Frameworks & Audits

Frameworks, audits and assurance programs

Assurance instruments that are not ISO management-system standards: attestations, authorization programs, certifiable frameworks and audit schemes. Each record names its class honestly — an attestation is a report, not a certificate — and every fact links to the owner's own pages, dated to when we last checked them.

Certification 37 records

ACSSACertification
Automation and Control System Security Assurance

ACSSA is ISASecure's ISA/IEC 62443 certification for a deployed control system and asset owner policies and procedures, not a product.

ADISA Standard 8.0Certification
ADISA ICT Asset Recovery Standard 8.0

ADISA ICT Asset Recovery Standard 8.0 certifies processors that handle IT asset disposal; ADISA Certification owns and audits the scheme.

AS9100Certification
AS9100 (IAQG 9100 series)

AS9100 is the aerospace quality management certification of IAQG's 9100 series, run under the IAF-endorsed ICOP scheme with the OASIS supplier register.

CEIVCertification
Center of Excellence for Independent Validators

CEIV is IATA's certification family for special cargo: four programs — Pharma, Live Animals, Fresh, and Lithium Batteries — validate handling standards.

CO₂ Performance LadderCertification
CO₂ Performance Ladder

The CO₂ Performance Ladder is a Dutch-owned certification scheme (SKAO) that gives certified bidders an award advantage in public tenders.

COPC CX StandardCertification
COPC Customer Experience (CX) Standard

COPC CX Standard Release 8.0 is a performance management standard for contact centres and customer operations; COPC Inc. certifies against it.

CPCSCCertification
Canadian Program for Cyber Security Certification

Canada's cyber security certification for defence suppliers, run by Public Services and Procurement Canada and National Defence, with three levels.

CRACertification
Cyber Resilience Audit scheme

The Cyber Resilience Audit scheme certifies AUDITORS delivering independent cyber audits based on the NCSC's Cyber Assessment Framework.

CSCCertification
CyberSecure Canada

CyberSecure Canada is a voluntary federal certification program for small and medium-sized enterprises, evaluated by a certification body accredited by the SCC.

Cyber EssentialsCertification
Cyber Essentials

Cyber Essentials is the UK's NCSC-developed certification scheme, delivered through IASME, named as a supplier condition in Procurement Policy Note 09/14.

DCCCertification
Defence Cyber Certification

Defence Cyber Certification is the MOD's four-level certification route evidencing compliance with the UK Cyber Security Model, launched May 2025.

DPFCertification
EU-US Data Privacy Framework

The EU-US Data Privacy Framework is a self-certification program for personal-data transfers, run and verified by the U.S. International Trade Administration.

ENSCertification
Esquema Nacional de Seguridad

Esquema Nacional de Seguridad is Spain's statutory security framework for public-sector information systems, set by Real Decreto 311/2022.

EUCCCertification
European Common Criteria-based Cybersecurity Certification Scheme

EUCC is the EU's first Cybersecurity Act certification scheme for ICT products, based on Common Criteria and applied from 27 February 2025.

FTUSA FPSCertification
Fair Trade Certified — Factory Production Standard

A Fair Trade Certified factory complies with Fair Trade USA's Factory Production Standard; brands that source from it get licensed to use the label.

GDPR-CARPACertification
GDPR-Certified Assurance Report-based Processing Activities

GDPR-CARPA is a GDPR Article 42 certification scheme created and run directly by Luxembourg's data protection authority, the CNPD.

Global CBPRCertification
Global Cross-Border Privacy Rules Certification

Global CBPR is a government-backed privacy certification for cross-border data transfers, awarded by independent third-party Accountability Agents.

Green AwardCertification
Green Award

Green Award is a certification and incentive program for ships, established in 1994, issuing separate three-year certificates for ship and office.

HDSCertification
Hébergeur de Données de Santé

HDS is a French statutory certification for anyone hosting personal health data as a GDPR-article-28 processor, issued by COFRAC-accredited bodies.

HITRUST CSFCertification
HITRUST CSF

HITRUST CSF is a certifiable framework owned by HITRUST, serving as the control set for HITRUST assessments at the e1, i1 and r2 levels.

IASME CACertification
IASME Cyber Assurance

IASME Cyber Assurance is a two-level UK certification for security governance, sold only to organisations holding a valid Cyber Essentials certificate.

ISMS-PCertification
Personal Information & Information Security Management System

ISMS-P is South Korea's integrated certification for information security and personal-data management, statutory for defined ICT operators.

Kantara InitiativeCertification
Kantara Initiative

Kantara Initiative runs global identity-assurance certification programs, assessing services against standards including NIST SP 800-63 and the UK's DIATF.

MASECertification
MASE

MASE is a French occupational safety, health and environment certification scheme run by a network of local industry associations, not a government body.

MTCSCertification
Multi-Tiered Cloud Computing Security (SS 584)

MTCS (Singapore Standard SS 584:2020) is a three-level cloud security certification, published under the Information Technology Standards Committee.

NAID AAACertification
NAID AAA Certification

NAID AAA Certification is i-SIGMA's voluntary program for member companies providing secure information destruction. Membership comes first.

O-TTPSCertification
Open Trusted Technology Provider Standard

O-TTPS is The Open Group's certification standard against maliciously tainted and counterfeit ICT products, with a live public certification register.

PeppolCertification
Peppol Service Provider Certification

Peppol Service Provider Certification governs who may run an Access Point or Service Metadata Publisher on OpenPeppol's e-procurement network.

Route to Net ZeroCertification
Route to Net Zero Standard

Carbon Trust's Route to Net Zero Standard has three certification tiers, guiding organizations to independently verify carbon reductions toward Net Zero.

SCCCertification
Safety Certificate Contractors

SCC is an occupational safety certification family (SCC*, SCC**, SCP, SCCP), issued by accredited bodies such as TÜV across several European markets.

SCS 9001Certification
SCS 9001

SCS 9001 is TIA's certifiable cyber and supply chain security standard for the ICT industry, with optional benchmarking across supply chains.

SDLACertification
Security Development Lifecycle Assurance

SDLA is ISASecure's ISA/IEC 62443-4-1 certification for a security development lifecycle — it certifies the development site, not a product.

SOACertification
Attestazione SOA

Attestazione SOA is Italy's qualification requirement for public construction contracts of €150,000 or more, issued by ANAC-authorized bodies.

TIA-942Certification
ANSI/TIA-942

ANSI/TIA-942 audits and certifies data center infrastructure against four Rated tiers, carried out by TIA-licensed third-party bodies.

Tier CertificationCertification
Uptime Institute Tier Certification

Uptime Institute's Tier Certification rates data centers across four infrastructure levels, from basic capacity to fully fault-tolerant.

TL 9000Certification
TL 9000

TL 9000 is TIA QuEST Forum's ICT-industry certification, extending ISO 9001:2015 with telecom-specific requirements for certified organizations.

TrustArcCertification
TrustArc / TRUSTe Certification Programs

TrustArc operates TRUSTe-branded certification, verification and validation products for privacy compliance, not all equally strong.

Attestation 18 records

AAF 01/20Attestation
Assurance reports on internal controls of service organisations made available to third parties (Technical Release 01/20 AAF)

AAF 01/20 is an ICAEW technical release enabling a service organisation's independent auditor to issue an assurance opinion on its internal controls.

BeSaCCAttestation
BeSaCC

BeSaCC is a Belgian safety attestation for smaller, lower-risk contractors — reviewed by an expert panel, not audited by a certification body like SCC.

C5Attestation
Cloud Computing Compliance Criteria Catalogue

C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate.

CSPAttestation
Customer Security Programme

Swift's Customer Security Programme (CSP) is a mandatory yearly attestation against baseline security controls for all Swift network users.

CyberReadyAttestation
CyberReady

CyberReady issues a validation or verification statement — not a certificate — for CAN/DGSI 104, the Digital Governance Council's SME cyber security baseline.

ENX VCSAttestation
ENX Vehicle Cyber Security

ENX VCS is ENX Association's ISO/SAE 21434-based third-party audit scheme for a supplier's Vehicle Cybersecurity Management System, issuing a label.

ISAE 3000 (Revised)Attestation
International Standard on Assurance Engagements (ISAE) 3000 (Revised), Assurance Engagements Other than Audits or Reviews of Historical Financial Information

ISAE 3000 (Revised) is the IAASB's general standard for assurance engagements other than audits or reviews of historical financial information.

ISAE 3402Attestation
International Standard on Assurance Engagements (ISAE) 3402, Assurance Reports on Controls at a Service Organization

ISAE 3402 is the IAASB's assurance standard for reports on controls at a service organization relevant to user entities' financial reporting.

SBTiAttestation
Science Based Targets initiative

SBTi is a corporate climate action organization that validates the scientific basis of companies' emissions-reduction targets, not a certification body.

Secure Software Development Attestation FormAttestation
Secure Software Development Attestation Form

A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.

SOC 1Attestation
SOC 1

SOC 1 is an AICPA attestation on a service organization's controls relevant to user entities' internal control over financial reporting.

SOC 2Attestation
SOC 2

SOC 2 is an AICPA attestation: the output is an examination report, not a certificate, examining a service organization's system and controls.

SOC 3Attestation
SOC 3

SOC 3 is an AICPA attestation report: a general-use summary that, unlike SOC 2, can be freely distributed without the same level of detail.

SOC for CybersecurityAttestation
SOC for Cybersecurity

SOC for Cybersecurity is an AICPA attestation engagement in which a CPA reports on an organization's enterprise-wide cybersecurity risk management program.

SOC for Supply ChainAttestation
SOC for Supply Chain

SOC for Supply Chain is an AICPA attestation: an examination report on controls in a production, manufacturing, or distribution system — not a certificate.

SOX §404 (ITGC)Attestation
Sarbanes-Oxley Act Section 404 — Internal Control Over Financial Reporting Assessment and Attestation

SOX §404 requires covered U.S. issuers to assess internal control over financial reporting, with an independent auditor's attestation for accelerated filers.

SSPAAttestation
Supplier Security & Privacy Assurance Program

Microsoft SSPA is Microsoft's own supplier compliance program, not a portable certificate — suppliers self-attest annually to its Data Protection Requirements.

TISAXAttestation
Trusted Information Security Assessment Exchange

TISAX is ENX Association's assessment and label exchange mechanism for automotive-industry information security, based on third-party assessment.

Authorization program 10 records

ACN Cloud Qualification SchemeAuthorization program
ACN Cloud Qualification Scheme

ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud.

CSPAuthorization program
Contract Security Program

The Contract Security Program (CSP) screens contractors bidding on federal contracts that carry security requirements; PSPC administers it.

FedRAMPAuthorization program
Federal Risk and Authorization Management Program

FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.

GovRAMPAuthorization program
GovRAMP

GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.

IRS Pub 1075Authorization program
Tax Information Security Guidelines for Federal, State and Local Agencies

IRS Publication 1075 sets the controls agencies, agents, contractors and sub-contractors must meet as a condition of receiving Federal Tax Information.

MARS-EAuthorization program
Minimum Acceptable Risk Standards for Exchanges

MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4.

PSN CoCoAuthorization program
PSN Code of Connection

PSN Code of Connection is the application process and yearly certificate required to connect to the UK's Public Services Network.

QTSPAuthorization program
eIDAS Qualified Trust Service Provider Status

eIDAS Qualified Trust Service Provider status follows a conformity assessment by an accredited body and listing on an EU Trusted List.

SecNumCloudAuthorization program
SecNumCloud

SecNumCloud is a French state qualification for cloud service providers, granted by ANSSI, covering SaaS, PaaS, CaaS and IaaS activities.

TX-RAMPAuthorization program
Texas Risk and Authorization Management Program

TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.

Framework 51 records

AI RMF 1.0Framework
AI Risk Management Framework

NIST AI RMF 1.0 is a voluntary NIST framework for managing AI risk, built around four functions: Govern, Map, Measure, Manage.

AQAP-2110Framework
Allied Quality Assurance Publication AQAP-2110 — NATO Quality Assurance Requirements for Design, Development and Production

AQAP-2110 is a NATO quality assurance publication applied when a defence contract references it; NATO calls it a NATO STANDARD, not a certification.

ASPICEFramework
Automotive SPICE

Automotive SPICE is VDA QMC's process assessment model, version 4.0 (December 2023), rating development processes on capability levels CL0 to CL5.

BIO2Framework
BIO2 (Baseline Informatiebeveiliging Overheid 2)

BIO2 is the Dutch government's baseline information-security framework, now legally anchored for organisations within the Cyberbeveiligingswet's scope.

CAFFramework
Cyber Assessment Framework

The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience, structured around 4 objectives and 41 assessments.

CCCS Cloud Security Assessment ProgramFramework
Cloud Service Provider (CSP) Information Technology Security (ITS) Assessment Program

The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate.

CCMFramework
Cloud Controls Matrix

The CSA Cloud Controls Matrix is a cybersecurity control framework for cloud computing, structured in 17 domains, maintained by the Cloud Security Alliance.

CIS ControlsFramework
CIS Critical Security Controls

The CIS Critical Security Controls are CIS's prescriptive defense framework; v8.1 is current, organized as 18 Controls across three Implementation Groups.

CISIS12Framework
CISIS12

CISIS12 is a German information security management methodology, positioned between ISO/IEC 27001 and BSI IT-Grundschutz for mid-sized organisations.

CJIS Security PolicyFramework
FBI CJIS Security Policy

The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate.

CMMIFramework
CMMI

CMMI is a process model, now run by ISACA, that rates organizations through an appraisal — not a certificate — resulting in a Maturity Level rating.

COBITFramework
COBIT

COBIT is ISACA's framework for the governance and management of enterprise IT, currently COBIT 2019 — it is a framework, not a certificate.

CPoCFramework
Contactless Payments on COTS (CPoC)

CPoC lets a merchant's phone or tablet accept contactless payments via its own NFC hardware — PCI SSC put it into a sunset period from 1 May to 31 October 2026.

CRI ProfileFramework
CRI Profile

CRI Profile is named in FFIEC's own sunset statement as one industry resource institutions may consider — not a designated successor to the CAT.

DESC ISRFramework
Information Security Regulation

DESC's Information Security Regulation sets minimum security controls for all Dubai Government Entities, formalized under Resolution No. 13 of 2012.

DIATFFramework
UK digital identity and attributes trust framework

The UK digital identity and attributes trust framework is DSIT's certification scheme for digital identity and attribute services, run day-to-day by OfDIA.

E8Framework
Essential Eight

The Essential Eight is an ASD mitigation-strategy set with four maturity levels (ML0-ML3); ML2 is a mandatory baseline for PSPF-covered federal entities.

Fair WearFramework
Fair Wear (Foundation)

Fair Wear is a multi-stakeholder initiative that garment and textile brands join to build human rights and environmental due diligence into their supply chains.

FFIEC CATFramework
Cybersecurity Assessment Tool

The FFIEC sunset its Cybersecurity Assessment Tool (CAT) on August 31, 2025; it was a voluntary self-assessment, not an examination requirement.

HACCPFramework
HACCP

HACCP is the hazard-control methodology in Codex CXC 1-1969; US, EU, UK and Canadian rules quoted here require procedures built on its principles.

Higg FEMFramework
Higg Facility Environmental Module

Higg FEM is Cascale's self-assessment tool for facility environmental performance — water, waste, chemicals, energy — not a certificate.

Higg FSLMFramework
Higg Facility Social & Labor Module

Higg FSLM is Cascale's module for assessing wages, working hours, health and safety and employee treatment inside factories.

ICAEW PAFramework
ICAEW Practice Assurance

ICAEW Practice Assurance is a framework of principles-based quality assurance standards ICAEW member firms and practising certificate holders must follow.

ISO/IEC 17025Framework
ISO/IEC 17025

ISO/IEC 17025:2017 sets competence requirements for testing and calibration laboratories, and accreditation bodies assess laboratories against it.

ISO/IEC 22237Framework
ISO/IEC 22237-1

ISO/IEC 22237-1 sets the general principles and classification system for data centers; the series' other parts are mostly withdrawn or still in draft.

ISO/IEC 27002Framework
ISO/IEC 27002

ISO/IEC 27002:2022 is the information security controls guidance standard; ISO assigns the certifiable requirements role to ISO/IEC 27001, not to it.

ISO/IEC 27017Framework
ISO/IEC 27017

ISO/IEC 27017 gives cloud-specific security controls on top of ISO/IEC 27002; the current edition is 27017:2026 — the 2015 text is withdrawn.

ISO/IEC 27018Framework
ISO/IEC 27018

ISO/IEC 27018 guides protection of PII in public clouds where the provider acts as PII processor; the current edition is 27018:2025 (third edition).

MAS TRM GuidelinesFramework
Guidelines on Risk Management Practices – Technology Risk

MAS's Guidelines on Risk Management Practices – Technology Risk set best-practice standards for Singapore financial institutions managing technology risk.

MPoCFramework
Mobile Payments on COTS (MPoC)

MPoC is PCI SSC's standard for accepting PIN and contactless card data on one COTS device, evaluated by PCI-Recognized Laboratories.

MVSPFramework
Minimum Viable Secure Product

Minimum Viable Secure Product is a public-domain security baseline checklist for enterprise-ready products, published under a CC0 license.

NERC CIPFramework
Critical Infrastructure Protection Reliability Standards

NERC CIP is the mandatory cybersecurity reliability standard family for the U.S. bulk-power system, developed by NERC and approved by FERC.

NESASFramework
Network Equipment Security Assurance Scheme

NESAS is GSMA's voluntary security assurance scheme for mobile network equipment — it audits vendor processes and evaluates products, issuing no certificate.

NIST CSF 2.0Framework
The NIST Cybersecurity Framework (CSF) 2.0

The NIST Cybersecurity Framework 2.0 is guidance a business aligns with, not a certification — published by NIST as CSWP 29 on 26 February 2024.

NIST SP 800-171Framework
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

NIST SP 800-171 is NIST's framework for protecting Controlled Unclassified Information in nonfederal systems; DoD contracts bind it through DFARS clauses.

NIST SP 800-37 Rev. 2 / RMFFramework
Risk Management Framework for Information Systems and Organizations

NIST's Risk Management Framework (SP 800-37) is a 7-step lifecycle process ending in an Authorization to Operate, not a control checklist.

NIST SP 800-53 Rev. 5Framework
Security and Privacy Controls for Information Systems and Organizations

NIST SP 800-53 is a catalog of security and privacy controls; FIPS 200 requires U.S. federal agencies to meet minimum requirements using it.

P2PEFramework
P2PE Standard

P2PE is a PCI SSC standard for point-to-point encrypted payment solutions, validated by independent P2PE Assessors — PCI SSC itself does not mandate it.

PCI 3DS CoreFramework
PCI 3DS Core Security Standard

PCI 3DS Core is PCI SSC's standard for entities operating ACS, DS or 3DSS environments, assessed by qualified 3DS Assessors — not mandated by PCI SSC itself.

PCI 3DS SDKFramework
PCI 3DS SDK Security Standard

PCI 3DS SDK is PCI SSC's product-level standard for 3DS Software Development Kits, evaluated by PCI-Recognized Laboratories — now in its formal sunset period.

PCI Card ProductionFramework
Card Production and Provisioning Security Requirements

Card Production and Provisioning is two PCI SSC standards — Logical and Physical — assessed by CPSA-P/CPSA-L assessors, with no product listing.

PCI DSSFramework
PCI DSS

PCI DSS is PCI SSC's data security standard for payment account data; v4.0.1 is the only active version, and no compliance certificate is recognized.

PCI PINFramework
PIN Security Standard

PIN Security is a PCI SSC standard for secure PIN management, assessed by independent Qualified PIN Assessors — PCI SSC itself does not mandate it.

PCI TSPFramework
Token Service Provider (TSP) Standard

PCI TSP sets requirements for token service providers issuing EMV payment tokens, assessed by specially qualified P2PE Assessors — not mandated by PCI SSC.

RBI CSFFramework
Cyber Security Framework in Banks

RBI's 2016 circular directs scheduled commercial banks (excluding Regional Rural Banks) to build cyber security governance, an SOC, and incident reporting.

Secure SLCFramework
Secure Software Lifecycle (Secure SLC) Standard

Secure SLC Standard is PCI SSC's organization-level standard for a software vendor's secure development lifecycle, assessed by PCI Secure SLC Assessors.

Secure Software StandardFramework
Secure Software Standard

Secure Software Standard is PCI SSC's product-level standard for payment software, assessed by PCI Secure Software Assessors — successor to the retired PA-DSS.

SLCPFramework
Social & Labor Convergence Program

SLCP calls itself "a multi-stakeholder initiative" running the Converged Assessment Framework (CAF), a shared social-data tool for facilities.

SPoCFramework
Software-based PIN Entry on COTS (SPoC) Standard

SPoC lets merchants accept PIN entry on an ordinary smartphone or tablet — PCI SSC put the standard into a formal sunset period from 1 May to 31 October 2026.

TMSAFramework
Tanker Management and Self-Assessment

TMSA is one of OCIMF's four Management Self-Assessment titles: tanker companies assess their own safety management systems against KPIs.

UAE IA RegulationFramework
UAE Information Assurance Regulation

The UAE IA Regulation sets minimum information-security controls that TDRA-designated critical entities must implement and demonstrate compliance with.

Audit methodology 33 records

AA1000ASAudit methodology
AA1000 Assurance Standard

The AA1000 Assurance Standard (AA1000AS v3) is AccountAbility's assurance standard for sustainability reporting, open to organizations of any size or sector.

BEPIAudit methodology
amfori BEPI

amfori describes amfori BEPI as a solution for environmental risk management, using a self-risk assessment and onsite audit — not a certificate.

Better WorkAudit methodology
Better Work

Better Work is a joint ILO–IFC program, not a certification: it assesses garment factories and offers advisory visits to improve working conditions.

CBESTAudit methodology
CBEST Threat Intelligence-Led Assessments

CBEST is the Bank of England, PRA and FCA's intelligence-led penetration testing regime for assessing cyber resilience of systemically important firms.

CDIAudit methodology
Chemical Distribution Institute

CDI is a Dutch non-profit foundation that runs marine, terminal and packed-cargo inspections for the bulk and packaged chemical supply chain.

DigiD ICT-beveiligingsassessment (DigiD ICT Security Assessment)Audit methodology
DigiD ICT-beveiligingsassessment (DigiD ICT Security Assessment)

Organisations using DigiD must complete an annual ICT security assessment, overseen by Logius under the Dutch Ministry of the Interior.

DSPTAudit methodology
Data Security and Protection Toolkit

The DSPT is NHS England's mandatory self-assessment toolkit for organisations with access to NHS patient data — the output is a status, not a certificate.

EPCSAudit methodology
Electronic Prescriptions for Controlled Substances — third-party audit or certification requirement (21 CFR § 1311.300)

EPCS is the DEA rule under 21 CFR 1311.300: providers of electronic prescription or pharmacy applications must obtain a third-party audit.

FLAAudit methodology
Fair Labor Association

Fair Labor Association runs two distinct programs: Fair Labor Accreditation for organizations and separate on-site Fair Labor Assessments in factories.

Global MMOG/LEAudit methodology
Global Materials Management Operations Guideline / Logistics Evaluation

Global MMOG/LE is the Odette–AIAG self-assessment tool for materials management and logistics, version 6.0 (March 2023), classifying sites A, B or C.

GovAssureAudit methodology
GovAssure

GovAssure is the UK government's scheme for assessing government critical systems against the NCSC Cyber Assessment Framework.

HECVATAudit methodology
Higher Education Community Vendor Assessment Toolkit

HECVAT is a self-assessment questionnaire created by leaders in higher education with EDUCAUSE, Internet2 and REN-ISAC, hosted at no cost.

ICSAudit methodology
ICS — Initiative for Compliance and Sustainability

ICS is a shared social-audit protocol for 70 multinational retailers and brands; its audits are, in the owner's own words, neither certificates nor labels.

IFQPAudit methodology
IATA Fuel Quality Pool

The IATA Fuel Quality Pool is a group of airlines that share fuel inspection reports and inspection workload at airports worldwide.

IOSAAudit methodology
IATA Operational Safety Audit

IOSA is IATA's operational safety audit program: airlines are registered on the IOSA Registry, and IATA membership requires staying registered.

ISAGOAudit methodology
IATA Safety Audit for Ground Operations

ISAGO is IATA's safety audit program for ground handling providers: registration and station accreditation each run for 24 months.

ISSA 5000Audit methodology
ISSA 5000

ISSA 5000 is IAASB's general standard for sustainability assurance engagements, effective for periods beginning on or after December 15, 2026.

NUPICAudit methodology
Nuclear Procurement Issues Corporation

NUPIC is a joint audit program of US and international nuclear plant operators that evaluates shared suppliers on a 33-month schedule.

Peer Review ProgramAudit methodology
Peer Review Program

The AICPA & CIMA Peer Review Program requires firms performing accounting or auditing work to undergo a peer review of their engagements or quality control.

PSCIAudit methodology
Pharmaceutical Supply Chain Initiative

PSCI is a non-profit membership organization whose members share third-party supplier audits across the pharmaceutical and healthcare value chain.

RBA VAPAudit methodology
RBA Validated Assessment Program

The RBA Validated Assessment Program is an on-site audit methodology for RBA Code compliance, carried out by independent third-party firms, not RBA itself.

RSCIAudit methodology
Responsible Supply Chain Initiative

RSCI is a Berlin-based automotive association that runs a standardized audit program for social and environmental risks in the supply chain.

Rx-360Audit methodology
Rx-360

Rx-360 is a pharmaceutical supply-chain consortium that runs shared supplier audits and licenses the resulting reports to its members.

SCANAudit methodology
SCAN — Supplier Compliance Audit Network

SCAN is a single security audit accepted across its member network of importers, manufacturers and transportation providers, cutting duplicate audits.

SCLAudit methodology
Safety Culture Ladder (Veiligheidsladder)

Safety Culture Ladder 2.0 is a five-step assessment method NEN administers to measure safety awareness and behaviour in organisations.

SIREAudit methodology
Ship Inspection Report Programme

SIRE is OCIMF's Ship Inspection Report Programme; its current version, SIRE 2.0, produces tanker inspection reports held in a risk-assessment database.

SMETAAudit methodology
SMETA

Sedex calls SMETA "the world's most widely used social audit," a methodology it owns and evolves, audited by independent third-party firms it names.

SQASAudit methodology
Safety & Quality Assessment for Sustainability

SQAS is Cefic's on-site assessment scheme for logistics service providers and chemical distributors, run by independent accredited assessors.

TfSAudit methodology
Together for Sustainability

Together for Sustainability is a Brussels-based association of chemical companies that scores and audits suppliers through two shared instruments.

TIBER-EUAudit methodology
TIBER-EU

TIBER-EU is the ECB-coordinated, EU-wide framework for threat intelligence-based ethical red-teaming, aligned with DORA's threat-led penetration testing.

TPNAudit methodology
Trusted Partner Network

TPN is not a certification — it's MPA's voluntary assessment program rating a facility's security readiness as a Shield tier: Blue, Silver, Gold, or Gold Star.

VSAAudit methodology
Vendor Security Alliance Questionnaire

The Vendor Security Alliance Questionnaire is a free, self-assessment vendor security questionnaire issued by a non-profit coalition of companies.

WCAAudit methodology
Workplace Conditions Assessment

WCA (Workplace Conditions Assessment) is Intertek's audit program that evaluates workplace conditions across supply chains — it is not a certificate.

Prequalification register 16 records

ACSPrequalification register
Approved Contractor Scheme

The Approved Contractor Scheme is the SIA's voluntary, statutory-register company approval scheme for the UK private security industry.

AvettaPrequalification register
Avetta

Avetta is a supplier prequalification and compliance platform used by buyer companies to vet contractor safety, insurance and performance records.

BuildingConfidencePrequalification register
BuildingConfidence

BuildingConfidence is Achilles' UK construction pre-qualification scheme, which the owner says incorporates SSIP and CAS and goes beyond both.

CHASPrequalification register
CHAS

CHAS is a founding member scheme of SSIP, offering three graded levels of health and safety pre-qualification assessment for contractors.

ConstructionlinePrequalification register
Constructionline

Constructionline is a UK construction supplier pre-qualification database, checked by buyers via login — not a certificate a supplier holds independently.

CSA STARPrequalification register
Security, Trust, Assurance and Risk (STAR)

CSA STAR is the Cloud Security Alliance's cloud assurance program, built around a publicly accessible registry of provider security submissions.

ISNPrequalification register
ISNetworld

ISNetworld is a contractor and supplier information-management platform that hiring clients use to review safety, insurance, and compliance records.

JOSCARPrequalification register
JOSCAR

JOSCAR is a shared supplier pre-qualification register operated by Hellios Information Limited for the UK defence, aerospace and security sector.

PQ-BahnPrequalification register
Präqualifikationsverfahren PQ-Bahn

PQ-Bahn is Deutsche Bahn's own prequalification procedure for infrastructure-procurement tenders — DB's requirement, not a state certification.

RISASPrequalification register
RISAS

RISAS is RSSB's approval scheme for railway suppliers of the most challenging, high-risk work, initially scoped to rolling-stock overhaul.

RISQSPrequalification register
RISQS

RISQS is RSSB's supplier qualification scheme for the UK rail industry, used by Network Rail only for direct, safety-critical (RICCL-coded) suppliers.

SafeContractorPrequalification register
SafeContractor

SafeContractor is a UKAS-accredited health and safety pre-qualification scheme and a founding member of SSIP, covering eleven listed sectors.

SSIPPrequalification register
Safety Schemes in Procurement

SSIP is a mutual-recognition scheme joining UK health and safety pre-qualification schemes, so an approval from one member scheme is accepted by the others.

StartBANKPrequalification register
StartBANK

StartBANK is a Norwegian supplier prequalification network for construction and engineering, operated by Achilles since it launched in 2005 with NHO.

Utilities NCEPrequalification register
Utilities NCE

Utilities NCE is Achilles' qualification system for utility suppliers in Central and Northern Europe, not a certificate the supplier holds.

UVDBPrequalification register
UVDB

UVDB is Achilles's prequalification network for UK regulated utilities, used by buyers including Anglian Water and Scottish Water to assess suppliers.

Trust mark 6 records

Rating 2 records

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.