Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Guide

Is SOC 2 a certification? Who can issue what

Readiness work gets you prepared. Formal outcomes, such as a SOC 2 report or an ISO/IEC 27001 certificate, can only come from independent parties with specific authority. Here is who can issue what.

Compliance6 min read

By Security Inspect · Sources checked

Key takeaways

  • Readiness work prepares you for a formal outcome; only a party with authority under each program's rules can issue the outcome itself.
  • A SOC 2 report comes from a licensed CPA firm acting as service auditor, and an ISO/IEC 27001 certificate comes from a certification body, ideally an accredited one.
  • Your acquirer or the payment brands decide how you validate PCI DSS: a Report on Compliance from a PCI SSC-listed QSA Company (or by an ISA, where your acquirer accepts one), or a Self-Assessment Questionnaire you complete yourself.
  • There is no official HIPAA certification, and HHS doesn't recognize private certifications regarding the Security Rule.
  • Independence rules keep the people who helped you prepare out of your formal assessment.

Note: Program status

CMMC program update — September 26, 2026: CMMC implementation remains paused in Phase 1 following the suspension of Phase II on July 13, 2026. Phase I self-assessment requirements remain in force. During the suspension, procurement requirements may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC).

Three different things that often get blurred

Security and compliance conversations tend to mix up three kinds of work. Keeping them separate helps you plan the right project, hire the right people, and describe your status accurately to customers.

The practical test is simple. Ask who is allowed to issue the outcome your customer or regulator is asking for. Then make sure the party you hire for that step holds that authority and is independent from the people who helped you prepare.

  • Readiness: preparing for a formal outcome. It covers scoping, finding gaps, fixing them, and organizing evidence. Internal staff or outside advisors can do it.
  • Assessment: evaluating controls against a set of requirements. An assessment can be informal and internal, or formal and performed by an authorized independent party.
  • Certification or attestation: a formal outcome, such as a certificate, an audit opinion, or an attestation report, issued by a party with authority to issue it under that program's rules.

SOC 2: an independent CPA firm's report, not a certificate

A SOC 2 report is an attestation report defined by the AICPA. Only an independent, licensed CPA firm, known in the AICPA's guidance as the service auditor, can perform the examination and issue the report, which includes its opinion on your system description and your controls relevant to the Trust Services Criteria.

There is no official SOC 2 certification. A Type 1 report covers the design of controls as of a specific date. A Type 2 report also covers how those controls operated throughout a review period.

Readiness work for SOC 2 usually means choosing which Trust Services Criteria categories to include, defining the system in scope, closing control gaps, and setting up evidence collection before the review period begins.

ISO/IEC 27001: certificates come from certification bodies, not ISO or consultants

ISO and IEC publish the ISO/IEC 27001 standard, but neither issues certificates to organizations. Certification comes from a certification body that audits your information security management system against the standard.

Check whether the certification body is accredited by a recognized accreditation body. ISO notes that accreditation isn't compulsory, but many customers ask specifically for accredited certification, and accredited certificates can be checked in IAF CertSearch. Certification starts with an initial audit in two stages, continues with surveillance audits in the following years, and is renewed through a recertification audit in the third year of each cycle.

The consultants who help you build the management system, write the Statement of Applicability, or run your risk assessment should not be the ones who certify it.

PCI DSS: QSA Companies, ASVs, and self-assessment

The PCI Security Standards Council maintains PCI DSS and qualifies the companies that assess against it. It does not decide who must validate compliance. Payment card brands and acquiring banks do, based on factors such as transaction volume and how card data is handled.

You can confirm a QSA Company's or an ASV's status on the Council's public lists before you sign an engagement.

  • Formal third-party assessments are performed by a Qualified Security Assessor (QSA) Company, which is responsible for the Report on Compliance.
  • An individual QSA holds that status only while employed by a QSA Company and assesses on that company's behalf.
  • Required external vulnerability scans come from an Approved Scanning Vendor (ASV) on the Council's list.
  • Eligible organizations may validate with a Self-Assessment Questionnaire, which they complete and sign themselves.

CMMC: self-assessment or an authorized C3PAO

CMMC is the Department of Defense program for contractors that handle Federal Contract Information or Controlled Unclassified Information. The level and assessment type your contract requires determine who assesses you.

CMMC ecosystem members, such as C3PAOs, their assessors and CMMC professionals, who served as a consultant to prepare an organization for any CMMC assessment within the previous three years may not take part in its Level 2 certification assessment (32 CFR 170.8(b)(17)(ii)(G)). The program's current implementation is shown in the dated update on this page; confirm what your own contract requires as well.

  • Level 1: an annual self-assessment by your own organization.
  • Level 2: either a self-assessment or a certification assessment by a Certified Third-Party Assessment Organization (C3PAO) authorized by the Cyber AB, depending on what the contract requires.
  • Level 3: an assessment performed by the government.

HIPAA: no official certification

The HIPAA Security Rule applies to covered entities and their business associates, and the HHS Office for Civil Rights enforces it. HHS says no standard requires a covered entity to certify its compliance, that it doesn't endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and that such certifications don't absolve an organization of its legal obligations.

What you can show instead is the work itself: a current, documented risk analysis, a risk management plan, policies and procedures, business associate agreements, training records, and evidence that safeguards are in place and periodically evaluated.

Questions to ask before you hire help

Whether you are hiring for readiness work or for the formal outcome itself, a few questions keep the roles clear.

  • Is this provider authorized to issue the outcome we need, and where can we verify that?
  • Is the party issuing the outcome independent from anyone who helped design or run our controls?
  • Will we contract directly with the independent auditor or assessor?
  • Does the proposal promise a pass? No honest readiness provider can guarantee what an independent party will conclude.
  • What will we have at the end: a gap list, a remediation plan, organized evidence, or a formal report?

Where our work fits

  • Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
  • When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

Questions

Is SOC 2 a certification?

No. A SOC 2 report is an attestation report: a licensed CPA firm, acting as service auditor, examines your system description and controls and gives an opinion on them. There is no AICPA-issued or state-recognized individual SOC 2 certification either, and no individual credential authorizes anyone to issue a SOC 2 report.

Is there an official HIPAA certification?

No. HHS says no standard requires a covered entity to certify its compliance, and it doesn't endorse or recognize private certifications regarding the Security Rule. What the rule does require is a periodic technical and nontechnical evaluation, which you can perform internally or with an outside organization.

Can the firm that helped us prepare also issue our certificate or report?

Generally not. Accredited ISO/IEC 27001 certification bodies may not provide management system consultancy, and a CPA firm that designs or implements the controls it examines impairs its independence. CMMC bars ecosystem members, such as C3PAOs and their assessors, who consulted on an organization's preparation from its Level 2 certification assessment process for three years. Under PCI SSC rules, an assessor may not assess controls they designed, developed, or implemented (PCI SSC FAQ 1562).

Primary sources

Related guides

Terms in this guide

More on this site

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Talk through your situation with a practitioner

Every engagement begins with a written scope and proposal.

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.