BITS Financial Services Roundtable
Certification Member Login Here:
Photograph
Our Company

Why should I have my company's product certified?

The BITS certification process is a consistent, objective means of evaluating and testing for security standards. Earning the BITS Tested Mark helps reduce the real and perceived risks that can act as a barrier to customers purchasing technology products. The BITS Tested Mark demonstrates to customers that your company is aware of and cares about security issues. When your product earns the BITS Tested Mark, your company improves safety and security for everyone. Certification helps build consumer confidence, leads to more widespread use of technology, and promotes the growth of e-commerce.

How should my company prepare for product certification?
Technology companies should approach testing with a high degree of confidence that their product will meet all necessary criteria. Therefore, companies should prepare for the certification process by first downloading the appropriate criteria and performing an internal assessment of the product against the criteria. BITS may be consulted during this period. Once the product is ready to be tested, a testing facility can be contacted for testing service contracts.
Back To Top

How can I estimate the cost of testing?
The total cost and time involved in testing depends upon many factors, including product breadth and complexity, the criteria being tested against, and how well the product meets the criteria. Therefore, it is difficult to estimate testing costs.

Contracts between the testing facility and the technology vendor provide hourly or fixed-fee charges and cost estimates. BITS maintains an independent testing option that offers a potentially faster and more affordable method for smaller firms to complete testing.
Back To Top

Are products evaluated at the source-code level?
Source-code reviews will not be performed, nor will any on-site reviews of the development process. The testing process focuses on the security functionality of the product.
Back To Top

What is the life of the BITS Tested Mark?
The BITS Tested Mark is good for the life of the specific version of the product tested as long as:

  • the product remains in compliance with the security criteria;
  • the company remains in compliance with the seal use rules;
  • the company pays the annual seal use fee; and
  • the product is not materially modified.

Please see the seal sublicense agreement for specific terms for using and complying with the certification seal.
Back To Top

Where can I go for more information?
For more information about the BITS Product Certification Program, please contact Ann Patterson, ann@fsround.org.
Back To Top

BITS Product Certification Program
Overview
Security Criteria
Alignment with Common Criteria
BITS Tested Mark -
Product List
Frequently Asked Questions

"Wells Fargo intends to satisfy all of our customers' financial needs. We know retaining our customers' business depends on fulfilling their expectations for quality service, including securing their personal information and financial transactions. We regard the BITS Tested Mark as the minimum acceptable assurance that the technology products we buy meet Wells Fargo's explicit standards for security and privacy."
-Richard M. Kovacevich, Chairman and CEO, Wells Fargo & Company