We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · PCI QSA authorised

Document and attestation validation

Confirm that a document, attestation, certificate or report bearing the CyberSigma name is genuine. Enter the reference exactly as it appears on the document to check it against our records.

Enter the reference number

Enter the document, attestation or certificate reference exactly as printed.

If a valid reference does not validate, contact our team with the document details for manual verification.

What you can validate here

This tool confirms documents that carry a CyberSigma reference. CyberSigma is a PCI SSC-listed Qualified Security Assessor and a CERT-In empanelled auditor — it issues assessment and attestation documents, but it does not issue ISO or other third-party management-system certificates. Those are issued by an accredited independent certification body; where CyberSigma provided implementation and readiness, we coordinate the engagement and can point you to the issuing body for verification.

  • PCI DSS Attestation of Compliance (AoC)Issued by CyberSigma
  • PCI DSS Report on Compliance (RoC) referenceIssued by CyberSigma
  • VAPT certificateAssessment performed by CyberSigma
  • Safe-to-host certificateIssued by CyberSigma
  • Security / compliance assessment reportAssessment performed by CyberSigma
  • Training certificate (SigmaAcademy)Issued by CyberSigma
  • Independent certification-body certificate (e.g. ISO 27001)Referenced for verification only

PCI DSS:the PCI Security Standards Council does not recognise unofficial “PCI DSS compliance certificates” as validation documents. The official PCI SSC forms — the Attestation of Compliance (AoC) and Report on Compliance (RoC) — are the recognised evidence of PCI DSS validation. This tool references the AoC or RoC that CyberSigma, as a PCI SSC-listed Qualified Security Assessor, produced for the engagement; it does not issue an independent “PCI DSS certificate.”

To verify an ISO 27001 or other independent certificate, check it with the certification body named on the certificate. This tool validates the CyberSigma-issued documents above and, where applicable, the reference to a coordinated certification.

Questions beyond document validation?

Our team can help with assessment, attestation and certification-readiness for your regulatory environment.