Services

Certification

Scheme set-up, operation and certification activities delivered with ISO/IEC 17065 impartiality and state-of-the-art technical rigor.

Introduction

What certification covers

Certification delivers solid, opposable proof that products, solutions and services comply with established security requirements. Buyers, regulators and insurers increasingly treat the certificate — not the marketing claim — as the contractual reference.

Internet of Trust runs certification activities end-to-end, from scheme set-up and lab accreditation to evaluation monitoring, results review and certification decision — every activity delivered under criteria that guarantee impartiality and technical state-of-the-art, in line with ISO/IEC 17065:2012.

This page covers our two-phase approach — Build and Operate — the deliverables expected from a certification body, and the engagement modes for scheme owners and certification authorities.

ISO/IEC 27005

Scheme set-up

Scheme operation

Lab accreditation

Evaluation monitoring

Certification decision

Process

Build and Operate

Two structural phases — Build then Operate — underpinned by continuous project planning, evidence preparation, lab coordination and full-audit-trail documentation.

01

Build

Create the management and certification body, accredit the initial labs, install the scheme information system, run pilot evaluations, register the scheme with competent authorities and launch interest groups.

02

Operate

Apply scheme processes, accredit labs, monitor evaluations, issue certificates, interact with stakeholders, lead interest groups and communicate on behalf of the scheme owner.

Delivery plan

What we deliver

A complete certification-body toolkit — from lab accreditation packages to public registries and stakeholder communication material.

Lab accreditation

Accreditation files, technical assessments and surveillance plans aligned to ISO/IEC 17025.

Product/solution/service certificates

Issued under ISO/IEC 17065 with documented decision rationale.

Information resources

Public registries, certificate databases, transparency reports.

Accreditation, evaluation & certification processes

Templates and instructions for scheme users, evaluators, certifiers and auditors.

Communication plan & media

Presentations, white papers, FAQs and ecosystem feedback loops.

Engagement modes

Types of services

Two engagement shapes covering full scheme operation and targeted certification activities.

Mode 01

Scheme Operation

Launch a new scheme or manage an existing one — management structure, daily activities, lab accreditation, product certification, scheme documentation maintenance.

Mode 02

Certification Activities

Skilled technical resources for certification request analysis, evaluation monitoring, results review and certification decision under a given scheme.

Operational details

Cross-cutting activities

Day-to-day certification work spans request intake, evidence review, lab coordination and decision documentation — all tracked with full audit trail.

Project planning & evidence preparation

Acceptance of certification requests, analysis of input documentation and evaluation plans, planning of evidence delivery and lab milestones.

Lab coordination & documentation

Continuous evaluation monitoring, technical arbitration, results review and certification decision with full audit trail.

Related case studies

Calypso HCE Scheme Creation and Operation

Created and operated a dedicated mobile security certification scheme for Calypso HCE ticketing — from security requirements and governance to lab coordination and the first certified SDK, preserving trust in the existing hardware ecosystem while opening the…

Read case study →

GlobalPlatform TEE Scheme Creation and Operation

Built and operated the GlobalPlatform TEE security evaluation and certification scheme mapping TEE specifications to Common Criteria, defining Protection Profile-style…

Read case study →

Contact us

Request this document

We’ll send you access by email.