Frameworks & Audits
Frameworks, audits and assurance programs
Assurance instruments that are not ISO management-system standards: attestations, authorization programs, certifiable frameworks and audit schemes. Each record names its class honestly — an attestation is a report, not a certificate — and every fact links to the owner's own pages, dated to when we last checked them.
Certification 37 records
ACSSA is ISASecure's ISA/IEC 62443 certification for a deployed control system and asset owner policies and procedures, not a product.
ADISA ICT Asset Recovery Standard 8.0 certifies processors that handle IT asset disposal; ADISA Certification owns and audits the scheme.
AS9100 is the aerospace quality management certification of IAQG's 9100 series, run under the IAF-endorsed ICOP scheme with the OASIS supplier register.
CEIV is IATA's certification family for special cargo: four programs — Pharma, Live Animals, Fresh, and Lithium Batteries — validate handling standards.
The CO₂ Performance Ladder is a Dutch-owned certification scheme (SKAO) that gives certified bidders an award advantage in public tenders.
COPC CX Standard Release 8.0 is a performance management standard for contact centres and customer operations; COPC Inc. certifies against it.
Canada's cyber security certification for defence suppliers, run by Public Services and Procurement Canada and National Defence, with three levels.
The Cyber Resilience Audit scheme certifies AUDITORS delivering independent cyber audits based on the NCSC's Cyber Assessment Framework.
CyberSecure Canada is a voluntary federal certification program for small and medium-sized enterprises, evaluated by a certification body accredited by the SCC.
Cyber Essentials is the UK's NCSC-developed certification scheme, delivered through IASME, named as a supplier condition in Procurement Policy Note 09/14.
Defence Cyber Certification is the MOD's four-level certification route evidencing compliance with the UK Cyber Security Model, launched May 2025.
The EU-US Data Privacy Framework is a self-certification program for personal-data transfers, run and verified by the U.S. International Trade Administration.
Esquema Nacional de Seguridad is Spain's statutory security framework for public-sector information systems, set by Real Decreto 311/2022.
EUCC is the EU's first Cybersecurity Act certification scheme for ICT products, based on Common Criteria and applied from 27 February 2025.
A Fair Trade Certified factory complies with Fair Trade USA's Factory Production Standard; brands that source from it get licensed to use the label.
GDPR-CARPA is a GDPR Article 42 certification scheme created and run directly by Luxembourg's data protection authority, the CNPD.
Global CBPR is a government-backed privacy certification for cross-border data transfers, awarded by independent third-party Accountability Agents.
Green Award is a certification and incentive program for ships, established in 1994, issuing separate three-year certificates for ship and office.
HDS is a French statutory certification for anyone hosting personal health data as a GDPR-article-28 processor, issued by COFRAC-accredited bodies.
HITRUST CSF is a certifiable framework owned by HITRUST, serving as the control set for HITRUST assessments at the e1, i1 and r2 levels.
IASME Cyber Assurance is a two-level UK certification for security governance, sold only to organisations holding a valid Cyber Essentials certificate.
ISMS-P is South Korea's integrated certification for information security and personal-data management, statutory for defined ICT operators.
Kantara Initiative runs global identity-assurance certification programs, assessing services against standards including NIST SP 800-63 and the UK's DIATF.
MASE is a French occupational safety, health and environment certification scheme run by a network of local industry associations, not a government body.
MTCS (Singapore Standard SS 584:2020) is a three-level cloud security certification, published under the Information Technology Standards Committee.
NAID AAA Certification is i-SIGMA's voluntary program for member companies providing secure information destruction. Membership comes first.
O-TTPS is The Open Group's certification standard against maliciously tainted and counterfeit ICT products, with a live public certification register.
Peppol Service Provider Certification governs who may run an Access Point or Service Metadata Publisher on OpenPeppol's e-procurement network.
Carbon Trust's Route to Net Zero Standard has three certification tiers, guiding organizations to independently verify carbon reductions toward Net Zero.
SCC is an occupational safety certification family (SCC*, SCC**, SCP, SCCP), issued by accredited bodies such as TÜV across several European markets.
SCS 9001 is TIA's certifiable cyber and supply chain security standard for the ICT industry, with optional benchmarking across supply chains.
SDLA is ISASecure's ISA/IEC 62443-4-1 certification for a security development lifecycle — it certifies the development site, not a product.
Attestazione SOA is Italy's qualification requirement for public construction contracts of €150,000 or more, issued by ANAC-authorized bodies.
ANSI/TIA-942 audits and certifies data center infrastructure against four Rated tiers, carried out by TIA-licensed third-party bodies.
Uptime Institute's Tier Certification rates data centers across four infrastructure levels, from basic capacity to fully fault-tolerant.
TL 9000 is TIA QuEST Forum's ICT-industry certification, extending ISO 9001:2015 with telecom-specific requirements for certified organizations.
TrustArc operates TRUSTe-branded certification, verification and validation products for privacy compliance, not all equally strong.
Attestation 18 records
AAF 01/20 is an ICAEW technical release enabling a service organisation's independent auditor to issue an assurance opinion on its internal controls.
BeSaCC is a Belgian safety attestation for smaller, lower-risk contractors — reviewed by an expert panel, not audited by a certification body like SCC.
C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate.
Swift's Customer Security Programme (CSP) is a mandatory yearly attestation against baseline security controls for all Swift network users.
CyberReady issues a validation or verification statement — not a certificate — for CAN/DGSI 104, the Digital Governance Council's SME cyber security baseline.
ENX VCS is ENX Association's ISO/SAE 21434-based third-party audit scheme for a supplier's Vehicle Cybersecurity Management System, issuing a label.
ISAE 3000 (Revised) is the IAASB's general standard for assurance engagements other than audits or reviews of historical financial information.
ISAE 3402 is the IAASB's assurance standard for reports on controls at a service organization relevant to user entities' financial reporting.
SBTi is a corporate climate action organization that validates the scientific basis of companies' emissions-reduction targets, not a certification body.
A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.
SOC 1 is an AICPA attestation on a service organization's controls relevant to user entities' internal control over financial reporting.
SOC 2 is an AICPA attestation: the output is an examination report, not a certificate, examining a service organization's system and controls.
SOC 3 is an AICPA attestation report: a general-use summary that, unlike SOC 2, can be freely distributed without the same level of detail.
SOC for Cybersecurity is an AICPA attestation engagement in which a CPA reports on an organization's enterprise-wide cybersecurity risk management program.
SOC for Supply Chain is an AICPA attestation: an examination report on controls in a production, manufacturing, or distribution system — not a certificate.
SOX §404 requires covered U.S. issuers to assess internal control over financial reporting, with an independent auditor's attestation for accelerated filers.
Microsoft SSPA is Microsoft's own supplier compliance program, not a portable certificate — suppliers self-attest annually to its Data Protection Requirements.
TISAX is ENX Association's assessment and label exchange mechanism for automotive-industry information security, based on third-party assessment.
Authorization program 10 records
ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud.
The Contract Security Program (CSP) screens contractors bidding on federal contracts that carry security requirements; PSPC administers it.
FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.
GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.
IRS Publication 1075 sets the controls agencies, agents, contractors and sub-contractors must meet as a condition of receiving Federal Tax Information.
MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4.
PSN Code of Connection is the application process and yearly certificate required to connect to the UK's Public Services Network.
eIDAS Qualified Trust Service Provider status follows a conformity assessment by an accredited body and listing on an EU Trusted List.
SecNumCloud is a French state qualification for cloud service providers, granted by ANSSI, covering SaaS, PaaS, CaaS and IaaS activities.
TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.
Framework 51 records
NIST AI RMF 1.0 is a voluntary NIST framework for managing AI risk, built around four functions: Govern, Map, Measure, Manage.
AQAP-2110 is a NATO quality assurance publication applied when a defence contract references it; NATO calls it a NATO STANDARD, not a certification.
Automotive SPICE is VDA QMC's process assessment model, version 4.0 (December 2023), rating development processes on capability levels CL0 to CL5.
BIO2 is the Dutch government's baseline information-security framework, now legally anchored for organisations within the Cyberbeveiligingswet's scope.
The Cyber Assessment Framework is the NCSC's outcome-based framework for assessing cyber resilience, structured around 4 objectives and 41 assessments.
The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate.
The CSA Cloud Controls Matrix is a cybersecurity control framework for cloud computing, structured in 17 domains, maintained by the Cloud Security Alliance.
The CIS Critical Security Controls are CIS's prescriptive defense framework; v8.1 is current, organized as 18 Controls across three Implementation Groups.
CISIS12 is a German information security management methodology, positioned between ISO/IEC 27001 and BSI IT-Grundschutz for mid-sized organisations.
The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate.
CMMI is a process model, now run by ISACA, that rates organizations through an appraisal — not a certificate — resulting in a Maturity Level rating.
COBIT is ISACA's framework for the governance and management of enterprise IT, currently COBIT 2019 — it is a framework, not a certificate.
CPoC lets a merchant's phone or tablet accept contactless payments via its own NFC hardware — PCI SSC put it into a sunset period from 1 May to 31 October 2026.
CRI Profile is named in FFIEC's own sunset statement as one industry resource institutions may consider — not a designated successor to the CAT.
DESC's Information Security Regulation sets minimum security controls for all Dubai Government Entities, formalized under Resolution No. 13 of 2012.
The UK digital identity and attributes trust framework is DSIT's certification scheme for digital identity and attribute services, run day-to-day by OfDIA.
The Essential Eight is an ASD mitigation-strategy set with four maturity levels (ML0-ML3); ML2 is a mandatory baseline for PSPF-covered federal entities.
Fair Wear is a multi-stakeholder initiative that garment and textile brands join to build human rights and environmental due diligence into their supply chains.
The FFIEC sunset its Cybersecurity Assessment Tool (CAT) on August 31, 2025; it was a voluntary self-assessment, not an examination requirement.
HACCP is the hazard-control methodology in Codex CXC 1-1969; US, EU, UK and Canadian rules quoted here require procedures built on its principles.
Higg FEM is Cascale's self-assessment tool for facility environmental performance — water, waste, chemicals, energy — not a certificate.
Higg FSLM is Cascale's module for assessing wages, working hours, health and safety and employee treatment inside factories.
ICAEW Practice Assurance is a framework of principles-based quality assurance standards ICAEW member firms and practising certificate holders must follow.
ISO/IEC 17025:2017 sets competence requirements for testing and calibration laboratories, and accreditation bodies assess laboratories against it.
ISO/IEC 22237-1 sets the general principles and classification system for data centers; the series' other parts are mostly withdrawn or still in draft.
ISO/IEC 27002:2022 is the information security controls guidance standard; ISO assigns the certifiable requirements role to ISO/IEC 27001, not to it.
ISO/IEC 27017 gives cloud-specific security controls on top of ISO/IEC 27002; the current edition is 27017:2026 — the 2015 text is withdrawn.
ISO/IEC 27018 guides protection of PII in public clouds where the provider acts as PII processor; the current edition is 27018:2025 (third edition).
MAS's Guidelines on Risk Management Practices – Technology Risk set best-practice standards for Singapore financial institutions managing technology risk.
MPoC is PCI SSC's standard for accepting PIN and contactless card data on one COTS device, evaluated by PCI-Recognized Laboratories.
Minimum Viable Secure Product is a public-domain security baseline checklist for enterprise-ready products, published under a CC0 license.
NERC CIP is the mandatory cybersecurity reliability standard family for the U.S. bulk-power system, developed by NERC and approved by FERC.
NESAS is GSMA's voluntary security assurance scheme for mobile network equipment — it audits vendor processes and evaluates products, issuing no certificate.
The NIST Cybersecurity Framework 2.0 is guidance a business aligns with, not a certification — published by NIST as CSWP 29 on 26 February 2024.
NIST SP 800-171 is NIST's framework for protecting Controlled Unclassified Information in nonfederal systems; DoD contracts bind it through DFARS clauses.
NIST's Risk Management Framework (SP 800-37) is a 7-step lifecycle process ending in an Authorization to Operate, not a control checklist.
NIST SP 800-53 is a catalog of security and privacy controls; FIPS 200 requires U.S. federal agencies to meet minimum requirements using it.
P2PE is a PCI SSC standard for point-to-point encrypted payment solutions, validated by independent P2PE Assessors — PCI SSC itself does not mandate it.
PCI 3DS Core is PCI SSC's standard for entities operating ACS, DS or 3DSS environments, assessed by qualified 3DS Assessors — not mandated by PCI SSC itself.
PCI 3DS SDK is PCI SSC's product-level standard for 3DS Software Development Kits, evaluated by PCI-Recognized Laboratories — now in its formal sunset period.
Card Production and Provisioning is two PCI SSC standards — Logical and Physical — assessed by CPSA-P/CPSA-L assessors, with no product listing.
PCI DSS is PCI SSC's data security standard for payment account data; v4.0.1 is the only active version, and no compliance certificate is recognized.
PIN Security is a PCI SSC standard for secure PIN management, assessed by independent Qualified PIN Assessors — PCI SSC itself does not mandate it.
PCI TSP sets requirements for token service providers issuing EMV payment tokens, assessed by specially qualified P2PE Assessors — not mandated by PCI SSC.
RBI's 2016 circular directs scheduled commercial banks (excluding Regional Rural Banks) to build cyber security governance, an SOC, and incident reporting.
Secure SLC Standard is PCI SSC's organization-level standard for a software vendor's secure development lifecycle, assessed by PCI Secure SLC Assessors.
Secure Software Standard is PCI SSC's product-level standard for payment software, assessed by PCI Secure Software Assessors — successor to the retired PA-DSS.
SLCP calls itself "a multi-stakeholder initiative" running the Converged Assessment Framework (CAF), a shared social-data tool for facilities.
SPoC lets merchants accept PIN entry on an ordinary smartphone or tablet — PCI SSC put the standard into a formal sunset period from 1 May to 31 October 2026.
TMSA is one of OCIMF's four Management Self-Assessment titles: tanker companies assess their own safety management systems against KPIs.
The UAE IA Regulation sets minimum information-security controls that TDRA-designated critical entities must implement and demonstrate compliance with.
Audit methodology 33 records
The AA1000 Assurance Standard (AA1000AS v3) is AccountAbility's assurance standard for sustainability reporting, open to organizations of any size or sector.
amfori describes amfori BEPI as a solution for environmental risk management, using a self-risk assessment and onsite audit — not a certificate.
Better Work is a joint ILO–IFC program, not a certification: it assesses garment factories and offers advisory visits to improve working conditions.
CBEST is the Bank of England, PRA and FCA's intelligence-led penetration testing regime for assessing cyber resilience of systemically important firms.
CDI is a Dutch non-profit foundation that runs marine, terminal and packed-cargo inspections for the bulk and packaged chemical supply chain.
Organisations using DigiD must complete an annual ICT security assessment, overseen by Logius under the Dutch Ministry of the Interior.
The DSPT is NHS England's mandatory self-assessment toolkit for organisations with access to NHS patient data — the output is a status, not a certificate.
EPCS is the DEA rule under 21 CFR 1311.300: providers of electronic prescription or pharmacy applications must obtain a third-party audit.
Fair Labor Association runs two distinct programs: Fair Labor Accreditation for organizations and separate on-site Fair Labor Assessments in factories.
Global MMOG/LE is the Odette–AIAG self-assessment tool for materials management and logistics, version 6.0 (March 2023), classifying sites A, B or C.
GovAssure is the UK government's scheme for assessing government critical systems against the NCSC Cyber Assessment Framework.
HECVAT is a self-assessment questionnaire created by leaders in higher education with EDUCAUSE, Internet2 and REN-ISAC, hosted at no cost.
ICS is a shared social-audit protocol for 70 multinational retailers and brands; its audits are, in the owner's own words, neither certificates nor labels.
The IATA Fuel Quality Pool is a group of airlines that share fuel inspection reports and inspection workload at airports worldwide.
IOSA is IATA's operational safety audit program: airlines are registered on the IOSA Registry, and IATA membership requires staying registered.
ISAGO is IATA's safety audit program for ground handling providers: registration and station accreditation each run for 24 months.
ISSA 5000 is IAASB's general standard for sustainability assurance engagements, effective for periods beginning on or after December 15, 2026.
NUPIC is a joint audit program of US and international nuclear plant operators that evaluates shared suppliers on a 33-month schedule.
The AICPA & CIMA Peer Review Program requires firms performing accounting or auditing work to undergo a peer review of their engagements or quality control.
PSCI is a non-profit membership organization whose members share third-party supplier audits across the pharmaceutical and healthcare value chain.
The RBA Validated Assessment Program is an on-site audit methodology for RBA Code compliance, carried out by independent third-party firms, not RBA itself.
RSCI is a Berlin-based automotive association that runs a standardized audit program for social and environmental risks in the supply chain.
Rx-360 is a pharmaceutical supply-chain consortium that runs shared supplier audits and licenses the resulting reports to its members.
SCAN is a single security audit accepted across its member network of importers, manufacturers and transportation providers, cutting duplicate audits.
Safety Culture Ladder 2.0 is a five-step assessment method NEN administers to measure safety awareness and behaviour in organisations.
SIRE is OCIMF's Ship Inspection Report Programme; its current version, SIRE 2.0, produces tanker inspection reports held in a risk-assessment database.
Sedex calls SMETA "the world's most widely used social audit," a methodology it owns and evolves, audited by independent third-party firms it names.
SQAS is Cefic's on-site assessment scheme for logistics service providers and chemical distributors, run by independent accredited assessors.
Together for Sustainability is a Brussels-based association of chemical companies that scores and audits suppliers through two shared instruments.
TIBER-EU is the ECB-coordinated, EU-wide framework for threat intelligence-based ethical red-teaming, aligned with DORA's threat-led penetration testing.
TPN is not a certification — it's MPA's voluntary assessment program rating a facility's security readiness as a Shield tier: Blue, Silver, Gold, or Gold Star.
The Vendor Security Alliance Questionnaire is a free, self-assessment vendor security questionnaire issued by a non-profit coalition of companies.
WCA (Workplace Conditions Assessment) is Intertek's audit program that evaluates workplace conditions across supply chains — it is not a certificate.
Prequalification register 16 records
The Approved Contractor Scheme is the SIA's voluntary, statutory-register company approval scheme for the UK private security industry.
Avetta is a supplier prequalification and compliance platform used by buyer companies to vet contractor safety, insurance and performance records.
BuildingConfidence is Achilles' UK construction pre-qualification scheme, which the owner says incorporates SSIP and CAS and goes beyond both.
CHAS is a founding member scheme of SSIP, offering three graded levels of health and safety pre-qualification assessment for contractors.
Constructionline is a UK construction supplier pre-qualification database, checked by buyers via login — not a certificate a supplier holds independently.
CSA STAR is the Cloud Security Alliance's cloud assurance program, built around a publicly accessible registry of provider security submissions.
ISNetworld is a contractor and supplier information-management platform that hiring clients use to review safety, insurance, and compliance records.
JOSCAR is a shared supplier pre-qualification register operated by Hellios Information Limited for the UK defence, aerospace and security sector.
PQ-Bahn is Deutsche Bahn's own prequalification procedure for infrastructure-procurement tenders — DB's requirement, not a state certification.
RISAS is RSSB's approval scheme for railway suppliers of the most challenging, high-risk work, initially scoped to rolling-stock overhaul.
RISQS is RSSB's supplier qualification scheme for the UK rail industry, used by Network Rail only for direct, safety-critical (RICCL-coded) suppliers.
SafeContractor is a UKAS-accredited health and safety pre-qualification scheme and a founding member of SSIP, covering eleven listed sectors.
SSIP is a mutual-recognition scheme joining UK health and safety pre-qualification schemes, so an approval from one member scheme is accepted by the others.
StartBANK is a Norwegian supplier prequalification network for construction and engineering, operated by Achilles since it launched in 2005 with NHO.
Utilities NCE is Achilles' qualification system for utility suppliers in Central and Northern Europe, not a certificate the supplier holds.
UVDB is Achilles's prequalification network for UK regulated utilities, used by buyers including Anglian Water and Scottish Water to assess suppliers.
Trust mark 6 records
The Conveyancing Quality Scheme is the Law Society's accreditation for SRA-regulated practices in residential conveyancing, renewed every 12 months.
The EU Cloud Code of Conduct is a voluntary GDPR Article 40 code; cloud providers declare adherence and SCOPE Europe verifies compliance annually.
The AWS Foundational Technical Review (FTR) is a self-service review of AWS Partner solutions; AWS calls the outcome an approval and a badge, not a certificate.
Lexcel is a legal practice quality mark owned by the Law Society of England and Wales, awarded after assessment by an independent body.
The Specialist Quality Mark is the Legal Aid Agency's quality standard for legal services providers in England and Wales, audited under LAA licence.
The Wills and Inheritance Quality Scheme is the Law Society's quality mark for practices advising on wills and estate administration.
Rating 2 records
PSO-Prestatieladder is a TNO-developed inclusion rating that over 200 Dutch contracting authorities have used as a procurement instrument since 2012.
RightShip is a commercial maritime risk platform; its Safety Score benchmarks a vessel's past performance and its vetting outcome is buyer-specific.
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.