On this page
An ISO 27001 certifying body, which the standards call a certification body, audits a company’s information security management system (ISMS) against ISO/IEC 27001 and decides whether to issue the certificate. ISO writes the standard but does not certify anyone. A separate accreditation body, such as ANAB in the United States, UKAS in the United Kingdom, or DAkkS in Germany, checks that the certifying body is competent and impartial.
To check one, find the legal entity named in your proposal in its accreditor’s directory with ISO/IEC 27001 inside the listed scope. Once the certificate is issued, look it up in IAF CertSearch. The steps are below.
This page explains the roles, the audit cycle, and the questions to put to a body before you sign. It does not rank bodies. Our ISO 27001 certification companies page compares them by legal entity, accreditor, accredited scope, and primary evidence, and the ISO 27001 certification cost guide covers what the audits cost.
Who certifies, who accredits, and who checks whom
An ISO 27001 certificate is backed by a chain of checks, shown here from the standards down to your company.
Role: Publish ISO/IEC 27001:2022, which your ISMS must meet, and ISO/IEC 27006-1:2024, which adds requirements for bodies that audit and certify an ISMS. ISO does not issue certificates.
Check it at: iso.org, for the current edition of each standard.
Role: Admits national accreditation bodies to its multilateral recognition arrangement after peer evaluation. Signatories accept each other's accredited work as equivalent, except where law prohibits it.
Check it at: the Global ACI site, which lists the signatory accreditation bodies.
Role: Assesses a certifying body for competence and impartiality and lists the standards it is accredited to certify.
Check it at: the accreditor's public directory.
Role: Audits your ISMS, decides on certification, issues the certificate, and returns for surveillance and recertification. The people who decide are not the people who audited.
Check it at: the accreditor's directory and IAF CertSearch.
Role: Operates the ISMS. The certificate covers only the scope you defined.
Check it at: the scope statement and dates on your own certificate.
ISO says accreditation gives independent confirmation of a certifying body’s competence, but it is not compulsory, and a body without it is not automatically disreputable. The party that decides what counts is your customer. Ask which accreditors it accepts before you buy, and get the answer in writing.
IAF, Global ACI, and the names you will still see
Older guides, vendor pages, and many certifying-body sites describe the International Accreditation Forum (IAF) and its Multilateral Recognition Arrangement (MLA) as the global layer. Global ACI became fully operational on 1 January 2026 and assumed the former roles of IAF and the International Laboratory Accreditation Cooperation. IAF’s legacy site says IAF ceased operations on that date. Global ACI now publishes the recognition arrangement as the Global ACI MRA.
The certificate database kept its old name, IAF CertSearch. A customer who asks for an “IAF MLA” signatory is most likely asking about the same recognition arrangement, but confirm the wording before you answer a questionnaire.
What ISO/IEC 27006-1 adds to the audit
A certifying body works to ISO/IEC 17021-1, the general requirements for bodies that audit and certify management systems. ISO/IEC 27006-1:2024 adds the requirements specific to an ISMS. ISO describes its purpose as making sure ISMS certifications are issued competently, consistently, and impartially.
Two parts matter to a buyer:
- The standard calculates audit time from the number of people working within the ISMS scope, and the 2024 edition counts non-employees such as freelancers when they fall inside that scope. Audit days and day rates drive the fee, so headcount and scope decide what you pay.
- It replaced ISO/IEC 27006:2015, which ISO now lists as withdrawn. ANAB required its accredited ISMS bodies to use the 2024 edition for all clients by 31 March 2026, so ask any body whether its accreditation covers the 2024 edition.
How to verify a certifying body and a certificate
- Get the legal name of the issuing entity from the proposal. The brand and the accredited entity often differ. The records behind our directory list Bureau Veritas as “Bureau Veritas Certification Holding SAS - UK Branch” and TÜV Rheinland as “TUV Rheinland of North America, Inc.”
- Find that entity in its accreditor’s directory. ANAB links a directory of accredited management systems certification bodies from its ISO/IEC 27001 page, and UKAS lists accredited organisations under Who’s accredited. For any other accreditor, search its public register or ask it directly.
- Check that ISO/IEC 27001 sits inside the accredited scope. Accreditation for another management standard does not cover ISMS certification. Record the accreditor, the legal entity, the scope, and the date you checked.
- Look up the certificate in IAF CertSearch. ISO says CertSearch aggregates accreditation-body and certification-body data, so one lookup confirms the certificate and the body’s accreditation status together. Compare the name, certificate number, standard, scope, and dates.
- Treat a missing or mismatched record as a question, not a verdict. Under IAF MD 28:2023, certifying bodies must upload data on all management system certificates at least monthly, with conformance assessed from 27 October 2024. A gap can be an upload delay or a real problem. Ask the body in writing, and ask the accreditor if the answer does not settle it.
A logo or accreditation mark on a certificate is not evidence by itself, because a lookup can be checked and an image can be copied. Also check that the certificate cites ISO/IEC 27001:2022. The transition deadline for 2013 certificates was 31 October 2025.
The certification cycle: Stage 1, Stage 2, surveillance, recertification
A first certificate needs a two-stage audit and a separate certification decision. The certificate then runs for up to three years. Surveillance audits must happen at least once per calendar year except in recertification years, and the first falls within 12 months of the certification decision. Recertification happens before the certificate expires.
| Audit | When | What the body tests |
|---|---|---|
| Stage 1 | Before Stage 2 | Scope, the required documentation, and readiness for Stage 2, including a completed internal audit and management review |
| Stage 2 | After Stage 1 | Whether the ISMS and the selected controls operate as documented, through sampling and interviews |
| Certification decision | After Stage 2, once findings are corrected | A review by people who did not run the audit |
| Surveillance, years 1 and 2 | First within 12 months of the decision, then at least once per calendar year | A sample of the ISMS, not the whole system |
| Recertification | Year 3, before expiry | The whole ISMS again, for a new three-year certificate |
Stage 1 and Stage 2 sit before month 0 on the chart, so the first surveillance clock starts at the certification decision, not at kickoff. Ask for a price on every line before you sign, because the lowest first-year quote can leave out the surveillance and recertification years. The ISO 27001 certification cost guide shows how to compare them.
Questions to ask a certifying body
Send every candidate the same scope description and compare written answers.
- Which legal entity will issue my certificate, and where does the accreditor list it with ISO/IEC 27001 in scope?
- Which accreditation body covers the office and country that will audit me, and does it cover ISO/IEC 27006-1:2024?
- How many audit days do you assign to Stage 1, Stage 2, each surveillance audit, and recertification, and how did you count my headcount and contractors?
- Who will audit, what cloud and software experience do they have, and will the lead auditor stay for the cycle?
- Do you, or any company in your group, sell ISMS consulting, readiness, or internal audits?
- How do you handle nonconformities, complaints, appeals, suspension, and a transfer to another body?
- Will you upload my certificate to IAF CertSearch, and how soon after issue?
- What does each year of the cycle cost, and what changes the price?
The fifth question matters because ISO/IEC 17021-1 clause 5.2.5 says the certification body and any part of the same legal entity shall not offer or provide management system consultancy. The standard also treats consultancy or internal audits from a related organisation as a threat to impartiality, and names a two-year gap before certifying as a recognised mitigation. Keep your implementation consultant and your certifying body under separate contracts. Our ISO 27001 consultants page covers the implementation side.
Using one firm for ISO 27001 and SOC 2
A certifying body is not a CPA firm, and a SOC 2 report is not an ISO certificate. The two come from different issuers under different rules.
| SOC 2 report | ISO 27001 certificate | |
|---|---|---|
| Issued by | A licensed CPA firm | An accredited certifying body |
| Rules the issuer follows | AICPA attestation standards | ISO/IEC 17021-1 and ISO/IEC 27006-1 |
| What you receive | A report with the auditor’s opinion on your controls | A certificate with a scope statement and dates |
| How a reader verifies it | Ask the firm, then check its CPA licence and peer review | Accreditor directory and IAF CertSearch |
The AICPA describes SOC reports as services CPAs provide, and our SOC 2 auditor certification guide explains how to check a firm’s authority to issue one. A consultancy, a compliance platform, or a certifying body that is not a CPA firm cannot sign your SOC 2 report.
One brand can still deliver both. In our directory, Baker Tilly lists a certification body named Baker Tilly Certifications LLC, and Schellman lists Schellman Compliance, LLC. Ask any dual-scope firm to name the entity that signs the SOC 2 report, the entity that issues the certificate, and the accreditor behind the certificate. Expect separate engagement letters and separate fees. Shared evidence is possible but not automatic: SOC 2 and ISO 27001 differ in scope, period, and sampling, so ask for an evidence map that marks what each issuer will accept.
Where to go next
- Compare bodies by accredited scope and primary evidence on ISO 27001 certification companies.
- Price the three-year cycle with the ISO 27001 certification cost guide.
- See which SOC 2 firms also hold an ISO 27001 certification-body role on SOC 2 and ISO 27001 auditors.
More in Framework Comparisons