Per-employee certification
Individual security-awareness certificates that demonstrate competence, not attendance. Audit-ready, time-stamped, regulator-defensible.
A certificate that says "this employee completed the training module" is an attestation of completion. An auditor will look at it, file it, and ask the next question. A certificate that says "this employee passed a standardised assessment under controlled conditions, scoring above a defensible threshold" is evidence of competence. An auditor will treat it differently.
The difference is whether the certificate carries verification metadata — when it was issued, against what assessment version, with what item-bank size, at what passing threshold, with what retake history. GetCheckmark certificates carry that metadata. Auditors notice; it shortens the audit conversation.
Each certificate is published to a tenant-specific verification endpoint with a unique verification key. The endpoint allows third-party verification (auditor, regulator, customer due-diligence team) of the certificate's validity without exposing the underlying assessment content.
Certificates align with the platform's framework mapping (next section). Each certificate explicitly states which framework controls it provides evidence against, allowing audit teams to trace control evidence from the certificate forward into the audit work-paper.
Typical deliverables
- Per-employee certificates with verification metadata
- Tenant-specific verification endpoint
- Framework-control mapping per certificate
- Time-stamped attestation aligned with audit-trail expectations
- Integration into HRIS and identity systems via SCIM
Engagement model
Included in the standard platform subscription. Custom verification-endpoint branding and standalone verifier deployment are available as professional-services engagements.
Get in touch
To discuss whether this service is a fit for your organisation, contact us at team@getcheckmark.com or use the contact form.