SIAS v1.0
SIAS v1.0: the SecurityInspect Assurance Standard
These are the requirements SecurityInspect assesses against, published so you can see exactly what a certificate means. Each domain page lists every control with its objective, testable requirement and pass criteria.
How the standard is organized
SIAS v1.0 has 19 domains and 92 controls. 57 controls are mandatory: they must be met whenever they apply.
| Code | Domain | Controls | Mandatory |
|---|---|---|---|
| GOV | Governance and security ownership | 5 | 3 |
| RSK | Risk management | 4 | 2 |
| AST | Asset inventory | 4 | 2 |
| IAM | Identity, access and MFA | 6 | 5 |
| DAT | Data classification and protection | 4 | 2 |
| CRY | Encryption and key management | 4 | 3 |
| SDC | Secure development and change management | 6 | 4 |
| VPM | Vulnerability and patch management | 6 | 3 |
| CLD | Cloud and infrastructure security | 5 | 3 |
| APP | Application and API security | 5 | 3 |
| NET | Network and endpoint security | 5 | 3 |
| LOG | Logging, monitoring and alerting | 4 | 3 |
| INC | Incident response | 4 | 3 |
| BCR | Backup, recovery and business continuity | 5 | 2 |
| TPR | Third-party and supply-chain risk | 5 | 3 |
| WFS | Workforce security | 5 | 3 |
| PHY | Physical safeguards | 5 | 3 |
| PRV | Privacy-related security safeguards | 5 | 2 |
| CMC | Continuous monitoring and material-change reporting | 5 | 5 |
Each control states its objective, the testable requirement, when it applies, the evidence required, the automated and manual tests, the interviews or observations, its severity, the pass criteria, acceptable compensating controls, remediation requirements, related controls and informative framework mappings. The domain pages show the parts that say what has to be true: objective, requirement, applicability, pass criteria, severity and mappings.
How a control is rated
| Outcome | Points | When |
|---|---|---|
| Met | 100 | Every pass criterion satisfied with validated evidence |
| Met (compensating control) | 100 | The pass criteria are satisfied through a validated compensating control |
| Partially met | 50 | Every remaining finding is limited in extent (a partial failure, as the standard defines it) and rated Medium or Low |
| Not met | 0 | Any remaining finding is not limited in extent, or is rated High or Critical, or half or more of the control’s pass criteria failed |
| Not applicable | Not counted | Only for conditional controls, with a written rationale approved by the quality reviewer |
A control can be rated Met only when at least one piece of its evidence was obtained or produced by SecurityInspect (a direct test, an observation, or a system extract obtained by SecurityInspect) and corroborated by evidence of a different type. Interviews and supplied documents alone are never enough.
How the score is calculated
Each control is weighted by severity: Critical 8, High 4, Medium 2, Low 1. A domain score is the weighted share of available points across that domain’s applicable controls. The overall score is calculated the same way across every applicable control in the scope. Scores are truncated, not rounded, to one decimal place.
Worked example: a domain with one Critical control Met, two High controls Met, one Medium control Partially met and one Low control Not met scores 100 × (8 + 8 + 1 + 0) ÷ (8 + 8 + 2 + 1) = 89.4.
How the decision is made
The checks run in a fixed order. Every one must pass. No score can make up for a failed check.
- G0 · Preconditions
Independence safeguards confirmed; no false, altered, misleading or withheld evidence; the declared scope matches what was observed; SecurityInspect’s analysis software ran the automated tests assigned to it.
- G1 · Completeness
All 19 domains assessed for the scope; every applicable control tested.
- G2 · No unresolved critical findings
No unresolved critical findings anywhere in the scope. Only remediation that SecurityInspect has retested resolves a critical finding. Accepting the risk does not.
- G3 · Mandatory controls
Every applicable mandatory control met, directly or through a validated compensating control.
- G4 · High findings
At most 3 unresolved High findings, including any not tied to a specific control, none on a mandatory control, each under an approved, time-limited exception with a remediation plan due within 90 days.
- G5 · Domain scores
Every domain scores at least 70.0.
- G6 · Overall score
The overall score is at least 85.0.
- G7 · The decision
An independent certification decision-maker reviews the file. Passing every check is necessary but not sufficient: the decision-maker may refuse, with written reasons grounded in the standard, but may never certify when a check has failed.
Exceptions and compensating controls
Exceptions
An exception lets a specific High, Medium or Low finding on a non-mandatory control stay open at decision for a limited time: up to 90 days for High and 180 days for Medium or Low, never past the certificate’s expiry. It never adds points, and it is never allowed for a critical finding or a mandatory control. Exceptions are approved by the certification decision-maker with the quality reviewer’s written agreement.
Compensating controls
A compensating control is accepted only when it addresses the original risk to at least the same degree, the organization has a documented reason it can’t meet the requirement directly, SecurityInspect tests it as rigorously as the original, and the quality reviewer approves it (plus a second independent reviewer for a Critical-severity control). It is retested at every surveillance review.
SecurityInspect Verified profiles
SecurityInspect Verified assesses one declared profile:
| Profile | Scope |
|---|---|
| VP-EXT | The external attack surface of declared internet-facing domains, IP addresses and services |
| VP-APP | One named web application and its APIs |
| VP-CLD | Named cloud tenants or accounts |
The same independence and integrity preconditions apply. There must be no unresolved Critical or High findings in the tested scope, every applicable mandatory profile control must be met, the profile score must be at least 85.0, and every domain with at least two applicable profile controls must score at least 70.0.
Framework mappings
Each control lists informative cross-references to the HIPAA Security Rule, PCI DSS v4.0.1, the AICPA Trust Services Criteria and ISO/IEC 27001:2022, by identifier only.
What framework mappings mean
SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.
Versions
Control IDs never change meaning and are never reused. Each certificate names the version it was assessed against. When a new version is published, this page gives the transition dates.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to us about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.