Skip to main content

Certifications

Track ISO, SOC 2, HIPAA, and PCI-DSS certifications alongside accreditations and attestations. Never miss a renewal deadline with proactive reminders.

Prove certification status the moment a customer, auditor, or procurement team asks.

Scattered Credentials, Stalled Sales

Your organization holds certifications that customers, partners, and regulators rely on: SOC 2 reports, ISO standards, HIPAA attestations, PCI-DSS compliance. Each has its own renewal cycle, surveillance schedule, and expiration date.

When a customer asks “Are you SOC 2 certified?” you need an immediate, provable answer. When a certification lapses because no one tracked the deadline, the consequences ripple — stalled sales cycles, derailed procurement approvals, questions about your compliance standing. Lextree’s Certifications module gives you a registry for every third-party certification, accreditation, and attestation your organization holds.

Every Certification

Organizations hold certifications across multiple standards — ISO 27001, SOC 2, HIPAA, PCI-DSS, ISO 9001. Each comes from a different certifying body, follows its own renewal cycle, and requires its own audit schedule.

Lextree tracks the credential, its scope, its certifying body, and its expiration. You see every active certification across every entity without digging through email or asking which team manages which standard. When ISO 27001 and SOC 2 audits overlap, or a PCI-DSS recertification coincides with an ISO surveillance audit, you coordinate from one view. Renewal reminders start 180 days before expiration — this lead time reflects reality, because scheduling a recertification audit and preparing documentation takes months. Follow-ups at 90, 60, and 30 days keep the renewal visible. Teams still getting started on a spreadsheet can pull our business certification tracker template to organize renewal dates before moving them into a registry like this one.

Prove What You Shared

Holding a certification is half the story. Proving it is the other half: a customer requests your SOC 2 report, a partner needs ISO 27001 for vendor qualification.

Attestation tracking captures each instance of compliance proof you provide: the recipient, the framework, the delivery date, the method. When an attestation relates to an underlying certification, the two records link — a clear chain from credential to proof. Over time, this builds an audit trail of your compliance communications. When a customer asks whether they received last year’s SOC 2 report, the record is there.

Accreditations

Accreditations authorize your organization to perform specific activities: educational programs, laboratory testing, healthcare services. AACSB for a business school, Joint Commission for a healthcare facility, A2LA for a testing laboratory — each requires periodic reaccreditation and site visits.

Lextree tracks accreditations with the same rigor as certifications: expiration dates, renewal reminders, status history. When a site visit occurs, you record the details, findings, and required follow-up actions. The accrediting body’s report attaches directly to the record. For organizations holding both certifications and accreditations, one registry covers everything.

In Context

Certifications don’t exist in isolation. Your SOC 2 supports vendor qualification processes your customers run. Your ISO 27001 may be a contractual requirement.

In Lextree, certifications sit alongside entity registrations, insurance policies, licenses and permits, and contracts. When you view an entity’s compliance profile, you see everything — not just the certifications one team manages. GRC platforms like Vanta, Drata, and Secureframe help you pass the audit. Lextree captures grant date, expiration, and who received proof, so renewal reminders ensure you never forget when the next audit is due.

Trusted by

An established platform, not a new bet

15 years
In market
118 jurisdictions
Where customers operate

Built secure

The record auditors trust. Protected the way they expect.

Lextree is built for the people who lose sleep over compliance, so security isn’t optional.

  • Encrypted in transit and at rest

    Every byte that moves through Lextree travels over TLS 1.2 or higher, and the managed infrastructure it runs on encrypts stored data with AES-256.

  • Hosted in audited, SOC 2 facilities

    Lextree runs on infrastructure certified to SOC 2 Type II, hosted in ISO 27001 data centers.

  • Role-based access, scoped to your data

    Users see only what their role allows, and Lextree subscribers never see each other's data.

  • An automatic trail of every change

    Every create, update, and delete is logged automatically — in the same database transaction — with the user who made it, a timestamp, and the fields that changed.

  • Daily backups, point-in-time recovery

    Your data is backed up on managed infrastructure, with point-in-time recovery to roll back to a moment before a mistake.

  • Passwordless sign-in, SSO, and MFA

    Sign in without passwords — Lextree never stores one to be stolen — with multi-factor authentication available and SAML or OIDC single sign-on on Enterprise plans.

Read the full security overview →
Part of these solutions

Certifications is one piece of a bigger picture

See how this module combines with others to solve common compliance challenges.


Common questions

Frequently asked questions

What kinds of certifications belong in this module?
Corporate-level certifications and attestations — SOC 2, ISO 27001, ISO 9001, PCI-DSS, HIPAA, HITRUST, FedRAMP, supplier diversity (MBE, WBE, DBE), B Corp, industry-specific certifications, and any other recurring attestation your organization holds or pursues.
Is this for the certifications we hold, or the ones we require from vendors?
Both — but they’re separate records. The Certifications module tracks what your own entities hold. Vendor-side certifications (a vendor’s SOC 2 report, their insurance attestations) live on the vendor record in the Vendors module.
Can we track the audit cycle leading up to a certification?
Yes. Each certification carries its readiness phase, audit fieldwork dates, report issuance, and the next renewal cycle. The Workflow feature can route the pre-audit checklist through the controls owners who need to attest.
Does Lextree store the audit reports and certificates?
Yes. The issued certificate, the auditor’s report, supporting evidence, and any qualifications or exceptions all attach to the certification record. Customers who request your SOC 2 get the current letter without a chase.
Can certifications cover multiple entities or specific locations?
Yes. Each certification names the scope — which entities, which products, which locations are covered. When you add a new product line or location, you can see immediately whether your existing certifications cover it or whether a scope expansion is needed.
Does Lextree send reminders for upcoming audits and renewals?
Yes. Certifications carry their next-audit date and renewal date with advance notifications. SOC 2 Type II audits, ISO surveillance audits, and certification renewals fire reminders well in advance so audit prep starts on time.
Pricing

Every plan includes all 17 modules

Tiers add user limits, granular permissions, and enterprise controls. Modules stay constant.

  • Pro

    $75/ mo

    Includes 5 seats, then $5 / seat

    For teams moving off spreadsheets and scattered files.

    Start free trial →
  • Business

    $550/ mo

    Includes 5 seats, then $7.50 / seat

    For businesses that need collaboration, workflows, and reporting.

    Start free trial →
  • Enterprise

    $950/ mo

    Includes 5 seats, then $10 / seat

    For organizations with security, governance, and scale needs.

    Start free trial →

Stop managing compliance from memory.

Search