Attestation Letter
Definition
A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body, confirming that an organisation has met the requirements of a particular standard or compliance regime. Auditors should not substitute a penetration test report for an attestation letter when the applicable regime requires one.
- Issued by
- Qualified assessor, e.g. PCI QSA or ISO 27001 certification body
- Purpose
- Confirms compliance with a specific standard
- Not a substitute for
- A penetration test report, where an attestation is required
- Context
- Compliance and audit interface
Common questions
Why can't a penetration test report replace an attestation letter?+
A penetration test report documents findings from a point-in-time technical assessment against a defined scope, while an attestation letter is a formal statement by an accredited assessor that a specific compliance regime's requirements have been met. Regulators or business partners requiring an attestation want that accredited sign-off, which a raw test report does not provide.
Who typically requests an attestation letter and why?+
Business partners, payment processors, and regulators commonly request one before onboarding a vendor or renewing a contract, using it as third-party assurance that a compliance obligation such as PCI DSS or ISO 27001 has actually been verified rather than self-declared.
Related terms
- Common Vulnerability Scoring System (CVSS)
- A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
- Red Team Exercise
- A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical)...
- Remediation Verification Test
- A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that...
- Rules of Engagement (RoE)
- The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...