"Can you send us your security certification?" is one of the most expensive ambiguous sentences in B2B sales. It might mean a certificate, an auditor's report, a test result or a questionnaire — each with a different issuer, timeline and price. Asking which, before scoping anything, routinely saves months.
| Type | What it proves | Issued by | Typical lead time | Renewal |
|---|---|---|---|---|
| Certification (ISO 27001, ISO 42001) | A management system conforms to a standard | Accredited certification body | 6–12 months first time | Surveillance yearly, recert at 3 years |
| Attestation (SOC 2) | Controls were suitably designed and, for Type II, operated over a period | CPA firm | 6–12 months incl. observation window | Annual |
| Regulatory assessment (NCA ECC, SAMA, PCI RoC) | Compliance with a mandated control set | Regulator or approved assessor | Varies by regime | Per regulator cycle |
| Self-assessment (PCI SAQ, CIS) | Your own assertion against a defined set | You | Days to weeks | Annual |
| Penetration test | Exploitable weaknesses found by testers at a point in time | Security testing firm | 2–6 weeks | Annual, plus on change |
| Questionnaire response (CAIQ, SIG, bespoke) | Your answers to a buyer's specific questions | You | Hours to weeks | Per request |
Note what none of these prove: that you are secure today. A certificate covers a management system, an attestation covers a past period, a pen test covers one moment. They are evidence of discipline, not a guarantee — which is exactly why buyers increasingly ask for several.
The distinctions that cause real confusion
- Certificate vs report. ISO produces a one-page certificate; SOC 2 produces a detailed report your customer reads, including any exceptions. "We have SOC 2" says less than it sounds until someone opens it.
- Type I vs Type II. Type I is design at a point in time; Type II is operation across a period. Enterprise buyers almost always mean Type II.
- Scan vs penetration test. A scan finds known vulnerabilities at breadth; a test finds chained and logic flaws at depth. Frameworks generally expect both, and a scan report submitted as a pen test is spotted immediately.
- Bridge letter vs report. A bridge letter is management's unaudited assertion covering the gap since the report period. It is not assurance.
Answer any of them from one evidence base
GRC Copilot keeps control status and evidence current, so certifications, questionnaires and customer reviews are answered from records rather than rebuilt each time.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Choosing what to pursue
Follow the buyers rather than the marketing. North American enterprise software procurement generally asks for SOC 2; international and Gulf buyers expect ISO 27001; regulated sectors impose their own assessment regardless. Where several apply, build one control set and sequence — the overlap is large and the second one costs a fraction of the first.
What to ask before scoping
- Which specific document do you need — a certificate, a report, or answers?
- If SOC 2: Type I or II, and which trust services criteria?
- What scope must it cover — which product, which environments?
- By when, and will an interim position be accepted?
The fourth question matters more than teams expect. Many buyers will accept a readiness assessment plus a committed date, which unblocks a deal months before a certificate could exist.
Frequently asked questions
Is SOC 2 a certification?
No. It is an attestation report from a CPA firm — there is no certificate and no pass mark.
Can a pen test substitute for certification?
No. It tests technical exposure at a moment; certification tests whether you run a management system. Most frameworks require both.
What is fastest to obtain?
A questionnaire response, then a self-assessment, then a pen test. Certification and attestation are the long leads because both need accumulated evidence.
Do buyers accept a readiness assessment?
Often, alongside a committed timeline. It is worth asking rather than assuming a deal is blocked.
Key takeaways
- Establish which document the customer actually wants before scoping anything.
- Certificates are binary; attestation reports are read in detail, exceptions included.
- None of these prove present-day security — they evidence discipline.
- A readiness position plus a date unblocks more deals than teams expect.