Certifications and audit status
This page states what the firm holds, what is under way with a target, and what has not been started. It is deliberately specific. A security questionnaire that arrives before the second meeting should be answerable from this page.
| Certification | State | Detail |
|---|---|---|
| SOC 2 Type II | Input pending | Readiness position and target date are being confirmed (D-G). No claim is made here until it is. |
| ISO/IEC 27001 | Not started | Not held and not currently in scope. Stated rather than omitted. |
| Group-level attestations | Input pending | Where a certification is held at group level by GDA Group rather than by the practice, it will be named here and linked to the canonical record on gda.group (D-I). |
Where an engagement requires a certification the practice does not hold, we say so at the first meeting rather than at vendor review.
Why this page is specific rather than reassuring
A trust page that implies certifications it does not hold fails at exactly the moment it matters: a vendor-review analyst asks for the report, and there is no report. The cost of that is not a lost certification — it is that everything else the firm has published is now treated as unverified.
The firm’s real certification position is an open input (D-G). Until it is confirmed, this page says so rather than filling the gap, and the gaps page tracks it alongside everything else that is not finished.