You finished. Now say so, without saying it wrong.
6 templates for announcing a compliance milestone — LinkedIn, X, customer email, press release, website copy and RFP boilerplate — and, more importantly, the exact claim each framework actually permits.
The most common mistake in a compliance announcement is a claim that does not exist. There is no SOC 2 certificate. There is no HIPAA certification, from anyone. A prospect’s security reviewer knows both of those, and the sentence meant to build confidence spends it instead. This kit covers 7 frameworks and calls out 11 phrasings to avoid.
Free, no email required, and reusable whether or not you use Keel.
What you may and may not claim
Start here, then pick a template. The noun matters more than the tone.
SOC 2
What you hold: An attestation report issued by a licensed CPA firm.
Accurate
- We have completed a SOC 2 Type II examination.
- Our SOC 2 Type II report is available under NDA.
- We maintain a SOC 2 Type II report covering Security and Availability.
Avoid
- “SOC 2 certified” — SOC 2 produces an auditor’s attestation report, not a certificate. There is no certifying body and no certificate to hold. Security reviewers notice this one immediately.
- “SOC 2 compliant” — Weaker and vaguer than the truth. You have a report with an opinion in it and a defined scope — say which type and which criteria instead.
Why: SOC 2 is performed under the AICPA’s attestation standards. The deliverable is a report containing a practitioner’s opinion; no certificate is issued.
ISO/IEC 27001
What you hold: A certificate issued by an accredited certification body.
Accurate
- We are ISO/IEC 27001:2022 certified.
- Our ISMS is certified to ISO/IEC 27001:2022 by <certification body>.
- Certificate number <n>, valid to <date>, covering <scope statement>.
Avoid
- “ISO 27001 compliant” — If you hold the certificate, say certified — it is the stronger and more precise claim. "Compliant" is what companies say when they have not been certified, so it reads as a hedge.
- “ISO certified” — ISO publishes many standards. Name the one and the year, or the claim is unverifiable.
Why: ISO 27001 is certifiable. An accredited body audits the ISMS and issues a certificate with a defined scope and expiry. Certification is genuinely held here, unlike SOC 2.
HIPAA
What you hold: Nothing is issued. HIPAA has no certification regime.
Accurate
- We support customers’ HIPAA obligations and will sign a BAA.
- Our controls are mapped to the HIPAA Security Rule safeguards.
- We operate as a Business Associate under a signed BAA.
Avoid
- “HIPAA certified” — No such certification exists — not from HHS, not from anyone. Any vendor claiming it is either mistaken or selling a meaningless private badge, and saying it marks you as one of them.
- “HIPAA compliant (unqualified)” — Compliance is a continuing state assessed against your own use, not a status you attain. Say what you actually do: the safeguards you implement and the BAA you sign.
Why: HHS does not certify or endorse any HIPAA compliance product or service. Compliance is assessed by regulators against a covered entity or business associate, never conferred in advance.
GDPR
What you hold: No general certification exists. Article 42 anticipates approved certification mechanisms; there is no universal GDPR certificate to hold.
Accurate
- We process personal data in accordance with the GDPR.
- We act as a processor under Article 28 and offer a DPA with SCCs.
- Our record of processing activities is maintained under Article 30.
Avoid
- “GDPR certified” — There is no general GDPR certification. Cite the concrete artifacts instead — a DPA, SCCs, a RoPA, a named DPO if you have one.
Why: The GDPR provides for certification mechanisms under Article 42, approved by supervisory authorities for specific scopes. None functions as a universal "GDPR certified" badge.
PCI DSS
What you hold: An Attestation of Compliance (AOC), supported by a ROC or an SAQ depending on your level.
Accurate
- We validated PCI DSS v4.0.1 compliance as a Level <n> service provider.
- Our Attestation of Compliance is available on request.
Avoid
- “PCI certified” — The regime issues an attestation, and the correct verb is validated. Level and scope matter — an SAQ is not a ROC, and saying so plainly builds more trust than blurring it.
Why: The PCI Security Standards Council defines validation via ROC or SAQ with an accompanying AOC. There is no certificate.
NIST SP 800-171
What you hold: A self-assessment and score, or — for CMMC — a certificate issued by a C3PAO after assessment.
Accurate
- We have implemented all 110 NIST SP 800-171 Rev. 2 requirements.
- Our self-assessment score is posted in SPRS.
- We are preparing for a CMMC Level 2 assessment.
Avoid
- “CMMC certified (before assessment)” — CMMC certification comes from a C3PAO after an assessment. Implementing 800-171 is the preparation, not the certificate — and in the defense supply chain this distinction is contractual.
- “NIST certified” — NIST publishes standards; it does not certify companies against them.
Why: 800-171 is implemented and self-assessed, with scores reported in SPRS. CMMC Level 2 certification is issued by an authorised third-party assessment organisation.
ISO 9001
What you hold: A certificate issued by an accredited certification body.
Accurate
- Our quality management system is certified to ISO 9001:2015.
- Certified by <body>, certificate <n>, scope <statement>.
Avoid
- “ISO 9001 approved” — Certified is the term the regime uses. "Approved" is vague enough that a reader cannot tell what happened.
Why: ISO 9001 is certifiable by accredited bodies, on the same model as ISO 27001.
Templates
Replace everything in <angle brackets>. They are deliberately not a templating syntax —
an unreplaced <SCOPE> is obvious at a glance in a way a stray
{{scope}} is not.
LinkedIn post
Lead with what changed for the customer, not with the badge. The certificate is the evidence, not the news.
<Company> has completed its <FRAMEWORK — use the exact phrasing from the claims table>.
What that means for the people who buy from us: the security questions that used to take us two weeks to answer are now answered, in writing, before you ask them. Our <report/certificate> is available <under NDA / on request / on our trust page>.
The part worth saying out loud: this was not a document exercise. It changed how we do access reviews, how we onboard vendors, and how quickly we notice when something drifts.
<Link to your trust page>
X post
Under 280 characters including the link, which counts as 23 whatever its length.
<Company> has completed its <FRAMEWORK>. Our <report/certificate> is available <under NDA/on request>, and the security questionnaire you were about to send us is mostly already answered here: <link>
Customer email / newsletter
Existing customers care about what it changes for them. Say that first, and give them something to forward to their own security team.
Subject: <Company> has completed its <FRAMEWORK>
Hi <name>,
A short note that may save your security team some time: <Company> has completed its <FRAMEWORK>, covering <scope>.
If you have ever had to vouch for us internally, this is the thing to forward. Our <report/certificate> is available <under NDA / on request>, and our trust page lists the controls, the scope and the current status: <link>
Nothing about how we work with you changes. What changes is how quickly we can answer your security review — and how much of it we can answer before you ask.
<Sign-off>
Press release
Keep the claim in the first paragraph precise; that is the sentence that gets quoted and the one a reviewer will check. Avoid superlatives you cannot evidence.
<CITY>, <DATE> — <Company>, <one-line description>, today announced it has completed its <FRAMEWORK>, covering <scope statement>.
The <examination/certification> was <performed by / issued by> <firm or accredited body> and covers <criteria or clauses>. <Company>'s <report/certificate> is available to customers and prospects <under NDA / on request>.
"<Quote from an executive about why this matters to customers — concrete, not triumphant. What can a customer do now that they could not before?>" said <name>, <title> at <Company>.
<Optional paragraph: what the program covers day to day — access reviews, vendor assessments, incident response — so the announcement describes an operating practice rather than an event.>
About <Company>
<Boilerplate.>
Media contact: <name, email>
Website & footer
The highest-traffic place the claim appears, and the one most likely to go stale. Put a date or a status on it, and link to something a reader can verify.
<Company> maintains <accurate claim from the table above>. Scope: <scope>. Last <assessed/certified>: <date>.
View our trust page: <link>
RFP / security questionnaire boilerplate
Written to be pasted into a response field. Precision here is worth more than warmth.
<Company> has completed its <FRAMEWORK>, <performed by/issued by> <firm or body>, covering <scope>. The <report/certificate> is dated <date> and is available <under NDA / on request>.
Our security program includes documented policies reviewed <cadence>, periodic access reviews, vendor risk assessments, security awareness training, and an incident response plan tested <cadence>. Evidence for each is maintained and dated, and is available to reviewers on request.
Two things worth doing before you publish
Put a date on the claim. A website footer that says “SOC 2 Type II” with no period is the compliance equivalent of undated evidence — it was true once, and a reader cannot tell whether it still is. A date makes it verifiable and makes the renewal visible to you as well.
Say the scope. Every one of these regimes covers a defined scope, and an announcement that omits it invites the reader to assume the largest possible one. Naming it is more credible, not less.
See a trust page in the demo More free toolkits
This kit describes how each framework issues its artifacts, so you can name yours correctly. It is not legal or marketing-compliance advice, and it does not replace review by your auditor, certification body or counsel before you publish a claim about your own scope.