Logo Menu

ISO 27001 certification companies: compare 15 evidenced certification bodies

Certification bodies audit your Information Security Management System and decide whether to issue the certificate; consultants build the system but cannot certify their own work. This directory includes only role-safe records with primary evidence of ISO 27001 certification authority, then exposes the legal entity, accreditation, scope, location, evidence date, and source buyers need to verify.

Compare 15 bodies ↓

By Peter Korpak / Updated

Verified bodies
15primary evidence
Authority named
13in source record
Scope documented
13in source record
Verified directory

Compare evidenced ISO 27001 certification bodies

Every listed firm has current primary evidence that it can perform certification audits and issue ISO/IEC 27001 certificates. Search by firm, accreditation authority, location, scope, or industry.

Selection and evidence key

1 · Legal entity
Match the certification entity shown here to the entity named in the proposal and primary evidence.
2 · Eligible role
Every row has structured evidence for the certification-body role. Consulting, a lead-auditor credential, or the firm’s own certificate does not qualify.
3 · Authority and scope
Use the named authority and detailed ISO/IEC 27001 scope when published. “Not published” means no authority is recorded; “Not verified” means detailed scope is absent.
4 · Evidence
Check the record date and open the primary source before signing. Eligibility is evidenced; the directory does not rank service quality.

Rows follow the source dataset’s deterministic order. Paid placement does not change eligibility or order.

360 Advanced

St. Petersburg, FL, USA

Provider role
ISO 27001 certification body
Legal entity
360 Advanced Compass Rose
Accreditation authority
ANSI National Accreditation Board (ANAB)
Verified scope
Not verified
Industries in record
Enterprise IT Outsourcing, Managed Security, Healthcare Claims Management, B2B SaaS
Evidence checked

Armanino LLP

San Ramon, CA, USA

Provider role
ISO 27001 certification body
Legal entity
Armanino Certified, LLC
Accreditation authority
ANAB
Verified scope
ISO/IEC 27001 and ISO/IEC 27701
Industries in record
Technology, Healthcare, Financial Services, Private Equity
Evidence checked

BARR Advisory

Kansas City, MO, USA

Provider role
ISO 27001 certification body
Legal entity
BARR Certifications
Accreditation authority
ANAB
Verified scope
ISO/IEC 27001:2022
Industries in record
B2B SaaS, Cloud Infrastructure (AWS, Azure, GCP), FinTech, Healthcare Technology
Evidence checked

Coalfire

Chicago, IL, USA

Provider role
ISO 27001 certification body
Legal entity
Coalfire Certification
Accreditation authority
ANAB and UKAS
Verified scope
ISO/IEC 27001
Industries in record
Cloud Infrastructure, Federal/Government, FinTech & Payments, Healthcare
Evidence checked

Johanson Group

Colorado Springs, CO, USA

Provider role
ISO 27001 certification body
Legal entity
Johanson Group LLP
Accreditation authority
IAS
Verified scope
ISO/IEC 27001:2022
Industries in record
B2B SaaS, Startups (Pre-Series A through Series B), FinTech, HealthTech
Evidence checked

Prescient Security

Nashville, TN, USA

Provider role
ISO 27001 certification body
Legal entity
Prescient Security LLC
Accreditation authority
IAS
Verified scope
ISO/IEC 27001:2022
Industries in record
B2B SaaS, FinTech, HealthTech, Cloud Technology
Evidence checked

Schellman

Tampa, FL, USA

Provider role
ISO 27001 certification body
Legal entity
Schellman Compliance, LLC
Accreditation authority
ANAB and UKAS
Verified scope
ISO/IEC 27001
Industries in record
Government/Defense, Healthcare, Financial Services, Technology/SaaS
Evidence checked

Securisea

Annapolis, MD, USA

Provider role
ISO 27001 certification body
Legal entity
Securisea CB, LLC
Accreditation authority
ANAB
Verified scope
ISO/IEC 27001, ISO/IEC 27701, and ISO/IEC 27018
Industries in record
B2B SaaS, Cloud Services, Healthcare, Financial Services
Evidence checked

Sensiba LLP

Pleasanton, CA, USA

Provider role
ISO 27001 certification body
Legal entity
Sensiba LLP
Accreditation authority
Not published
Verified scope
ISO/IEC 27001
Industries in record
B2B SaaS, Technology, FinTech, Life Sciences & Healthcare
Evidence checked

AARC-360

Atlanta, GA, USA

Provider role
ISO 27001 certification body
Legal entity
AARC-360
Accreditation authority
IAS
Verified scope
ISO/IEC 27001:2022
Industries in record
Technology, Financial Services, Healthcare, Government
Evidence checked

BSI Group

London, UK, UK

Provider role
ISO 27001 certification body
Legal entity
BSI Assurance UK Limited
Accreditation authority
UKAS
Verified scope
ISO/IEC 27001:2022
Industries in record
Technology, Financial Services, Healthcare, Manufacturing
Evidence checked

Frank, Rimerman + Co.

Palo Alto, CA, USA

Provider role
ISO 27001 certification body
Legal entity
Frank, Rimerman Information Security
Accreditation authority
ANAB
Verified scope
ISO/IEC 27001 and ISO/IEC 27701
Industries in record
SaaS, Software, FinTech, Healthcare
Evidence checked

SAV Associates

Toronto, ON, Canada

Provider role
ISO 27001 certification body
Legal entity
SAV Associates
Accreditation authority
SCC
Verified scope
Not verified
Industries in record
Technology, Financial Services, Healthcare, FinTech
Evidence checked

Thoropass

New York, NY, USA

Provider role
ISO 27001 certification body
Legal entity
Thoropass Certification LLC
Accreditation authority
Not published
Verified scope
ISO/IEC 27001
Industries in record
B2B SaaS, FinTech, HealthTech, AI
Evidence checked
Methodology

How did a firm qualify for this ISO 27001 directory?

A record qualifies only when the firm’s own current material or an accreditor registry states that the named certification body can audit and issue ISO/IEC 27001 certification. We checked all 15 legacy candidates on August 5, 2026. A consultancy, an unaffiliated referral partner, a lead-auditor credential, or an ISO certificate held by the firm does not qualify.

The directory publishes an accreditation authority or scope only when the primary record supports it; otherwise the row says “Not published” or “Not verified.” SOC 2 prices and timelines are deliberately absent because those fields describe a different engagement. Paid placement cannot change eligibility, order, verification, or recommendation. Read the full directory methodology →

Role separation

Consultants implement the ISMS; certification bodies audit and certify it.

Separate the two roles before comparing proposals. The same brand group may offer both only through impartial legal entities and teams.

Factor ISO 27001 consultantCertification body
Primary job Design and prepare the ISMSAudit the ISMS and decide certification
Typical work Scope, risk assessment, SoA, policies, remediationStage 1, Stage 2, surveillance, recertification
Can issue the certificate? NoYes, inside accredited scope
Evidence to verify Named practitioners and deliverablesAccreditor record, legal entity, standard and scope
Selection method

How to verify and choose a certification body

Shortlist by accredited scope and geography first, then compare sector experience, audit-day assumptions, transfer rules, and coordination with your independent consultant.

01Verify the legal entity and accredited scope

Match the proposal to the legal entity in the primary evidence. Confirm ISO/IEC 27001 is active in the accreditor record; a generic ISO badge, lead-auditor credential, or certificate held by the provider does not prove authority to certify you.

02Confirm geography, scope, and auditor competence

Ask which office and accreditation cover the engagement, whether remote audit methods fit the proposed scope, and whether the assigned audit team has experience with your industry, cloud architecture, and integrated management systems.

03Compare the complete three-year cycle

Require the quote to separate Stage 1, Stage 2, annual surveillance, travel, certificate administration, and year-three recertification. The lowest initial fee can be the higher lifecycle cost when surveillance or audit-day assumptions are omitted.

04Protect independence and transfer rights

Keep implementation consulting outside the certification decision. Ask how the body handles complaints, appeals, certificate suspension, scope changes, and transfers if service quality or commercial terms change during the cycle.

FAQ

ISO 27001 certification-body questions

The role, accreditation, audit-stage, independence, and verification questions to settle before signing a certification proposal.

What is an ISO 27001 certification body?

An ISO 27001 certification body is an independent organisation accredited to audit an Information Security Management System and issue the certificate. The body performs Stage 1 and Stage 2, makes the certification decision, returns for annual surveillance, and handles recertification in year three.

What is the difference between accreditation and certification?

Accreditation evaluates the certification body; certification evaluates your organisation. National accreditation bodies such as ANAB, UKAS, IAS, or SCC assess whether a certification body is competent and impartial. The accredited body then audits your ISMS and issues the ISO 27001 certificate.

Can my ISO 27001 consultant also certify my ISMS?

No. A consultant can design the ISMS, write policies, run a gap assessment, and prepare evidence, but the certification body must remain impartial. Keep implementation and certification in separate contracts and ask each provider to identify the legal entity performing its role.

What happens in Stage 1 and Stage 2?

Stage 1 reviews the ISMS scope, required documentation, internal audit, management review, and readiness for full assessment. Stage 2 tests whether the ISMS and selected controls operate in practice. Unresolved major nonconformities prevent certification until the body verifies corrective action.

How do I verify an ISO 27001 certification body?

Open the body’s current primary evidence or accreditor record, confirm ISO/IEC 27001 is inside the accredited scope, match the legal entity on the proposal, and verify the certificate through IAF CertSearch or the named national accreditation body. A logo or consultant partnership is not enough.
Tell us your scope

Need certification-body quotes without exposing your company?

Send the ISMS scope, locations, headcount, and certification deadline. We manually review the request before any certification body receives an anonymized brief.

Free and anonymous. We’ll follow up by email.