InsightsBy Dr Rizwan Ahmad and Syed Saad Arshad Kazmi · 04 Aug 2026 · 9 min readShare on LinkedIn

Assurance That Matters: Five Tests That Separate Assurance From Reassurance

Assurance is one of the most used and least examined words in cybersecurity. Five tests, and one question underneath them, that determine whether an assessment is worth relying on.

Assurance has become one of the most heavily used words in cybersecurity, and one of the least examined. It appears in service catalogues, capability statements and procurement documents across the industry, usually without anyone stopping to ask what it is supposed to mean or what would have to be true for it to be worth anything.

That matters, because assurance is not a deliverable. It is a transfer of confidence. When an organisation says it has assurance over a control, a system or a supplier, it is saying that someone else’s judgement is now standing behind a decision it would otherwise have to make blind. The question that follows is uncomfortable and rarely asked: on what basis should that confidence be extended?

This is our answer, and it is the reason our work carries the line “assurance that matters”. Not all assurance does.

What assurance is actually for

Assurance exists to reduce uncertainty for someone who is relying on it. Usually that someone is not the organisation buying the engagement. It is a bank deciding whether to accept a merchant’s risk, a customer deciding whether to hand over their data, a regulator deciding whether an entity is meeting its obligations, or a board deciding whether it has discharged its duty.

That third-party dependence is the whole point, and it sets a high bar. A report that only satisfies the organisation that commissioned it has not produced assurance. It has produced reassurance, which is a different and considerably cheaper commodity. The difference between the two is the subject of everything that follows.

Five tests of assurance that matters

1. Is the independence structural, or merely stated?

Almost every provider in this market describes itself as independent. The word costs nothing to claim. What distinguishes genuine independence is whether it is enforced by something outside the provider’s own goodwill.

Accredited certification bodies operate under ISO/IEC 17021-1, which does not permit a body to provide consultancy to an organisation and then certify that same organisation. The prohibition is not a courtesy. It is a condition of accreditation, it is audited, and breaching it costs the body its status. The same logic underpins the PCI Security Standards Council’s rules for Qualified Security Assessors.

This creates an obligation that most buyers never see: an accredited body has to be willing to lose revenue to preserve its position. A provider that can both advise you on your controls and then attest to them has no such constraint. That may be perfectly ethical in practice, but the safeguard is a promise rather than a structure, and promises are not what assurance is supposed to rest on.

2. Who assures the assurer?

This is the question we have argued matters most, including in our published research and in our submission to the Australian Government’s consultation on critical infrastructure reform. If an organisation relies on a certificate, the value of that certificate depends entirely on the credibility of whoever issued it.

There is an established chain for this. Accreditation bodies operate under ISO/IEC 17011 and accredit certification bodies against ISO/IEC 17021-1. Those accreditation bodies are themselves peer-evaluated through international arrangements, which is what allows a certificate issued in one country to be recognised in another. In payments, the PCI Security Standards Council performs the equivalent function, qualifying assessor companies, requalifying them annually and publishing them on a register anyone can search.

Where that chain is absent, a certificate is a document produced by a company that decided it was qualified to produce it. Sometimes that judgement is sound. But the recipient has no way to tell, and “trust us” is precisely what assurance is meant to replace.

3. Is it evidence against a defined standard, or an opinion?

Assurance that matters is testable. It states what was assessed, against which requirements, using what procedures, over what scope and period, and what evidence was examined. Someone reading it later can follow the reasoning and see where the conclusion came from.

A PCI DSS Report on Compliance runs to hundreds of pages for exactly this reason. An ISO management system audit follows documented criteria and produces findings that trace to clauses. The rigour is not bureaucracy for its own sake. It is what makes the conclusion reviewable by someone who was not in the room, which is the only way a third party can safely rely on it.

An assessment that produces a favourable summary without that underlying structure is asking the reader to accept a verdict without the case.

4. Is the competence tested, current and named?

Standards specify who may perform the work. Qualified Security Assessors sit examinations, requalify on a defined cycle and work under a quality-management regime their assessor company must maintain. ISO auditors must demonstrate competence in both auditing and the technical field, and certification bodies must evidence that competence to their accreditation body.

There is a simple diagnostic here for buyers. Ask who will actually perform the assessment, what they are qualified to do, and whether their name will appear on the report. Assurance that matters is signed. Somebody stakes their professional standing on the conclusion, and can be found afterwards if it turns out to be wrong.

5. Can you verify it without taking anyone’s word?

The final test is the most practical. A claim of accredited status should be checkable at source, in a register maintained by the accrediting authority rather than the provider. If verification depends on a logo on a website or a PDF supplied by the party being assessed, it is not verification.

We publish our own register listing prominently for this reason, and we encourage prospective clients to check it rather than take our description of ourselves at face value. A provider that is genuinely accredited loses nothing by inviting that scrutiny.

The test underneath all five: could it have failed?

There is a question that sits beneath the others, and it is the one we would ask if we were buying assurance rather than providing it.

Was there a realistic possibility that this engagement would conclude unfavourably?

If the answer is no, whatever was purchased was not assurance. An assessment that can only ever confirm what the client hoped to hear carries no information. Its conclusion was determined before the work began. The uncomfortable corollary is that a provider whose commercial model depends on clients passing has an interest that competes with the reliability of its own opinion, and the people relying on that opinion are usually not the people paying for it.

This is why we treat the ability to deliver an adverse finding as the defining feature of the work rather than an unfortunate risk of it. An assessor who cannot say no is not performing assurance. They are performing agreement.

Why the distinction is becoming sharper

Three developments are converging to make loose assurance harder to sustain.

Regulators are asking who signed. The Australian Government’s critical infrastructure reforms have raised the prospect of mandatory independent assurance over risk management programmes, and the surrounding debate has focused specifically on the competence and independence of whoever performs it. Australia’s prudential regime already requires independent review by appropriately skilled and functionally independent specialists. The direction of travel is towards asking not merely whether an assessment happened, but whether the person performing it was qualified and free to disagree.

Standards are tightening the evidence. PCI DSS v4.0.1 pushed the standard away from point-in-time confirmation towards continuous, evidenced operation of controls. The newer requirements are considerably harder to satisfy with documentation alone.

AI is raising the stakes and the scrutiny. ISO/IEC 42001 arrived because organisations deploying AI needed a way to demonstrate governance to people who cannot inspect the systems themselves. We conducted the certification audit behind New Zealand’s first ISO/IEC 42001 certification, and the experience reinforced the point of this article: the certificate matters because of what stood behind it, not because of the logo on it.

What to ask before you buy assurance

If you are commissioning an assessment, certification or audit, these questions separate the substantive from the superficial. They are also fair questions to ask us.

  1. Who accredits or qualifies you, and where can I verify that independently?
  2. Are you permitted to consult on the same controls you assess, and if so, how is that managed?
  3. Who specifically will perform the work, what are their qualifications, and will they be named in the report?
  4. Against which standard and which version, over what scope and what period?
  5. What would cause you to issue an adverse conclusion, and when did you last do so?
  6. Who is entitled to rely on the resulting report, and what does it actually say they may rely on?

A provider offering assurance that matters will answer all six without discomfort, because the answers are the product.

Frequently asked questions

What is the difference between assurance and consultancy?

Consultancy helps an organisation design, build or improve its controls. Assurance provides an independent opinion, for the benefit of third parties, on whether those controls meet a defined standard. Under ISO/IEC 17021-1 an accredited certification body cannot do both for the same client, because advising on a control and then attesting to it compromises the independence the attestation depends on.

Why does accreditation matter if the assessor is competent?

Because the person relying on the report usually cannot assess competence directly. Accreditation under ISO/IEC 17011 and ISO/IEC 17021-1, or qualification through the PCI Security Standards Council, provides an external, auditable check on competence, impartiality and method, and it is verifiable on a public register. Without it, a buyer is relying on a self-assessment of the assessor.

How can I verify that a certification body or QSA is genuinely accredited?

Check the register maintained by the accrediting or qualifying authority rather than material supplied by the provider. PCI Qualified Security Assessor companies are listed on the PCI Security Standards Council’s website, and accredited certification bodies are listed by their accreditation body. Verification that depends on a logo or a supplied PDF is not verification.

What makes an assessment worth relying on?

It states the standard and version, the scope and period, the procedures performed and the evidence examined, and it is signed by named, qualified people. Crucially, there must have been a genuine possibility of an adverse conclusion. An assessment that could only ever confirm the desired outcome conveys no information to the third parties relying on it.

Assurance that matters

Cianaa is an independent certification and assessment body operating across New Zealand and Australia. We are a PCI Qualified Security Assessor registered with the PCI Security Standards Council since 2014 and a PCI 3DS Assessor, and our ISO auditors work within the accredited certification framework. We do not consult on the controls we assess, and our listings can be verified at source.

If you want assurance that will hold up in front of the people who will actually rely on it, talk to our assessors, read our impartiality commitment, or browse our open-access research.

Compliance assurance

Talk to Cianaa Technologies

Talk to Cianaa Technologies for independent, evidence-based compliance assurance across the Australasian region.

Book a discovery call
Enjoyed this article?

Get the next one in your inbox

One email when we publish. Written by named auditors, never by a marketing robot. Unsubscribe anytime with one click.

Double opt-in. No spam, no list-selling, covered by our privacy policy.

Similar Posts