HomeAssessors

Assessors

Who is allowed to audit what.

For each framework: the kind of firm or agency that can assess or certify it, who accredits those assessors, and the public register where one exists. Consultants who help you prepare are a different category and cannot certify the work they helped build.

Share
Sponsored
Find
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Audit the Modern WayFind an accredited assessor
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here
FrameworkAssessed byAccredited byRegisterListed firms
21 CFR 111FDA investigators (government inspection). Voluntary third-party cGMP audits and certifications exist but do not replace FDA inspection.
21 CFR 117/FSMAFDA investigators, and state agencies inspecting under contract with FDA (government inspection). Third-party GFSI-benchmarked audits (SQF, BRCGS, FSSC 22000) cover the same ground but are voluntary and customer-driven.
21 CFR 211FDA investigators (government inspection). Foreign regulators under mutual recognition agreements and PIC/S-aligned authorities may inspect the same site for their own markets.
API Q1API itself. Auditors approved by API conduct Monogram license audits and APIQR management system registration audits; there is no market of independent certification bodies for API Q1 as there is for ISO 9001.API Quality Registrar (APIQR) is itself an ANAB-accredited certification body for management system registrations; the Monogram licensing program is API's own product-marking schemeAmerican Petroleum Institute (API Monogram and APIQR programs)
AS9100Certification bodies accredited under the IAQG scheme (9104-1) by an IAQG-recognized accreditation body, using IAQG-authenticated aerospace auditorsIAQG-recognized accreditation bodies (for example ANAB in the US, UKAS in the UK, DAkkS in Germany, JAB in Japan) working under IAQG oversightRegister ↗
AS9120Certification bodies accredited under the IAQG scheme (9104-1) by an IAQG-recognized accreditation body, using IAQG-authenticated aerospace auditorsIAQG-recognized accreditation bodies (ANAB, UKAS, DAkkS, JAB, and others) under IAQG oversightRegister ↗
BRCGSBRCGS-approved certification bodies accredited to ISO/IEC 17065 for the specific BRCGS standard, using BRCGS-registered auditorsNational accreditation bodies recognized by BRCGS (for example UKAS, ANAB, and other Global ACI signatories), with BRCGS running its own compliance and auditor competence oversight on topRegister ↗
CMMIISACA Certified CMMI Lead Appraisers sponsored by a licensed CMMI Partner organization, using the CMMI Appraisal Method (Benchmark, Sustainment, Evaluation, or Action Plan Reappraisal)ISACA (licenses Partners, certifies Lead Appraisers, and quality-reviews appraisal submissions)Register ↗
FDA 21 CFR 820/QMSRFDA investigators (government inspection). MDSAP-recognized auditing organizations conduct audits that FDA accepts in lieu of routine surveillance inspections for participating manufacturers.Register ↗BSI Group America Inc., DEKRA Certification B.V., DNV Product Assurance AS
FSSC 22000/ISO 22000FSSC-licensed certification bodies accredited to ISO/IEC 17021-1 with ISO/TS 22003-1 for the FSSC 22000 scheme; for ISO 22000 alone, any accredited certification body with food safety scopeNational accreditation bodies recognized by Foundation FSSC (for example ANAB, UKAS, RvA, DAkkS), which are Global ACI (formerly IAF) signatories; FSSC also runs its own integrity program over licensed certification bodiesRegister ↗
GMP/cGMPGovernment inspectors: FDA investigators in the US; national competent authority GMP inspectors in the EU (issuing GMP certificates recorded in EudraGMDP); WHO prequalification inspection teams; other national regulators, many coordinated through PIC/S. Third-party GMP audits by customers or contracted auditors supplement but do not replace regulatory inspection.
HACCPGovernment inspectors where HACCP is mandated (FDA investigators and state partners for seafood and juice; FSIS inspection personnel and enforcement investigators for meat and poultry; EU competent authorities). Third-party certification body auditors assess HACCP as part of GFSI scheme audits.
IATF 16949IATF-recognized certification bodies under contract with an IATF Global Oversight Office, using IATF-qualified auditorsIATF Global Oversight Offices (IAOB in the US, VDA QMC in Germany, ANFIA in Italy, SMMT in the UK, IATF France) recognize and witness certification bodies; there is no national accreditation body routeRegister ↗ABS Quality Evaluations, Inc., AFNOR Certification, Amtivo (USA) Inc.
ISO 13485Accredited certification bodies for ISO 13485 (many are also EU notified bodies and MDSAP auditing organizations); MDSAP-recognized auditing organizations for the single audit program; notified bodies for EU MDR/IVDR conformity assessmentNational accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement for ISO 13485 certification; the MDSAP regulatory authority council for MDSAP auditing organizations; EU member state designating authorities for notified bodiesRegister ↗BSI Group America Inc. (MDSAP AO), DEKRA Certification B.V. (MDSAP AO), DNV Product Assurance AS (MDSAP AO)
ISO 17025Accreditation bodies themselves (not certification bodies), using lead assessors plus technical assessors expert in the lab's disciplines. In the US the main general-purpose bodies are A2LA, ANAB, PJLA, and NIST's NVLAP for specific programs.Peer evaluation among accreditation bodies under the Global ACI mutual recognition arrangement (formerly the ILAC MRA); accreditation bodies are assessed against ISO/IEC 17011Register ↗A2LA (American Association for Laboratory Accreditation), ANAB (ANSI National Accreditation Board)
ISO 9001Accredited certification body (registrar) accredited to ISO/IEC 17021-1 for quality management systemsNational accreditation bodies that are signatories to the Global ACI (formerly IAF) multilateral arrangement, such as ANAB (US), UKAS (UK), DAkkS (Germany), JAS-ANZ, and many othersRegister ↗
NadcapPRI-employed or PRI-contracted Nadcap auditors assigned by PRI; there is no market of competing certification bodies. Audit findings are reviewed by PRI staff engineers and approved by the industry task group for that commodity.Performance Review Institute (PRI), Nadcap program
R2/RIOSSERI-approved certification bodies accredited to ISO/IEC 17021-1 for the R2 scheme, using SERI-trained R2 auditorsANAB (US), JAS-ANZ (Australia and New Zealand), and NABCB (India) accredit R2v3 certification bodies; SERI runs an assurance program over certification bodies and auditors on topRegister ↗
SQFSQFI-licensed certification bodies accredited to ISO/IEC 17065 for the SQF program, using SQFI-registered auditorsAccreditation bodies licensed by SQFI (such as ANAB and other recognized bodies), which assess certification bodies annually against ISO/IEC 17065 and the SQF program requirementsRegister ↗
3-DSA PCI SSC qualified 3DS Assessor company with qualified 3DS assessor employees, performing the assessment per the 3DS Assessor Program Guide and producing a Report on Compliance and Attestation of Compliance.PCI Security Standards Council qualification (not a national accreditation body).Register ↗
CCPA/CPRANo certification. Enforcement is by the CPPA and the Attorney General through investigations and administrative or civil actions. The cybersecurity audit must be performed by a qualified, objective, independent professional (internal or external) using accepted auditing standards, and the business certifies completion to the CPPA; the audit is not a government-issued approval.
CMMC/NIST 800-171Level 1 and Level 2 (self): the organization's own assessment with senior official affirmation. Level 2 (certification): a C3PAO authorized by the Cyber AB, using certified CMMC assessors. Level 3: the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).The Cyber AB (Cybersecurity Maturity Model Certification Accreditation Body), under contract with the Department, authorizes C3PAOs and accredits assessors; DCMA DIBCAC assesses the C3PAOs themselves.Register ↗
FTC Safeguards/GLBAGovernment enforcement only. The FTC investigates and brings enforcement actions; there is no certification or third-party audit requirement. Institutions may commission independent assessments voluntarily or under a consent order.
GDPRNo mandatory assessor. Supervisory authorities (for example CNIL, the Irish DPC, the German state authorities) investigate and enforce. Voluntary Article 42 certification is issued by certification bodies accredited under Article 43 against EDPB-approved criteria, or by the supervisory authority itself.National accreditation bodies under ISO/IEC 17065 (with supervisory authority requirements) or the supervisory authority itself, per Article 43; the EDPB approves criteria for European Data Protection Seals.Register ↗
HIPAAGovernment enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary.
HITRUSTA HITRUST Authorized External Assessor organization (approved and trained by HITRUST) performs validated assessments; HITRUST itself performs quality assurance and issues the certification. Self-assessments are available for readiness only.HITRUST authorizes and periodically requalifies External Assessor organizations; no national accreditation body is involved.Register ↗Schellman, A-LIGN, Coalfire
ISO 27001An accredited certification body (registrar) operating under ISO/IEC 17021-1 and ISO/IEC 27006, with an accreditation scope that includes ISO/IEC 27001.National accreditation bodies that are IAF MLA signatories, such as ANAB (US), UKAS (UK), DAkkS (Germany) and their peers. Unaccredited certificates exist and are not recognized in the same way.Register ↗
ISO 27017An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27017 in the audit scope and issues a certificate or statement referencing 27017 alongside the 27001 certificate.National accreditation bodies (ANAB, UKAS and peers) accredit the certification body for ISO/IEC 27001; 27017 coverage is added under that accreditation, and practice varies by body.Register ↗
ISO 27018An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27018 in the audit scope and issues a certificate or statement referencing it.National accreditation bodies (ANAB, UKAS and peers) under the certification body's ISO/IEC 27001 accreditation; practice for listing 27018 on certificates varies by body.Register ↗
NIST CSFNone. There is no NIST or government assessor. Organizations self-assess or hire consultants for an independent CSF assessment; some CPA firms offer a SOC for Cybersecurity examination using the CSF as control criteria.
NY DFS 23 NYCRR 500Government enforcement only. DFS examines covered entities and can impose penalties; there is no certification. Class A companies must obtain independent audits of their cybersecurity program (internal or external auditors free from influence over the program), but DFS does not certify those auditors.
PCI DSSA PCI SSC qualified Qualified Security Assessor (QSA) company with certified QSA employees performs the ROC. Certified Internal Security Assessors (ISAs) can support internal assessments where the acquirer permits. Approved Scanning Vendors (ASVs) perform quarterly external vulnerability scans. Small merchants self-assess on an SAQ.PCI Security Standards Council qualifies QSA, ISA and ASV companies and individuals; there is no national accreditation body.Register ↗
PCI P2PEA PCI SSC qualified P2PE Assessor company (a QSA company additionally qualified for P2PE) with qualified P2PE assessor employees, producing the P2PE Report on Validation.PCI Security Standards Council qualification.Register ↗
PCI PA-P2PEA PCI SSC qualified P2PE Application Assessor company, which is a P2PE Assessor company additionally qualified to validate applications on behalf of vendors.PCI Security Standards Council qualification.Register ↗
PCI SSFA PCI SSC qualified SSF Assessor company with employees qualified as Secure Software Assessors and/or Secure SLC Assessors, producing the Report on Validation and Attestation of Validation.PCI Security Standards Council qualification.Register ↗
QPAA PCI SSC qualified QPA company with qualified QPA employees, performing the on-site assessment per the QPA Program Guide.PCI Security Standards Council qualification.Register ↗
SOC 2A licensed CPA firm (independent certified public accountants) performing the examination under the AICPA attestation standards and issuing the service auditor's report.State board CPA licensure and the AICPA peer review program; no scheme-level accreditor and no public registry of SOC auditors.
TISAXAn ENX-approved TISAX audit provider (approval decided by the TISAX Committee) using auditors qualified for the ISA. Only approved providers can perform AL2 and AL3 assessments that produce labels.ENX Association approves audit providers and monitors their quality; there is no national accreditation body in the chain, although many providers are also accredited certification bodies for ISO 27001.Register ↗BSI Group Deutschland GmbH, Bureau Veritas Services, DEKRA Certification GmbH
42 CFR Part 2HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification.
ACHC/CHAPACHC and CHAP surveyors employed or contracted by each accreditor, typically clinicians with home care or hospice experience. Surveys for Medicare deemed programs are unannounced.CMS grants and periodically renews deeming authority to each accrediting organization after reviewing its standards and survey process; state survey agencies run validation surveys on a sample of accredited providers.Register ↗Accreditation Commission for Health Care (ACHC), Community Health Accreditation Partner (CHAP), The Joint Commission
ARC-AMPEIndependent third-party security and privacy assessors engaged by the entity (security control assessment for Administering Entities; third-party auditors under the EDE program for Direct Enrollment Entities). CMS reviews the assessment package and grants the authority to connect or approval to operate. There is no certification body.
CARFCARF surveyors, who are peer professionals employed in accredited or comparable organizations, trained and assigned by CARF. Surveys are scheduled and on site for two to three days.
CLIAState survey agencies acting for CMS (and CMS regional offices) survey Certificate of Compliance labs. CMS-approved accreditation organizations survey Certificate of Accreditation labs: AABB, A2LA, ACHC, ASHI, COLA, College of American Pathologists, and The Joint Commission. Exempt states (Washington and New York) run their own equivalent programs.CMS approves accreditation organizations and exempt state programs under 42 CFR Part 493 Subpart E and reviews them periodically; state agencies perform validation surveys on about five percent of accredited labs each year.Register ↗College of American Pathologists (CAP), COLA, The Joint Commission
CMS ARSSecurity control assessors approved or contracted by CMS perform assessments; the CMS authorizing official grants the authorization to operate. Third-party assessments and continuous monitoring evaluate controls at the frequencies ARS specifies.CMS CISO and authorizing officials. No external accreditation body.
CMS Business AssessmentIndependent third-party auditors engaged by the entity and meeting the independence rules in 45 CFR 155.221 and the CMS auditor guidelines; the auditor for the business audit must have no access or privileges on the system being audited. CMS reviews the submission and approves or denies.
CMS CoPsState survey agencies (state health departments under agreement with CMS) and CMS regional offices conduct certification, complaint, and validation surveys. CMS-approved accrediting organizations survey providers that choose deemed status: The Joint Commission, DNV Healthcare, the Center for Improvement in Healthcare Quality, ACHC, AAAHC, CHAP, and others depending on provider type.CMS approves accrediting organizations for deeming authority for a fixed term after reviewing standards and survey processes, and oversees them through validation surveys and performance reviews.Register ↗The Joint Commission, DNV Healthcare, Center for Improvement in Healthcare Quality (CIHQ)
CMS EDEIndependent, objective third-party auditors selected by the entity that meet the qualification and independence requirements in the CMS guidelines and 45 CFR 155.221 (experience with NIST standards and HIPAA for the privacy and security audit; no system access for the business audit). CMS reviews and approves the audit results.
CMS ProgramsVaries: CMS security control assessors and authorizing officials for ARS; independent third-party assessors and auditors chosen by the entity for ARC-AMPE and EDE, with CMS review; state survey agencies and CMS-approved accrediting organizations for the CoPs.
DEA EPCSFor applications, either a third-party audit by a person qualified to perform SysTrust, WebTrust, or SAS 70 style engagements (now SOC) or by a Certified Information Systems Auditor who performs compliance audits as a regular business, or certification by an organization DEA has approved. Practitioners and pharmacies are not separately certified but are subject to DEA inspection and enforcement.DEA approves certifying organizations for the certification route (verify the current list with DEA; no public registry is maintained on the DEA site). Auditors under the audit route are qualified by their professional credentials rather than DEA approval.
Health Information Act (HIA)The Office of the Information and Privacy Commissioner of Alberta reviews PIAs, investigates complaints and breach reports, conducts audits and inquiries, and issues orders. There is no certification and no third-party assessor role in the Act.
Joint CommissionJoint Commission surveyors, employed or contracted clinicians, administrators, engineers, and life safety specialists, assigned in teams sized to the organization.CMS approves The Joint Commission's deeming programs and reviews them periodically; state agencies perform validation surveys on a sample of accredited organizations.Register ↗
MARS-EIndependent third-party security control assessors engaged by the entity, with CMS reviewing the package and issuing the authority to connect. No certification body.
NCQANCQA surveyors (physician and administrative reviewers) conduct the review; NCQA's Review Oversight Committee determines the accreditation status. HEDIS data must be audited by an NCQA-licensed HEDIS compliance auditor.
NYS 405.46 Hospital CyberNew York State Department of Health surveyors, who can review cybersecurity compliance during Article 28 surveillance and complaint investigations, and the Department's enforcement staff. There is no certification.
OIG 7-element programNo certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews.
TEFCAThe RCE reviews applications, oversees conformance testing, and monitors QHINs. Security certification is assessed by HITRUST authorized external assessor firms under the HITRUST r2 program. There is no other third-party certifier for TEFCA itself.The RCE, under ONC/ASTP oversight, designates QHINs. HITRUST authorizes its external assessor firms.
AICPA SQMS No.1Peer reviewers under the AICPA Peer Review Program (a qualified CPA firm and team captain approved by the program), administered by state CPA societies or the National Peer Review Committee. State boards of accountancy generally require enrollment in peer review as a condition of licensure.AICPA Peer Review Board sets reviewer qualifications and program standards; state boards of accountancy recognize the program for licensure.Register ↗
BSA/AMLExaminers from the institution's functional regulator: OCC, FDIC, Federal Reserve, and NCUA for depository institutions; SEC and FINRA for broker-dealers; IRS Small Business/Self-Employed for MSBs and other non-bank institutions; state regulators alongside them. FinCEN retains enforcement authority. There is no certification.
DORANational competent authorities for each entity type (for example BaFin, the CSSF, the Central Bank of Ireland, the AMF and ACPR) supervise and enforce. The ESAs act as lead overseers for critical ICT third-party providers. There is no certification scheme; supervision is by regulator review and inspection.
FFIECFederal and state bank and credit union examiners (OCC, FDIC, Federal Reserve, NCUA, state banking departments) using the handbook's examination procedures. Independent internal or external audits are expected but are not a certification.
FINRA 3110 WSPsFINRA Member Supervision examiners conduct cycle and cause examinations; SEC Division of Examinations examiners also review supervision. There is no certification.
IRS WISP/Pub 4557No routine inspection or certification. The FTC enforces the Safeguards Rule; the IRS can revoke a PTIN or EFIN for false renewal statements and runs e-file provider monitoring visits. State boards of accountancy and licensing bodies may act on data security failures.
SEC 206(4)-7SEC Division of Examinations staff conduct examinations; state securities regulators examine state-registered advisers. There is no certification or third-party audit requirement.
SOX ICFRManagement performs the 404(a) assessment. The 404(b) attestation must be issued by a public accounting firm registered with the PCAOB, applying AS 2201 as part of the integrated audit.Public Company Accounting Oversight Board (registration and inspection of audit firms), under SEC oversight.Register ↗Deloitte & Touche LLP, Ernst & Young LLP, KPMG LLP
SWIFT CSPAn independent assessment by either an internal second or third line of defense function (risk, compliance, internal audit) that is independent of the first line, or an external assessment provider. Swift maintains a directory of CSP assessment providers that employ certified assessors.Swift sets eligibility for the assessment provider directory; listed companies employ at least two assessors who passed the Swift CSP assessor certification exam. There is no separate accreditation body.Register ↗
CJISGovernment audit only. The FBI CJIS Audit Unit audits each state CJIS Systems Agency (CSA), and the CSA audits the local agencies and contractors that connect through it. There is no third-party certification body for CJIS.
CSA STARLevel 1: none (self-assessment). Level 2 STAR Certification: an accredited ISO/IEC 27001 certification body that is also a CSA-approved STAR auditor. Level 2 STAR Attestation: a licensed CPA firm performing a SOC 2 examination that is a CSA-approved STAR auditor.CSA approves STAR auditors; the underlying ISO certification body is accredited by a national accreditation body (ANAB, UKAS and peers) and the CPA firm is licensed and peer reviewed under AICPA rules.Register ↗A-LIGN, BARR Certifications, Schellman & Company
FedRAMPA Third Party Assessment Organization (3PAO) accredited by A2LA to ISO/IEC 17020 plus the FedRAMP-specific R311 requirements and recognized by FedRAMP. The 3PAO performs readiness assessments, the security assessment plan and report, and annual assessments.A2LA (American Association for Laboratory Accreditation), with FedRAMP recognition of the accredited 3PAO.Register ↗A-LIGN, Coalfire, Fortreum
ISO 20000-1An accredited certification body (registrar) operating under ISO/IEC 17021-1 with a scope covering ISO/IEC 20000-1, using ISO/IEC 20000-6 for its own competence requirements.National accreditation bodies that are IAF MLA signatories, such as ANAB (US), UKAS (UK) and their peers.Register ↗
StateRAMPA Third Party Assessment Organization (3PAO) accredited by A2LA and recognized by FedRAMP; the provider engages and pays the assessor. Core status is validated by the GovRAMP PMO without a 3PAO.A2LA, with FedRAMP recognition of the 3PAO.Register ↗A-LIGN, Coalfire, Fortreum
TX-RAMPGovernment reviewer: DIR staff assess the provider's questionnaire responses and evidence. No third-party assessor is required, though FedRAMP or GovRAMP 3PAO packages can be submitted for reciprocity.
ISAE 3402A professional accountant in public practice (a licensed audit or chartered accountancy firm) acting as the service auditor. In most countries this means a firm that is licensed to sign assurance reports under the local professional body and that follows the IAASB quality management standards.
SOC 1A licensed CPA firm (a firm of independent certified public accountants) that performs the examination and issues the service auditor's report.AICPA membership and state board CPA licensure; firms performing attestation engagements are subject to the AICPA peer review program. No separate scheme accreditor.
SOC 3A licensed CPA firm performing the SOC 2 examination; the SOC 3 is issued by the same service auditor.State board CPA licensure and the AICPA peer review program. No scheme-level accreditor.
SOC for CybersecurityA licensed CPA firm performing the examination under the AICPA attestation standards.State board CPA licensure and the AICPA peer review program. No scheme-level accreditor.
DFARSLevel 1 and some Level 2 requirements are self-assessed and affirmed. Level 2 certification assessments are performed by CMMC Third-Party Assessment Organizations (C3PAOs). Level 3 assessments are performed by the Defense Contract Management Agency's DIBCAC. DoD may also conduct medium and high assessments under 7020.The Cyber AB (CMMC Accreditation Body) accredits C3PAOs; individual assessors are certified through the CMMC Assessors and Instructors Certification Organization.Register ↗
DoD compliance requirementsVaries by component: self-assessment and affirmation (FAR 52.204-21, CMMC Level 1), C3PAOs (CMMC Level 2), DCMA DIBCAC (CMMC Level 3 and DFARS 7020 assessments), DISA and DoD authorizing officials (Cloud SRG provisional authorizations, RMF), DCSA industrial security representatives (NISPOM), and DDTC or BIS for export controls.The Cyber AB for C3PAOs; FedRAMP-recognized accreditation for 3PAOs used in cloud authorizations; government agencies otherwise assess directly.Register ↗
Microsoft SSPA DPRIndependent assessors chosen by the supplier from firms meeting Microsoft's qualification guidance, which points to recognized professional bodies such as the AICPA and IFAC members; in practice CPA firms and established security assessment firms. Microsoft does not operate a closed assessor list but does publish the assessment report template the assessor must use.
NIST IR 8286DNone.
NIST SP 800-161None for the publication itself; SR controls derived from it are assessed within FedRAMP (3PAOs), FISMA (agency assessors), and CMMC (C3PAOs) engagements.
NIST SP 800-218None. Self-attestation by the software producer's senior executive; agencies may accept a third-party assessment from a FedRAMP-recognized 3PAO in place of the form.
NIST SP 800-30None for the document itself. Risk assessments produced with it are reviewed by whichever assessor governs the parent program (3PAOs, C3PAOs, agency assessors, ISO certification bodies).
NIST SP 800-34None for the document itself; contingency plans built on it are reviewed by the assessor of the parent program (3PAOs, agency assessors, C3PAOs).
NIST SP 800-37Independent control assessors: agency or contracted assessment teams for FISMA systems, FedRAMP-recognized 3PAOs for cloud services, and DoD assessment teams (security control assessors) for defense systems. The authorization decision itself is made by a government authorizing official.For FedRAMP, 3PAOs are accredited by A2LA (and other bodies recognized by the FedRAMP PMO) to ISO/IEC 17020 with FedRAMP requirements. Agency assessors are designated by the agency.Register ↗
NIST SP 800-39None.
NIST SP 800-53None for the catalog itself. Within adopting programs: FedRAMP-recognized 3PAOs for cloud services, agency security control assessors for FISMA systems, DoD assessors for defense systems, and C3PAOs for the CMMC subset.Program-specific: A2LA and other FedRAMP-recognized bodies for 3PAOs; the Cyber AB for C3PAOs; agencies designate their own assessors.Register ↗
NIST SP 800-61None for the document itself; incident response capabilities built on it are examined within parent programs (FedRAMP 3PAOs, C3PAOs, agency assessors, ISO certification bodies).
DOT/FMCSAFMCSA safety investigators and state enforcement partners under the Motor Carrier Safety Assistance Program (government audit and investigation). Roadside inspections by certified officers feed the CSA scores.
EPA RCRAState environmental agency inspectors in authorized states, and EPA regional inspectors (government inspection and enforcement). No certification exists.
ISNetworld/AvettaPlatform reviewers (ISN's RAVS team, Avetta's review specialists) grading documents against client and regulatory checklists; hiring clients may additionally audit contractors in the field. No independent certification or accreditation exists.
OSHA written programsOSHA compliance safety and health officers, or State Plan inspectors (government inspection). No certification exists; voluntary recognition programs such as VPP and SHARP involve OSHA or consultation program evaluation.
State harassment-prevention mandatesState civil rights or labor agencies on complaint or investigation (government enforcement); no certification. Training and policy records are most often tested in litigation and agency charge responses.
ISO 14001Accredited certification body (registrar) accredited to ISO/IEC 17021-1 for environmental management systemsNational accreditation bodies that are signatories to the Global ACI (formerly IAF) multilateral arrangement, such as ANAB (US), UKAS (UK), DAkkS (Germany), JAS-ANZRegister ↗
ISO 22301Accredited certification body accredited to ISO/IEC 17021-1 for business continuity management systemsNational accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZRegister ↗
ISO 42001Accredited certification body accredited to ISO/IEC 17021-1 with ISO/IEC 42006 requirements for AI management system certificationNational accreditation bodies; ANAB launched its ISO/IEC 42001 accreditation program in January 2024 and several US and international certification bodies now hold ANAB accreditation for it. Other accreditation bodies have followed or are in progress (verify for the specific certification body you choose).Register ↗
ISO 45001Accredited certification body accredited to ISO/IEC 17021-1 for OH&S management systems (ISO/IEC TS 17021-10)National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZRegister ↗
ISO 50001Accredited certification body accredited to ISO/IEC 17021-1 with ISO 50003 requirements for energy management system auditingNational accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkSRegister ↗
CPSANone identifiable. For the CREST exam, CREST itself administers the test to individuals.
EU AI ActDepends on the system. Most Annex III high-risk providers self-assess through the internal control procedure in Annex VI. Third-party assessment by a notified body is required for certain biometric systems where harmonized standards are not fully applied, and for Annex I products it runs through the notified body already used under the sectoral product law. General-purpose model providers are supervised directly by the AI Office.National notifying authorities designate notified bodies, normally on the basis of accreditation by the national accreditation body under Regulation (EC) 765/2008. Designations are published in the Commission's NANDO database.Register ↗
EU CRAManufacturer self-assessment (internal control, Module A) for the default category. Notified bodies for important products where harmonized standards are not fully applied and for products where the manufacturer chooses third-party assessment. Conformity assessment bodies under the EU Cybersecurity Act certification schemes (for example EUCC) where a European certificate is used. Notified body provisions applied from June 11, 2026.National notifying authorities designate CRA notified bodies, with accreditation by the national accreditation body (for example DAkkS, COFRAC, UKAS is not applicable) as the normal basis. Listings appear in NANDO once designations begin.Register ↗
NIST AI RMFNone. There is no NIST certification or accredited assessor for the AI RMF; organizations self-attest or fold the framework into another audited scheme such as ISO/IEC 42001.
NIST Privacy FrameworkNone. No certification exists. Organizations self-assess or have privacy controls examined as part of another engagement such as a SOC 2 privacy criteria report or ISO/IEC 27701 audit.
OWASP LLM Top 10None. No certification. Penetration testers and red teams use it as a scope, but any firm may do so and no body qualifies them for this list specifically.
OWASP SAMMNone mandated. Self-assessment or any consultant; the project does not qualify or license assessors.
SLCSoftware Security Framework (SSF) Assessor companies qualified by PCI SSC to perform Secure SLC assessments. Individual assessors must be employed by a qualified company and complete PCI SSC training.PCI Security Standards Council qualifies and lists SSF Assessor companies.Register ↗
US State Privacy LawsNone. Compliance is enforced by state attorneys general and the California Privacy Protection Agency through investigations and civil actions; there is no certification or licensed assessor. California's regulations on cybersecurity audits and risk assessments, when in force, will require certain businesses to obtain an independent audit and file certifications with the agency (verify the current CPPA regulation status and effective dates).
C-TPATCBP Supply Chain Security Specialists (government officers) perform validations and revalidations. There are no private third-party certifiers for CTPAT; consultants can prepare a member but cannot validate it.
FCPANone required by law. Companies self-assess, use internal audit, or commission independent program reviews by law firms or forensic accountants. After an enforcement resolution DOJ may impose an independent compliance monitor chosen from candidates the company proposes.
Franchise brand standardsThe franchisor's own field consultants, quality assurance staff, or contracted mystery shoppers and third-party inspection firms audit franchisees against the standards. No government body inspects brand standards; the FTC and state regulators police disclosure and unfair practices, not operating standards.
ISO 27701Accredited certification bodies operating under ISO/IEC 17021-1 with the sector-specific requirements of ISO/IEC 27006-2 (PIMS audits).National accreditation bodies that are signatories to the IAF (now Global ACI) multilateral arrangement, for example ANAB, UKAS, DAkkS, JAS-ANZ. Not every accreditation body has yet extended scopes to the 2025 edition; check the certificate's accreditation mark.Register ↗
ITARDDTC's Office of Defense Trade Controls Compliance conducts company visits, reviews disclosures, and enforces; the Department of Justice prosecutes criminal violations. No private certifier exists; "ITAR certified" claims by vendors are marketing shorthand for being registered and having a program.
ABDOGovernment inspection by the Bureau Industrieveiligheid (MIVD). There are no private certifiers; consultants prepare, the Bureau authorizes.
ACNACN itself reviews applications and lists qualified services. Supporting ISO/IEC 27001 and related certificates come from accredited certification bodies, and ACN may require independent audit reports for higher levels. No separate class of ACN-licensed assessors exists.ACCREDIA (Italian national accreditation body) for the ISO/IEC certification bodies whose certificates support the application; ACN for the qualification decision itself.Register ↗
BIOInternal audit and the organization's own accountability line; registered IT auditors (RE, under NOREA) for the ENSIA audits at municipalities and for assurance reports requested by supervisory bodies. No certification body issues a BIO certificate.
BSI C5Independent auditors qualified to issue ISAE 3000 or IDW PS 860 assurance reports, which in Germany means Wirtschaftsprüfer (public auditors) and their firms; auditors from other jurisdictions may report under ISAE 3000 where they meet the catalog's independence and competence requirements. BSI itself does not audit or certify.
CCCSelf-assessment by the in-scope organization, reported to the NCA, with the NCA (and for critical infrastructure the relevant sector regulator) able to audit and verify. There is no private certification scheme for the CCC; consultants assist but do not certify on the NCA's behalf.
CCCS ITSG-33Departmental security assessors (internal or contracted) for departmental systems, with authorization by the departmental authority; CCCS assessors for cloud service providers under the CSP IT Security Assessment Program. No private certification exists.
CERT-INCERT-In itself supervises and can request information; CERT-In empanelled information security auditing organizations conduct audits where a regulator or government body requires one (for example for government websites and applications and certain regulated sectors). The empanelment is a public list maintained by CERT-In.CERT-In empanels auditing organizations directly through periodic empanelment rounds.Register ↗
Crown Commercial Service (UK)Cyber Essentials certification bodies licensed by IASME for the certification element; contracting authorities and CCS assess questionnaire responses themselves; NCSC-recognized bodies or UKAS-accredited certification bodies where ISO/IEC 27001 is required.IASME (as NCSC's delivery partner) for Cyber Essentials certification bodies; UKAS for ISO/IEC 27001 certification bodies.Register ↗
CyFunConformity Assessment Bodies accredited by BELAC under the CyFun conformity assessment scheme and authorized by the CCB. Verification at Basic level and certification at Important and Essential levels.BELAC, the Belgian national accreditation body, with CCB authorization of each body.Register ↗
Cyber Essentials PlusCertification bodies licensed by IASME, employing qualified Cyber Essentials assessors. Cyber Essentials Plus assessments must be performed by a licensed certification body's assessor; the basic level is marked by a certification body against the applicant's self-assessment.IASME licenses and audits certification bodies on behalf of NCSC; NCSC sets scheme policy and the technical requirements.Register ↗
CyberTrustFor Standard and Silver, the scheme operator validates the self-declaration for completeness and plausibility. For Gold, a qualified auditor accredited under Section 18 of the Austrian NIS Act (NISG) performs an audit. Platinum follows the scheme's stated audit requirements.For Gold audits, auditor qualification rests on accreditation as a qualified body under the Austrian NIS Act (overseen by the Austrian NIS authority); the scheme operator issues the label.Register ↗
DESCFor CSP certification, certification bodies approved by DESC that operate under the ISO/IEC 27001 certification scheme; DESC itself reviews ISR compliance reporting and can audit government entities. Verify the current list of DESC-approved certification bodies on the DESC certifications page.DESC approves certification bodies for its schemes; those bodies typically also hold accreditation from a national accreditation body for ISO/IEC 27001 (for example the Emirates International Accreditation Centre or UKAS).Register ↗
DTLSGS auditors under the Digital Trust Label certification scheme. Before the handover, SGS acted as the independent audit partner for the foundation.
ECCSelf-assessment and reporting by the organization, reviewed by the NCA, which may audit and verify directly; sector regulators may conduct their own reviews. No private certification scheme exists for the ECC.
ENSFor Media and Alta categories, certification bodies accredited by ENAC under the ENS certification scheme perform the audit and issue the Certificación de Conformidad. For Básica, the organization issues a Declaración de Conformidad after a self-assessment (an external audit is optional).ENAC (Entidad Nacional de Acreditación), Spain's national accreditation body; the CCN publishes the list of accredited certification bodies.Register ↗AENOR CONFIA, Audertis Audit Services, BDO Auditores
Essential 8Self-assessment by the entity following ASD's assessment guide; independent assessment by IRAP assessors (for Commonwealth reporting) or by specialist assessment firms. ASD does not certify Essential Eight compliance.ASD endorses IRAP assessors; no accreditor exists for other Essential Eight assessors.Register ↗
HDSCertification bodies accredited by COFRAC under the HDS accreditation standard (based on ISO/IEC 17021-1 and 27006). Nine bodies were reported as accredited as of the most recent ANS communication (verify the current list on the ANS site).COFRAC (Comité français d'accréditation).Register ↗
IRAPIRAP assessors, individuals endorsed by ASD after meeting experience, qualification, and training requirements and passing the IRAP course; they work independently or within consultancies. Assessors do not accredit or certify; authorization is made by the consuming agency.ASD endorses and lists IRAP assessors and sets the assessment methodology.Register ↗
ISMAPAudit firms registered on the ISMAP assessor list maintained by IPA (in practice the large Japanese audit firms and affiliates of international networks). Registration decisions are made by the ISMAP Steering Committee.IPA (as ISMAP operator) registers assessors; assessors are typically CPA-regulated audit firms operating under Japanese assurance standards.Register ↗
IT-GrundschutzAuditors certified by the BSI for ISO 27001 audits on the basis of IT-Grundschutz; the audit report is reviewed by the BSI, which issues the certificate. Plain ISO/IEC 27001 certification against IT-Grundschutz-aligned controls can also be obtained from accredited certification bodies, but only the BSI issues the IT-Grundschutz certificate.BSI (as certification body and auditor licensor) for the IT-Grundschutz certificate; DAkkS-accredited certification bodies for conventional ISO/IEC 27001 certificates.Register ↗
MTCSCertification bodies accredited by the Singapore Accreditation Council for the MTCS certification scheme (for example BSI, SOCOTEC Certification Singapore, and TÜV SÜD are among bodies offering it; verify current accreditation on the SAC site).Singapore Accreditation Council (SAC), part of Enterprise Singapore.Register ↗
MeitYSTQC Directorate auditors (a MeitY body) perform the empanelment audit; supporting ISO certifications come from accredited certification bodies. No private firm can grant empanelment.Register ↗
NCSC CAFSector competent authorities (for example Ofgem, DfT, DHSC, Ofcom, the Drinking Water Inspectorate) review operator self-assessments and may inspect; independent assurance reviewers verify GovAssure self-assessments; no certificate is issued.
NCSC Cyber Security v3.1As for NCSC CAF: sector competent authorities and GovAssure independent assurance reviewers; no certificate.
QNRCSCertification bodies approved by the NCSA under the National Information Security Compliance Framework perform NIA certification audits; the NCSA supervises and can audit directly. No independent private scheme exists outside the NCSA's approval.NCSA approves certification bodies for NIA certification.
SAMA CSFSelf-assessment by the member organization reviewed and audited by SAMA supervisors; SAMA may direct independent assessments by external firms. No private certification exists.
SecNumCloudEvaluation by ANSSI with audits performed by PASSI-qualified audit providers (Prestataires d'audit de la sécurité des systèmes d'information, qualified by ANSSI); the qualification decision is ANSSI's. No other body can issue SecNumCloud.ANSSI qualifies both the audit providers (PASSI) and the cloud providers; PASSI qualification itself relies on accreditation by COFRAC under ISO/IEC 17065.Register ↗
UK MoD compliance requirementsMOD reviews Supplier Assurance Questionnaires through the Supplier Cyber Protection Service and may audit; Cyber Essentials certification bodies licensed by IASME certify the baseline; Defence Cyber Certification is assessed by IASME-licensed certification bodies; MOD security staff (and DE&S Principal Security Advisers) assess facility and classified-handling compliance.IASME (on behalf of NCSC for Cyber Essentials and of the MOD for Defence Cyber Certification) licenses certification bodies; the MOD assesses directly for the remainder.Register ↗

All assessor listings →

Need a hand implementing it?

Find a Consultant Who Does This Work

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Keep Your Written Policies in One Place

Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.