Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. STANDARDS AND CERTIFICATIONS

STANDARDS AND CERTIFICATIONS

Your customer asked for an acronym. Start by learning what it delivers.

Not every requirement ends in a certificate. Some end in a label, others in an audit report, and three of the ten standards on this page produce no certificate at all, however often the market writes otherwise. Below is what each one is, who tends to ask for it, and where DM11 fits.

Information security management

  • ISO/IEC 27001

    What you end up holding

    A certificate, issued by an accredited body

    The international standard for an information security management system, and the one most often named in tenders and vendor questionnaires. It certifies how the company manages risk rather than any technology, which is why it applies to every sector and forms the base the other standards build on.

    See the page
  • ISO/IEC 27701

    What you end up holding

    A certificate, and since 2025 without needing ISO 27001

    The privacy management system standard. Until 2019 it was an extension and could not be certified without ISO 27001 underneath it; the revision published in October 2025 made the standard stand-alone and removed the barrier that forced a company to build an entire security management system before it could certify privacy. This is the route for a company that already handles data protection in practice and now has to prove it to a customer or a regulator.

    See the page

Required by your customer

  • TISAX®

    What you end up holding

    Labels, not a certificate

    The automotive industry's assessment and exchange mechanism, run by the ENX Association. The official participant handbook states plainly that no TISAX certificate exists: what you obtain are labels, valid for three years. The assessment is carried out by an accredited audit provider, never by whoever prepared you.

    See the page
  • SOC 2

    What you end up holding

    An independent audit report

    A report on your controls, written and signed by an independent audit firm against the trust services criteria set by the AICPA. It is not a certificate and there is no seal: what your customer receives is the full report to read. Type I looks at the design at a point in time; Type II observes the operation across a period.

    See the page
  • TPN · Trusted Partner Network

    What you end up holding

    Shields, not a certification

    The Motion Picture Association's content security assessment, for companies serving studios and streaming platforms. The official guide states that the assessment is not an approval, a certification or a pass/fail: each content owner decides independently, using the result as a baseline. Since September 2025 there are four shields, built on version 5.3.1 of the MPA Best Practices.

    See the page
  • PCI DSS for IATA agencies

    What you end up holding

    A self-assessment the agency signs itself

    IATA requires PCI DSS compliance from anyone handling a passenger's card. For most accredited agencies the route is the self-assessment questionnaire, and the name is no accident: the agency is the one who declares. DM11 organises the environment, reduces the scope and produces the evidence that stands behind that signature.

    See the page

Payments

  • PCI DSS

    What you end up holding

    An attestation of compliance

    The card brands' security standard, mandatory for anyone who stores, processes or transmits cardholder data. How demanding it gets depends on transaction volume and on your role in the chain. Where the route calls for a formal assessment, it is carried out by a QSA accredited by the PCI SSC.

    See the page

Technical references

  • CIS Controls

    What you end up holding

    A technical reference, no certificate

    A set of controls in priority order from the Center for Internet Security, with implementation groups by company size. There is no CIS certification: the value is in being the most direct list of where to start, and in bridging to the standards that do certify.

    See the page
  • NIST Cybersecurity Framework

    What you end up holding

    A technical reference, no certificate

    The framework from the US standards institute, organised into functions that run from identify to recover. It is voluntary and cannot be certified, and it is the language a board understands when it needs to follow maturity over time rather than a yes or a no.

    See the page

WHERE DM11 FITS

DM11 prepares you. Someone else always assesses.

The separation is the same for every standard on this page, and it is not our choice: whoever prepares cannot assess. DM11 runs the gap assessment, builds the plan, implements the controls with your team and organises the evidence in the form the assessor expects. Where your route calls for a formal assessment, it is carried out by an accredited body, audit firm or assessor, with the roles kept apart.

  • An assessment of what already exists, before any project is proposed

  • A plan in priority order, with an owner and a date

  • Implementation alongside your team, not instead of it

  • A rehearsal of the assessment, so the result stops being a surprise

  • Reuse across standards: evidence produced once serves several

Not sure which one your customer is asking for?

Bring us the contract clause or the questionnaire you received. We will tell you which standard answers it, what you already have in house that counts, and what is genuinely missing.

Talk to a specialist