Several members from the O&P community urged me to write a series of blog posts about CERT Audits. The consensus among the practitioners was that the subject of CERT Audits needs more attention, and that the requirements are unfair and unrealistic.
It looks to me like the O&P community is going to get crushed with these audits.
If you are unfamiliar with blogging, scroll down until the January 30th post (you will have to click on the "next" tab at the bottom of the page). Read that, and work your way up. There was one post per day from January 30th until now, with questions and answers from the CERT Task Force regarding the audit requirements.
We hope you take the time to read and comment on any or all of the posts. What do you think about CERT Audits? The CERT requirements? Is there anything the O&P community should do?
We look forward to reading about what you think.