Certification boundary
Readiness vs certification
Netallion helps an organisation understand, evidence and improve its readiness for an external assessment or certification — and prepares a structured handoff for the body that performs it. Netallion does not certify, accredit, or guarantee compliance, and its outputs are not certificates.
This page is the boundary. It is deliberately plain, and it is true today.
What Netallion is
- An evidence assurance and compliance-readiness platform.
- A tool to collect and organise evidence — and, on assessed engagements, to assess whether that evidence sufficiently supports each applicable requirement, preserve the assessment and review history, and produce a traceable readiness result.
- A producer of preparation and handoff artefacts: a readiness report, evidence index, Statement of Applicability, gap tracker, and an audit-ready export with a SHA-256 integrity manifest.
- A workspace that supports human review, challenge and override of findings, where those operating processes exist for the engagement.
What Netallion is not
- Not a certification body and not accredited by any accreditation body (for example, under the IAF/ILAC framework).
- Not an issuer of certificates — no Netallion output is, or implies, a certificate.
- Not a guarantee of compliance, certification success, or audit outcome.
- Not a real-time or continuous compliance monitor. Assessment is of uploaded, periodic evidence; there is no real-time control telemetry.
- Not a licensed audit firm. Netallion has no in-house licensed audit delivery, and does not imply equivalence to one.
The ecosystem
Who does what
Certification is an ecosystem. Netallion occupies one clearly-bounded place in it.
| Actor | Role | Netallion’s relationship |
|---|---|---|
| Standards body (e.g. ISO) | Develops the standard; does not certify organisations. | Netallion maps controls to the standard’s requirements. |
| Accreditation body (e.g. under IAF) | Accredits certification bodies. | None — Netallion is not accredited. |
| Certification body / auditor | Performs the accredited audit and issues the certificate. | Netallion prepares the evidence handoff for this body; it does not replace it. |
| Independent assessor / consultant | Delivers a readiness opinion — not a certificate. | Netallion is the workspace; the opinion is the assessor’s, under their competence and independence. |
| Netallion | Readiness + evidence assurance + handoff preparation. | The boundary stated at the top of this page. |
The provenance ladder
Every output is labelled with the highest review level it actually reached — never above it
The ladder has four rungs, and Netallion only ever stands on the first three.
| Level | Meaning | Permitted label | Must NOT be called |
|---|---|---|---|
| Self-Assessed (R0–R2) | System/AI findings and/or your own self-attestation. | “Self-assessed readiness”; “indicative”. | reviewed, independent, assessor-approved, certified. |
| Reviewed (R3) | An authorised assessor — a distinct identity — reviewed and finalised the findings. | “Reviewed readiness assessment”. | certified, accredited, compliant. |
| Independent (R3 + independence) | R3 where the reviewer is genuinely independent of implementation, with no invalidating conflict. | “Independent readiness assessment”. | certification, accredited certificate. |
| Certification | Issued by an accredited certification body. | Netallion never issues this. | — |
The label is derived, never typed. A user cannot select a higher rung than the engagement earned: a self-assessed or AI outcome can never resolve to “Reviewed”, and a reviewed outcome can never resolve to “Independent” unless the independence gate passed. A failed independence test auto-downgrades the wording to “Reviewed”, and it cannot be overridden manually.
Discipline
When may we say “independent”?
“Independent” may be used only when ALL of these hold for the engagement — and only after an external legal/assurance review permits the wording in public copy.
- 1The reviewer did not implement or advise on the controls being assessed.
- 2There is no commercial or personal conflict a reasonable auditor would consider invalidating.
- 3The reviewer meets documented competence criteria for the framework in scope.
- 4The review followed a versioned methodology with quality-review sampling and a defined report-signing authority.
Independence is a relationship, not a role — appointing an “independent assessor” does not, by itself, make an engagement independent. And before the word appears in any public copy, the operating model passes an external legal/assurance review.
Framing
What we say — and what we never say
The claims below are the line. We stay on the honest side of it, everywhere.
✅ We say
- “Prepares a structured evidence index and assessment history to support your certification body's audit.”
- “Get audit-ready: know which requirements are genuinely supported before the auditor or customer finds the gaps.”
- “A reviewed opinion of readiness against a defined scope — not a certificate.”
❌ We never say
- “Get certified with Netallion. / ISO 27001 certified.”
- “Pass your audit, guaranteed.”
- “Replaces your auditor / certification body.”
- “Continuous assurance / continuous monitoring.”
- “Independently verified (for a self-assessed or reviewed outcome).”
This boundary changes only if Netallion establishes a licensed or accredited arrangement — a major legal event, not a copy edit. Legal review precedes publication of any Reviewed or Independent tier wording.
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.
Know exactly where you stand — and where the line is
See how readiness preparation and evidence assurance hand off cleanly to the body that certifies.