Enterprise & government
Security claims need scope, not slogans.
Guidance for buyers who must separate a company-wide marketing statement from a verified claim about a specific product, service, deployment, and authorization boundary.
Where to start
Section guide
Procurement guidance
Questions to settle before you shortlist, ask vendors, and sign.
Read the guidanceSecurity & authorization evidence
How we record a claim: exact product, deployment, program, scope, source, and date.
See the evidence standardHosted vs. self-managed
The trade-offs between vendor-hosted and self-managed deployment.
Open the comparison topicSix things every claim must pin down
Required elements of a claim
- Product or service
- Name the exact service, API, or product in scope, not only the vendor.
- Deployment
- Identify commercial cloud, government cloud, on-premises, or self-managed deployment.
- Authorization
- State the program and impact level only when supported by the relevant authority's current record.
- Scope & exclusions
- Describe what is covered and what is not. Do not generalize a service authorization to every product.
- Primary evidence
- Link to the authoritative listing or the precise documentation supporting the claim.
- Verification date
- Record when the claim was checked and when it should be reviewed again.