ISO 27001 Accreditation vs Certification: What It Means and How to Verify It
ISO 27001 accreditation is something your certification body holds, not your company. Here is how the accreditation chain works, what ISO/IEC 27006-1:2024 requires, and how to check any ISO 27001 certificate in five minutes.
ISO 27001 accreditation is not something your company can get. Companies are certified to ISO 27001. Certification bodies are accredited to audit and certify them. When a sales deck or supplier says "ISO 27001 accredited", it usually means certified by an accredited body. Sometimes it means nothing at all.
The difference matters. An accredited ISO 27001 certificate can be checked by any customer, in any country. An unaccredited one can be printed by anyone. This guide explains how the accreditation chain works and what the rules require of a certification body. If you are choosing an accredited ISO 27001 certification body, the five-step check below takes about five minutes.
Quick answer: ISO 27001 accreditation is held by certification bodies, not companies. An accreditation body such as UAF, ANAB or UKAS checks that a certification body is competent and impartial to audit an ISMS. The rules it uses are ISO/IEC 17021-1 and ISO/IEC 27006-1:2024. Your company earns ISO 27001 certification from that accredited body. To check a certificate, confirm the certification body's ISMS scope and its accreditation body's IAF MLA status. Then search IAF CertSearch.
ISO 27001 Accreditation vs Certification: The Short Answer
Certification and accreditation sit at two different levels. The International Accreditation Forum (IAF) defines accreditation as the independent evaluation of conformity assessment bodies for impartiality and competence. Certification is the third-party attestation that your system meets the standard.
| ISO 27001 certification | ISO 27001 accreditation | |
|---|---|---|
| Who gets it | Your organization | The certification body that audits you |
| Who grants it | An accredited certification body | An accreditation body, such as UAF, ANAB or UKAS |
| Standard used | ISO/IEC 27001:2022 | ISO/IEC 17021-1 and ISO/IEC 27006-1:2024 |
| What it proves | Your ISMS meets ISO 27001 | The certification body is competent and impartial to audit an ISMS |
| How to check it | The certification body's register, IAF CertSearch | The accreditation body's directory, the IAF list of MLA signatories |
For the wider picture across all standards, read our guide to what an accredited ISO certification body is.
Why Your Company Can't Be "ISO 27001 Accredited"
The IAF is clear on this point: organizations are certified, and certification bodies are accredited. ISO 27001 sets requirements for your information security management system (ISMS). It says nothing about accrediting anyone. So when you see "ISO 27001 accredited" on a website, it usually means one of three things.
Loose wording
The company holds an ISO 27001 certificate from an accredited body. Common, and usually fine, but still worth checking.
A non-accredited certificate
The certificate came from a body with no recognized accreditation for information security. Customers and tenders may reject it.
A misleading claim
The company has no certificate, or one that has expired or been withdrawn.
If you are writing your own marketing copy, say "ISO 27001 certified" and name the certification body. It is accurate, and it lets buyers verify you.
Getting certified for the first time? Our step-by-step guide covers scope, Stage 1, Stage 2, timelines and what drives audit days.
Read: How to get ISO 27001 certifiedHow ISO 27001 Accreditation Works: Four Levels of Trust
ISO 27001 accreditation is a chain. Each level checks the one below it, so a certificate at the bottom can be trusted worldwide.
- 01The IAF and its MLAThe IAF runs the Multilateral Recognition Arrangement (MLA). Accreditation bodies that sign it are peer-evaluated, so their accredited certificates are accepted across member economies.
- 02Accreditation bodiesBodies such as UAF, ANAB and UKAS assess certification bodies against ISO/IEC 17021-1 and, for information security, ISO/IEC 27006-1.
- 03Certification bodiesAccredited certification bodies audit your ISMS in two stages, make an independent certification decision and run yearly surveillance audits.
- 04Your organizationYou hold the ISO 27001 certificate for a defined scope of people, locations and services.
Accreditation is granted by scope. A certification body may be accredited for ISO 9001 but not for ISO 27001. Always check that information security management systems are in the certification body's accredited scope.
What ISO/IEC 27006-1:2024 Requires of an ISO 27001 Certification Body
ISO/IEC 27006-1 is the standard behind ISO 27001 accreditation. It adds information security rules on top of the general certification body standard, ISO/IEC 17021-1. The current edition, ISO/IEC 27006-1:2024, was published in March 2024. It replaced ISO/IEC 27006:2015 and its 2020 amendment.
According to ANAB, the US accreditation body, the 2024 edition makes four practical changes:
Audit time
Audit days are calculated from an "effective number of personnel" in scope, not a flat figure.
Remote audits
New rules on when and how remote audit methods can be used and reported.
2022 controls
Guidance is aligned with the ISO/IEC 27001:2022 Annex A controls.
Auditor competence
Fixed years-of-experience rules for ISMS auditors are replaced by competence requirements.
ANAB gave its accredited certification bodies until 31 March 2026 to apply the 2024 edition to all clients. Other accreditation bodies set similar transition periods. In practice, your audit time should be calculated from your real headcount and scope. A flat price that ignores both is a warning sign.
Who Checks ISO 27001 Accreditation, and When
Accreditation is rarely checked by the company that holds the certificate. It is checked by the people who rely on it.
- Enterprise procurement. Security questionnaires often ask for the certificate, the certification body and the accreditation body behind it.
- Public tenders. Many tenders accept only certificates issued under accreditation. An unaccredited certificate can fail the compliance check before your bid is scored.
- Your customers' auditors. When your customers are audited, their auditors may ask how they assessed you. An accredited certificate is the simplest answer.
- Investors and acquirers. Due diligence teams check that the security claims in your data room can be verified.
If you plan to use your certificate in any of these places, choose an accredited certification body from the start. Switching later means another audit cycle.
Accredited vs Non-Accredited ISO 27001 Certificates
Non-accredited certificates are sometimes cheaper and faster. They often cost more in the end, when a customer or tender rejects them.
| What buyers check | Accredited certificate | Non-accredited certificate |
|---|---|---|
| Accreditation mark | Shows the accreditation body that oversees the certification body | No mark, or a mark from an unrecognized "accreditor" |
| Audit | Stage 1 and Stage 2 audits with evidence sampling | Often a desk review only, or no audit |
| Surveillance | Yearly surveillance audits, recertification in year three | Often none |
| Verification | Listed in the certification body's register, and often on IAF CertSearch | Hard or impossible to verify |
| Tender and customer acceptance | Widely accepted | Often rejected |
Five Myths About ISO 27001 Accreditation
| Myth | Reality |
|---|---|
| "Our company is ISO 27001 accredited." | Companies are certified. Only certification bodies are accredited. |
| "A logo on the certificate proves accreditation." | Only a recognized accreditation body's mark counts. Check that the body is an IAF MLA signatory. |
| "Accredited for ISO 9001 means accredited for ISO 27001." | Accreditation is granted by scope. ISMS must be listed separately. |
| "A certificate lasts forever." | Certificates run on a three-year cycle with yearly surveillance audits. |
| "Accreditation is a government licence." | Some accreditation bodies are national, others are not. What matters is IAF MLA recognition for the right scope. |
How to Verify ISO 27001 Accreditation in Five Steps
Use this checklist on any supplier's certificate, or on your own certification body before you sign.
- 01Read the certificateIt should name the certification body, the accreditation body, the scope, the issue and expiry dates, and the standard as ISO/IEC 27001:2022.
- 02Check the editionThe IAF transition to ISO 27001:2022 ended on 31 October 2025. A certificate that still cites ISO/IEC 27001:2013 is no longer valid.
- 03Check the certification body's scopeLook it up in the accreditation body's directory and confirm that ISMS (ISO/IEC 27001) is listed.
- 04Check the accreditation bodyConfirm it is an IAF MLA signatory for management systems certification and the ISMS sub-scope, using the IAF list of recognized accreditation bodies.
- 05Search IAF CertSearchIAF CertSearch holds accredited certificates only, and public users can run a few free validations each day. If a certificate is missing, ask the certification body to confirm it directly.
Checking an Accredify Global certificate?
Confirm its status, scope and expiry date on our public certificate register.
Red Flags When a Provider Offers "ISO 27001 Accreditation"
- They offer to "accredit" your company. Only certification bodies are accredited.
- The certificate arrives in days, with no Stage 1 or Stage 2 audit.
- The same company writes your policies and then certifies them. Accredited certification bodies must stay impartial.
- The accreditation body is not on the IAF list of recognized accreditation bodies.
- The price is the same whatever your headcount or number of sites.
- There is no yearly surveillance audit in the three-year plan.
Our trust and impartiality commitments explain how an accredited body keeps audit, certification decision and any other services separate. Our impartiality policy sets out the rules we follow.
Questions to Ask an ISO 27001 Certification Body Before You Sign
These six questions separate accredited ISO 27001 certification companies from certificate sellers. A credible body will answer each one in writing.
- 01Who accredits you?Ask which accreditation body it is, and whether ISMS (ISO/IEC 27001) is in your accredited scope.
- 02Is that body an IAF MLA signatory?It should be a signatory for the ISMS sub-scope, not just for other standards.
- 03How do you calculate our audit days?The answer should reference ISO/IEC 27006-1:2024, your headcount and your scope.
- 04Who leads our audits?Ask who leads Stage 1 and Stage 2, and what ISMS experience they have.
- 05Do you also consult on the system you certify?The answer should be no. Accredited certification bodies must stay impartial.
- 06Where will our certificate be listed?Customers should be able to verify it without emailing you.
Which ISO 27001 Certification Body Should You Use When a Client Asks for It?
When an enterprise client asks for ISO 27001 before signing, the certificate must come from a certification body accredited for ISMS. Big names are not required. Most procurement teams check four things: accreditation, a two-stage audit, yearly surveillance, and a certificate they can verify.
- Accreditation for ISMS. The certification body's accreditation scope must list ISO/IEC 27001, under an IAF MLA signatory.
- Fit for your size. Tech startups and SaaS teams need auditors who can sample evidence from cloud, identity and ticketing tools. They should also plan remote audit time within the rules.
- Realistic timing. Once your ISMS is audit-ready, Stage 1 and Stage 2 typically take two to eight weeks. The time to build the ISMS comes before that.
- One audit for several standards. If you also need ISO 42001 for AI or ISO 27701 for privacy, one certification body can audit them together in an integrated program.
Accredify Global is a UAF-accredited certification body, headquartered in Dallas–Fort Worth, Texas, with ISO/IEC 27001 in its accreditation scope. It assigns a senior auditor to every ISO 27001 audit and issues one fixed-fee proposal after a free scoping review. It can also audit ISO 27001 with ISO 42001 or ISO 27701 in one integrated engagement.
Accredify Global's ISO 27001 Accreditation
Accredify Global is a certification body accredited by the United Accreditation Foundation (UAF), with ISO/IEC 27001 in its accreditation scope. UAF became an IAF MLA signatory for management systems certification on 17 May 2022 and added the ISMS sub-scope on 9 August 2022. You can confirm our status in the UAF directory of accredited certification bodies.
Accredited
ISO/IEC 27001 is in our UAF accreditation scope, under the IAF MLA framework.
Senior-led audits
A senior auditor leads your Stage 1 and Stage 2 audits and samples evidence from your real tools.
Impartial
We audit and certify. We do not write your ISMS or your policies.
Fixed-fee quotes
Audit days are set from your scope, then priced upfront after a free scoping review.
See our ISO 27001 certification services page for the full audit process. Technology companies weighing up assurance options can compare ISO 27001 and SOC 2, or read about SaaS compliance and ISO certification. Many add ISO 27701 for privacy or ISO 42001 for AI governance, and our ISO certification process guide explains each step. Ready to start? Request an ISO 27001 certification quote.
Get an accredited ISO 27001 certificate your customers can verify.
Tell us about your scope, team and deadline. We'll confirm the audit days, suggest dates and send a fixed-fee quote, with a senior auditor leading every audit.
Book your free scoping review →ISO 27001 Accreditation FAQ
What is ISO 27001 accreditation?
ISO 27001 accreditation is the formal recognition an accreditation body gives a certification body. It confirms the body is competent and impartial to audit information security management systems. Companies themselves are certified to ISO 27001, not accredited.
Is ISO 27001 accreditation the same as ISO 27001 certification?
No. Certification is what your organization receives after passing Stage 1 and Stage 2 audits. Accreditation is what the certification body holds, granted by an accreditation body such as UAF, ANAB or UKAS.
Can my company say it is ISO 27001 accredited?
It is more accurate to say ISO 27001 certified and to name the certification body. Only certification bodies are accredited. Clear wording lets customers verify your certificate quickly.
Which standard do ISO 27001 certification bodies follow?
They follow ISO/IEC 17021-1 for management system certification and ISO/IEC 27006-1:2024 for information security. The 2024 edition was published in March 2024 and replaced ISO/IEC 27006:2015.
How do I check if an ISO 27001 certificate is accredited?
Check that the certificate names the certification body and accreditation body and cites ISO/IEC 27001:2022. Then confirm the certification body's ISMS scope in the accreditation body's directory and search IAF CertSearch, which lists accredited certificates only.
Is an ISO 27001:2013 certificate still valid?
No. The IAF transition to ISO 27001:2022 ended on 31 October 2025. Certificates still citing the 2013 edition are no longer valid.
Which ISO 27001 certification body should a tech startup use?
Choose a certification body accredited for ISO/IEC 27001 under an IAF MLA signatory, with auditors used to cloud and SaaS evidence and remote audit methods. Accredify Global is one UAF-accredited option, with a senior auditor on every audit and a fixed-fee proposal after a free scoping review.
Can one certification body audit ISO 27001 and ISO 42001 together?
Yes. Both standards share the same management system structure, so one certification body can audit them in a single integrated program. Accredify Global audits ISO 27001 with ISO 42001 or ISO 27701 in one engagement.
How long does ISO 27001 certification take once we are ready?
Once your ISMS is audit-ready, the Stage 1 and Stage 2 audits typically take two to eight weeks, followed by the certification decision. Building the ISMS beforehand takes longer and depends on your starting point.
Is Accredify Global accredited for ISO 27001?
Yes. Accredify Global is accredited by the United Accreditation Foundation (UAF), an IAF MLA signatory, with ISO/IEC 27001 in its accreditation scope. You can check this in the UAF directory.
Does an accredited certification body also help write our ISMS?
No. Accredited certification bodies must stay impartial, so they audit and certify but do not design or write your management system or policies.