The certification trap
There's a comforting belief in the compliance community that if you can collect enough badges, you've effectively eliminated risk. The logic is simple: get your SOC 2 Type II, secure your CMMC Level 2 certification, tick the GDPR boxes, and you've built a fortress. It turns the act of risk management into a shopping list.
The problem is that we've started treating certificates as substitutes for actual hygiene.
Look at this week's noise. We see firms like MoonPay expanding their SOC 2 certifications to cover more products. At the same time, OSF HealthCare has just paid over half a million dollars to settle a federal privacy claim after a ransomware attack exposed some 54,000 patients. The distance between "certified" and "secure" isn't just a gap; it's a canyon.
When a firm chases a certification, they aren't necessarily fixing their vulnerabilities. They're fixing the evidence of those vulnerabilities. They're ensuring that when an auditor asks for a screenshot of a firewall rule, the screenshot is there. It's a performance.
This performative compliance extends beyond cybersecurity into the broader regulatory sphere. The SEC is currently targeting Registered Investment Advisers who failed to deduct broker-dealer compensation from client fees. This isn't a failure of a complex "risk framework". It's a failure of basic arithmetic and honest bookkeeping. You can have the most sophisticated compliance software on the market, but if your staff doesn't actually subtract the fee from the balance, you're in breach.
The argument for certifications is that they establish a baseline. Proponents say that without these frameworks, we'd have no common language for trust.
That might be true, but the current system encourages a "check-the-box" mentality that actually blinds firms to their own failings. If the auditor didn't ask about it during the window of assessment, the firm assumes the risk doesn't exist. This creates a dangerous lag. We see this in the breach at Paidwork, where over 23 million user records were exposed. I suspect if we looked at their paperwork from six months prior, the "access control" box was likely ticked.
The second-order effect here falls squarely on the auditors and the insurers. For years, insurers have accepted a SOC 2 report as a proxy for a lower risk profile. But as breaches continue to hit firms with pristine paperwork, the insurance market will stop trusting the badge. We'll move toward a world where underwriters demand raw telemetry or continuous monitoring rather than a PDF signed by a third party every twelve months.
The auditors are equally exposed. When a firm that was "certified" last quarter suffers a catastrophic failure, the question inevitably turns to why the auditor didn't spot the gap. The certification becomes a liability for the person who issued it.
Then there is the matter of what we choose to ignore while chasing these badges. While firms obsess over framework alignment, they miss the subtle shift in how regulators are actually thinking. The FTC is currently linking privacy violations with broader consumer protection laws. They aren't looking for a certificate; they're looking at the actual outcome for the consumer.
We've spent a decade building a bureaucracy of proof. We can prove we have a policy. We can prove someone read the policy. We can prove we have a tool to monitor the policy. But as any civil servant will tell you, there is a vast difference between having a process and achieving a result.
The real question for the CISO or the Compliance Officer isn't "Which certification do we need next?" but rather "What is the most basic thing we are currently pretending is handled because it's in our policy manual?".
I suspect many would be horrified by the answer. I'll be watching the SEC's move toward materiality-focused disclosure under Paul Atkins. If they actually strip away the noise and focus on what truly matters, the era of the "compliance badge" might finally end.