IT Glossary
Access certification is the documented sign-off proving access was reviewed. Learn how it works, how it differs from reviews, and why auditors need it.
July 3, 2026
Access certification is the formal, documented attestation that a user's access has been reviewed and either approved or revoked by an accountable owner. It is the auditable output of an access review: where the review checks access, certification records the sign-off as evidence. Auditors look for certification to confirm that access governance actually took place.
Access review and access certification differ in focus and output. The review focuses on the act of checking and produces decisions to keep or revoke. The certification focuses on the recorded attestation and produces signed, time-stamped evidence. Auditors treat the review as the activity and the certification as the proof.
Ahead of a SOC 2 audit, a company needs proof, not just intent, that access was reviewed. Each manager certifies their team's access with a recorded approval, producing an exportable attestation per user and app. That artifact is exactly what the auditor samples. Without certification, even a thorough review leaves no evidence the auditor can accept.
The review is the act of checking access appropriateness. The certification is the formal, recorded sign-off that serves as audit evidence.
Because it proves the review happened and who approved each access decision, which intent alone cannot demonstrate.
The accountable owner, usually a manager or resource owner, who can judge whether each access right is still justified.