Attestation
What is Attestation?
A formal declaration by an independent party (such as a CPA firm) that an organisation's controls or processes meet specified criteria. SOC reports are a form of attestation, distinct from certification.
Terms that appear alongside attestation
Each of these is named in at least one of the same controls as attestation. The number is how many controls name both.
- nist 18 shared controls
- compliance 16 shared controls
- integrity 15 shared controls
- audit 13 shared controls
- authentication 11 shared controls
- iso 27001 11 shared controls
- soc 2 11 shared controls
- cybersecurity 10 shared controls
Frameworks that govern attestation
What the standards actually require on attestation
Requirements naming attestation across 6 standards, quoted from the control text.
Enterprise attestation per WebAuthn L3 6.5.4 + CTAP2.1. Standard attestation is ANONYMOUS per AAGUID batch (so individual authenticators are not identifiable) to protect privacy. ENTERPRISE ATTESTATION carries the AUTHENTICATOR-UNIQUE IDENTIFIER (e.g.
FIDO2-Enterprise-Attestation · Enterprise Attestation and AAGUID Allowlisting →Sets the Annex V requirements for qualified electronic attestations of attributes (incl. verification of the attributes' accuracy and binding to the subject), and provides for their use in public services (Art 45c).
EIDAS-Art.45d · Requirements for qualified electronic attestation of attributes →Produce Verification Summary Attestations after verifying an artifact, so downstream consumers can rely on the verification result without rerunning all checks.
SLSA-VSA-1 · Verification Summary Attestation →The practitioner must consider materiality when planning procedures and evaluating findings, recognising that materiality in attestation may be qualitative as well as quantitative.
SSAE-11 · Materiality in Attestation →STAR Attestation, developed in collaboration with the AICPA, is a third-party attestation that combines a SOC 2 examination with the CCM criteria, performed by a licensed CPA firm.
STAR-L2-02 · STAR Attestation (SOC 2 + CCM) →An attestation is provided confirming that the test was conducted in accordance with the TIBER-EU requirements.
TIBER-3.7 · Attestation →Questions people ask about attestation
What is Attestation?
Why is Attestation important for compliance?
Which compliance frameworks address Attestation?
Where can I learn more about Attestation?
See how Attestation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.