The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
STANDARDS AND CERTIFICATIONS
Each of these ends in a different document, and the difference reshapes the whole project. One gives you a certificate from an accredited body, another a label, another an audit report, another a shield, and others give you your real state, measured, which is what holds all the earlier ones up. Below is what each one is, what it gives you at the end, who tends to ask for it, and where DM11 fits.
Send us the contract wording or the questionnaire you received. We read it and tell you which of these answers it, before you work through the whole list.
Talk to a specialistWhat you end up holding
A certificate, issued by an accredited body
The international standard for an information security management system, and the one most often named in tenders and vendor questionnaires. It certifies the way the company manages risk, which makes it valid for any sector and any size. It is also the base the other standards draw on: much of the evidence assembled here goes on to answer SOC 2, TISAX and the next questionnaire that arrives.
See the pageWhat you end up holding
A privacy certificate, which since 2025 stands on its own
The privacy management system standard. The revision published in October 2025 made the standard independent: today a company certifies privacy without first building an entire security management system, as the previous text required. This is the route for a company that already meets Brazil's General Data Protection Law in practice and needs to prove it to a customer or a regulator, with a document issued by an accredited body.
See the pageWhat you end up holding
Labels, valid for three years
The automotive industry's assessment and exchange mechanism, run by the ENX Association. The official participant handbook is direct about the outcome: they are labels, valid for three years. It is what a carmaker, or one of its large suppliers, puts in the contract before releasing project information. The assessment is carried out by an accredited audit provider, always separate from whoever prepared you.
See the pageWhat you end up holding
An independent audit report, Type I or Type II
A report on your controls, written and signed by an independent audit firm against the trust services criteria set by the AICPA, the American institute of accountants. Your customer receives the full report to read, with the auditor's opinion on every control. Type I looks at the design at a point in time, and Type II observes the operation across a period.
See the pageWhat you end up holding
Shields published in the TPN+ registry
The Motion Picture Association's content security assessment, for companies serving studios and streaming platforms. The result goes into the TPN+ registry, and each content owner decides on its own from there, which is how the audiovisual market works. Since September 2025 there are four shields, built on version 5.3.1 of the MPA Best Practices.
See the pageWhat you end up holding
A self-assessment you sign, with the evidence behind it
IATA requires PCI DSS compliance from anyone handling a passenger's card. For most accredited agencies the route is the self-assessment questionnaire, and the name is no accident: the agency is the one who declares. DM11 organises the environment, reduces the scope and produces the evidence that stands behind that signature.
See the pageWhat you end up holding
An attestation of compliance, the document your customer asks for
The card brands' security standard, mandatory for anyone who stores, processes or transmits cardholder data. The version in force is 4.0.1, and the requirements that were still recommendations became obligations in March 2025. How demanding it gets changes with transaction volume and with your role in the chain: merchant, service provider, or both at once. A company serving other businesses confirms its scope every six months. Where the route calls for a formal assessment, it is carried out by a QSA, the assessor accredited by the council that maintains the standard. The bigger gain comes before that: shrinking the territory the data travels through reduces what has to be audited.
See the pageWhat you end up holding
Evidence of the fourteen controls, in the form the supervisor asks for
CMN Resolution 4.893/2021 set the cybersecurity policy for financial institutions, and BCB Resolution 85/2021 did the same for payment institutions. In December 2025, CMN Resolution 5.274 and BCB Resolution 538 made specific what had been general: there are now fourteen minimum controls, including intelligence work with monitoring across the internet, the deep web and the dark web. Penetration testing acquired a minimum annual frequency, carried out with independence and impartiality by a specialist engaged for that purpose. The Pix and reserve transfer system environments gained requirements of their own, from physical and logical isolation to control of private keys. The compliance deadline for institutions already operating was 1 March 2026, and what counts now is sustaining that routine.
See the pageWhat you end up holding
An assessment of your real state, with evidence and a plan in order
A set of controls in priority order from the Center for Internet Security, with implementation groups by company size. It is the assessment the market recognises for measuring where the company stands today, with evidence behind every answer, and it is what the board uses to decide where the next investment goes. ISO 27001 and SOC 2 reuse that work afterwards.
See the pageWhat you end up holding
A maturity profile, comparable from one year to the next
The framework from the US standards institute, organised into functions that run from identify to recover. It is the language a board understands when it wants to follow maturity over time: you define today's profile and the target profile, and you measure the distance between the two from one year to the next. Adoption is the company's own choice, and it serves any sector.
See the pageWhat you end up holding
A verification report, with a verdict on every requirement
The foundation behind the most widely used application security references in the world. The Top 10 gathers the most critical risks in web applications, and the 2025 edition is the first revision since 2021. ASVS 5.0, the application security verification standard, turns the generic request to test into requirements with an item-by-item verdict that fits into a contract. There are dedicated lists for APIs, the interfaces between systems, for mobile applications and for products built on language models, alongside SAMM, which measures the maturity of your development. It is the yardstick your customer and your penetration tester both recognise.
See the pageWhat you end up holding
An auditable report, with the phases declared in the contract
The Penetration Testing Execution Standard describes the phases a penetration test moves through, from the pre-engagement agreement to the report. With the method declared in the contract, you know what will be done in each phase, you compare proposals from different suppliers on the work rather than on the price, and you receive a report another professional can audit later. It is what turns buying a test into an informed decision, and what gives the result value after delivery, when someone needs to reconstruct what was done.
See the pageWhat you end up holding
A map of your detection coverage, technique by technique
MITRE's knowledge base, which organises the behaviour of real attackers by tactic and by technique, drawn from observed cases. It describes what the adversary does, and that is what lets you measure whether your detection covers what matters. It also gives your response team a common vocabulary and lets a penetration test show the path it took, with the technique named at every step. The work lies in choosing the techniques that matter to your sector and proving each one.
See the pageWhat you end up holding
An assessment of your AI system against attacks on the model itself
The same structure as ATT&CK, applied to artificial intelligence and machine learning systems. It covers the ground that falls outside ATT&CK: training data poisoning, model extraction, input manipulation and the attacks that exploit the model itself, and not only the infrastructure around it. It is the reference that carries the assessment through to the model and to the data pipeline feeding it, together with the application that exposes both.
See the pageWhat you end up holding
A compliance file, with an inventory, a legal basis and an officer
Brazil's General Data Protection Law applies to any company processing personal data in the country, of any size. What it demands is demonstrable compliance: an inventory of processing activities, a recorded legal basis, data subject requests answered within the deadline and a named officer, with the evidence kept. No LGPD certificate exists in Brazil, and this set is precisely the proof that is accepted. When a customer or a regulator asks for a document issued by a third party, the route is ISO 27701.
See the pageWHERE DM11 FITS
The separation is the same for every standard on this page, and it is not our choice: whoever prepares cannot assess. DM11 runs the gap assessment, builds the plan, implements the controls with your team and organises the evidence in the form the assessor expects. Where your route calls for a formal assessment, it is carried out by an accredited body, audit firm or assessor, with the roles kept apart.
An assessment of what already exists, before any project is proposed
A plan in priority order, with an owner and a date
Implementation alongside your team, not instead of it
A rehearsal of the assessment, so the result stops being a surprise
Reuse across standards: evidence produced once serves several
Bring us the contract clause or the questionnaire you received. We will tell you which standard answers it, what you already have in house that counts, and what is genuinely missing.
Talk to a specialist