Cetonix is not a conformity assessment body. We coordinate certification through accredited CABs and we separately deliver penetration testing with our own in-house team. That structure creates one real conflict, and this page exists to name it rather than bury it.
Cetonix provides principled, credible and value-added coordination of certification, and independent technical security testing. We achieve this by ensuring:
This policy is reviewed periodically for relevance and suitability.
| Certification | Security testing | |
|---|---|---|
| Who holds the accreditation | The appointed CAB | Not applicable — accreditation under ISO/IEC 17021-1 does not govern penetration testing |
| Who performs the work | Auditors engaged through the CAB | Cetonix’s own in-house team |
| Who makes the decision | The CAB, independently of Cetonix | Cetonix issues the report in its own name |
| Whose name is on the output | The CAB’s certificate, with its accreditation mark | Cetonix |
| What Cetonix does | Selects and appoints the CAB, manages scope, scheduling, readiness and non-conformity closure | Scopes, tests, reports and retests |
If Cetonix arranges your certification audit and performs your penetration test, then a report we wrote becomes evidence in an audit whose auditors we appointed. Under ISO/IEC 27001:2022 a penetration test typically evidences Annex A 8.8 (technical vulnerability management) and A 8.29 (security testing in development and acceptance). The same commercial party sits on both sides of that evidence.
The certification decision is made by the CAB and not by us, which limits the exposure but does not remove it: we chose the CAB, and we wrote the evidence.
If you would prefer maximum separation, the cleanest arrangement is to have us coordinate certification and appoint an unrelated firm for the penetration test, or the reverse. We will tell you that on the call, and it is worth raising with your CAB before appointment rather than at surveillance.
Cetonix does not provide management system consultancy to organizations whose certification we coordinate, and does not conduct internal audits for them. Readiness support, gap assessment and remediation planning are offered only where Cetonix is not arranging the certification. Personnel who have provided consultancy to a client take no part in certification activities for that client for two years.
Complaints about Cetonix’s own conduct are handled under our complaint handling process. Complaints or appeals about a certification decision are matters for the CAB that made the decision, and ultimately for its accreditation body — we will give you the correct contact and will not obstruct it.
Cetonix and its personnel, internal and external, act impartially and do not allow commercial, financial or other pressures to compromise impartiality. All personnel are required to disclose any situation that may present a conflict of interest. This is recorded, used to identify threats to impartiality, and such personnel are not used unless it can be demonstrated that no conflict exists.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.