Glossary

Attestation vs Certification

An attestation is a professional’s written opinion about your claims: a CPA firm examines your controls and attests, in a detailed report, to whether they’re designed and operating effectively. SOC 1, SOC 2, and SOC 3 are attestations. There is no pass/fail and no certificate — there’s an opinion, exceptions and all, that your customers read.

A certification is a pass/fail verdict against a standard by an accredited body, producing a certificate anyone can verify. ISO 27001 and PCI DSS (via ROC/AOC) work this way.

Why the distinction matters commercially

Certificates travel light — a logo in the sales deck, a one-page PDF in procurement. Attestation reports travel heavy — NDA-gated, dozens of pages, actually read by security teams. That’s also their respective strengths: the certificate opens doors; the report survives scrutiny behind them. It’s why “we’re SOC 2 certified” is technically wrong (and security reviewers notice) — the correct claim is “we hold a SOC 2 Type II report,” shareable under NDA, with a SOC 3 as the public companion.

The buyer’s-eye view

Enterprise reviewers weigh who stands behind each document: the CPA firm’s name on an attestation, the accreditation behind a certificate. Both can be undermined by a weak issuer — which is why choosing your auditor is a commercial decision, not a procurement afterthought.

Related Terms

ISMS — An ISMS is the management system ISO 27001 certifies — the loop of risk assessment, controls, internal audit, and review that runs your security program.

SOC 3 — A SOC 3 is the public, general-use version of a SOC 2 Type II report — same audit, no confidential detail, freely publishable on your website.

SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.