Back to blog
Comparisons

Certification, attestation, audit, pen test: which one does your customer mean?

A customer asking for "your security certification" may want any of six different things, with wildly different cost and lead time. What each one proves, who issues it, and how long it takes.
GRC Copilot Team
Certification, attestation, audit, pen test: which one does your customer mean?

"Can you send us your security certification?" is one of the most expensive ambiguous sentences in B2B sales. It might mean a certificate, an auditor's report, a test result or a questionnaire — each with a different issuer, timeline and price. Asking which, before scoping anything, routinely saves months.

TypeWhat it provesIssued byTypical lead timeRenewal
Certification (ISO 27001, ISO 42001)A management system conforms to a standardAccredited certification body6–12 months first timeSurveillance yearly, recert at 3 years
Attestation (SOC 2)Controls were suitably designed and, for Type II, operated over a periodCPA firm6–12 months incl. observation windowAnnual
Regulatory assessment (NCA ECC, SAMA, PCI RoC)Compliance with a mandated control setRegulator or approved assessorVaries by regimePer regulator cycle
Self-assessment (PCI SAQ, CIS)Your own assertion against a defined setYouDays to weeksAnnual
Penetration testExploitable weaknesses found by testers at a point in timeSecurity testing firm2–6 weeksAnnual, plus on change
Questionnaire response (CAIQ, SIG, bespoke)Your answers to a buyer's specific questionsYouHours to weeksPer request
Note what none of these prove: that you are secure today. A certificate covers a management system, an attestation covers a past period, a pen test covers one moment. They are evidence of discipline, not a guarantee — which is exactly why buyers increasingly ask for several.

The distinctions that cause real confusion

  • Certificate vs report. ISO produces a one-page certificate; SOC 2 produces a detailed report your customer reads, including any exceptions. "We have SOC 2" says less than it sounds until someone opens it.
  • Type I vs Type II. Type I is design at a point in time; Type II is operation across a period. Enterprise buyers almost always mean Type II.
  • Scan vs penetration test. A scan finds known vulnerabilities at breadth; a test finds chained and logic flaws at depth. Frameworks generally expect both, and a scan report submitted as a pen test is spotted immediately.
  • Bridge letter vs report. A bridge letter is management's unaudited assertion covering the gap since the report period. It is not assurance.

Answer any of them from one evidence base

GRC Copilot keeps control status and evidence current, so certifications, questionnaires and customer reviews are answered from records rather than rebuilt each time.

Choosing what to pursue

Follow the buyers rather than the marketing. North American enterprise software procurement generally asks for SOC 2; international and Gulf buyers expect ISO 27001; regulated sectors impose their own assessment regardless. Where several apply, build one control set and sequence — the overlap is large and the second one costs a fraction of the first.

What to ask before scoping

  1. Which specific document do you need — a certificate, a report, or answers?
  2. If SOC 2: Type I or II, and which trust services criteria?
  3. What scope must it cover — which product, which environments?
  4. By when, and will an interim position be accepted?

The fourth question matters more than teams expect. Many buyers will accept a readiness assessment plus a committed date, which unblocks a deal months before a certificate could exist.

Frequently asked questions

Is SOC 2 a certification?

No. It is an attestation report from a CPA firm — there is no certificate and no pass mark.

Can a pen test substitute for certification?

No. It tests technical exposure at a moment; certification tests whether you run a management system. Most frameworks require both.

What is fastest to obtain?

A questionnaire response, then a self-assessment, then a pen test. Certification and attestation are the long leads because both need accumulated evidence.

Do buyers accept a readiness assessment?

Often, alongside a committed timeline. It is worth asking rather than assuming a deal is blocked.

Key takeaways

  • Establish which document the customer actually wants before scoping anything.
  • Certificates are binary; attestation reports are read in detail, exceptions included.
  • None of these prove present-day security — they evidence discipline.
  • A readiness position plus a date unblocks more deals than teams expect.
#certification #attestation #audit #penetration-test #questionnaire #comparison