SECURO CERT

Schemes

Standards and schemes

Eleven schemes, four different kinds of deliverable, and three delivery modes. The table below states what you actually receive at the end of each one, and who is permitted to issue it.

What you receive

Six of these schemes do not produce a certificate. That is a fact about the schemes, not a limitation of any particular body — and it is the single most common thing misrepresented in this market.

Scheme Deliverable Who may issue Mode Effort
ISO/IEC 27001
Information Security Management
Certificate of Registration Issued only by a certification body accredited to ISO/IEC 17021-1. Direct High
ISO/IEC 27701
Privacy Information Management
Certificate of Registration (extension) Issued only by a body accredited to ISO/IEC 17021-1, as an extension to an existing 27001 certification. Direct Medium
ISO/IEC 27017
Cloud Security Controls
Certificate of Registration (sector extension) Issued only by a body accredited to ISO/IEC 17021-1, alongside 27001. Direct Low
ISO/IEC 27018
Personal Data in Public Clouds
Certificate of Registration (sector extension) Issued only by a body accredited to ISO/IEC 17021-1, alongside 27001. Direct Low
ISO 22301
Business Continuity Management
Certificate of Registration Issued only by a certification body accredited to ISO/IEC 17021-1. Direct Medium
SOC 2
Type I and Type II
Attestation report and opinion letter Issued only by a licensed CPA firm under AICPA attestation standards. There is no such thing as a SOC 2 certi… Managed High
PCI DSS
Payment Card Industry Data Security Standard
Report on Compliance and Attestation of Compliance Assessed only by a Qualified Security Assessor company listed by the PCI Security Standards Council. No PCI D… Joint High
HITRUST CSF
Healthcare and Enterprise Security
Validated assessment; certification issued by HITRUST Performed by an Authorised External Assessor organisation. The certification decision and the certificate its… Managed High
TISAX
European Automotive Supply Chain
Assessment result and label published on the ENX portal Performed only by an ENX-approved audit provider. The scheme prohibits the issue of certificates: the outcome… Joint Medium
CMMC
US Defense Supply Chain
Assessment result filed to SPRS Level 2 certification assessments are performed only by an authorised C3PAO. Results are recorded in governme… Managed High
CSA STAR
Cloud Security Alliance Registry
Public registry entry (Level 1 self-assessment or Level 2 third-party) Level 1 is self-assessed and published by the provider. Level 2 requires an accredited certification body and… Direct Low

Attestation, assessment and label schemes

SOC 2

Type I and Type II · TSC 2017 (rev. 2022)

An attestation engagement, not a certification. A CPA firm renders an opinion on whether controls were suitably designed (Type I) and operated effect…

Deliverable: Attestation report and opinion letter

PCI DSS

Payment Card Industry Data Security Standard · v4.0.1

A prescriptive control standard for anyone storing, processing or transmitting cardholder data. Validation produces a Report on Compliance and a sign…

Deliverable: Report on Compliance and Attestation of Compliance

HITRUST CSF

Healthcare and Enterprise Security · v11

A prescriptive control framework that harmonises HIPAA, NIST and ISO requirements with scored maturity. The assessor validates evidence; HITRUST perf…

Deliverable: Validated assessment; certification issued by HITRUST

TISAX

European Automotive Supply Chain · ISA 6

The automotive sector's shared information security assessment. Results are exchanged between OEMs and suppliers through the ENX portal rather than d…

Deliverable: Assessment result and label published on the ENX portal

CMMC

US Defense Supply Chain · 2.0 Level 2

Verifies protection of Controlled Unclassified Information across the US defense industrial base. The outcome lives in government systems and flows d…

Deliverable: Assessment result filed to SPRS

CSA STAR

Cloud Security Alliance Registry · CCM v4

A public registry of cloud provider security posture built on the Cloud Controls Matrix. Its value is transparency: buyers read the entry directly ra…

Deliverable: Public registry entry (Level 1 self-assessment or Level 2 third-party)

Schemes not listed here

Sector and national schemes not on this list are delivered through the partner network in Managed mode. The partner body and its accreditation are named before the engagement starts, not after.