SecurityInspect doesn’t provide incident response through this channel.

Renewal

Renewal is a full reassessment against the current SIAS version, with 12 months of evidence. Apply at least 180 days before the expiry date, so that the assessment, any remediation, the independent review and the decision can finish in time. A certificate renewed on time keeps its ID, so its badge keeps working.

Suspension

  • A suspended certificate is not valid. SecurityInspect may suspend a certificate while it investigates or while a problem is fixed, for up to 90 days. After that, the certificate is reinstated or revoked.
  • Reasons for suspension include an unreported change, a failed or overdue surveillance review, a special review, or badge misuse under review.
  • The public record gives only a short neutral reason, never details of any finding or incident.

Revocation

SecurityInspect revokes a certificate for cause, including false or misleading evidence; material misrepresentation of the scope; a significant system change that wasn’t reported; a serious security incident affecting the scope, where the review finds that a certified control was not in place, the incident was not reported to us on time, or the fix was not verified; a critical vulnerability left unresolved; misuse of the badge; failed surveillance; or refusal to cooperate with surveillance or reassessment.

Withdrawal and expiry

A certificate is withdrawn when it ends early without an adverse finding: at the holder’s request, because the scope was retired, because the entity ceased to operate, or because SecurityInspect withdrew the standard version. A holder can’t withdraw a certificate to avoid a revocation that is under way. A certificate expires when its 12 months end without a completed reassessment.

The record keeps the history

Every status change stays on the verification record with its date and a short public reason. Nothing is deleted. Records remain available for at least 6 years after a certificate ends.

Appeals

An applicant or holder can appeal a certification, suspension or revocation decision within 30 days of the decision. An appeals panel of people who took no part in the decision hears it. We acknowledge every appeal in writing and tell you when to expect a decision.

How complaints and appeals are handled

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.