Schemes
Standards and schemes
Eleven schemes, four different kinds of deliverable, and three delivery modes. The table below states what you actually receive at the end of each one, and who is permitted to issue it.
What you receive
Six of these schemes do not produce a certificate. That is a fact about the schemes, not a limitation of any particular body — and it is the single most common thing misrepresented in this market.
| Scheme | Deliverable | Who may issue | Mode | Effort |
|---|---|---|---|---|
|
ISO/IEC 27001
Information Security Management |
Certificate of Registration | Issued only by a certification body accredited to ISO/IEC 17021-1. | Direct | High |
|
ISO/IEC 27701
Privacy Information Management |
Certificate of Registration (extension) | Issued only by a body accredited to ISO/IEC 17021-1, as an extension to an existing 27001 certification. | Direct | Medium |
|
ISO/IEC 27017
Cloud Security Controls |
Certificate of Registration (sector extension) | Issued only by a body accredited to ISO/IEC 17021-1, alongside 27001. | Direct | Low |
|
ISO/IEC 27018
Personal Data in Public Clouds |
Certificate of Registration (sector extension) | Issued only by a body accredited to ISO/IEC 17021-1, alongside 27001. | Direct | Low |
|
ISO 22301
Business Continuity Management |
Certificate of Registration | Issued only by a certification body accredited to ISO/IEC 17021-1. | Direct | Medium |
|
SOC 2
Type I and Type II |
Attestation report and opinion letter | Issued only by a licensed CPA firm under AICPA attestation standards. There is no such thing as a SOC 2 certi… | Managed | High |
|
PCI DSS
Payment Card Industry Data Security Standard |
Report on Compliance and Attestation of Compliance | Assessed only by a Qualified Security Assessor company listed by the PCI Security Standards Council. No PCI D… | Joint | High |
|
HITRUST CSF
Healthcare and Enterprise Security |
Validated assessment; certification issued by HITRUST | Performed by an Authorised External Assessor organisation. The certification decision and the certificate its… | Managed | High |
|
TISAX
European Automotive Supply Chain |
Assessment result and label published on the ENX portal | Performed only by an ENX-approved audit provider. The scheme prohibits the issue of certificates: the outcome… | Joint | Medium |
|
CMMC
US Defense Supply Chain |
Assessment result filed to SPRS | Level 2 certification assessments are performed only by an authorised C3PAO. Results are recorded in governme… | Managed | High |
|
CSA STAR
Cloud Security Alliance Registry |
Public registry entry (Level 1 self-assessment or Level 2 third-party) | Level 1 is self-assessed and published by the provider. Level 2 requires an accredited certification body and… | Direct | Low |
Management system certification
ISO/IEC 27001
Information Security Management · 2022
A management system standard. It certifies that an organisation runs a documented, risk-driven process for protecting information — not that any part…
Deliverable: Certificate of Registration
ISO/IEC 27701
Privacy Information Management · 2019
Extends the 27001 management system to cover personal data, mapping controls to controller and processor roles. Frequently used to evidence GDPR acco…
Deliverable: Certificate of Registration (extension)
ISO/IEC 27017
Cloud Security Controls · 2015
A cloud-specific control set covering the split of responsibility between cloud provider and cloud customer — virtual machine hardening, administrati…
Deliverable: Certificate of Registration (sector extension)
ISO/IEC 27018
Personal Data in Public Clouds · 2019
Controls for public cloud providers acting as processors of personal data: disclosure handling, return and deletion, sub-processor transparency, and …
Deliverable: Certificate of Registration (sector extension)
ISO 22301
Business Continuity Management · 2019
Certifies a business continuity management system: impact analysis, recovery objectives, tested continuity plans, and exercise evidence. Auditors loo…
Deliverable: Certificate of Registration
Attestation, assessment and label schemes
SOC 2
Type I and Type II · TSC 2017 (rev. 2022)
An attestation engagement, not a certification. A CPA firm renders an opinion on whether controls were suitably designed (Type I) and operated effect…
Deliverable: Attestation report and opinion letter
PCI DSS
Payment Card Industry Data Security Standard · v4.0.1
A prescriptive control standard for anyone storing, processing or transmitting cardholder data. Validation produces a Report on Compliance and a sign…
Deliverable: Report on Compliance and Attestation of Compliance
HITRUST CSF
Healthcare and Enterprise Security · v11
A prescriptive control framework that harmonises HIPAA, NIST and ISO requirements with scored maturity. The assessor validates evidence; HITRUST perf…
Deliverable: Validated assessment; certification issued by HITRUST
TISAX
European Automotive Supply Chain · ISA 6
The automotive sector's shared information security assessment. Results are exchanged between OEMs and suppliers through the ENX portal rather than d…
Deliverable: Assessment result and label published on the ENX portal
CMMC
US Defense Supply Chain · 2.0 Level 2
Verifies protection of Controlled Unclassified Information across the US defense industrial base. The outcome lives in government systems and flows d…
Deliverable: Assessment result filed to SPRS
CSA STAR
Cloud Security Alliance Registry · CCM v4
A public registry of cloud provider security posture built on the Cloud Controls Matrix. Its value is transparency: buyers read the entry directly ra…
Deliverable: Public registry entry (Level 1 self-assessment or Level 2 third-party)
Schemes not listed here
Sector and national schemes not on this list are delivered through the partner network in Managed mode. The partner body and its accreditation are named before the engagement starts, not after.