Skip to content

Attestation Letter

Definition

A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body, confirming that an organisation has met the requirements of a particular standard or compliance regime. Auditors should not substitute a penetration test report for an attestation letter when the applicable regime requires one.

Issued by
Qualified assessor, e.g. PCI QSA or ISO 27001 certification body
Purpose
Confirms compliance with a specific standard
Not a substitute for
A penetration test report, where an attestation is required
Context
Compliance and audit interface

Common questions

Why can't a penetration test report replace an attestation letter?+

A penetration test report documents findings from a point-in-time technical assessment against a defined scope, while an attestation letter is a formal statement by an accredited assessor that a specific compliance regime's requirements have been met. Regulators or business partners requiring an attestation want that accredited sign-off, which a raw test report does not provide.

Who typically requests an attestation letter and why?+

Business partners, payment processors, and regulators commonly request one before onboarding a vendor or renewing a contract, using it as third-party assurance that a compliance obligation such as PCI DSS or ISO 27001 has actually been verified rather than self-declared.

Related terms

Common Vulnerability Scoring System (CVSS)
A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
Red Team Exercise
A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical)...
Remediation Verification Test
A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that...
Rules of Engagement (RoE)
The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop...
Scope Creep
The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.