Attestation
An attestation is a formal declaration by a vendor confirming that specific security controls are in place. Attestations are a standard component of questionnaire-based assessments but are self-reported, unlike outside-in technical ratings, which are independently observed.
Attestation is a vendor's formal declaration that specific security controls are in place, typically backed by an independent audit such as a SOC 2 report. It's a standard part of questionnaire-based assessments, and like the questionnaire itself, it's evidence the vendor supplies, not the independently observed data behind an outside-in rating.
In cybersecurity, attestation is about assurance, not signatures. It's distinct from the legal sense of witnessing a document or notarizing a signature. Here it means a credible claim that a set of controls exists and works, most often delivered as a SOC 2 report or an ISO 27001 certificate.
The value of an attestation rests entirely on who verified it and what they actually looked at, which is why two attestations that sound identical can be worth very different things. A logo on a report means little until you know the standard behind it and the scope it covers.
What Are the Types of Attestation?
Attestation comes in a few forms, and they differ mainly in who does the verifying. The distinction that matters most is whether an independent party stands behind the claim:
- Third-party attestation: an independent auditor verifies the controls, as in a SOC 2 report.
- Certification: an accredited body confirms a standard is met, as with ISO 27001.
- Self-attestation: the organization attests to its own controls, with no outside check.
Type II Attestations Test Controls Over Time
A SOC 2 has two flavors, and the difference is bigger than it looks.
- Type I checks that controls are designed correctly on a single day.
- Type II tests whether they actually operated across a period, often six to twelve months.
That's why a Type II sits near the top of the credibility ladder, because a control that works for a day is easy to stage and a control that works for a year is not. Self-attestation sits at the bottom, since nobody independently checked it, and a claim you make about yourself is only as good as your candor.
Between those poles sit certifications, which carry the weight of an accredited body but vary widely in how deeply they test what they certify.
How Is Attestation Used in Third-Party Risk Management?
In third-party risk management, an attestation lets a vendor prove its security once and share that proof with many customers. Instead of answering every customer's questionnaire from scratch, a vendor hands over a SOC 2 report or an ISO certificate that an outside auditor has already tested against a defined standard. That shifts the work in a few ways:
- Independently tested: an outside auditor has already checked the claim against a defined standard, instead of the customer taking the vendor's word for it.
- Faster review: the customer reads one tested artifact instead of scoring a fresh questionnaire from scratch.
- Less busywork for the vendor: it maintains one rigorous report rather than a hundred inconsistent questionnaire answers.
- A shared input: attestations are still a standard part of the same questionnaire-based assessment as the forms themselves, feeding the same third party risk assessment process, and carry more weight because someone independently stood behind the work.
A program still has to read the fine print, though. An attestation's value depends entirely on what it actually covers, and the most important details are usually in the scope section that nobody reads.
How Is Attestation Different From a Security Questionnaire?
An attestation is verified by an independent party, while a security questionnaire is filled out by the vendor itself. That single difference drives everything else. A security questionnaire is flexible, cheap, and easy to tailor, but it's self-reported and only as honest as the person filling it in. An attestation is credible and hard to game, but it's narrow, periodic, and expensive to produce. Neither replaces the other. Strong due diligence uses the questionnaire to ask the questions and the attestation to check the answers, then treats any gap between the two as a flag worth chasing rather than a rounding error.
Where Does Attestation Fall Short?
An attestation proves something was true for a defined scope during a defined window, and no more. Three limits deserve attention:
- It's point-in-time. A clean SOC 2 from last year says little about today, and the window is widening. Black Kite's 2026 Third-Party Breach Report found that breaches now take an average of 117 days from discovery to public disclosure, up from 76 days the year before. A vendor can be compromised, know it, and still be sitting inside a valid audit window when you read its report.
- Scope is everything. A report can exclude the exact system that later gets breached.
- It rests on trust in the auditor and the boundary the vendor chose to test, which leaves room for a favorable review window or a carefully drawn scope.
A Clean Attestation Is Not Immunity
The cautionary case is a vendor that looks fine on paper and still gets breached. When Okta became a third-party incident that rippled out to its customers, Black Kite's own monitoring had it carrying a respectable B rating with red flags sitting behind the grade. An attestation is evidence, not immunity. The paperwork tells you a vendor was in good shape when the auditor visited. It says nothing about the port that opened last week or the credentials that leaked yesterday, and attackers work in that gap on purpose.
How Does Continuous Monitoring Complement Attestation?
Continuous monitoring fills the gap between attestations by watching a vendor's real posture every day, not once a year. An attestation tells you a vendor passed an audit. It can't tell you the vendor opened a risky port last week or turned up in a breach yesterday. The certificate is a photo, and the vendor keeps living after the shutter clicks.
Pair Periodic Proof With a Live Signal
Pairing the periodic proof of an attestation with continuous monitoring of outside-in evidence gives a program both the depth of an audit and the freshness of live data. That combination is the backbone of modern vendor compliance management, where a static certificate and a live risk signal finally sit side by side. It also keeps a clean attestation from lulling a program into compliance that looks complete on paper and stale in practice. The attestation still matters, because it proves depth an outside scan can't. The monitoring matters because it proves currency the attestation can't. Used together, they answer the two questions a third-party risk program actually cares about, whether this vendor was built well and whether it's holding up right now.