Attestation
Also known as: Independent verification, Third-party assurance
A formal declaration by an independent practitioner that a subject matter meets specific criteria. It provides external verification that internal controls are functioning as claimed by the organization.
Why it matters
Without this, a company cannot prove its security posture to enterprise clients during procurement. An auditor may issue a "qualified" opinion if gaps exist, signaling high risk to stakeholders. This failure often results in lost revenue or breached contractual SLAs. Ultimately, the CISO or CFO is accountable for the accuracy of these claims.
In practice
A licensed CPA firm typically handles this during a SOC 2 audit. They request evidence such as system-generated logs and policy sign-offs during the testing phase. This process produces an Attestation Report, which summarizes the auditor's findings and opinion. In a first-year engagement, the focus is on establishing the control baseline. Repeat engagements concentrate on the "period of performance," verifying that controls remained effective over time.
Worked example
FinTechFlow needed a SOC 2 Type II report for its Q4 2023 audit. The auditor examined the "Logical Access" control, specifically requesting evidence of monthly password rotations. They discovered that 15% of administrative accounts had not changed passwords in over 90 days. This finding was documented as an exception in the final report. Consequently, FinTechFlow received a qualified opinion rather than a clean one.
Common mistakes
- Confusing it with self-certification; this leads to legal risk when clients discover no independent party verified the controls.
- Signing management assertions without reviewing supporting evidence first, which can lead to inaccurate reporting.
- Failing to align the testing window with the actual report date, causing gaps in coverage.
- Assuming a "clean" report means zero risks exist; it only means controls met the specified criteria.
Frequently asked questions
What is the difference between attestation and certification?
Certification usually confirms an entity meets a standard, whereas attestation is a formal statement by a third party about specific subject matter. For example, ISO 27001 is a certification; SOC 2 is an attestation.
How do I prepare for a SOC 2 attestation?
Start by defining your Trust Services Criteria and gathering evidence like screenshots and logs for every control. Perform a gap analysis to find weaknesses before the auditor arrives.
Who is qualified to provide an official attestation?
In many frameworks, such as SOC 2, only a licensed CPA (Certified Public Accountant) or a registered firm can issue the final report. Other auditors may perform assessments, but they cannot "attest" in the formal accounting sense.
What evidence is typically required for an attestation?
Auditors look for population lists and samples, such as a list of all new hires followed by their signed NDAs. They also require configuration screenshots and change tickets to prove controls are active.
When does an attestation report expire?
While reports do not technically "expire," most enterprise clients require one dated within the last 12 months. This ensures the security posture is current and not based on outdated data.
More terms
Working papers · High-risk AI system · Materiality · Readiness assessment · Sampling · Data Protection Impact Assessment · Records of processing activities · Products with digital elements