Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

SIAS v1.0

SIAS v1.0: the SecurityInspect Assurance Standard

These are the requirements SecurityInspect assesses against, published so you can see exactly what a certificate means. Each domain page lists every control with its objective, testable requirement and pass criteria.

How the standard is organized

SIAS v1.0 has 19 domains and 92 controls. 57 controls are mandatory: they must be met whenever they apply.

Each control states its objective, the testable requirement, when it applies, the evidence required, the automated and manual tests, the interviews or observations, its severity, the pass criteria, acceptable compensating controls, remediation requirements, related controls and informative framework mappings. The domain pages show the parts that say what has to be true: objective, requirement, applicability, pass criteria, severity and mappings.

How a control is rated

Control outcomes and points
OutcomePointsWhen
Met100Every pass criterion satisfied with validated evidence
Met (compensating control)100The pass criteria are satisfied through a validated compensating control
Partially met50Every remaining finding is limited in extent (a partial failure, as the standard defines it) and rated Medium or Low
Not met0Any remaining finding is not limited in extent, or is rated High or Critical, or half or more of the control’s pass criteria failed
Not applicableNot countedOnly for conditional controls, with a written rationale approved by the quality reviewer

A control can be rated Met only when at least one piece of its evidence was obtained or produced by SecurityInspect (a direct test, an observation, or a system extract obtained by SecurityInspect) and corroborated by evidence of a different type. Interviews and supplied documents alone are never enough.

How the score is calculated

Each control is weighted by severity: Critical 8, High 4, Medium 2, Low 1. A domain score is the weighted share of available points across that domain’s applicable controls. The overall score is calculated the same way across every applicable control in the scope. Scores are truncated, not rounded, to one decimal place.

Worked example: a domain with one Critical control Met, two High controls Met, one Medium control Partially met and one Low control Not met scores 100 × (8 + 8 + 1 + 0) ÷ (8 + 8 + 2 + 1) = 89.4.

How the decision is made

The checks run in a fixed order. Every one must pass. No score can make up for a failed check.

  1. G0 · Preconditions

    Independence safeguards confirmed; no false, altered, misleading or withheld evidence; the declared scope matches what was observed; SecurityInspect’s analysis software ran the automated tests assigned to it.

  2. G1 · Completeness

    All 19 domains assessed for the scope; every applicable control tested.

  3. G2 · No unresolved critical findings

    No unresolved critical findings anywhere in the scope. Only remediation that SecurityInspect has retested resolves a critical finding. Accepting the risk does not.

  4. G3 · Mandatory controls

    Every applicable mandatory control met, directly or through a validated compensating control.

  5. G4 · High findings

    At most 3 unresolved High findings, including any not tied to a specific control, none on a mandatory control, each under an approved, time-limited exception with a remediation plan due within 90 days.

  6. G5 · Domain scores

    Every domain scores at least 70.0.

  7. G6 · Overall score

    The overall score is at least 85.0.

  8. G7 · The decision

    An independent certification decision-maker reviews the file. Passing every check is necessary but not sufficient: the decision-maker may refuse, with written reasons grounded in the standard, but may never certify when a check has failed.

Exceptions and compensating controls

Exceptions

An exception lets a specific High, Medium or Low finding on a non-mandatory control stay open at decision for a limited time: up to 90 days for High and 180 days for Medium or Low, never past the certificate’s expiry. It never adds points, and it is never allowed for a critical finding or a mandatory control. Exceptions are approved by the certification decision-maker with the quality reviewer’s written agreement.

Compensating controls

A compensating control is accepted only when it addresses the original risk to at least the same degree, the organization has a documented reason it can’t meet the requirement directly, SecurityInspect tests it as rigorously as the original, and the quality reviewer approves it (plus a second independent reviewer for a Critical-severity control). It is retested at every surveillance review.

SecurityInspect Verified profiles

SecurityInspect Verified assesses one declared profile:

SecurityInspect Verified profiles
ProfileScope
VP-EXTThe external attack surface of declared internet-facing domains, IP addresses and services
VP-APPOne named web application and its APIs
VP-CLDNamed cloud tenants or accounts

The same independence and integrity preconditions apply. There must be no unresolved Critical or High findings in the tested scope, every applicable mandatory profile control must be met, the profile score must be at least 85.0, and every domain with at least two applicable profile controls must score at least 70.0.

Framework mappings

Each control lists informative cross-references to the HIPAA Security Rule, PCI DSS v4.0.1, the AICPA Trust Services Criteria and ISO/IEC 27001:2022, by identifier only.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

How SIAS relates to other security frameworks

Versions

Control IDs never change meaning and are never reused. Each certificate names the version it was assessed against. When a new version is published, this page gives the transition dates.

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.