A plain-English guide to the two kinds of security certification: ACS vs NSI… and why the same company can be certified for one and not the other.

Picture a security company that turns up with everything in order. The guards are SIA licensed. The directors are vetted. The firm holds ACS approval and will happily show you the certificate. Then they fit your CCTV and access control… and there is no certification covering any of that work at all.

That is not a rogue operator cutting corners. It is a normal, well-run business that holds the certification for one thing it does and not the other. And it catches buyers out constantly, because most people assume one security certificate covers the whole company.

It doesn’t. There are two different worlds of security certification – ACS and NSI being the two names you’ll meet most – and they sit on top of two different sets of standards. A company can live in one without ever touching the other. If you buy security services or you sell them, this is the thing worth getting straight.

Lollipop’s Jo Shaer sat down with Amy Perkins from Compliant Creations to map it out. Amy spent years as a compliance director inside the security industry before setting up on her own. She now takes guarding and events companies through ACS, ISO and the other schemes that prove they know what they are doing. She lives in this detail every day. This article is the result of that conversation.

Two activities, two certifications

The cleanest way to understand security certification is to stop thinking about companies and start thinking about activities.

A security firm might guard a building. It might also install the cameras watching that building. Those are two different activities. They are certified in two completely different ways.

The guarding side is covered by the SIA’s Approved Contractor Scheme – ACS. This is about people and the services they deliver. Manned guarding, door supervision, key holding, mobile patrols and watching CCTV from a control room. It is assessed against British Standards written for those services and the whole thing runs under the Security Industry Authority, the body that regulates the private security industry.

Note that last one carefully. ACS can cover CCTV operation – licensed people monitoring cameras. That is a different thing from CCTV installation – fitting the cameras in the first place. Same three letters, two different jobs. Hold that thought, because it is exactly where buyers come unstuck.

The installation side – fitting intruder alarms, CCTV systems, access control – is covered by third-party certification from bodies like NSI and SSAIB, assessed against the British Standards written for installing those systems.

Same building. Same supplier, sometimes. Two entirely separate certifications, because the work is entirely separate.

As Amy put it, when buyers come across these terms the confusion is almost guaranteed:

“Sometimes my clients don’t understand the difference between the ACS, NSI and SSAIB, so I have to explain. The ACS is the voluntary scheme introduced by the SIA, whereas NSI and SSAIB are the certificating bodies appointed by the SIA to assess against the ACS scheme.”

Amy, Compliant Creations Ltd

That is the heart of it. ACS is the scheme – the standard you are measured against. NSI and SSAIB are certification bodies – the independent assessors who check you against it. They are not competing badges. They sit at different points in the same chain.

So what actually is ACS?

ACS is a voluntary scheme run by the SIA for the manned, on-the-ground side of security. A company that achieves it has opened its management systems and its people up to independent inspection and met a defined standard.

Here is the part people miss. It is not mandatory. Amy is firm on this and she takes an honest line with her own clients when they ask whether they need it:

“If they ask me, do I need ACS, I don’t give them an answer. I answer with a question. Do your clients want you to have ACS? If your clients aren’t even asking you about it, then I would ask, do you think you need it? Because I can’t answer the question for you. You don’t need it to operate. What it does do is give buyers the same amount of assurance as every other accreditation does. It tells buyers that you’re working to a set standard.”

Amy, Compliant Creations Ltd

That is the right way to think about any voluntary certification. It does not give a company permission to trade. It gives a buyer a reason to trust them.

One detail surprises people. ACS approval is sector-specific. A company can be approved for security guarding but not for door supervision. The certificate is not a blanket. It covers named activities and only those.

ACS vs NSI: where the confusion really sits

Here is where the confusion peaks, so it is worth slowing down.

NSI and SSAIB do two jobs. That is exactly why people get tangled.

On the guarding side, they are two of the three bodies the SIA appoints to assess companies against ACS. The third is the British Assessment Bureau. So when a guarding firm goes for ACS, it is NSI, SSAIB or the British Assessment Bureau doing the actual assessing.

On the installation side, NSI and SSAIB run their own certification schemes for electronic security – intruder alarms, CCTV, access control – checking installers against the relevant British Standards for that equipment.

So the same two names show up in both worlds, doing related but different work. That is the bit that trips everyone up. When someone says “we’re NSI certified,” the only useful next question is: certified for what? Guarding? Installation? Both? One does not imply the other.

Amy makes the point that none of these bodies invents its own rulebook. They all measure against established British Standards:

“Ultimately, it all links back to British Standards. Within the private security industry there are a number of recognised standards and certification bodies such as NSI and SSAIB aren’t assessing against criteria they’ve created themselves. They’re assessing businesses against the relevant British Standards and industry requirements to ensure they consistently meet those expectations, all whilst meeting the requirements of the ACS scheme.”

Amy, Compliant Creations Ltd

That matters, because it is what makes the certification mean something. The standard is fixed and published by BSI. The certification body checks you against it. The assessment is independent. That is the difference between a badge a company awards itself and one that has been earned.

Why this catches buyers out

Most buyers of security services have never been taught any of this. They are not specifiers. They are facilities managers, office managers, business owners – people buying a service they assume is straightforward.

Amy sees the gap from the inside:

“I don’t think there is enough knowledge out there for buyers to understand the pros and cons of what it is they are purchasing and how it will benefit their business in the long run.”

Amy, Compliant Creations Ltd

And it is not really their fault. The scheme is voluntary, so nobody is obliged to explain it. The names overlap. The marketing rarely spells out scope. A guarding company that proudly displays its ACS approval and its SIA licences, then quietly fits CCTV with no installation certification at all, is not necessarily hiding anything. It may simply never have occurred to anyone that the two things are different.

That is the trap. A buyer sees a certificate, assumes it covers everything and never asks the question that would reveal the gap.

What a buyer should actually ask

If you commission security work, the protection here is simple and it costs you nothing. Once you understand the ACS vs NSI certification split, you ask one more question than you would have – and it’s the question that matters.

When a company tells you they are certified, ask what for. Then check the certification matches the work you are actually buying.

  • Buying guarding, door supervision or key holding? ACS approval is granted activity by activity, so a firm can be approved for guarding but not for key holding, even if they offer both. The logo on its own does not tell you which. So check the certification matches the work you are actually buying.
  • Buying an installed system – intruder alarm, CCTV, access control? Ask whether the company holds NSI or SSAIB certification for installation, against the British Standard for that system.
  • Buying both from the same supplier? Then you need to see both. One certificate does not stand in for the other.

How to check before you sign

You can verify all of this yourself – and which register you check depends on the service. For guarding, door supervision or key holding, the SIA publishes a public register of approved contractors that shows exactly which activities a company’s ACS approval covers. The SIA is clear that approval is granted for specific activities, not for the company as a whole, so the register is where you confirm the approval actually covers the service you are buying.

For installed systems, the NSI and SSAIB company finders show what a company is certified to install and in what scope. A real credential shows up on the right register, scoped to the exact service. A vague claim does not.

The certification bodies take this seriously. Their company finders list the exact categories a company is certified for – intruder alarms, CCTV, access control – so a logo on a website is never the final word. The register is.

Amy’s filter for her own clients works just as well for buyers. Do not accept “we’ve been doing this for years” as proof. Years are not evidence. Certification is.

What an installer should take from this

If you are a security or installation company reading this, the lesson runs the other way – and it is a commercial one.

If you do work that can be certified and you have not certified it, you are leaving the buyer to guess. Some will give you the benefit of the doubt. The good ones – the ones running real due diligence, the ones with budgets worth winning – increasingly will not.

And if you are certified, make sure the buyer can see exactly what for. Scope is everything. “NSI certified” on its own does not tell a procurement team whether you can certify the system they are about to commission. Spell it out: the scheme, the scope, the standard. Make it impossible to get wrong.

The certification bodies expect the same discipline. Their marks are tied to the specific services they have certified, not to everything you offer – so the cleanest thing you can do is make scope obvious yourself, before a buyer has to go digging.

This is the same shift happening across the whole sector. Buyers are being asked to prove they chose competent suppliers. The companies that make their competence – and its exact scope – easy to verify are the ones that get chosen.

The ones that leave it vague get passed over, however good the work actually is. We go deeper into this in our guide to how to win fire and security contracts by making competence easier to verify.

One more thing on the horizon

ACS is not standing still. The SIA has been consulting on a replacement – the Business Approval Scheme or BAS – intended to launch during the 2026/27 business year. It is designed to shift the emphasis from box-ticking towards the outcomes a security company actually delivers on the ground.

The detail is still being finalised, so nobody should be making firm claims about exactly how it will work yet. But the direction of travel is clear – and it is the same direction fire safety has already taken. More accountability. More emphasis on demonstrable competence. A named person who has to stand behind the choices they made.

For buyers and installers alike, getting the ACS vs NSI certification basics straight now is worth doing. What you hold. What it covers. How a buyer can check.


This article was written in collaboration with Amy at Compliant Creations, who guides security and guarding companies through ACS, ISO and related certification.

If you’re third-party certified, we make your competence visible to the buyers who need to see it – so you get chosen and the Responsible Person choosing you can show they did their due diligence. Contact the Lollies to find out more here.

This article references UK security industry regulation and certification schemes for context. It is not legal advice. For specific compliance or due diligence questions, readers should seek advice from a qualified solicitor or competent security professional.

Struggling to get enough of the Right enquiries?

Since 2010, Lollipop has helped Fire & Security businesses like yours stand out in a crowded market and win millions of pounds of work…

Our Fire & Security Visibility Engine™ gets the Right Message to the Right Person at the Right Time. So you can win more of the Right Work with less effort.

Curious how it could work for your business?

"Genuine enquiries… at a steady pace"
Phil Clarke, CCTV Hire & Sales
Book your free Visibility call with Jo

Limited slots available — book now to secure yours

Happy Fire & Security director

Trusted by the Fire & Security industry for websites, lead generation and sales since 2010...