Home›Assessors
Assessors
Who is allowed to audit what.
For each framework: the kind of firm or agency that can assess or certify it, who accredits those assessors, and the public register where one exists. Consultants who help you prepare are a different category and cannot certify the work they helped build.
Sponsored
Find
help
help
Consultants Assessors Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Audit the Modern WayFind an accredited assessor
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page.
Get help →Advertise here →
| Framework | Assessed by | Accredited by | Register | Listed firms |
|---|---|---|---|---|
| 21 CFR 111 | FDA investigators (government inspection). Voluntary third-party cGMP audits and certifications exist but do not replace FDA inspection. | |||
| 21 CFR 117/FSMA | FDA investigators, and state agencies inspecting under contract with FDA (government inspection). Third-party GFSI-benchmarked audits (SQF, BRCGS, FSSC 22000) cover the same ground but are voluntary and customer-driven. | |||
| 21 CFR 211 | FDA investigators (government inspection). Foreign regulators under mutual recognition agreements and PIC/S-aligned authorities may inspect the same site for their own markets. | |||
| API Q1 | API itself. Auditors approved by API conduct Monogram license audits and APIQR management system registration audits; there is no market of independent certification bodies for API Q1 as there is for ISO 9001. | API Quality Registrar (APIQR) is itself an ANAB-accredited certification body for management system registrations; the Monogram licensing program is API's own product-marking scheme | American Petroleum Institute (API Monogram and APIQR programs) | |
| AS9100 | Certification bodies accredited under the IAQG scheme (9104-1) by an IAQG-recognized accreditation body, using IAQG-authenticated aerospace auditors | IAQG-recognized accreditation bodies (for example ANAB in the US, UKAS in the UK, DAkkS in Germany, JAB in Japan) working under IAQG oversight | Register ↗ | |
| AS9120 | Certification bodies accredited under the IAQG scheme (9104-1) by an IAQG-recognized accreditation body, using IAQG-authenticated aerospace auditors | IAQG-recognized accreditation bodies (ANAB, UKAS, DAkkS, JAB, and others) under IAQG oversight | Register ↗ | |
| BRCGS | BRCGS-approved certification bodies accredited to ISO/IEC 17065 for the specific BRCGS standard, using BRCGS-registered auditors | National accreditation bodies recognized by BRCGS (for example UKAS, ANAB, and other Global ACI signatories), with BRCGS running its own compliance and auditor competence oversight on top | Register ↗ | |
| CMMI | ISACA Certified CMMI Lead Appraisers sponsored by a licensed CMMI Partner organization, using the CMMI Appraisal Method (Benchmark, Sustainment, Evaluation, or Action Plan Reappraisal) | ISACA (licenses Partners, certifies Lead Appraisers, and quality-reviews appraisal submissions) | Register ↗ | |
| FDA 21 CFR 820/QMSR | FDA investigators (government inspection). MDSAP-recognized auditing organizations conduct audits that FDA accepts in lieu of routine surveillance inspections for participating manufacturers. | Register ↗ | BSI Group America Inc., DEKRA Certification B.V., DNV Product Assurance AS | |
| FSSC 22000/ISO 22000 | FSSC-licensed certification bodies accredited to ISO/IEC 17021-1 with ISO/TS 22003-1 for the FSSC 22000 scheme; for ISO 22000 alone, any accredited certification body with food safety scope | National accreditation bodies recognized by Foundation FSSC (for example ANAB, UKAS, RvA, DAkkS), which are Global ACI (formerly IAF) signatories; FSSC also runs its own integrity program over licensed certification bodies | Register ↗ | |
| GMP/cGMP | Government inspectors: FDA investigators in the US; national competent authority GMP inspectors in the EU (issuing GMP certificates recorded in EudraGMDP); WHO prequalification inspection teams; other national regulators, many coordinated through PIC/S. Third-party GMP audits by customers or contracted auditors supplement but do not replace regulatory inspection. | |||
| HACCP | Government inspectors where HACCP is mandated (FDA investigators and state partners for seafood and juice; FSIS inspection personnel and enforcement investigators for meat and poultry; EU competent authorities). Third-party certification body auditors assess HACCP as part of GFSI scheme audits. | |||
| IATF 16949 | IATF-recognized certification bodies under contract with an IATF Global Oversight Office, using IATF-qualified auditors | IATF Global Oversight Offices (IAOB in the US, VDA QMC in Germany, ANFIA in Italy, SMMT in the UK, IATF France) recognize and witness certification bodies; there is no national accreditation body route | Register ↗ | ABS Quality Evaluations, Inc., AFNOR Certification, Amtivo (USA) Inc. |
| ISO 13485 | Accredited certification bodies for ISO 13485 (many are also EU notified bodies and MDSAP auditing organizations); MDSAP-recognized auditing organizations for the single audit program; notified bodies for EU MDR/IVDR conformity assessment | National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement for ISO 13485 certification; the MDSAP regulatory authority council for MDSAP auditing organizations; EU member state designating authorities for notified bodies | Register ↗ | BSI Group America Inc. (MDSAP AO), DEKRA Certification B.V. (MDSAP AO), DNV Product Assurance AS (MDSAP AO) |
| ISO 17025 | Accreditation bodies themselves (not certification bodies), using lead assessors plus technical assessors expert in the lab's disciplines. In the US the main general-purpose bodies are A2LA, ANAB, PJLA, and NIST's NVLAP for specific programs. | Peer evaluation among accreditation bodies under the Global ACI mutual recognition arrangement (formerly the ILAC MRA); accreditation bodies are assessed against ISO/IEC 17011 | Register ↗ | A2LA (American Association for Laboratory Accreditation), ANAB (ANSI National Accreditation Board) |
| ISO 9001 | Accredited certification body (registrar) accredited to ISO/IEC 17021-1 for quality management systems | National accreditation bodies that are signatories to the Global ACI (formerly IAF) multilateral arrangement, such as ANAB (US), UKAS (UK), DAkkS (Germany), JAS-ANZ, and many others | Register ↗ | |
| Nadcap | PRI-employed or PRI-contracted Nadcap auditors assigned by PRI; there is no market of competing certification bodies. Audit findings are reviewed by PRI staff engineers and approved by the industry task group for that commodity. | Performance Review Institute (PRI), Nadcap program | ||
| R2/RIOS | SERI-approved certification bodies accredited to ISO/IEC 17021-1 for the R2 scheme, using SERI-trained R2 auditors | ANAB (US), JAS-ANZ (Australia and New Zealand), and NABCB (India) accredit R2v3 certification bodies; SERI runs an assurance program over certification bodies and auditors on top | Register ↗ | |
| SQF | SQFI-licensed certification bodies accredited to ISO/IEC 17065 for the SQF program, using SQFI-registered auditors | Accreditation bodies licensed by SQFI (such as ANAB and other recognized bodies), which assess certification bodies annually against ISO/IEC 17065 and the SQF program requirements | Register ↗ | |
| 3-DS | A PCI SSC qualified 3DS Assessor company with qualified 3DS assessor employees, performing the assessment per the 3DS Assessor Program Guide and producing a Report on Compliance and Attestation of Compliance. | PCI Security Standards Council qualification (not a national accreditation body). | Register ↗ | |
| CCPA/CPRA | No certification. Enforcement is by the CPPA and the Attorney General through investigations and administrative or civil actions. The cybersecurity audit must be performed by a qualified, objective, independent professional (internal or external) using accepted auditing standards, and the business certifies completion to the CPPA; the audit is not a government-issued approval. | |||
| CMMC/NIST 800-171 | Level 1 and Level 2 (self): the organization's own assessment with senior official affirmation. Level 2 (certification): a C3PAO authorized by the Cyber AB, using certified CMMC assessors. Level 3: the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). | The Cyber AB (Cybersecurity Maturity Model Certification Accreditation Body), under contract with the Department, authorizes C3PAOs and accredits assessors; DCMA DIBCAC assesses the C3PAOs themselves. | Register ↗ | |
| FTC Safeguards/GLBA | Government enforcement only. The FTC investigates and brings enforcement actions; there is no certification or third-party audit requirement. Institutions may commission independent assessments voluntarily or under a consent order. | |||
| GDPR | No mandatory assessor. Supervisory authorities (for example CNIL, the Irish DPC, the German state authorities) investigate and enforce. Voluntary Article 42 certification is issued by certification bodies accredited under Article 43 against EDPB-approved criteria, or by the supervisory authority itself. | National accreditation bodies under ISO/IEC 17065 (with supervisory authority requirements) or the supervisory authority itself, per Article 43; the EDPB approves criteria for European Data Protection Seals. | Register ↗ | |
| HIPAA | Government enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary. | |||
| HITRUST | A HITRUST Authorized External Assessor organization (approved and trained by HITRUST) performs validated assessments; HITRUST itself performs quality assurance and issues the certification. Self-assessments are available for readiness only. | HITRUST authorizes and periodically requalifies External Assessor organizations; no national accreditation body is involved. | Register ↗ | Schellman, A-LIGN, Coalfire |
| ISO 27001 | An accredited certification body (registrar) operating under ISO/IEC 17021-1 and ISO/IEC 27006, with an accreditation scope that includes ISO/IEC 27001. | National accreditation bodies that are IAF MLA signatories, such as ANAB (US), UKAS (UK), DAkkS (Germany) and their peers. Unaccredited certificates exist and are not recognized in the same way. | Register ↗ | |
| ISO 27017 | An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27017 in the audit scope and issues a certificate or statement referencing 27017 alongside the 27001 certificate. | National accreditation bodies (ANAB, UKAS and peers) accredit the certification body for ISO/IEC 27001; 27017 coverage is added under that accreditation, and practice varies by body. | Register ↗ | |
| ISO 27018 | An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27018 in the audit scope and issues a certificate or statement referencing it. | National accreditation bodies (ANAB, UKAS and peers) under the certification body's ISO/IEC 27001 accreditation; practice for listing 27018 on certificates varies by body. | Register ↗ | |
| NIST CSF | None. There is no NIST or government assessor. Organizations self-assess or hire consultants for an independent CSF assessment; some CPA firms offer a SOC for Cybersecurity examination using the CSF as control criteria. | |||
| NY DFS 23 NYCRR 500 | Government enforcement only. DFS examines covered entities and can impose penalties; there is no certification. Class A companies must obtain independent audits of their cybersecurity program (internal or external auditors free from influence over the program), but DFS does not certify those auditors. | |||
| PCI DSS | A PCI SSC qualified Qualified Security Assessor (QSA) company with certified QSA employees performs the ROC. Certified Internal Security Assessors (ISAs) can support internal assessments where the acquirer permits. Approved Scanning Vendors (ASVs) perform quarterly external vulnerability scans. Small merchants self-assess on an SAQ. | PCI Security Standards Council qualifies QSA, ISA and ASV companies and individuals; there is no national accreditation body. | Register ↗ | |
| PCI P2PE | A PCI SSC qualified P2PE Assessor company (a QSA company additionally qualified for P2PE) with qualified P2PE assessor employees, producing the P2PE Report on Validation. | PCI Security Standards Council qualification. | Register ↗ | |
| PCI PA-P2PE | A PCI SSC qualified P2PE Application Assessor company, which is a P2PE Assessor company additionally qualified to validate applications on behalf of vendors. | PCI Security Standards Council qualification. | Register ↗ | |
| PCI SSF | A PCI SSC qualified SSF Assessor company with employees qualified as Secure Software Assessors and/or Secure SLC Assessors, producing the Report on Validation and Attestation of Validation. | PCI Security Standards Council qualification. | Register ↗ | |
| QPA | A PCI SSC qualified QPA company with qualified QPA employees, performing the on-site assessment per the QPA Program Guide. | PCI Security Standards Council qualification. | Register ↗ | |
| SOC 2 | A licensed CPA firm (independent certified public accountants) performing the examination under the AICPA attestation standards and issuing the service auditor's report. | State board CPA licensure and the AICPA peer review program; no scheme-level accreditor and no public registry of SOC auditors. | ||
| TISAX | An ENX-approved TISAX audit provider (approval decided by the TISAX Committee) using auditors qualified for the ISA. Only approved providers can perform AL2 and AL3 assessments that produce labels. | ENX Association approves audit providers and monitors their quality; there is no national accreditation body in the chain, although many providers are also accredited certification bodies for ISO 27001. | Register ↗ | BSI Group Deutschland GmbH, Bureau Veritas Services, DEKRA Certification GmbH |
| 42 CFR Part 2 | HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification. | |||
| ACHC/CHAP | ACHC and CHAP surveyors employed or contracted by each accreditor, typically clinicians with home care or hospice experience. Surveys for Medicare deemed programs are unannounced. | CMS grants and periodically renews deeming authority to each accrediting organization after reviewing its standards and survey process; state survey agencies run validation surveys on a sample of accredited providers. | Register ↗ | Accreditation Commission for Health Care (ACHC), Community Health Accreditation Partner (CHAP), The Joint Commission |
| ARC-AMPE | Independent third-party security and privacy assessors engaged by the entity (security control assessment for Administering Entities; third-party auditors under the EDE program for Direct Enrollment Entities). CMS reviews the assessment package and grants the authority to connect or approval to operate. There is no certification body. | |||
| CARF | CARF surveyors, who are peer professionals employed in accredited or comparable organizations, trained and assigned by CARF. Surveys are scheduled and on site for two to three days. | |||
| CLIA | State survey agencies acting for CMS (and CMS regional offices) survey Certificate of Compliance labs. CMS-approved accreditation organizations survey Certificate of Accreditation labs: AABB, A2LA, ACHC, ASHI, COLA, College of American Pathologists, and The Joint Commission. Exempt states (Washington and New York) run their own equivalent programs. | CMS approves accreditation organizations and exempt state programs under 42 CFR Part 493 Subpart E and reviews them periodically; state agencies perform validation surveys on about five percent of accredited labs each year. | Register ↗ | College of American Pathologists (CAP), COLA, The Joint Commission |
| CMS ARS | Security control assessors approved or contracted by CMS perform assessments; the CMS authorizing official grants the authorization to operate. Third-party assessments and continuous monitoring evaluate controls at the frequencies ARS specifies. | CMS CISO and authorizing officials. No external accreditation body. | ||
| CMS Business Assessment | Independent third-party auditors engaged by the entity and meeting the independence rules in 45 CFR 155.221 and the CMS auditor guidelines; the auditor for the business audit must have no access or privileges on the system being audited. CMS reviews the submission and approves or denies. | |||
| CMS CoPs | State survey agencies (state health departments under agreement with CMS) and CMS regional offices conduct certification, complaint, and validation surveys. CMS-approved accrediting organizations survey providers that choose deemed status: The Joint Commission, DNV Healthcare, the Center for Improvement in Healthcare Quality, ACHC, AAAHC, CHAP, and others depending on provider type. | CMS approves accrediting organizations for deeming authority for a fixed term after reviewing standards and survey processes, and oversees them through validation surveys and performance reviews. | Register ↗ | The Joint Commission, DNV Healthcare, Center for Improvement in Healthcare Quality (CIHQ) |
| CMS EDE | Independent, objective third-party auditors selected by the entity that meet the qualification and independence requirements in the CMS guidelines and 45 CFR 155.221 (experience with NIST standards and HIPAA for the privacy and security audit; no system access for the business audit). CMS reviews and approves the audit results. | |||
| CMS Programs | Varies: CMS security control assessors and authorizing officials for ARS; independent third-party assessors and auditors chosen by the entity for ARC-AMPE and EDE, with CMS review; state survey agencies and CMS-approved accrediting organizations for the CoPs. | |||
| DEA EPCS | For applications, either a third-party audit by a person qualified to perform SysTrust, WebTrust, or SAS 70 style engagements (now SOC) or by a Certified Information Systems Auditor who performs compliance audits as a regular business, or certification by an organization DEA has approved. Practitioners and pharmacies are not separately certified but are subject to DEA inspection and enforcement. | DEA approves certifying organizations for the certification route (verify the current list with DEA; no public registry is maintained on the DEA site). Auditors under the audit route are qualified by their professional credentials rather than DEA approval. | ||
| Health Information Act (HIA) | The Office of the Information and Privacy Commissioner of Alberta reviews PIAs, investigates complaints and breach reports, conducts audits and inquiries, and issues orders. There is no certification and no third-party assessor role in the Act. | |||
| Joint Commission | Joint Commission surveyors, employed or contracted clinicians, administrators, engineers, and life safety specialists, assigned in teams sized to the organization. | CMS approves The Joint Commission's deeming programs and reviews them periodically; state agencies perform validation surveys on a sample of accredited organizations. | Register ↗ | |
| MARS-E | Independent third-party security control assessors engaged by the entity, with CMS reviewing the package and issuing the authority to connect. No certification body. | |||
| NCQA | NCQA surveyors (physician and administrative reviewers) conduct the review; NCQA's Review Oversight Committee determines the accreditation status. HEDIS data must be audited by an NCQA-licensed HEDIS compliance auditor. | |||
| NYS 405.46 Hospital Cyber | New York State Department of Health surveyors, who can review cybersecurity compliance during Article 28 surveillance and complaint investigations, and the Department's enforcement staff. There is no certification. | |||
| OIG 7-element program | No certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews. | |||
| TEFCA | The RCE reviews applications, oversees conformance testing, and monitors QHINs. Security certification is assessed by HITRUST authorized external assessor firms under the HITRUST r2 program. There is no other third-party certifier for TEFCA itself. | The RCE, under ONC/ASTP oversight, designates QHINs. HITRUST authorizes its external assessor firms. | ||
| AICPA SQMS No.1 | Peer reviewers under the AICPA Peer Review Program (a qualified CPA firm and team captain approved by the program), administered by state CPA societies or the National Peer Review Committee. State boards of accountancy generally require enrollment in peer review as a condition of licensure. | AICPA Peer Review Board sets reviewer qualifications and program standards; state boards of accountancy recognize the program for licensure. | Register ↗ | |
| BSA/AML | Examiners from the institution's functional regulator: OCC, FDIC, Federal Reserve, and NCUA for depository institutions; SEC and FINRA for broker-dealers; IRS Small Business/Self-Employed for MSBs and other non-bank institutions; state regulators alongside them. FinCEN retains enforcement authority. There is no certification. | |||
| DORA | National competent authorities for each entity type (for example BaFin, the CSSF, the Central Bank of Ireland, the AMF and ACPR) supervise and enforce. The ESAs act as lead overseers for critical ICT third-party providers. There is no certification scheme; supervision is by regulator review and inspection. | |||
| FFIEC | Federal and state bank and credit union examiners (OCC, FDIC, Federal Reserve, NCUA, state banking departments) using the handbook's examination procedures. Independent internal or external audits are expected but are not a certification. | |||
| FINRA 3110 WSPs | FINRA Member Supervision examiners conduct cycle and cause examinations; SEC Division of Examinations examiners also review supervision. There is no certification. | |||
| IRS WISP/Pub 4557 | No routine inspection or certification. The FTC enforces the Safeguards Rule; the IRS can revoke a PTIN or EFIN for false renewal statements and runs e-file provider monitoring visits. State boards of accountancy and licensing bodies may act on data security failures. | |||
| SEC 206(4)-7 | SEC Division of Examinations staff conduct examinations; state securities regulators examine state-registered advisers. There is no certification or third-party audit requirement. | |||
| SOX ICFR | Management performs the 404(a) assessment. The 404(b) attestation must be issued by a public accounting firm registered with the PCAOB, applying AS 2201 as part of the integrated audit. | Public Company Accounting Oversight Board (registration and inspection of audit firms), under SEC oversight. | Register ↗ | Deloitte & Touche LLP, Ernst & Young LLP, KPMG LLP |
| SWIFT CSP | An independent assessment by either an internal second or third line of defense function (risk, compliance, internal audit) that is independent of the first line, or an external assessment provider. Swift maintains a directory of CSP assessment providers that employ certified assessors. | Swift sets eligibility for the assessment provider directory; listed companies employ at least two assessors who passed the Swift CSP assessor certification exam. There is no separate accreditation body. | Register ↗ | |
| CJIS | Government audit only. The FBI CJIS Audit Unit audits each state CJIS Systems Agency (CSA), and the CSA audits the local agencies and contractors that connect through it. There is no third-party certification body for CJIS. | |||
| CSA STAR | Level 1: none (self-assessment). Level 2 STAR Certification: an accredited ISO/IEC 27001 certification body that is also a CSA-approved STAR auditor. Level 2 STAR Attestation: a licensed CPA firm performing a SOC 2 examination that is a CSA-approved STAR auditor. | CSA approves STAR auditors; the underlying ISO certification body is accredited by a national accreditation body (ANAB, UKAS and peers) and the CPA firm is licensed and peer reviewed under AICPA rules. | Register ↗ | A-LIGN, BARR Certifications, Schellman & Company |
| FedRAMP | A Third Party Assessment Organization (3PAO) accredited by A2LA to ISO/IEC 17020 plus the FedRAMP-specific R311 requirements and recognized by FedRAMP. The 3PAO performs readiness assessments, the security assessment plan and report, and annual assessments. | A2LA (American Association for Laboratory Accreditation), with FedRAMP recognition of the accredited 3PAO. | Register ↗ | A-LIGN, Coalfire, Fortreum |
| ISO 20000-1 | An accredited certification body (registrar) operating under ISO/IEC 17021-1 with a scope covering ISO/IEC 20000-1, using ISO/IEC 20000-6 for its own competence requirements. | National accreditation bodies that are IAF MLA signatories, such as ANAB (US), UKAS (UK) and their peers. | Register ↗ | |
| StateRAMP | A Third Party Assessment Organization (3PAO) accredited by A2LA and recognized by FedRAMP; the provider engages and pays the assessor. Core status is validated by the GovRAMP PMO without a 3PAO. | A2LA, with FedRAMP recognition of the 3PAO. | Register ↗ | A-LIGN, Coalfire, Fortreum |
| TX-RAMP | Government reviewer: DIR staff assess the provider's questionnaire responses and evidence. No third-party assessor is required, though FedRAMP or GovRAMP 3PAO packages can be submitted for reciprocity. | |||
| ISAE 3402 | A professional accountant in public practice (a licensed audit or chartered accountancy firm) acting as the service auditor. In most countries this means a firm that is licensed to sign assurance reports under the local professional body and that follows the IAASB quality management standards. | |||
| SOC 1 | A licensed CPA firm (a firm of independent certified public accountants) that performs the examination and issues the service auditor's report. | AICPA membership and state board CPA licensure; firms performing attestation engagements are subject to the AICPA peer review program. No separate scheme accreditor. | ||
| SOC 3 | A licensed CPA firm performing the SOC 2 examination; the SOC 3 is issued by the same service auditor. | State board CPA licensure and the AICPA peer review program. No scheme-level accreditor. | ||
| SOC for Cybersecurity | A licensed CPA firm performing the examination under the AICPA attestation standards. | State board CPA licensure and the AICPA peer review program. No scheme-level accreditor. | ||
| DFARS | Level 1 and some Level 2 requirements are self-assessed and affirmed. Level 2 certification assessments are performed by CMMC Third-Party Assessment Organizations (C3PAOs). Level 3 assessments are performed by the Defense Contract Management Agency's DIBCAC. DoD may also conduct medium and high assessments under 7020. | The Cyber AB (CMMC Accreditation Body) accredits C3PAOs; individual assessors are certified through the CMMC Assessors and Instructors Certification Organization. | Register ↗ | |
| DoD compliance requirements | Varies by component: self-assessment and affirmation (FAR 52.204-21, CMMC Level 1), C3PAOs (CMMC Level 2), DCMA DIBCAC (CMMC Level 3 and DFARS 7020 assessments), DISA and DoD authorizing officials (Cloud SRG provisional authorizations, RMF), DCSA industrial security representatives (NISPOM), and DDTC or BIS for export controls. | The Cyber AB for C3PAOs; FedRAMP-recognized accreditation for 3PAOs used in cloud authorizations; government agencies otherwise assess directly. | Register ↗ | |
| Microsoft SSPA DPR | Independent assessors chosen by the supplier from firms meeting Microsoft's qualification guidance, which points to recognized professional bodies such as the AICPA and IFAC members; in practice CPA firms and established security assessment firms. Microsoft does not operate a closed assessor list but does publish the assessment report template the assessor must use. | |||
| NIST IR 8286D | None. | |||
| NIST SP 800-161 | None for the publication itself; SR controls derived from it are assessed within FedRAMP (3PAOs), FISMA (agency assessors), and CMMC (C3PAOs) engagements. | |||
| NIST SP 800-218 | None. Self-attestation by the software producer's senior executive; agencies may accept a third-party assessment from a FedRAMP-recognized 3PAO in place of the form. | |||
| NIST SP 800-30 | None for the document itself. Risk assessments produced with it are reviewed by whichever assessor governs the parent program (3PAOs, C3PAOs, agency assessors, ISO certification bodies). | |||
| NIST SP 800-34 | None for the document itself; contingency plans built on it are reviewed by the assessor of the parent program (3PAOs, agency assessors, C3PAOs). | |||
| NIST SP 800-37 | Independent control assessors: agency or contracted assessment teams for FISMA systems, FedRAMP-recognized 3PAOs for cloud services, and DoD assessment teams (security control assessors) for defense systems. The authorization decision itself is made by a government authorizing official. | For FedRAMP, 3PAOs are accredited by A2LA (and other bodies recognized by the FedRAMP PMO) to ISO/IEC 17020 with FedRAMP requirements. Agency assessors are designated by the agency. | Register ↗ | |
| NIST SP 800-39 | None. | |||
| NIST SP 800-53 | None for the catalog itself. Within adopting programs: FedRAMP-recognized 3PAOs for cloud services, agency security control assessors for FISMA systems, DoD assessors for defense systems, and C3PAOs for the CMMC subset. | Program-specific: A2LA and other FedRAMP-recognized bodies for 3PAOs; the Cyber AB for C3PAOs; agencies designate their own assessors. | Register ↗ | |
| NIST SP 800-61 | None for the document itself; incident response capabilities built on it are examined within parent programs (FedRAMP 3PAOs, C3PAOs, agency assessors, ISO certification bodies). | |||
| DOT/FMCSA | FMCSA safety investigators and state enforcement partners under the Motor Carrier Safety Assistance Program (government audit and investigation). Roadside inspections by certified officers feed the CSA scores. | |||
| EPA RCRA | State environmental agency inspectors in authorized states, and EPA regional inspectors (government inspection and enforcement). No certification exists. | |||
| ISNetworld/Avetta | Platform reviewers (ISN's RAVS team, Avetta's review specialists) grading documents against client and regulatory checklists; hiring clients may additionally audit contractors in the field. No independent certification or accreditation exists. | |||
| OSHA written programs | OSHA compliance safety and health officers, or State Plan inspectors (government inspection). No certification exists; voluntary recognition programs such as VPP and SHARP involve OSHA or consultation program evaluation. | |||
| State harassment-prevention mandates | State civil rights or labor agencies on complaint or investigation (government enforcement); no certification. Training and policy records are most often tested in litigation and agency charge responses. | |||
| ISO 14001 | Accredited certification body (registrar) accredited to ISO/IEC 17021-1 for environmental management systems | National accreditation bodies that are signatories to the Global ACI (formerly IAF) multilateral arrangement, such as ANAB (US), UKAS (UK), DAkkS (Germany), JAS-ANZ | Register ↗ | |
| ISO 22301 | Accredited certification body accredited to ISO/IEC 17021-1 for business continuity management systems | National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZ | Register ↗ | |
| ISO 42001 | Accredited certification body accredited to ISO/IEC 17021-1 with ISO/IEC 42006 requirements for AI management system certification | National accreditation bodies; ANAB launched its ISO/IEC 42001 accreditation program in January 2024 and several US and international certification bodies now hold ANAB accreditation for it. Other accreditation bodies have followed or are in progress (verify for the specific certification body you choose). | Register ↗ | |
| ISO 45001 | Accredited certification body accredited to ISO/IEC 17021-1 for OH&S management systems (ISO/IEC TS 17021-10) | National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZ | Register ↗ | |
| ISO 50001 | Accredited certification body accredited to ISO/IEC 17021-1 with ISO 50003 requirements for energy management system auditing | National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS | Register ↗ | |
| CPSA | None identifiable. For the CREST exam, CREST itself administers the test to individuals. | |||
| EU AI Act | Depends on the system. Most Annex III high-risk providers self-assess through the internal control procedure in Annex VI. Third-party assessment by a notified body is required for certain biometric systems where harmonized standards are not fully applied, and for Annex I products it runs through the notified body already used under the sectoral product law. General-purpose model providers are supervised directly by the AI Office. | National notifying authorities designate notified bodies, normally on the basis of accreditation by the national accreditation body under Regulation (EC) 765/2008. Designations are published in the Commission's NANDO database. | Register ↗ | |
| EU CRA | Manufacturer self-assessment (internal control, Module A) for the default category. Notified bodies for important products where harmonized standards are not fully applied and for products where the manufacturer chooses third-party assessment. Conformity assessment bodies under the EU Cybersecurity Act certification schemes (for example EUCC) where a European certificate is used. Notified body provisions applied from June 11, 2026. | National notifying authorities designate CRA notified bodies, with accreditation by the national accreditation body (for example DAkkS, COFRAC, UKAS is not applicable) as the normal basis. Listings appear in NANDO once designations begin. | Register ↗ | |
| NIST AI RMF | None. There is no NIST certification or accredited assessor for the AI RMF; organizations self-attest or fold the framework into another audited scheme such as ISO/IEC 42001. | |||
| NIST Privacy Framework | None. No certification exists. Organizations self-assess or have privacy controls examined as part of another engagement such as a SOC 2 privacy criteria report or ISO/IEC 27701 audit. | |||
| OWASP LLM Top 10 | None. No certification. Penetration testers and red teams use it as a scope, but any firm may do so and no body qualifies them for this list specifically. | |||
| OWASP SAMM | None mandated. Self-assessment or any consultant; the project does not qualify or license assessors. | |||
| SLC | Software Security Framework (SSF) Assessor companies qualified by PCI SSC to perform Secure SLC assessments. Individual assessors must be employed by a qualified company and complete PCI SSC training. | PCI Security Standards Council qualifies and lists SSF Assessor companies. | Register ↗ | |
| US State Privacy Laws | None. Compliance is enforced by state attorneys general and the California Privacy Protection Agency through investigations and civil actions; there is no certification or licensed assessor. California's regulations on cybersecurity audits and risk assessments, when in force, will require certain businesses to obtain an independent audit and file certifications with the agency (verify the current CPPA regulation status and effective dates). | |||
| C-TPAT | CBP Supply Chain Security Specialists (government officers) perform validations and revalidations. There are no private third-party certifiers for CTPAT; consultants can prepare a member but cannot validate it. | |||
| FCPA | None required by law. Companies self-assess, use internal audit, or commission independent program reviews by law firms or forensic accountants. After an enforcement resolution DOJ may impose an independent compliance monitor chosen from candidates the company proposes. | |||
| Franchise brand standards | The franchisor's own field consultants, quality assurance staff, or contracted mystery shoppers and third-party inspection firms audit franchisees against the standards. No government body inspects brand standards; the FTC and state regulators police disclosure and unfair practices, not operating standards. | |||
| ISO 27701 | Accredited certification bodies operating under ISO/IEC 17021-1 with the sector-specific requirements of ISO/IEC 27006-2 (PIMS audits). | National accreditation bodies that are signatories to the IAF (now Global ACI) multilateral arrangement, for example ANAB, UKAS, DAkkS, JAS-ANZ. Not every accreditation body has yet extended scopes to the 2025 edition; check the certificate's accreditation mark. | Register ↗ | |
| ITAR | DDTC's Office of Defense Trade Controls Compliance conducts company visits, reviews disclosures, and enforces; the Department of Justice prosecutes criminal violations. No private certifier exists; "ITAR certified" claims by vendors are marketing shorthand for being registered and having a program. | |||
| ABDO | Government inspection by the Bureau Industrieveiligheid (MIVD). There are no private certifiers; consultants prepare, the Bureau authorizes. | |||
| ACN | ACN itself reviews applications and lists qualified services. Supporting ISO/IEC 27001 and related certificates come from accredited certification bodies, and ACN may require independent audit reports for higher levels. No separate class of ACN-licensed assessors exists. | ACCREDIA (Italian national accreditation body) for the ISO/IEC certification bodies whose certificates support the application; ACN for the qualification decision itself. | Register ↗ | |
| BIO | Internal audit and the organization's own accountability line; registered IT auditors (RE, under NOREA) for the ENSIA audits at municipalities and for assurance reports requested by supervisory bodies. No certification body issues a BIO certificate. | |||
| BSI C5 | Independent auditors qualified to issue ISAE 3000 or IDW PS 860 assurance reports, which in Germany means Wirtschaftsprüfer (public auditors) and their firms; auditors from other jurisdictions may report under ISAE 3000 where they meet the catalog's independence and competence requirements. BSI itself does not audit or certify. | |||
| CCC | Self-assessment by the in-scope organization, reported to the NCA, with the NCA (and for critical infrastructure the relevant sector regulator) able to audit and verify. There is no private certification scheme for the CCC; consultants assist but do not certify on the NCA's behalf. | |||
| CCCS ITSG-33 | Departmental security assessors (internal or contracted) for departmental systems, with authorization by the departmental authority; CCCS assessors for cloud service providers under the CSP IT Security Assessment Program. No private certification exists. | |||
| CERT-IN | CERT-In itself supervises and can request information; CERT-In empanelled information security auditing organizations conduct audits where a regulator or government body requires one (for example for government websites and applications and certain regulated sectors). The empanelment is a public list maintained by CERT-In. | CERT-In empanels auditing organizations directly through periodic empanelment rounds. | Register ↗ | |
| Crown Commercial Service (UK) | Cyber Essentials certification bodies licensed by IASME for the certification element; contracting authorities and CCS assess questionnaire responses themselves; NCSC-recognized bodies or UKAS-accredited certification bodies where ISO/IEC 27001 is required. | IASME (as NCSC's delivery partner) for Cyber Essentials certification bodies; UKAS for ISO/IEC 27001 certification bodies. | Register ↗ | |
| CyFun | Conformity Assessment Bodies accredited by BELAC under the CyFun conformity assessment scheme and authorized by the CCB. Verification at Basic level and certification at Important and Essential levels. | BELAC, the Belgian national accreditation body, with CCB authorization of each body. | Register ↗ | |
| Cyber Essentials Plus | Certification bodies licensed by IASME, employing qualified Cyber Essentials assessors. Cyber Essentials Plus assessments must be performed by a licensed certification body's assessor; the basic level is marked by a certification body against the applicant's self-assessment. | IASME licenses and audits certification bodies on behalf of NCSC; NCSC sets scheme policy and the technical requirements. | Register ↗ | |
| CyberTrust | For Standard and Silver, the scheme operator validates the self-declaration for completeness and plausibility. For Gold, a qualified auditor accredited under Section 18 of the Austrian NIS Act (NISG) performs an audit. Platinum follows the scheme's stated audit requirements. | For Gold audits, auditor qualification rests on accreditation as a qualified body under the Austrian NIS Act (overseen by the Austrian NIS authority); the scheme operator issues the label. | Register ↗ | |
| DESC | For CSP certification, certification bodies approved by DESC that operate under the ISO/IEC 27001 certification scheme; DESC itself reviews ISR compliance reporting and can audit government entities. Verify the current list of DESC-approved certification bodies on the DESC certifications page. | DESC approves certification bodies for its schemes; those bodies typically also hold accreditation from a national accreditation body for ISO/IEC 27001 (for example the Emirates International Accreditation Centre or UKAS). | Register ↗ | |
| DTL | SGS auditors under the Digital Trust Label certification scheme. Before the handover, SGS acted as the independent audit partner for the foundation. | |||
| ECC | Self-assessment and reporting by the organization, reviewed by the NCA, which may audit and verify directly; sector regulators may conduct their own reviews. No private certification scheme exists for the ECC. | |||
| ENS | For Media and Alta categories, certification bodies accredited by ENAC under the ENS certification scheme perform the audit and issue the Certificación de Conformidad. For Básica, the organization issues a Declaración de Conformidad after a self-assessment (an external audit is optional). | ENAC (Entidad Nacional de Acreditación), Spain's national accreditation body; the CCN publishes the list of accredited certification bodies. | Register ↗ | AENOR CONFIA, Audertis Audit Services, BDO Auditores |
| Essential 8 | Self-assessment by the entity following ASD's assessment guide; independent assessment by IRAP assessors (for Commonwealth reporting) or by specialist assessment firms. ASD does not certify Essential Eight compliance. | ASD endorses IRAP assessors; no accreditor exists for other Essential Eight assessors. | Register ↗ | |
| HDS | Certification bodies accredited by COFRAC under the HDS accreditation standard (based on ISO/IEC 17021-1 and 27006). Nine bodies were reported as accredited as of the most recent ANS communication (verify the current list on the ANS site). | COFRAC (Comité français d'accréditation). | Register ↗ | |
| IRAP | IRAP assessors, individuals endorsed by ASD after meeting experience, qualification, and training requirements and passing the IRAP course; they work independently or within consultancies. Assessors do not accredit or certify; authorization is made by the consuming agency. | ASD endorses and lists IRAP assessors and sets the assessment methodology. | Register ↗ | |
| ISMAP | Audit firms registered on the ISMAP assessor list maintained by IPA (in practice the large Japanese audit firms and affiliates of international networks). Registration decisions are made by the ISMAP Steering Committee. | IPA (as ISMAP operator) registers assessors; assessors are typically CPA-regulated audit firms operating under Japanese assurance standards. | Register ↗ | |
| IT-Grundschutz | Auditors certified by the BSI for ISO 27001 audits on the basis of IT-Grundschutz; the audit report is reviewed by the BSI, which issues the certificate. Plain ISO/IEC 27001 certification against IT-Grundschutz-aligned controls can also be obtained from accredited certification bodies, but only the BSI issues the IT-Grundschutz certificate. | BSI (as certification body and auditor licensor) for the IT-Grundschutz certificate; DAkkS-accredited certification bodies for conventional ISO/IEC 27001 certificates. | Register ↗ | |
| MTCS | Certification bodies accredited by the Singapore Accreditation Council for the MTCS certification scheme (for example BSI, SOCOTEC Certification Singapore, and TÜV SÜD are among bodies offering it; verify current accreditation on the SAC site). | Singapore Accreditation Council (SAC), part of Enterprise Singapore. | Register ↗ | |
| MeitY | STQC Directorate auditors (a MeitY body) perform the empanelment audit; supporting ISO certifications come from accredited certification bodies. No private firm can grant empanelment. | Register ↗ | ||
| NCSC CAF | Sector competent authorities (for example Ofgem, DfT, DHSC, Ofcom, the Drinking Water Inspectorate) review operator self-assessments and may inspect; independent assurance reviewers verify GovAssure self-assessments; no certificate is issued. | |||
| NCSC Cyber Security v3.1 | As for NCSC CAF: sector competent authorities and GovAssure independent assurance reviewers; no certificate. | |||
| QNRCS | Certification bodies approved by the NCSA under the National Information Security Compliance Framework perform NIA certification audits; the NCSA supervises and can audit directly. No independent private scheme exists outside the NCSA's approval. | NCSA approves certification bodies for NIA certification. | ||
| SAMA CSF | Self-assessment by the member organization reviewed and audited by SAMA supervisors; SAMA may direct independent assessments by external firms. No private certification exists. | |||
| SecNumCloud | Evaluation by ANSSI with audits performed by PASSI-qualified audit providers (Prestataires d'audit de la sécurité des systèmes d'information, qualified by ANSSI); the qualification decision is ANSSI's. No other body can issue SecNumCloud. | ANSSI qualifies both the audit providers (PASSI) and the cloud providers; PASSI qualification itself relies on accreditation by COFRAC under ISO/IEC 17065. | Register ↗ | |
| UK MoD compliance requirements | MOD reviews Supplier Assurance Questionnaires through the Supplier Cyber Protection Service and may audit; Cyber Essentials certification bodies licensed by IASME certify the baseline; Defence Cyber Certification is assessed by IASME-licensed certification bodies; MOD security staff (and DE&S Principal Security Advisers) assess facility and classified-handling compliance. | IASME (on behalf of NCSC for Cyber Essentials and of the MOD for Defence Cyber Certification) licenses certification bodies; the MOD assesses directly for the remainder. | Register ↗ |
Need a hand implementing it?
Find a Consultant Who Does This Work
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Keep Your Written Policies in One Place
Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.
See how AllyMatter works ↗From $29/mo, 20 editors, unlimited staff