Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. STANDARDS AND CERTIFICATIONS

STANDARDS AND CERTIFICATIONS

Your customer asked for an acronym. Start by learning what it delivers.

Each of these ends in a different document, and the difference reshapes the whole project. One gives you a certificate from an accredited body, another a label, another an audit report, another a shield, and some are legal obligations or technical references with no document at all. Below is what each one is, what it gives you at the end, who tends to ask for it, and where DM11 fits.

Information security management

  • ISO/IEC 27001

    What you end up holding

    A certificate, issued by an accredited body

    The international standard for an information security management system, and the one most often named in tenders and vendor questionnaires. It certifies how the company manages risk rather than any technology, which is why it applies to every sector and forms the base the other standards build on.

    See the page
  • ISO/IEC 27701

    What you end up holding

    A certificate, and since 2025 without needing ISO 27001

    The privacy management system standard. Until 2019 it was an extension and could not be certified without ISO 27001 underneath it; the revision published in October 2025 made the standard stand-alone and removed the barrier that forced a company to build an entire security management system before it could certify privacy. This is the route for a company that already handles data protection in practice and now has to prove it to a customer or a regulator.

    See the page

Required by your customer

  • TISAX®

    What you end up holding

    Labels, valid for three years

    The automotive industry's assessment and exchange mechanism, run by the ENX Association. The official participant handbook states plainly that no TISAX certificate exists: what you obtain are labels, valid for three years. The assessment is carried out by an accredited audit provider, never by whoever prepared you.

    See the page
  • SOC 2

    What you end up holding

    An independent audit report

    A report on your controls, written and signed by an independent audit firm against the trust services criteria set by the AICPA. It is not a certificate and there is no seal: what your customer receives is the full report to read. Type I looks at the design at a point in time; Type II observes the operation across a period.

    See the page
  • TPN · Trusted Partner Network

    What you end up holding

    Shields published in the TPN+ registry

    The Motion Picture Association's content security assessment, for companies serving studios and streaming platforms. The official guide states that the assessment is not an approval, a certification or a pass/fail: each content owner decides independently, using the result as a baseline. Since September 2025 there are four shields, built on version 5.3.1 of the MPA Best Practices.

    See the page
  • PCI DSS for IATA agencies

    What you end up holding

    A self-assessment the agency signs itself

    IATA requires PCI DSS compliance from anyone handling a passenger's card. For most accredited agencies the route is the self-assessment questionnaire, and the name is no accident: the agency is the one who declares. DM11 organises the environment, reduces the scope and produces the evidence that stands behind that signature.

    See the page

Payments and financial system

  • PCI DSS

    What you end up holding

    An attestation of compliance

    The card brands' security standard, mandatory for anyone who stores, processes or transmits cardholder data. How demanding it gets depends on transaction volume and on your role in the chain. Where the route calls for a formal assessment, it is carried out by a QSA accredited by the PCI SSC.

    See the page
  • Brazilian Central Bank cybersecurity resolutions

    What you end up holding

    A regulatory obligation, and the deadline has passed

    CMN Resolution 4.893/2021 set the cybersecurity policy for financial institutions, and BCB Resolution 85/2021 did the same for payment institutions, in force since 1 August 2021. That text already carried a list of minimum controls, a formally accountable director, an annual report taken to the board by 31 March, and its own rules for contracting data processing, storage and cloud computing, including abroad. On 18 December 2025, CMN Resolution 5.274 and BCB Resolution 538 extended both, with more detailed requirements and specific attention to the Pix and reserve transfer system environments. The compliance deadline for institutions already operating was 1 March 2026, and it has already passed.

    Talk about this standard

Technical references

  • CIS Controls

    What you end up holding

    A measured picture of your state, and a plan in order

    A set of controls in priority order from the Center for Internet Security, with implementation groups by company size. There is no CIS certification: the value is in being the most direct list of where to start, and in bridging to the standards that do certify.

    See the page
  • NIST Cybersecurity Framework

    What you end up holding

    A maturity profile, tracked over time

    The framework from the US standards institute, organised into functions that run from identify to recover. It is voluntary and cannot be certified, and it is the language a board understands when it needs to follow maturity over time rather than a yes or a no.

    See the page
  • OWASP

    What you end up holding

    An open and freely available technical reference

    The foundation behind the most widely used application security references in the world, all of them free. The Top 10 lists the most critical risks in web applications, and the 2025 edition is the first revision since 2021. ASVS 5.0 is the list of verifiable requirements, the one you can write into a contract and actually test against rather than merely discuss. There is also the API Top 10, MAS for mobile applications, the Top 10 for applications built on language models, which is today the reference for generative AI security, and SAMM, for measuring the maturity of your development process. None of them certifies anyone: the value is in being the yardstick your customer and your penetration tester both recognise.

    Talk about this standard
  • PTES

    What you end up holding

    A declared method, making proposals comparable

    The Penetration Testing Execution Standard describes the phases a penetration test moves through, from the pre-engagement agreement to the report. It exists for a practical reason: with no declared method, two tests carrying the same name deliver incomparable work, and the buyer has no way of knowing which one they received. It is what lets you require in the proposal what will happen in each phase, instead of accepting a price for a scope nobody wrote down.

    Talk about this standard
  • MITRE ATT&CK

    What you end up holding

    A public catalogue of attack techniques

    A public knowledge base organising how real attackers behave, by tactic and by technique, drawn from observed cases. It does not tell you what to install: it tells you what the adversary does. It serves to check whether your detection covers what matters, to give your response team a common language, and to let a penetration test show the path it took rather than hand over a loose list of flaws.

    Talk about this standard
  • MITRE ATLAS

    What you end up holding

    A public catalogue of attacks on AI systems

    The same structure as ATT&CK, applied to artificial intelligence and machine learning systems. It covers what ATT&CK does not: training data poisoning, model extraction, input manipulation and the attacks that exploit the model itself rather than the infrastructure around it. It is the reference missing from most AI assessments, which still test the server rather than the model.

    Talk about this standard

Brazilian regulation

  • LGPD

    What you end up holding

    A legal obligation, for a company of any size

    Brazil's General Data Protection Law applies to any company processing personal data in the country, with no opt-out and no minimum size. There is no LGPD certificate, and anyone offering one is selling something else: what exists is demonstrable compliance, with an inventory of processing activities, a recorded legal basis, a route for data subject requests and a named officer. When you have to prove that to a customer or a regulator with a third-party document, the route is ISO 27701.

    See the page

WHERE DM11 FITS

DM11 prepares you. Someone else always assesses.

The separation is the same for every standard on this page, and it is not our choice: whoever prepares cannot assess. DM11 runs the gap assessment, builds the plan, implements the controls with your team and organises the evidence in the form the assessor expects. Where your route calls for a formal assessment, it is carried out by an accredited body, audit firm or assessor, with the roles kept apart.

  • An assessment of what already exists, before any project is proposed

  • A plan in priority order, with an owner and a date

  • Implementation alongside your team, not instead of it

  • A rehearsal of the assessment, so the result stops being a surprise

  • Reuse across standards: evidence produced once serves several

Not sure which one your customer is asking for?

Bring us the contract clause or the questionnaire you received. We will tell you which standard answers it, what you already have in house that counts, and what is genuinely missing.

Talk to a specialist