Skip to main content

Accreditations

Audited by the people who audit us.

Empanelment and certification are not marketing badges. They are the reason a regulator will accept our report, and the reason we can sign an audit opinion at all.

Accredited and certified

CERT-In, ISO 9001, ISO 27001, ISO 20000, SOC 2 Type II and GDPR
  • CERT-In empanelled

    Empanelled by the Indian Computer Emergency Response Team to conduct security audits for government bodies and regulated entities.

  • ISO/IEC 27001

    Certified information security management system covering our own delivery, storage and handling of client data.

  • ISO/IEC 20000

    Certified service management, which is what keeps our SLAs meaningful rather than aspirational.

  • ISO 9001:2015

    Quality management across engagement delivery, reporting and review.

  • SOC 2 Type II

    Independently attested controls over security, availability and confidentiality, tested over a period rather than a point in time.

  • GDPR aligned

    Processing aligned to the GDPR for our European clients, with a DPA available on request.

  • STQC and GIGW

    Qualified to deliver STQC cyber security audit and GIGW compliance certification for government digital services.

  • UIDAI AUA / KUA

    Qualified to audit Aadhaar authentication and e-KYC user agencies against UIDAI requirements.

Our certification

The people testing your systems are certified to do it.

Threatsys engineers hold offensive, defensive, cloud, privacy and governance certifications from EC-Council, OffSec, ISC2, ISACA, CREST, IAPP, AWS and Microsoft.

  • Certified Penetration Testing Professional, issued by EC-Council
  • Certified Ethical Hacker, issued by EC-Council
  • Licensed Penetration Tester (Master), issued by EC-Council
  • Offensive Security Certified Professional, issued by OffSec
  • Offensive Security Certified Expert, issued by OffSec
  • Certified Red Team Professional, issued by Altered Security
  • Certified Red Team Operator, issued by Zero-Point Security
  • Certified Penetration Testing Engineer, issued by Mile2
  • CREST Registered Penetration Tester, issued by CREST
  • Computer Hacking Forensic Investigator, issued by EC-Council
  • Global Information Assurance Certification, issued by GIAC / SANS
  • Cyber Guardian Programme, issued by Cyber Guardian
  • Certified Information Systems Security Officer, issued by Mile2
  • Certified Information Systems Security Professional, issued by ISC2
  • Certified Information Systems Auditor, issued by ISACA
  • Certified Chief Information Security Officer, issued by EC-Council
  • AWS Certified Security, Specialty, issued by Amazon Web Services
  • Azure Security Engineer Associate, issued by Microsoft
  • Certified Information Privacy Professional, issued by IAPP

What each of these actually certifies

Certification logos are collected and displayed by nearly everyone in this industry, which has made them close to meaningless as a comparison tool. They are not meaningless individually, so here is what each one on this page genuinely tells you.

CERT-In empanelment means the Indian Computer Emergency Response Team has assessed the firm as competent to conduct information security audits, and it is a hard requirement for a large amount of government and regulated work. Where a rule calls for an empanelled auditor, a report from a firm that is not empanelled will not be accepted, regardless of its quality.

ISO/IEC 27001 certifies that we operate an information security management system to a defined standard, with defined scope. The scope is the part worth reading on anyone's certificate, including ours, because a certificate covering one office and a certificate covering the whole delivery organisation look identical at a glance.

SOC 2 Type II is the one we would point a sceptical buyer at first. A Type I attestation says controls were designed appropriately on a given date. Type II tests whether they actually operated across a period, which is materially harder and much closer to the question you care about.

ISO/IEC 20000 covers service management, which sounds like paperwork and shows up in practice as whether incidents, changes and requests are handled consistently rather than heroically. ISO 9001 covers quality management on the same logic.

How to read anyone's certificate, including ours

  • Check the scope statement, not the logo: which entity, which sites, which services are actually covered
  • Check the dates, and whether surveillance audits have happened between issue and now
  • Check the certification body, and whether it is itself accredited
  • For SOC 2, check whether it is Type I or Type II, and what period the Type II covers
  • For empanelment, check the current published list rather than a claim on a website
  • Ask for the report, not just the certificate, and expect to sign an NDA to get it

Why we hold the standards we assess against

There is an obvious argument that a firm auditing others should meet the same bar, and we agree with it, but the more practical reason is that holding a certification teaches you things about it that reading the standard does not.

Going through ISO 27001 certification ourselves, and then living with surveillance audits, is why our advice on it is specific rather than generic. We know which clauses generate the most argument with auditors, which evidence is accepted and which is questioned, and how much of the effort is genuinely about security versus about being able to demonstrate security. Those are different problems and clients are usually sold a solution to only one of them.

The same applies to SOC 2. Passing a Type II taught us how much of the difficulty sits in the operating period rather than the control design, which changes the advice we give clients about when to start.

What accreditation does not tell you

It is worth being straightforward about the limits, because the industry oversells this. Certification tells you a firm has a system and that an assessor checked it. It does not tell you whether the specific engineer assigned to your engagement is good, whether the report you receive will be readable, or whether findings will be reproduced before they reach you.

It also does not differentiate. The empanelled list is long. Every serious firm on it holds broadly the same certificates. If a proposal's main argument is its logo collection, it has not made an argument.

The questions that do differentiate are about method and people: how many days of manual testing are in the number, who performs them, whether retesting is included, and whether the engineer who tested your system will be on the debrief call. We would rather be judged on those.

Individual certifications, and why we pay for them

Alongside the organisational standards, our engineers hold individual certifications across offensive, defensive, cloud, privacy and governance disciplines: EC-Council, OffSec, ISC2, ISACA, CREST, IAPP, AWS and Microsoft among them. Several carry acknowledgements from vendor disclosure programmes at Facebook, Google, Microsoft, NASA, Sony, Mastercard and Adobe.

The training and examination costs sit with us rather than with the individual. That is a deliberate choice and a meaningful line in our budget. An engineer paying for their own certification is being asked to fund the firm's credibility out of their salary, and the predictable result is that certifications lapse quietly.

Research time is protected for the same reason. An engineer who has not looked at a new technique in six months is testing last year's estate against last year's methods, and no certificate on any wall corrects for that.

Verifying what we claim

Everything asserted on this page can be checked, and we would rather you checked it. Empanelment appears on CERT-In's published list. Our ISO certificates carry certification body references that can be validated with the issuing body directly.

Certificates we have issued to clients are a separate matter and can be verified on our verification page, which checks a reference against the issued register and returns not found if it is not there. It will never return a pass it cannot evidence, which is the only defensible way to run a verification tool.

Our own attestation reports, the Data Processing Addendum and the sub-processor list are available under NDA on request, usually within two working days.

Need our certificates for your audit?

Certificates, our own penetration test summary and insurance documents are available under NDA within two working days.