Skip to content

GuidesPublished 10 min read

Certification Claim Scoring: A Chicago Guide

a magnifying glass over a checklist with star ratings
Listen to this article · 13:40 · AI-generated narration
0:00 / 13:40
Chapters

Disclosure: this site is owned and operated by XL.net, a Chicago MSP that is itself ranked here. How we handle that conflict.

What does certification claim scoring measure?

It measures the documentation we were able to obtain, not the security of any firm. Security Certification carries a weight of 24 of 100 in our published score, and it treats two kinds of entry differently. Third-party documented certifications — backed by a named third-party issuer's document, evidence hosted on a third-party website, or a public registry entry — are scored additively by tier and checked automatically per certification. A firm's own undocumented claims follow a separate rule: they add 5 points each and stop at a ceiling.

That ceiling is the part buyers should read closely. IT Support Chicago scores a firm's own undocumented claims at 5 points each, capped at 25/100, so stacked claims reach a ceiling quickly. Once a provider's list of self-asserted frameworks passes the cap, adding another framework to the website changes nothing on the criterion — and it should change little in a buyer's confidence either. Expect diminishing returns from a lengthening list of claimed frameworks, both in our score and in your own reading of a capabilities page.

Our wording is deliberately narrow. We publish exactly two statuses for a certification entry: third-party documented, or the firm's own claim. An entry marked as the firm's own claim is one we hold no third-party documentation for, and it must never be described as certified, audited, or accredited. Neither mark is a verdict on posture, controls, or breach risk. If you want to run the same check yourself rather than lean on our records, our IT Provider Certification Verification Checklist sets out the evidence to ask for and where to look for it.

TL;DR

In our certification claim scoring, entries we hold third-party documentation for are scored additively by tier, while a firm's own undocumented claims add 5 points each and cap at 25/100 — so a lengthening list of claimed frameworks hits a ceiling fast. Across the Managed Service Provider (MSP) firms we scored on Security Certification, the median is 10.0 and the middle half runs 5.0 to 20.0, which tells a buyer how little separation the dimension usually creates. Both marks describe the documentation in our own records, never how secure any firm is.

  • Security Certification carries a weight of 24 of 100 in our published score.
  • A firm's own undocumented claims add 5 points each and cap at 25/100.
  • Median 10.0, mean 11.9, middle half 5.0 to 20.0, scored for 84 of 94 firms — little separation.
  • PCI DSS appears in our records for 20 vendors and CMMC Level 1 for 17, so a common framework rarely distinguishes anyone.
  • Ask which systems, services, and locations an attestation covers before you credit the badge.

How much separation does the certification criterion create?

Less than its weight implies. Across the firms IT Support Chicago scored on Security Certification, the median is 10.0 and the middle half runs from 5.0 to 20.0. The mean sits at 11.9, and the criterion was scored for 84 of 94 firms. Against a component worth 24 of 100, that middle half is the figure to keep in mind: half of the scored firms fall inside that band, with the median at 10.0. The quarter of scored firms above 20.0 is not something we publish a spread for, so read the band for what it is rather than as a description of the whole set.

The practical consequence is that certification data works better as a tie-breaker and a due-diligence prompt than as a ranking axis. If a provider's list is the reason it made your shortlist, check what else in the score is carrying it — client and employee reputation, and the proactive-versus-reactive staffing mix — because a modest attainment on this criterion is common across the firms we scored rather than an outlier signal. Our Provider Score Coverage guide explains how partial coverage on any criterion changes what a total score can tell you.

One caveat sits on the distribution itself. A criterion scored for 84 of 94 firms means some firms carry no record here at all, and a firm outside that count is one we hold no record for — not a firm that lacks certifications. Silence in our data is silence, not absence. The same applies in reverse: a firm at the low end of the range may hold attestations we simply could not document from public evidence, which is exactly the gap a direct request to the provider closes.

What a stack of claimed entries does and does not tell you

Read the IT provider certification marks in our table entry by entry, not as a total. A single certifications cell can carry a full stack — SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed) — with every one of them marked as the firm's own claim. For first use: SOC 2 stands for System and Organization Controls, ISO for the International Organization for Standardization, CMMC for the Cybersecurity Maturity Model Certification, and PCI DSS for the Payment Card Industry Data Security Standard.

What a cell like that tells a buyer is narrow but real: the firm presents those frameworks, and we hold no third-party issuer document, third-party hosted evidence, or registry entry for them. IT Support Chicago marks an entry as the firm's own claim when our records hold no third-party documentation for it. What it does not tell you is whether the attestation exists, when it was issued, who issued it, or what it covered. Until a buyer has those four answers, a stack of claims is a set of assertions our records could not document — neither proof nor a finding against the firm.

So treat the cell as a question list rather than a score. Ask the provider to name the issuer and produce the report, letter, or registry listing — under a non-disclosure agreement if needed — and ask which of your systems would fall inside the scope described in it. A provider with a genuine attestation usually has that paperwork within reach; a provider that cannot produce it has told you something useful without saying anything.

Entry markWhat our records holdWhat we never writeWhat to request from the provider
✓ (third-party documented)A named third-party issuer's document, evidence hosted on a third-party website, or a public registry entryAny conclusion about how secure the firm isThe scope statement — which systems, services, and locations the document covers
(claimed)No third-party documentation for that entryCertified, audited, or accreditedThe issuer's name, the report or registry entry, and the period it covers

Do the most common frameworks distinguish a provider?

Rarely. Our records at IT Support Chicago show PCI DSS for 20 vendors and CMMC Level 1 for 17, so neither badge distinguishes much. SOC 2 Type I appears for 11 vendors, and SOC 2 Type II and ISO 27001 for 7 vendors each. Those are counts of what our own records hold, not a reading of how widely each framework is held across the metro market — a firm outside a count is a firm we hold no record for. What the recurrence does tell a buyer is that seeing a familiar framework on a provider's list rarely separates it from the others on the shortlist.

The useful variation is inside the frameworks, not between them. A SOC 2 Type II attestation covers whether controls operated effectively over a multi-month observation period, while a Type I covers control design at a single point in time; the two words read alike on a website and mean different things in a report. ISO 27001 certification requires an accredited external audit of an information-security management system, which is why the certificate and registry entry matter more than the logo. PCI DSS applies to firms that store, process, or transmit cardholder data, and CMMC is the US Department of Defense's maturity certification for defense contractors and subcontractors.

That is why we treat scope questions as the real comparison, not the badge count. Two providers can both list the same framework while one scoped it to a single hosted platform and the other to the full service delivery environment your users would touch. We work through that distinction in more depth in Cybersecurity Scope vs Certifications in Chicago, which is the companion read to any framework list you are weighing.

Due diligence before you credit a framework list

For a Chicago IT buyer, due diligence on certifications is mostly a scope exercise. IT Support Chicago advises buyers to ask which systems and locations an attestation covers before crediting any framework list. A long list is not a substitute for that answer, and it is the one question that a provider with paperwork in hand can answer in a sentence.

Six requests cover most of the ground. First, who issued the attestation or certificate, and can you see the document or the public registry entry. Second, what period it covers and when the next assessment is due. Third, which entity is in scope — the provider's own corporate systems, a specific hosted platform, or the environment that would actually deliver your service. Fourth, which locations and which subcontractors or subservice organizations fall inside that boundary. Fifth, whether the scope includes the tools your users would touch, such as the remote monitoring platform and the ticketing system. Sixth, if you are in a regulated vertical, what contractual instruments come with it — a business-associate agreement where protected health information is involved under the Health Insurance Portability and Accountability Act (HIPAA), for example.

Write the answers down next to the provider's claims and compare them against the proposal. If the scope excludes the systems your service would run on, the framework is real and irrelevant at the same time. And keep the limitation in view: everything in our certification column — under either mark — describes documentation, not the strength of a provider's controls on the day something goes wrong.

Where the certification weight belongs in the decision

Keep it proportionate. IT Support Chicago weights Security Certification at 24 of 100, below Client Reputation at 29 of 100 and Proactive Issue Reduction at 27 of 100. Employee Reputation carries a weight of 20 of 100. The Security Certification weight is meaningful, but it is one of four public criteria, and the middle half of 5.0 to 20.0 means a shortlist ranked mainly on framework lists is being ranked on a dimension where the firms we scored sit close together.

It also should not stand in for commercial protection. Our position is that shorter agreements generally serve the buyer better, because long lock-ins mostly benefit the vendor, and that Service Level Agreement (SLA) clauses earn their keep mainly in multi-year deals as a way to share pain with the provider. Under a one-year term, or where you hold termination for convenience, the practical recourse is leaving — not invoking a credit. A framework list changes none of that arithmetic. We set the two against each other in Chicago SMB IT SLA vs Termination Rights.

Two further positions we hold shape how the certification column should be read alongside a quote. On size: bigger is not inherently better, and right-sizing to your environment matters more than headcount, so do not read a longer compliance list as a proxy for scale or scale as a proxy for quality. On price: a per-user monthly rate means nothing without the scope behind it, and the same is true of a certification list — both are summaries that only become comparable once you know what sits inside them. Ask for the scope, then compare.

Frequently asked questions

Does a claimed entry mean the provider is exaggerating?

No. It means our records hold no third-party issuer document, third-party hosted evidence, or registry entry for that framework. The attestation may well exist, which is why we describe the mark as the firm's own claim and never as a failure.

How many points can a provider earn from its own claims?

A firm's own undocumented claims add 5 points each and cap at 25/100. Entries we hold third-party documentation for are scored additively by tier instead.

Should a certification list decide my shortlist?

We would not let it. Security Certification carries a weight of 24 of 100, and across the firms we scored on it the median is 10.0 with the middle half between 5.0 and 20.0 — little separation to rank on.

Why is the criterion scored for only some of the firms you track?

It was scored for 84 of 94 firms. A firm outside that count is one we hold no record for on this criterion — not a firm we found to be uncertified.

What is the single best question to ask about a certification?

Which systems, services, and locations the attestation covers, and over what period. A framework that excludes the environment delivering your service tells you very little about your own risk.

All articles