QA Rating

Turning a certificate claim into a checked fact

QA Rating is published independently, and its publisher owns no company listed in this catalog.

A step-by-step check for the issuer, scope, and expiration date behind a testing vendor's certificate, before it goes into a contract.

A logo on a vendor's website tells a buyer that the vendor wants to be associated with a standard. It does not tell the buyer who was audited, what was audited, or when the audit last happened. This page walks through the single step that separates a certificate claim from a confirmed one: asking for the document behind the logo and checking the details on it that carry the actual information.

Two different documents share the word "certificate"

A certification can belong to a company or to a person, and the two are not interchangeable. An organizational certificate, such as an information-security management system certification, is issued to a named legal entity, usually for a defined set of locations or business units. An individual certificate is issued to one employee, tied to that person's name, and does not extend to colleagues or to the company as a whole.

A vendor can accurately state that it holds an organizational certification while also employing staff who hold unrelated personal credentials, and a buyer who does not separate the two ends up crediting the company for a qualification that only one employee holds. Before treating a certificate claim as covering "the team," ask which of the two categories it falls into.

Why the scope line outranks the badge

Every organizational certificate carries a scope statement written by the certifying body, and that statement is narrower than the company name on the certificate. A parent company can hold a certification that names only one delivery location, one business unit, or one specific service line, while the rest of the company operates outside that scope.

A buyer who checks only for the presence of a certificate, and skips the scope statement, can end up contracting with a team, office, or service line the certificate never covered. The scope statement also determines whether a general security or quality certification says anything about a regulated data type at all: a certification scoped to general information security does not, by itself, confirm that the same team is set up to handle a specific regulated category of data. A buyer sourcing a vendor from the Healthcare rankings should check whether the scope statement, or a separate attestation, names that data category directly.

What a verifiable audit report contains

An audit report and a website badge are not the same evidence. A badge is an image the vendor controls and can place on a page regardless of current status. An audit report is a document produced by an independent auditor or certifying body, and it names the auditor, states the scope, lists the controls or requirements tested, gives the audit date, and states the result.

Ask the vendor for the report itself. A summary written by the vendor's own marketing team restates the claim without adding evidence, and it typically omits the auditor's identifying detail. A full report or certificate document includes a registration or certificate number a buyer can quote back to the issuing body if verification is needed.

The request that produces a checkable answer

A short, specific request gets a specific answer. A vague request ("can you confirm you're certified?") gets a vague one. Send the vendor a request that names each element separately:

  • the exact legal entity and delivery location named on the certificate
  • the certificate or registration number and the name of the issuing or certifying body
  • the scope statement, quoted in the certifying body's own wording
  • the issue date and the expiration or next-audit date
  • the full audit report or certificate document as issued
  • for a personal credential, the name of the employee who holds it and confirmation that the same person will work on the engagement

In penetration testing this last point carries more weight than in most services, because the credential that answers who is running the test often belongs to one tester. The catalog cannot help with that question: every certificate it records is issued to a legal entity, and a credential held by a named individual has no field on a profile at all. The Penetration testing rankings give a starting list of candidates and the company-level accreditations confirmed for each; the tester-level question is put to every candidate directly.

Reading an expiration date instead of a logo

Most third-party certifications run on a fixed cycle set by the issuing body, with periodic surveillance checks and a full reissue at a stated interval. A certificate that has passed its stated expiration or next-audit date has lapsed until the audit is repeated. An expired certificate marks the point after which the last audit stops counting as current confirmation. The date on the certificate tells a buyer how old that confirmation is, and a confirmation older than the stated cycle needs to be renewed before it is treated as current.

Ask for the expiration or next-audit date on every certificate a vendor lists, and treat a certificate past that date as unconfirmed. If a vendor cannot produce a current date, that is itself an answer.

What an empty field in a vendor profile means for the next step

A vendor profile that lists no certificate for a given standard is recording the absence of a confirmed source. An empty certificate field is not a refusal to publish, only the absence of a confirmed answer, and the correct response is to ask the vendor directly.

Once the answers arrive, check them against the two tests above: does the scope statement name the team, location, and data category relevant to the engagement, and does the issue or audit date fall inside the current cycle. A certificate that fails either test needs a follow-up question before it goes into a contract, and a certificate that passes both is the kind of evidence worth keeping on file alongside the signed agreement.

Published by QA RatingPublished on September 3, 2026Updated on September 3, 2026

How this catalog decides what goes into a ranking, and on what basis rows are ordered, is on the methodology page. Every fact about a company comes from a listed source. A field without a source stays empty. A certificate counts as confirmed only when a registry, certificate or auditor report backs it; a certificate the company only claims about itself is published separately, under that label. Vendors can request a correction at hello@qa-rating.com. A correction is applied when it comes with a public source.