Certification · Audit · Assurance
One audit calendar. The right accredited body behind each scheme.
Securo Cert audits and certifies directly where it holds accreditation, and manages the engagement through a named accredited partner where it does not. Which of those applies is printed on every certificate and stated on every register entry, because a buyer who has to guess will assume the worse answer.
Public register
Schemes
Management system certification
Audited against a published standard, decided by a certification committee, issued as a certificate with a three-year cycle.
ISO/IEC 27001
Information Security Management · 2022
A management system standard. It certifies that an organisation runs a documented, risk-driven process for protecting information…
Deliverable: Certificate of Registration
ISO/IEC 27701
Privacy Information Management · 2019
Extends the 27001 management system to cover personal data, mapping controls to controller and processor roles. Frequently used t…
Deliverable: Certificate of Registration (extension)
ISO/IEC 27017
Cloud Security Controls · 2015
A cloud-specific control set covering the split of responsibility between cloud provider and cloud customer — virtual machine har…
Deliverable: Certificate of Registration (sector extension)
ISO/IEC 27018
Personal Data in Public Clouds · 2019
Controls for public cloud providers acting as processors of personal data: disclosure handling, return and deletion, sub-processo…
Deliverable: Certificate of Registration (sector extension)
ISO 22301
Business Continuity Management · 2019
Certifies a business continuity management system: impact analysis, recovery objectives, tested continuity plans, and exercise ev…
Deliverable: Certificate of Registration
Schemes
Attestation, assessment and label schemes
These do not produce certificates, whatever a competitor’s brochure says. SOC 2 produces an opinion from a CPA firm. PCI DSS produces a Report on Compliance and an Attestation of Compliance. TISAX produces a label on the ENX portal and prohibits certificates outright. Being told this before you buy is cheaper than being told it by your customer’s auditor.
SOC 2
Type I and Type II · TSC 2017 (rev. 2022)
An attestation engagement, not a certification. A CPA firm renders an opinion on whether controls were suitably designed (Type I)…
Deliverable: Attestation report and opinion letter
PCI DSS
Payment Card Industry Data Security Standard · v4.0.1
A prescriptive control standard for anyone storing, processing or transmitting cardholder data. Validation produces a Report on C…
Deliverable: Report on Compliance and Attestation of Compliance
HITRUST CSF
Healthcare and Enterprise Security · v11
A prescriptive control framework that harmonises HIPAA, NIST and ISO requirements with scored maturity. The assessor validates ev…
Deliverable: Validated assessment; certification issued by HITRUST
TISAX
European Automotive Supply Chain · ISA 6
The automotive sector's shared information security assessment. Results are exchanged between OEMs and suppliers through the ENX …
Deliverable: Assessment result and label published on the ENX portal
CMMC
US Defense Supply Chain · 2.0 Level 2
Verifies protection of Controlled Unclassified Information across the US defense industrial base. The outcome lives in government…
Deliverable: Assessment result filed to SPRS
CSA STAR
Cloud Security Alliance Registry · CCM v4
A public registry of cloud provider security posture built on the Cloud Controls Matrix. Its value is transparency: buyers read t…
Deliverable: Public registry entry (Level 1 self-assessment or Level 2 third-party)
How this works
Two delivery modes, always disclosed
No certification body holds accreditation for all eleven of these schemes. Bodies that imply otherwise are relying on you not checking. Securo Cert states which mode applies per scheme, per engagement, on the face of the document.
-
Direct
Securo Cert auditors, Securo Cert certification decision, accredited Securo Cert certificate.
-
Joint
Securo Cert auditors on the engagement, certification decision by the named partner body under their accreditation. The accredited artifact is theirs.
-
Managed
Partner auditors and partner decision. Securo Cert runs scoping, scheduling, evidence and remediation tracking across your whole scheme portfolio.
Lifecycle
What an engagement actually involves
Application and scoping
Boundary, sites, effective personnel, exclusions. Scope errors here are the most expensive mistake available and the hardest to unwind later.
Audit duration set
Derived from effective personnel, sites and complexity, then signed off by a scheme manager. Estimate it yourself first.
Stage 1 — documentation review
Readiness for Stage 2. Findings here are cheap; the same findings at Stage 2 cost a re-audit.
Stage 2 — implementation audit
Evidence that controls operate, not that they are documented. Sampling across sites and periods.
Non-conformity closure
Majors block certification and require verified correction. Minors require an accepted plan. Observations are advisory and carry no obligation.
Certification decision
Taken by personnel who did not perform the audit. This separation is not administrative theatre — it is what makes the decision worth anything.
Surveillance, years one and two
Continued conformity. A missed surveillance audit suspends the certificate, and the register shows it.
Recertification, year three
Full re-audit against the current version of the standard.
Impartiality
We do not sell you the answer and then mark your paper
Securo Cert does not provide readiness work, gap analysis, control implementation or remediation consultancy to any organisation it audits or certifies. Bodies that do both have an obvious incentive to find their own advice adequate.
This costs revenue. It is the reason a certificate from an impartial body means something, so it is not negotiable per client.
The same reasoning applies to the register. Suspended and withdrawn entries stay in it permanently — removing them would make a void document harder to catch, which serves nobody except whoever is holding one.