Skip to content
Back to the Journal
IT & Cyber Governance

The Certificate of Diligence: Moving from One‑Off Audits to Verifiable Governance

What the Certificate of Diligence actually is, what the two conditions are that gate it, and the four things it is not -- including the evidence verification and board-training proof it has never checked.

Vivid Risk Editorial6 min read

A Dated, Self-Reported Record

A “Pass/Fail” report from six months ago tells a partner very little about today. The Certificate of Diligence is our attempt at something with a clearer shelf life – but the honest version of what it offers is narrower than the phrase “certificate” suggests, so we would rather state it plainly than have you discover it in front of a customer.

What is a Certificate of Diligence?

It is a dated record that, on the day you last answered the questionnaire, your self-reported posture cleared two specific bars. It is not an audit, not a certification, and nobody at Vivid Risk checked your answers. What makes it more useful than a static report is that re-running the assessment recomputes it, so it tracks your current answers rather than a past state – not that anything is being monitored on your behalf.

What Actually Gates It

getCertificateEligibility() checks exactly two things, and both are computed from the answers you gave in the assessment:

1. A Vivid Maturity Index of 90 or above

On the proportional scoring model described in our Methodology. The bar used to be 85 and was raised, because at 85 an organisation with five severe controls failed outright scored exactly 85 and earned a certificate.

2. No severe control answered “No” or “Not sure”

The score alone is not enough. A certificate asserting diligence should not be issuable while a critical safeguard is missing, which is why this second condition exists. When a certificate is withheld, the report tells you which of the two conditions failed.

Re-running the assessment recomputes both, so the certificate follows your current answers rather than a past state.

What It Is Not

Being specific about this matters more than the marketing does, because the gap is where a customer gets hurt:

  • It is not evidence verification. Nothing gates the certificate on a document being uploaded, scanned or accepted. Evidence in the vault is a metadata register you maintain; it does not feed this calculation.
  • It is not proof of board training. NIS 2 Art. 20 does require management bodies to follow training, and that obligation is real — but Vivid Risk has no way to observe whether it happened and does not check.
  • It is not continuous. There is no monitoring rhythm, no freshness schedule, and no grace period that invalidates a certificate. It reflects your answers the last time you answered.
  • It is self-reported. Nobody at Vivid Risk checks your responses, and no regulator or auditor is obliged to accept it.

Why Does It Matter for Third Parties?

When you share a Certificate of Diligence with a partner or customer, what you are telling them is narrower than a certification, and more useful than nothing:

  • “We assessed ourselves against a cited control set, and here is the date we did it.”
  • “We scored 90 or above, and no severe control came back as a gap.”
  • “Here is the breakdown, so you can see what we claimed and press on any of it.”

The Process to Issuance

  1. Intake: Define your industry and regulatory scope through the IT Risk Assessment questionnaire.
  2. Answer the questionnaire. This is the only input to the calculation.
  3. Issuance: If your recomputed VMI is 90 or above and no severe control is answered “No” or “Not sure”, the Certificate of Diligence appears on the report. If either condition fails, the report says which one.

Closing the gaps the report raises — aligning your stack, training your management body, collecting the evidence behind each answer — is the work that makes the answers true. It is worth doing, and it is not what the certificate measures.

Conclusion

The Certificate of Diligence is about Defensibility. It provides internal leaders and external stakeholders with a clear, verifiable signal that the organization is fulfilling its duties under NIS 2 and other modern regulations. It turns “Trust” from a feeling into a verifiable metric.