skip to content

In security compliance, how do certification (ISO/IEC 27001), attestation (SOC 2) and self-assessment differ in who evaluates and what results?

level: juniorimportance: must knowfreq 55%

answer

  1. certificate versus opinion
  2. who signs the conclusion
  3. CPA practitioner, examination engagement
  4. affirmation by your own official

basics

~20 s

Certification means an independent body audits you against a standard and issues a certificate, as with ISO/IEC 27001. Attestation means a CPA practitioner gives an opinion against criteria, as in SOC 2. Self-assessment means you evaluate yourself and an official affirms it.

solid answer

~50 s

The difference is **who reaches the conclusion and what they issue**. In **certification**, an independent certification body audits the organization against a standard's requirements and issues a **certificate** of conformity - ISO/IEC 27001 is the usual example; CMMC Level 2 (C3PAO) is a *certification assessment* by an authorized or accredited third party. In **attestation**, a CPA - called a **practitioner** under the AICPA attestation standards - performs an **examination engagement** and expresses an **opinion** on subject matter or management's assertion against a set of criteria; a SOC 2 report is an attestation report on controls against the Trust Services Criteria, not a certificate. In **self-assessment**, the organization evaluates itself and a responsible official **affirms** the result, as in CMMC Level 2 (Self) or a PCI DSS Self-Assessment Questionnaire. Customers weigh them differently because independence and the report's content differ.

go deeper

for a junior

Recall the three models and one example of each: ISO/IEC 27001 certification, SOC 2 attestation, and a self-assessment with affirmation.

for a middle

Explain what each output actually asserts: a certificate of conformity, a practitioner's opinion against criteria, or an organization's affirmed self-evaluation.

for a senior

Show how you would answer a customer asking for assurance: which output fits their question, and how scope and period limit what any of them proves.

for a principal

Weigh which assurance model to pursue first given customer demand, cost and how much detail buyers need to see.

## Three ways to reach a compliance conclusion Candidates often say "we are SOC 2 certified". Interviewers use that phrase to test whether the candidate knows what their organization actually holds. The three models differ in **who evaluates**, **what standard of evidence applies** and **what document results**. | Model | Who evaluates | What results | Examples | |---|---|---|---| | **Certification** | An independent certification body, itself accredited | A certificate stating conformity with a standard, maintained by periodic audits | ISO/IEC 27001; CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) certification assessments | | **Attestation** | A CPA practitioner under the AICPA attestation standards | A report containing the practitioner's opinion against stated criteria | SOC 2 examination against the Trust Services Criteria | | **Self-assessment** | The organization itself | Its own results, affirmed by a responsible official | CMMC Level 1 and Level 2 (Self); PCI DSS Self-Assessment Questionnaire | ## Attestation in more detail The AICPA's attestation standards (the SSAEs) govern examination, review and agreed-upon procedures engagements. Under them: - the CPA performing an attestation engagement is called a **practitioner**; - in an **examination engagement**, the practitioner expresses an **opinion** on subject matter, or on an assertion about the subject matter, in relation to an identified set of **criteria**; - in a SOC 2 examination, those criteria are the **Trust Services Criteria**, and the practitioner evaluates whether controls were **suitably designed and operated effectively** to meet the entity's service commitments and system requirements. The output is a **report for its intended users**, not a public badge. The reader must read it: the scope, the period, the tested controls and any exceptions are the content. ## Certification in more detail Certification is a **conformity assessment**. For ISO/IEC 27001, an independent certification body audits the information security management system and, if it conforms, issues a certificate that is kept alive by periodic audits over its cycle. The certificate states *that* the organization conforms; it does not publish detailed test results. The CMMC rule shows the same pattern in a government programme: Level 2 (C3PAO) and Level 3 (DIBCAC) are called **certification assessments**, performed by authorized or accredited third parties, and the rule requires the accreditation body to meet ISO/IEC 17011 and to accredit assessment organizations to ISO/IEC 17020. ## Self-assessment in more detail Self-assessment trades independence for cost and speed: - Under **32 CFR 170**, a Level 1 or Level 2 (Self) assessment is performed by the organization, scored and submitted, and a senior official **affirms** compliance at each assessment and annually. - Under **PCI DSS**, eligible entities complete a **Self-Assessment Questionnaire (SAQ)** rather than a Report on Compliance by a Qualified Security Assessor. The affirmation matters (the CMMC rule requires one after certification assessments too, not only self-assessments): a false self-assessment is the signing official's problem, which is why self-assessment is not a lighter duty, only a cheaper process. ## What each tells a customer - A **certificate** says an independent body found conformity with a standard at its last audit. - An **attestation report** says what controls existed, how a practitioner tested them and what exceptions were found, over a stated period or at a point in time. - A **self-assessment** says what the organization concluded about itself, backed by its own official's signature. ## Choosing which to pursue The choice is usually driven by who is asking. Buyers who want to see how controls were tested tend to ask for an attestation report they can read; buyers who want a recognized badge across many markets tend to ask for a certificate; government programmes decide for you, as CMMC does by assigning self-assessment or third-party assessment per contract. Cost, lead time and how much detail the organization is willing to share with customers all enter the decision, and many organizations end up holding more than one. ## Common mistakes - **"SOC 2 certified."** SOC 2 is an attestation; the correct phrase is "we have a SOC 2 report" or "a SOC 2 examination". - **Treating a certificate as proof of every control.** Certification speaks to conformity with the standard's requirements within the certified scope, not to controls outside it. - **Treating self-assessment as optional rigour.** Where a regime allows it, it still carries formal affirmation and consequences for misstatement. A strong answer separates the three by evaluator and output, uses the words *certificate*, *opinion* and *affirmation* correctly, and explains why a buyer might ask for one rather than another.

  • Why can't a company say it is "SOC 2 certified"?
    Because a SOC 2 report is an attestation, not a certification. A CPA practitioner expresses an opinion against the Trust Services Criteria in an examination engagement; no certificate of conformity is issued, and the report is meant for specified users to read.
  • What does an affirmation add to a CMMC self-assessment?
    Under 32 CFR 170, a senior official affirms the organization's compliance at each assessment and annually. It turns the self-assessment into a formal statement the organization stands behind, with consequences if it is wrong.

saying these in an interview costs you the question

  • Calls a SOC 2 report a certification
  • Believes a certificate lists every control tested and its exceptions
  • Treats self-assessment as having no formal accountability
  • Thinks any consultant can issue an ISO/IEC 27001 certificate
  • Says an attestation report is a public seal for anyone to rely on