What are compliance certifications and attestations?
Compliance certifications and attestations are independent confirmations that an organization meets a security standard. The most common for SaaS vendors are SOC 2 reports and ISO/IEC 27001 certification. Others include PCI DSS, HIPAA assessments, and FedRAMP for US government work.
What the buyer is really asking
List only the certifications and reports you hold today, with their dates and scope. For one in progress, give the stage and expected date. Never list a framework you "align with" as if it were a certification.
Other ways buyers ask it
Every one of these wants the same answer:
- “What compliance certifications do you maintain?”
- “Do you have a SOC 2 Type II report?”
- “Are you ISO 27001 certified?”
- “Can you share your latest audit report?”
Evidence to have ready
- SOC 2 report or ISO 27001 certificate with dates
- A letter from your auditor for work in progress
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.