STANDARDS AND CERTIFICATIONS
Not every requirement ends in a certificate. Some end in a label, others in an audit report, and three of the ten standards on this page produce no certificate at all, however often the market writes otherwise. Below is what each one is, who tends to ask for it, and where DM11 fits.
What you end up holding
A certificate, issued by an accredited body
The international standard for an information security management system, and the one most often named in tenders and vendor questionnaires. It certifies how the company manages risk rather than any technology, which is why it applies to every sector and forms the base the other standards build on.
See the pageWhat you end up holding
A certificate, and since 2025 without needing ISO 27001
The privacy management system standard. Until 2019 it was an extension and could not be certified without ISO 27001 underneath it; the revision published in October 2025 made the standard stand-alone and removed the barrier that forced a company to build an entire security management system before it could certify privacy. This is the route for a company that already handles data protection in practice and now has to prove it to a customer or a regulator.
See the pageWhat you end up holding
Labels, not a certificate
The automotive industry's assessment and exchange mechanism, run by the ENX Association. The official participant handbook states plainly that no TISAX certificate exists: what you obtain are labels, valid for three years. The assessment is carried out by an accredited audit provider, never by whoever prepared you.
See the pageWhat you end up holding
An independent audit report
A report on your controls, written and signed by an independent audit firm against the trust services criteria set by the AICPA. It is not a certificate and there is no seal: what your customer receives is the full report to read. Type I looks at the design at a point in time; Type II observes the operation across a period.
See the pageWhat you end up holding
Shields, not a certification
The Motion Picture Association's content security assessment, for companies serving studios and streaming platforms. The official guide states that the assessment is not an approval, a certification or a pass/fail: each content owner decides independently, using the result as a baseline. Since September 2025 there are four shields, built on version 5.3.1 of the MPA Best Practices.
See the pageWhat you end up holding
A self-assessment the agency signs itself
IATA requires PCI DSS compliance from anyone handling a passenger's card. For most accredited agencies the route is the self-assessment questionnaire, and the name is no accident: the agency is the one who declares. DM11 organises the environment, reduces the scope and produces the evidence that stands behind that signature.
See the pageWhat you end up holding
An attestation of compliance
The card brands' security standard, mandatory for anyone who stores, processes or transmits cardholder data. How demanding it gets depends on transaction volume and on your role in the chain. Where the route calls for a formal assessment, it is carried out by a QSA accredited by the PCI SSC.
See the pageWhat you end up holding
A technical reference, no certificate
A set of controls in priority order from the Center for Internet Security, with implementation groups by company size. There is no CIS certification: the value is in being the most direct list of where to start, and in bridging to the standards that do certify.
See the pageWhat you end up holding
A technical reference, no certificate
The framework from the US standards institute, organised into functions that run from identify to recover. It is voluntary and cannot be certified, and it is the language a board understands when it needs to follow maturity over time rather than a yes or a no.
See the pageWHERE DM11 FITS
The separation is the same for every standard on this page, and it is not our choice: whoever prepares cannot assess. DM11 runs the gap assessment, builds the plan, implements the controls with your team and organises the evidence in the form the assessor expects. Where your route calls for a formal assessment, it is carried out by an accredited body, audit firm or assessor, with the roles kept apart.
An assessment of what already exists, before any project is proposed
A plan in priority order, with an owner and a date
Implementation alongside your team, not instead of it
A rehearsal of the assessment, so the result stops being a surprise
Reuse across standards: evidence produced once serves several
Bring us the contract clause or the questionnaire you received. We will tell you which standard answers it, what you already have in house that counts, and what is genuinely missing.
Talk to a specialist