Ask what the security claim actually supports
Statements such as enterprise-grade or security-focused need clarification before they can support a buying decision. Ask which control, service or independently assessed scope the vendor means rather than assuming the phrase is evidence. ISO: certification and accreditation
What a certification actually is, underneath the badge
Assurance documents differ. A management-system certificate, product certification, PCI attestation and SOC report have different subjects, methods and conclusions. Identify the document type and issuer before deciding what it demonstrates.
A current, relevant independent assessment can contribute evidence, but it is not a guarantee of service quality or freedom from incidents. An uncertified supplier may still provide useful control evidence; evaluate it against the risk and any mandatory procurement requirements.
What “checked properly” actually requires
The certificate itself, not a logo on a website — logos can be outdated, aspirational, or simply incorrect, and the actual certificate or attestation document is what carries the scope and date information that matters.
The scope statement, specifically — a certification can apply to one business unit, one location or one product line while the rest of the vendor’s business sits outside it entirely, and a buyer who doesn’t check scope can assume coverage that does not exist.
Check current status using the issuer or appropriate verification route, and read the applicable review or expiry arrangements. Do not assume all assurance documents have the same validity period or renewal process.
Relevance to what you are actually buying — a certification that is real, current and correctly scoped can still be irrelevant to the specific risk your engagement creates, if it covers a different part of the vendor’s operation than the one doing your work.
The question this actually answers
Ask what was assessed, for which entity and service, using which criteria, over what date or period, and with what limitations. Then decide whether that evidence answers the risk question in your proposed engagement.
Where this fits into how Bravewall works
Depending on the requirement, relevant certifications and independent assurance reports can help assess a technology or delivery contribution. Review scope, currency and relevance alongside practical capability and agreed responsibilities.
Build a short assurance register for the purchase
ISO distinguishes standards development from certification and accreditation. Use that distinction as a starting point, then apply the relevant scheme’s own terminology rather than calling every assurance document a certificate.
- Document type: record whether it is a certificate, attestation, examination report or training credential. For a SOC report, read its type, period, scope, exceptions and customer responsibilities; do not relabel it as an ISO-style certification.
- Identity and scope: match the legal entity and delivered service to the assessment. If infrastructure is hosted by another provider, distinguish the host’s evidence from the application vendor’s responsibilities. One organisation’s assurance does not automatically extend to another.
- Verification: record the issuer, reference number where applicable, current status and check date. Use an official directory or the issuer’s confirmation route. Do not rely solely on an image of a badge embedded in a sales presentation.
- Engagement relevance: identify the risk the evidence addresses and the remaining question. For example, a scoped management-system certificate may support governance assurance while a demonstration is still needed for privileged-access controls in your service.
- Decision: record accepted evidence, unresolved gaps, contractual conditions and the next review trigger. Assign residual risk to the authorised buyer-side owner; the presence of a certificate should not silently close every procurement question.
Ask for proportionate, shareable evidence and respect the confidentiality of reports. Where full disclosure is restricted, agree a suitable summary, controlled review or scoped confirmation. This approach evaluates evidence without implying that Bravewall or any unnamed contributor holds a particular credential, and without treating a badge as a substitute for delivery responsibility.

