Security Claims
This site takes no affiliate commissions and ranks no products. This is not legal or security advice.**
Certification logos are the least examined element of a vendor page. Each one is a real document with a scope, a period and an auditor, and all three are checkable. For a related operational perspective, Monitask also publishes a reference on wage percentage calculator.
Reviewed August 9, 2026.
What a certification actually is
A statement that an auditor examined something, at a point in time, against a defined standard, within a stated scope.
None of those four is on the badge. The badge is a graphic; the report is the document, and the difference between them is most of what this article is about.
For broader context, see CISA.
A certification is not a guarantee of security. It is evidence that a process exists and was assessed, which is genuinely useful and is a narrower claim than the logo implies.
The four things to check
One. The scope. Which systems, which services, which locations. A certification covering the corporate infrastructure and not the product you are buying is common and is technically accurate.
Two. The date and period. Some reports cover a point in time; others cover a period of operation. A report from three years ago describes a company that may no longer exist in that form.
Three. Who issued it. A named accredited auditor, or a self-assessment with a badge generator.
Four. Whether you can see it. A vendor selling to organisations will share the report under an agreement. One that shows only the logo has answered the question differently.
The distinctions worth knowing
Certification against attestation. Some frameworks certify a management system exists and operates; others attest that controls were tested. They answer different questions and both are worth having.
Type one against type two, in frameworks that use the terms: design at a point in time, against operation over a period. The second is substantially more informative and takes longer to obtain.
And compliance against certification. "Compliant with" is a self-description. "Certified against" involves an outside party. These appear in the same sentence on vendor pages and they are not the same claim.
What certification does not tell you
Whether this specific product is well built. It assesses process, not code.
Whether a breach will happen. Certified organisations are breached.
How they behave during an incident, which is a contract term rather than a certificate — notification timelines belong in the agreement.
And who their subprocessors are, which is a separate document and frequently more informative about actual exposure.
What to ask
"What is in scope for the certification, and can I see the report?"
"What period does it cover, and when is the next audit?"
"What is your breach notification timeline, and is it in the agreement?"
And "where is the subprocessor list?"
The last two matter more than the first two for most buyers, and only the first two appear on the website.
The proportionate position
For a small tool holding low-sensitivity data, a certification is a nice signal and not a requirement, and demanding one narrows the field to large vendors for no gain.
For anything holding personal data at scale, or anything your own customers will ask about, the report matters and asking for it is ordinary.
Match the scrutiny to what the tool holds — which requires knowing what it holds, and that is the question that should come first.
The short version
- A certification states that an auditor examined something, at a time, against a standard, within a scope — and none of those is on the badge
- Check the scope, the date and period, the issuing auditor, and whether the report itself is available under agreement
- Know the distinctions: certification against attestation, point-in-time against period of operation, and "compliant with" against "certified against"
- It does not tell you the product is well built, that a breach will not happen, how they behave in an incident, or who their subprocessors are
- Breach notification timelines and the subprocessor list matter more for most buyers, and neither appears on the website
- Match scrutiny to what the tool holds, which means establishing that first