Skip to content

Attestation

What is Attestation?

A formal declaration by an independent party (such as a CPA firm) that an organisation's controls or processes meet specified criteria. SOC reports are a form of attestation, distinct from certification.

Compliance

Each of these is named in at least one of the same controls as attestation. The number is how many controls name both.

What the standards actually require on attestation

Requirements naming attestation across 6 standards, quoted from the control text.

Enterprise attestation per WebAuthn L3 6.5.4 + CTAP2.1. Standard attestation is ANONYMOUS per AAGUID batch (so individual authenticators are not identifiable) to protect privacy. ENTERPRISE ATTESTATION carries the AUTHENTICATOR-UNIQUE IDENTIFIER (e.g.

FIDO2-Enterprise-Attestation · Enterprise Attestation and AAGUID Allowlisting

Sets the Annex V requirements for qualified electronic attestations of attributes (incl. verification of the attributes' accuracy and binding to the subject), and provides for their use in public services (Art 45c).

EIDAS-Art.45d · Requirements for qualified electronic attestation of attributes
SLSA6 controls

Produce Verification Summary Attestations after verifying an artifact, so downstream consumers can rely on the verification result without rerunning all checks.

SLSA-VSA-1 · Verification Summary Attestation

The practitioner must consider materiality when planning procedures and evaluating findings, recognising that materiality in attestation may be qualitative as well as quantitative.

SSAE-11 · Materiality in Attestation

STAR Attestation, developed in collaboration with the AICPA, is a third-party attestation that combines a SOC 2 examination with the CCM criteria, performed by a licensed CPA firm.

STAR-L2-02 · STAR Attestation (SOC 2 + CCM)

An attestation is provided confirming that the test was conducted in accordance with the TIBER-EU requirements.

TIBER-3.7 · Attestation

Questions people ask about attestation

What is Attestation?
A formal declaration by an independent party (such as a CPA firm) that an organisation's controls or processes meet specified criteria. SOC reports are a form of attestation, distinct from certification.
Why is Attestation important for compliance?
Attestation is a key concept in Compliance. Understanding attestation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Attestation?
Attestation appears in the requirement text of FIDO2 / WebAuthn, eIDAS 2.0 - EU Digital Identity Regulation, SLSA, SSAE 18 - Attestation Standards (SOC Reporting), CSA STAR (Security, Trust, Assurance, and Risk). Across these standards we have identified 32 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Attestation?
Explore our compliance framework pages to see how attestation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Attestation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.