STANDARDS AND CERTIFICATIONS
Each of these ends in a different document, and the difference reshapes the whole project. One gives you a certificate from an accredited body, another a label, another an audit report, another a shield, and some are legal obligations or technical references with no document at all. Below is what each one is, what it gives you at the end, who tends to ask for it, and where DM11 fits.
What you end up holding
A certificate, issued by an accredited body
The international standard for an information security management system, and the one most often named in tenders and vendor questionnaires. It certifies how the company manages risk rather than any technology, which is why it applies to every sector and forms the base the other standards build on.
See the pageWhat you end up holding
A certificate, and since 2025 without needing ISO 27001
The privacy management system standard. Until 2019 it was an extension and could not be certified without ISO 27001 underneath it; the revision published in October 2025 made the standard stand-alone and removed the barrier that forced a company to build an entire security management system before it could certify privacy. This is the route for a company that already handles data protection in practice and now has to prove it to a customer or a regulator.
See the pageWhat you end up holding
Labels, valid for three years
The automotive industry's assessment and exchange mechanism, run by the ENX Association. The official participant handbook states plainly that no TISAX certificate exists: what you obtain are labels, valid for three years. The assessment is carried out by an accredited audit provider, never by whoever prepared you.
See the pageWhat you end up holding
An independent audit report
A report on your controls, written and signed by an independent audit firm against the trust services criteria set by the AICPA. It is not a certificate and there is no seal: what your customer receives is the full report to read. Type I looks at the design at a point in time; Type II observes the operation across a period.
See the pageWhat you end up holding
Shields published in the TPN+ registry
The Motion Picture Association's content security assessment, for companies serving studios and streaming platforms. The official guide states that the assessment is not an approval, a certification or a pass/fail: each content owner decides independently, using the result as a baseline. Since September 2025 there are four shields, built on version 5.3.1 of the MPA Best Practices.
See the pageWhat you end up holding
A self-assessment the agency signs itself
IATA requires PCI DSS compliance from anyone handling a passenger's card. For most accredited agencies the route is the self-assessment questionnaire, and the name is no accident: the agency is the one who declares. DM11 organises the environment, reduces the scope and produces the evidence that stands behind that signature.
See the pageWhat you end up holding
An attestation of compliance
The card brands' security standard, mandatory for anyone who stores, processes or transmits cardholder data. How demanding it gets depends on transaction volume and on your role in the chain. Where the route calls for a formal assessment, it is carried out by a QSA accredited by the PCI SSC.
See the pageWhat you end up holding
A regulatory obligation, and the deadline has passed
CMN Resolution 4.893/2021 set the cybersecurity policy for financial institutions, and BCB Resolution 85/2021 did the same for payment institutions, in force since 1 August 2021. That text already carried a list of minimum controls, a formally accountable director, an annual report taken to the board by 31 March, and its own rules for contracting data processing, storage and cloud computing, including abroad. On 18 December 2025, CMN Resolution 5.274 and BCB Resolution 538 extended both, with more detailed requirements and specific attention to the Pix and reserve transfer system environments. The compliance deadline for institutions already operating was 1 March 2026, and it has already passed.
Talk about this standardWhat you end up holding
A measured picture of your state, and a plan in order
A set of controls in priority order from the Center for Internet Security, with implementation groups by company size. There is no CIS certification: the value is in being the most direct list of where to start, and in bridging to the standards that do certify.
See the pageWhat you end up holding
A maturity profile, tracked over time
The framework from the US standards institute, organised into functions that run from identify to recover. It is voluntary and cannot be certified, and it is the language a board understands when it needs to follow maturity over time rather than a yes or a no.
See the pageWhat you end up holding
An open and freely available technical reference
The foundation behind the most widely used application security references in the world, all of them free. The Top 10 lists the most critical risks in web applications, and the 2025 edition is the first revision since 2021. ASVS 5.0 is the list of verifiable requirements, the one you can write into a contract and actually test against rather than merely discuss. There is also the API Top 10, MAS for mobile applications, the Top 10 for applications built on language models, which is today the reference for generative AI security, and SAMM, for measuring the maturity of your development process. None of them certifies anyone: the value is in being the yardstick your customer and your penetration tester both recognise.
Talk about this standardWhat you end up holding
A declared method, making proposals comparable
The Penetration Testing Execution Standard describes the phases a penetration test moves through, from the pre-engagement agreement to the report. It exists for a practical reason: with no declared method, two tests carrying the same name deliver incomparable work, and the buyer has no way of knowing which one they received. It is what lets you require in the proposal what will happen in each phase, instead of accepting a price for a scope nobody wrote down.
Talk about this standardWhat you end up holding
A public catalogue of attack techniques
A public knowledge base organising how real attackers behave, by tactic and by technique, drawn from observed cases. It does not tell you what to install: it tells you what the adversary does. It serves to check whether your detection covers what matters, to give your response team a common language, and to let a penetration test show the path it took rather than hand over a loose list of flaws.
Talk about this standardWhat you end up holding
A public catalogue of attacks on AI systems
The same structure as ATT&CK, applied to artificial intelligence and machine learning systems. It covers what ATT&CK does not: training data poisoning, model extraction, input manipulation and the attacks that exploit the model itself rather than the infrastructure around it. It is the reference missing from most AI assessments, which still test the server rather than the model.
Talk about this standardWhat you end up holding
A legal obligation, for a company of any size
Brazil's General Data Protection Law applies to any company processing personal data in the country, with no opt-out and no minimum size. There is no LGPD certificate, and anyone offering one is selling something else: what exists is demonstrable compliance, with an inventory of processing activities, a recorded legal basis, a route for data subject requests and a named officer. When you have to prove that to a customer or a regulator with a third-party document, the route is ISO 27701.
See the pageWHERE DM11 FITS
The separation is the same for every standard on this page, and it is not our choice: whoever prepares cannot assess. DM11 runs the gap assessment, builds the plan, implements the controls with your team and organises the evidence in the form the assessor expects. Where your route calls for a formal assessment, it is carried out by an accredited body, audit firm or assessor, with the roles kept apart.
An assessment of what already exists, before any project is proposed
A plan in priority order, with an owner and a date
Implementation alongside your team, not instead of it
A rehearsal of the assessment, so the result stops being a surprise
Reuse across standards: evidence produced once serves several
Bring us the contract clause or the questionnaire you received. We will tell you which standard answers it, what you already have in house that counts, and what is genuinely missing.
Talk to a specialist