Three different things that often get blurred
Security and compliance conversations tend to mix up three kinds of work. Keeping them separate helps you plan the right project, hire the right people, and describe your status accurately to customers.
The practical test is simple. Ask who is allowed to issue the outcome your customer or regulator is asking for. Then make sure the party you hire for that step holds that authority and is independent from the people who helped you prepare.
- Readiness: preparing for a formal outcome. It covers scoping, finding gaps, fixing them, and organizing evidence. Internal staff or outside advisors can do it.
- Assessment: evaluating controls against a set of requirements. An assessment can be informal and internal, or formal and performed by an authorized independent party.
- Certification or attestation: a formal outcome, such as a certificate, an audit opinion, or an attestation report, issued by a party with authority to issue it under that program's rules.
SOC 2: an independent CPA firm's report, not a certificate
A SOC 2 report is an attestation report defined by the AICPA. Only an independent, licensed CPA firm, known in the AICPA's guidance as the service auditor, can perform the examination and issue the report, which includes its opinion on your system description and your controls relevant to the Trust Services Criteria.
There is no official SOC 2 certification. A Type 1 report covers the design of controls as of a specific date. A Type 2 report also covers how those controls operated throughout a review period.
Readiness work for SOC 2 usually means choosing which Trust Services Criteria categories to include, defining the system in scope, closing control gaps, and setting up evidence collection before the review period begins.
ISO/IEC 27001: certificates come from certification bodies, not ISO or consultants
ISO and IEC publish the ISO/IEC 27001 standard, but neither issues certificates to organizations. Certification comes from a certification body that audits your information security management system against the standard.
Check whether the certification body is accredited by a recognized accreditation body. ISO notes that accreditation isn't compulsory, but many customers ask specifically for accredited certification, and accredited certificates can be checked in IAF CertSearch. Certification starts with an initial audit in two stages, continues with surveillance audits in the following years, and is renewed through a recertification audit in the third year of each cycle.
The consultants who help you build the management system, write the Statement of Applicability, or run your risk assessment should not be the ones who certify it.
PCI DSS: QSA Companies, ASVs, and self-assessment
The PCI Security Standards Council maintains PCI DSS and qualifies the companies that assess against it. It does not decide who must validate compliance. Payment card brands and acquiring banks do, based on factors such as transaction volume and how card data is handled.
You can confirm a QSA Company's or an ASV's status on the Council's public lists before you sign an engagement.
- Formal third-party assessments are performed by a Qualified Security Assessor (QSA) Company, which is responsible for the Report on Compliance.
- An individual QSA holds that status only while employed by a QSA Company and assesses on that company's behalf.
- Required external vulnerability scans come from an Approved Scanning Vendor (ASV) on the Council's list.
- Eligible organizations may validate with a Self-Assessment Questionnaire, which they complete and sign themselves.
CMMC: self-assessment or an authorized C3PAO
CMMC is the Department of Defense program for contractors that handle Federal Contract Information or Controlled Unclassified Information. The level and assessment type your contract requires determine who assesses you.
CMMC ecosystem members, such as C3PAOs, their assessors and CMMC professionals, who served as a consultant to prepare an organization for any CMMC assessment within the previous three years may not take part in its Level 2 certification assessment (32 CFR 170.8(b)(17)(ii)(G)). The program's current implementation is shown in the dated update on this page; confirm what your own contract requires as well.
- Level 1: an annual self-assessment by your own organization.
- Level 2: either a self-assessment or a certification assessment by a Certified Third-Party Assessment Organization (C3PAO) authorized by the Cyber AB, depending on what the contract requires.
- Level 3: an assessment performed by the government.
HIPAA: no official certification
The HIPAA Security Rule applies to covered entities and their business associates, and the HHS Office for Civil Rights enforces it. HHS says no standard requires a covered entity to certify its compliance, that it doesn't endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and that such certifications don't absolve an organization of its legal obligations.
What you can show instead is the work itself: a current, documented risk analysis, a risk management plan, policies and procedures, business associate agreements, training records, and evidence that safeguards are in place and periodically evaluated.
Questions to ask before you hire help
Whether you are hiring for readiness work or for the formal outcome itself, a few questions keep the roles clear.
- Is this provider authorized to issue the outcome we need, and where can we verify that?
- Is the party issuing the outcome independent from anyone who helped design or run our controls?
- Will we contract directly with the independent auditor or assessor?
- Does the proposal promise a pass? No honest readiness provider can guarantee what an independent party will conclude.
- What will we have at the end: a gap list, a remediation plan, organized evidence, or a formal report?