Certifications
Track ISO, SOC 2, HIPAA, and PCI-DSS certifications alongside accreditations and attestations. Never miss a renewal deadline with proactive reminders.
Prove certification status the moment a customer, auditor, or procurement team asks.
Scattered Credentials, Stalled Sales
Your organization holds certifications that customers, partners, and regulators rely on: SOC 2 reports, ISO standards, HIPAA attestations, PCI-DSS compliance. Each has its own renewal cycle, surveillance schedule, and expiration date.
When a customer asks “Are you SOC 2 certified?” you need an immediate, provable answer. When a certification lapses because no one tracked the deadline, the consequences ripple — stalled sales cycles, derailed procurement approvals, questions about your compliance standing. Lextree’s Certifications module gives you a registry for every third-party certification, accreditation, and attestation your organization holds.
Every Certification
Organizations hold certifications across multiple standards — ISO 27001, SOC 2, HIPAA, PCI-DSS, ISO 9001. Each comes from a different certifying body, follows its own renewal cycle, and requires its own audit schedule.
Lextree tracks the credential, its scope, its certifying body, and its expiration. You see every active certification across every entity without digging through email or asking which team manages which standard. When ISO 27001 and SOC 2 audits overlap, or a PCI-DSS recertification coincides with an ISO surveillance audit, you coordinate from one view. Renewal reminders start 180 days before expiration — this lead time reflects reality, because scheduling a recertification audit and preparing documentation takes months. Follow-ups at 90, 60, and 30 days keep the renewal visible. Teams still getting started on a spreadsheet can pull our business certification tracker template to organize renewal dates before moving them into a registry like this one.
Prove What You Shared
Holding a certification is half the story. Proving it is the other half: a customer requests your SOC 2 report, a partner needs ISO 27001 for vendor qualification.
Attestation tracking captures each instance of compliance proof you provide: the recipient, the framework, the delivery date, the method. When an attestation relates to an underlying certification, the two records link — a clear chain from credential to proof. Over time, this builds an audit trail of your compliance communications. When a customer asks whether they received last year’s SOC 2 report, the record is there.
Accreditations
Accreditations authorize your organization to perform specific activities: educational programs, laboratory testing, healthcare services. AACSB for a business school, Joint Commission for a healthcare facility, A2LA for a testing laboratory — each requires periodic reaccreditation and site visits.
Lextree tracks accreditations with the same rigor as certifications: expiration dates, renewal reminders, status history. When a site visit occurs, you record the details, findings, and required follow-up actions. The accrediting body’s report attaches directly to the record. For organizations holding both certifications and accreditations, one registry covers everything.
In Context
Certifications don’t exist in isolation. Your SOC 2 supports vendor qualification processes your customers run. Your ISO 27001 may be a contractual requirement.
In Lextree, certifications sit alongside entity registrations, insurance policies, licenses and permits, and contracts. When you view an entity’s compliance profile, you see everything — not just the certifications one team manages. GRC platforms like Vanta, Drata, and Secureframe help you pass the audit. Lextree captures grant date, expiration, and who received proof, so renewal reminders ensure you never forget when the next audit is due.
An established platform, not a new bet
- 15 years
- In market
- 118 jurisdictions
- Where customers operate
The record auditors trust. Protected the way they expect.
Lextree is built for the people who lose sleep over compliance, so security isn’t optional.
Encrypted in transit and at rest
Every byte that moves through Lextree travels over TLS 1.2 or higher, and the managed infrastructure it runs on encrypts stored data with AES-256.
Hosted in audited, SOC 2 facilities
Lextree runs on infrastructure certified to SOC 2 Type II, hosted in ISO 27001 data centers.
Role-based access, scoped to your data
Users see only what their role allows, and Lextree subscribers never see each other's data.
An automatic trail of every change
Every create, update, and delete is logged automatically — in the same database transaction — with the user who made it, a timestamp, and the fields that changed.
Daily backups, point-in-time recovery
Your data is backed up on managed infrastructure, with point-in-time recovery to roll back to a moment before a mistake.
Passwordless sign-in, SSO, and MFA
Sign in without passwords — Lextree never stores one to be stolen — with multi-factor authentication available and SAML or OIDC single sign-on on Enterprise plans.
Certifications is one piece of a bigger picture
See how this module combines with others to solve common compliance challenges.
Compliance Calendar
One forward-looking calendar for every dated obligation your entities owe — and the proof you met each one.
Healthcare Compliance Tracking
One system to track every dated obligation each healthcare entity owes — good standing, facility licenses, insurance and COI, contracts, and board records — with proof you met each one.
Certification & Credential Expiration Tracking
Every credential that expires, its renewal date, and the proof it was current — in one register, without an enterprise compliance platform.
Risk & Compliance Management
Insurance, licenses, certifications — track every obligation that keeps your business authorized to operate.
GRC for Small Business
Enterprise-grade compliance infrastructure sized for lean legal and finance teams.
Subsidiary Management
Track registrations, taxes, insurance, and governance across every subsidiary in your corporate family.
Annual Compliance & Renewal Management
Never miss a filing deadline across entities, jurisdictions, and compliance domains.
Nonprofit Compliance
Board governance, grants, and regulatory filings — connected in one compliance hierarchy.
Regulatory Filing Management
Track every filing obligation from deadline to confirmation — across all jurisdictions and agencies.
Audit Readiness & Due Diligence
Prove compliance on any date — across entities, contracts, taxes, and governance.
Frequently asked questions
What kinds of certifications belong in this module?
Is this for the certifications we hold, or the ones we require from vendors?
Can we track the audit cycle leading up to a certification?
Does Lextree store the audit reports and certificates?
Can certifications cover multiple entities or specific locations?
Does Lextree send reminders for upcoming audits and renewals?
Every plan includes all 17 modules
Tiers add user limits, granular permissions, and enterprise controls. Modules stay constant.
Pro
$75/ moIncludes 5 seats, then $5 / seat
For teams moving off spreadsheets and scattered files.
Start free trial →Business
$550/ moIncludes 5 seats, then $7.50 / seat
For businesses that need collaboration, workflows, and reporting.
Start free trial →Enterprise
$950/ moIncludes 5 seats, then $10 / seat
For organizations with security, governance, and scale needs.
Start free trial →