For agencies, municipalities, and public bodies

ISO Certification for Public Sector Organizations: ISO 9001, ISO 27001, ISO 22301, and ISO 30301

ISO certification for public sector organizations gives citizens, auditors, and elected officials independent evidence. It shows that services are delivered consistently, data is protected, and records are kept. Accredify Global certifies public sector management systems, including ISO 9001, ISO 27001, ISO 22301, ISO 37001, and ISO 30301. We also run NIST and NIS2 readiness assessments. You get a tailored proposal after a free scoping review.

Public sector certification with Accredify Global
ISO 90012026 edition, transition by Sept 2029
ISO 370012016 certificates end Feb 2027
3 yrsCertificate cycle, yearly surveillance
61+Auditors
23+Technical experts
71Countries covered
ACCREDITED
Accredited Certification Body
Check our scope in the UAF directory
Verify Accreditation ↗
PROCUREMENT-READY
Written Proposal in Man-Days
Easy for buyers to evaluate
IMPARTIAL
Audit, Not Consulting
We assess; your team builds
TAILORED
One Tailored Proposal
After a free scoping review
In plain terms

What ISO Certification for Public Sector Bodies Covers

ISO certification for public sector organizations is an independent audit against ISO standards. It checks how an agency or public body manages services, information, continuity, and integrity. Most start with ISO 9001 and ISO 27001. Those running critical services add ISO 22301, and those with large budgets add ISO 37001. A successful audit leads to a certificate valid for three years.

Certification does not replace oversight by inspectors, auditors general, or regulators. It adds a structured, independent check that the system behind each service works, year after year, whatever happens to budgets or staff.

Accredify Global is an accredited certification body. We audit how services are really delivered, from a citizen request to the final response. Our reports use plain language that leaders and oversight bodies can use.

ServicesDelivered the same way every time
DataCitizen information protected
ContinuityCritical services kept running
RecordsCreated, kept, and disposed of properly
Where things stand

Public Sector Standards in 2026: ISO 9001:2026, ISO 37001:2025, and ISO 30301

ISO 9001:2026 was published on 16 September 2026. New certifications must use the 2026 edition from 31 March 2028, and 2015 certificates must transition by 30 September 2029. Agencies can plan the move into their normal audit cycle.

ISO 37001:2016 certificates end on 28 February 2027. The 2025 edition adds conflicts of interest and compliance culture, both central to public integrity. New anti-bribery certificates have used the 2025 edition since 31 August 2026.

A new edition of ISO 30301 is close. The records management standard reached its final approval stage in September 2026. It will replace the 2019 edition, and a transition period will follow.

16 Sep 2026ISO 9001:2026 published
28 Feb 2027ISO 37001:2016 certificates end
Sep 2026ISO 30301 in final approval

Sources: ISO 9001:2026 transition (Global ACI) · ISO 37001 transition (IAF MD 30) · ISO 30301 new edition (ISO)

Who this is for

Which Public Bodies Need ISO Certification?

Any organization that spends public money or holds citizen data.

Government agencies

Ministries, departments, and regulators.

Municipalities

Cities, counties, and local councils.

Public utilities

Water, power, and transit authorities. See ISO for energy.

State-owned enterprises

Companies owned or controlled by government.

Public health & education

Hospitals and schools. See ISO for education.

Government contractors

Suppliers to agencies. See ISO for defense.

Standards map

ISO Certification for Public Sector Bodies: Standards and What We Provide

Service quality and information security first, then continuity, integrity, and records.

Standard or frameworkWhat it coversWho usually needs itWhat Accredify Global provides
ISO 9001Quality of public servicesEvery agency, as a first stepCertification
ISO 27001Information securityAnyone holding citizen dataCertification
ISO 22301Business continuityEmergency and essential servicesCertification
ISO 37001Anti-briberyProcurement-heavy bodies and state-owned companiesCertification
ISO 30301Records managementArchives and records-heavy agenciesCertification
ISO 55001Asset managementInfrastructure and estate ownersCertification
ISO 14001Environmental managementAgencies with climate commitmentsCertification
ISO 45001Occupational health and safetyField and depot staffCertification
NIST CSF / SP 800-53US federal and state cybersecurity frameworksUS agencies and their suppliersReadiness assessment
NIS2EU cybersecurity lawEU central government and essential servicesReadiness assessment
GDPREU data protection lawBodies processing EU personal dataReadiness assessment

ISO 37001 is within our UAF accreditation scope. For the other standards listed, your proposal names the certification body that will issue your certificate.

The difference

Certifiable Standards vs Guidance Standards

Tenders sometimes ask for certificates that cannot exist. These guidance standards are useful, but no one can certify them.

Guidance standardWhat it offersThe certifiable route
ISO 18091How to apply ISO 9001 in local governmentCertify to ISO 9001
ISO 31000Risk management principles and processShow risk control through ISO 9001, 27001, or 22301
ISO 37000Governance of organizationsCertify integrity controls to ISO 37001
ISO 10004Monitoring customer satisfactionCovered within ISO 9001
ISO 26000Social responsibilityUse ISO 14001 and 45001 for certifiable parts

If a tender or policy names a guidance standard, ask the buyer what evidence they expect. Usually a certificate to the matching requirements standard, plus a short statement of how you apply the guidance, meets the intent.

On the audit

What a Public Sector Audit Checks

We follow real services, from a citizen request or case to the final outcome.

Areas we test

  • Service standards and how they are measured
  • Complaints and appeals handling
  • Access control for citizen and case data
  • Continuity plans tested with real exercises
  • Procurement controls and conflict of interest declarations
  • Records retention and disposal
  • Oversight of outsourced services

Common gaps we find

  • Service targets set but never reviewed
  • Leavers' access not removed on time
  • Continuity plans not tested since the last emergency
  • Contractor performance not monitored
  • Records kept far beyond their retention period
How it works

How ISO Certification for Public Sector Bodies Works, Step by Step

A common path: certify ISO 9001 and ISO 27001 together, then add continuity or records. Our ISO certification process guide has more detail.

Free scoping reviewServices, departments, sites, and standards.
Written proposalAudit man-days your procurement team can evaluate.
Stage 1 auditPolicies, scope, and readiness reviewed.
Stage 2 auditReal services and records tested.
Certification decisionA reviewer outside the audit team signs off.
Surveillance & renewalAnnual checks, then renewal in year three.

Working to a budget year or a policy deadline? Tell us in the scoping review and we will plan around it.

Book a free scoping review
Scope and cost

What Drives the Cost of Public Sector ISO Certification

There is no list price. The cost follows the audit man-days your scope needs, and a free scoping review gives you a tailored proposal.

What sets the audit time

  • People: staff in the departments in scope
  • Sites: offices, depots, and service centers
  • Services: how many and how complex
  • Outsourcing: services run by contractors
  • Standards: one standard, or an integrated audit

Ways to keep it efficient

  • Start with one department, then extend the scope
  • Combine quality, security, and continuity in one audit
  • Use one multi-site certificate across offices
  • Plan the ISO 9001:2026 move at your next audit
  • Close internal audit findings first
Choosing a partner

How to Choose a Certification Body for a Public Body

Checks worth making before you sign, especially under procurement rules.

What to checkWhy it matters
AccreditationCertificates should come from an accredited body. You can verify ours in the UAF directory.
Real certifiable standardsAvoid offers to certify guidance standards such as ISO 31000 or ISO 18091.
Public sector experienceAuditors should understand oversight, transparency, and procurement rules.
ImpartialityYour certification body should not also write your system.
Verifiable certificatesCitizens and partners should be able to check yours. Ours appear on our verification page.
PricingAsk for audit man-days in writing. Ours come in a tailored proposal.
Common questions

FAQ: ISO Certification for Public Sector Bodies

Straight answers on standards, government security schemes, NIS2, cost, and timeline.

Which ISO certification do public sector organizations need?

Most start with ISO 9001 for service quality and ISO 27001 for information security. Agencies that must keep services running add ISO 22301, and those handling large procurement budgets add ISO 37001.

Can a government agency get ISO 9001 certification?

Yes. ISO 9001 applies to any organization, including ministries, municipalities and public authorities. ISO 18091 gives guidance on applying it in local government, but ISO 18091 itself is not certified.

Which ISO standards cannot be certified?

Guidance standards cannot be certified. Examples are ISO 31000 on risk management, ISO 18091 for local government and ISO 10004 on customer satisfaction. ISO 26000 on social responsibility and ISO 37000 on governance are guidance too.

Does ISO 27001 meet government security requirements?

It helps, but it does not replace specific schemes. US federal cloud services need FedRAMP, many states use GovRAMP, and criminal justice data falls under the CJIS Security Policy. ISO 27001 covers much of the same ground.

Does Accredify Global perform FedRAMP or GovRAMP assessments?

No. Those assessments need an accredited third-party assessment organization under each program. We certify ISO 27001 and run NIST readiness assessments that support them.

What is ISO 30301?

ISO 30301 is the management system standard for records. It helps public bodies create, keep and dispose of records in a controlled way, which supports transparency, freedom of information requests and legal retention.

Do public bodies need ISO 37001?

Increasingly. Public procurement carries bribery risk, and ISO 37001 shows an agency or state-owned company runs an anti-bribery system. The 2025 edition replaced 2016, with a transition deadline of 28 February 2027.

Does NIS2 apply to public administration?

Yes, in the EU. NIS2 covers central government entities and, after a risk-based assessment, some regional ones. Member states can also extend it to local government. ISO 27001 is a strong base for meeting its risk management measures.

Can several departments share one certificate?

Yes. Departments or sites that run the same management system can share one multi-site certificate. The certification body audits a sample of sites and the central function every time.

Do public procurement rules allow us to hire a certification body?

That depends on your rules. Many agencies buy certification through a quotation or framework. We provide a written proposal with audit man-days, which most procurement teams can evaluate.

How long does ISO certification take for a public body?

Most organizations with a working management system certify in 6 to 12 weeks from Stage 1 to the certificate. Several departments, several standards or a new system take longer.

How much does ISO certification cost for government organizations?

The cost follows the audit man-days your scope needs. Headcount, sites, services and the standards in scope set the man-days. A free scoping review gives you a tailored proposal.

What changes with ISO 9001:2026 for public bodies?

ISO 9001:2026 was published on 16 September 2026. New certifications use the 2026 edition from 31 March 2028, and 2015 certificates must transition by 30 September 2029.

Can ISO 9001, 27001 and 22301 be audited together?

Yes. They share the same structure and can be audited in one integrated audit, which saves time for staff and simplifies reporting to leadership.

Does Accredify Global write our procedures?

No. As a certification body we must stay impartial, so we audit and certify but do not write your system. Your team, or a consultant you choose, closes any gaps.

Free scoping review

Give Citizens Evidence, Not Just Promises

Tell us about your services, departments, and deadlines. We'll map the right ISO certification for your public body and send a tailored proposal.

Book your free scoping review →

Last reviewed by the Accredify Global certification team.