Accreditations
Audited by the people who audit us.
Empanelment and certification are not marketing badges. They are the reason a regulator will accept our report, and the reason we can sign an audit opinion at all.
Accredited and certified

CERT-In empanelled
Empanelled by the Indian Computer Emergency Response Team to conduct security audits for government bodies and regulated entities.
ISO/IEC 27001
Certified information security management system covering our own delivery, storage and handling of client data.
ISO/IEC 20000
Certified service management, which is what keeps our SLAs meaningful rather than aspirational.
ISO 9001:2015
Quality management across engagement delivery, reporting and review.
SOC 2 Type II
Independently attested controls over security, availability and confidentiality, tested over a period rather than a point in time.
GDPR aligned
Processing aligned to the GDPR for our European clients, with a DPA available on request.
STQC and GIGW
Qualified to deliver STQC cyber security audit and GIGW compliance certification for government digital services.
UIDAI AUA / KUA
Qualified to audit Aadhaar authentication and e-KYC user agencies against UIDAI requirements.
Our certification
The people testing your systems are certified to do it.
Threatsys engineers hold offensive, defensive, cloud, privacy and governance certifications from EC-Council, OffSec, ISC2, ISACA, CREST, IAPP, AWS and Microsoft.
What each of these actually certifies
Certification logos are collected and displayed by nearly everyone in this industry, which has made them close to meaningless as a comparison tool. They are not meaningless individually, so here is what each one on this page genuinely tells you.
CERT-In empanelment means the Indian Computer Emergency Response Team has assessed the firm as competent to conduct information security audits, and it is a hard requirement for a large amount of government and regulated work. Where a rule calls for an empanelled auditor, a report from a firm that is not empanelled will not be accepted, regardless of its quality.
ISO/IEC 27001 certifies that we operate an information security management system to a defined standard, with defined scope. The scope is the part worth reading on anyone's certificate, including ours, because a certificate covering one office and a certificate covering the whole delivery organisation look identical at a glance.
SOC 2 Type II is the one we would point a sceptical buyer at first. A Type I attestation says controls were designed appropriately on a given date. Type II tests whether they actually operated across a period, which is materially harder and much closer to the question you care about.
ISO/IEC 20000 covers service management, which sounds like paperwork and shows up in practice as whether incidents, changes and requests are handled consistently rather than heroically. ISO 9001 covers quality management on the same logic.
How to read anyone's certificate, including ours
- Check the scope statement, not the logo: which entity, which sites, which services are actually covered
- Check the dates, and whether surveillance audits have happened between issue and now
- Check the certification body, and whether it is itself accredited
- For SOC 2, check whether it is Type I or Type II, and what period the Type II covers
- For empanelment, check the current published list rather than a claim on a website
- Ask for the report, not just the certificate, and expect to sign an NDA to get it
Why we hold the standards we assess against
There is an obvious argument that a firm auditing others should meet the same bar, and we agree with it, but the more practical reason is that holding a certification teaches you things about it that reading the standard does not.
Going through ISO 27001 certification ourselves, and then living with surveillance audits, is why our advice on it is specific rather than generic. We know which clauses generate the most argument with auditors, which evidence is accepted and which is questioned, and how much of the effort is genuinely about security versus about being able to demonstrate security. Those are different problems and clients are usually sold a solution to only one of them.
The same applies to SOC 2. Passing a Type II taught us how much of the difficulty sits in the operating period rather than the control design, which changes the advice we give clients about when to start.
What accreditation does not tell you
It is worth being straightforward about the limits, because the industry oversells this. Certification tells you a firm has a system and that an assessor checked it. It does not tell you whether the specific engineer assigned to your engagement is good, whether the report you receive will be readable, or whether findings will be reproduced before they reach you.
It also does not differentiate. The empanelled list is long. Every serious firm on it holds broadly the same certificates. If a proposal's main argument is its logo collection, it has not made an argument.
The questions that do differentiate are about method and people: how many days of manual testing are in the number, who performs them, whether retesting is included, and whether the engineer who tested your system will be on the debrief call. We would rather be judged on those.
Individual certifications, and why we pay for them
Alongside the organisational standards, our engineers hold individual certifications across offensive, defensive, cloud, privacy and governance disciplines: EC-Council, OffSec, ISC2, ISACA, CREST, IAPP, AWS and Microsoft among them. Several carry acknowledgements from vendor disclosure programmes at Facebook, Google, Microsoft, NASA, Sony, Mastercard and Adobe.
The training and examination costs sit with us rather than with the individual. That is a deliberate choice and a meaningful line in our budget. An engineer paying for their own certification is being asked to fund the firm's credibility out of their salary, and the predictable result is that certifications lapse quietly.
Research time is protected for the same reason. An engineer who has not looked at a new technique in six months is testing last year's estate against last year's methods, and no certificate on any wall corrects for that.
Verifying what we claim
Everything asserted on this page can be checked, and we would rather you checked it. Empanelment appears on CERT-In's published list. Our ISO certificates carry certification body references that can be validated with the issuing body directly.
Certificates we have issued to clients are a separate matter and can be verified on our verification page, which checks a reference against the issued register and returns not found if it is not there. It will never return a pass it cannot evidence, which is the only defensible way to run a verification tool.
Our own attestation reports, the Data Processing Addendum and the sub-processor list are available under NDA on request, usually within two working days.
Need our certificates for your audit?
Certificates, our own penetration test summary and insurance documents are available under NDA within two working days.































