Cetonix is not a conformity assessment body. We do not hold accreditation, we do not issue certificates, and we do not make certification decisions. We coordinate certification through a network of more than 100 accredited CABs — and we say so plainly, because a buyer who discovers it later is entitled to wonder what else was overstated.
This is a deliberate structure rather than a limitation. A single CAB is accredited for a finite set of standards under a finite set of accreditation bodies. Working across a network means we can put you with a body accredited for your exact standard under the accreditation your market recognizes, instead of selling you whichever scope one organization happens to hold.
The CABs we work with hold accreditation from national accreditation bodies including:

Do not take our word for any of this. Every accreditation body publishes a public directory of the CABs it accredits, with the exact scope of each accreditation. Cetonix will not appear in those directories, because Cetonix is not an accredited body. The CAB appointed to your engagement will.
Before you sign anything, ask us which CAB we propose to appoint and for what scope. We will name them in writing, and you can check them in the relevant directory before you commit. If a coordinator will not name the accredited body, that is the point at which to walk away — from us or from anyone.
On 1 January 2026 the International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) merged to form Global Accreditation Cooperation Incorporated (Global ACI). The former IAF MLA and ILAC MRA are now administered as a single Global ACI Multilateral Recognition Arrangement, and existing accredited certifications remain recognized without interruption.
Where a CAB in our network holds accreditation from a body that is a signatory to that arrangement, the certificate it issues is recognized as equivalent by accreditation bodies worldwide — including across the regional groupings formerly known as APAC and IAAC.
Training is the one area where the relationship is direct. Cetonix is approved by Exemplar Global (formerly RABQSA, part of the ASQ family) as a certified training provider, under Training Provider TP 06587. Exemplar Global provides personnel certification and credential management for individuals, and independently certifies training providers.
Approved Auditor / Lead Auditor training schemes:
We also deliver risk management training based on the ISO 31000:2018 guidelines. ISO 31000 is a guidance document rather than a certifiable management system standard, so it is listed separately from the schemes above.
Our security testing practice is not brokered. Penetration testing, secure code review and dynamic testing are delivered by Cetonix’s own in-house team, and the report is issued by us in our own name. Accreditation under ISO/IEC 17021-1 is irrelevant to the quality of a penetration test in any case — what matters there is the credentials of the people doing the testing and the quality of the report, which is why we publish full sample reports.
Because we appoint your certification auditors and can also test your systems, a penetration test we deliver may become the evidence reviewed in an audit we arranged. That is the same commercial party on both sides, and it is a real conflict rather than a theoretical one. We disclose it in writing before you engage, and our Quality & Impartiality Policy sets out how it is managed and what your options are.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.