Choosing an ISO 27001 certification body is the one decision in a certification project that is expensive to reverse. Get it wrong and you either hold a certificate your enterprise customers refuse to accept, or you spend three years with an auditor who does not understand how your business works. Get it right and the audit turns into a predictable annual event you can budget for.
This guide covers what changed in the global accreditation system on 1 January 2026, the seven criteria worth scoring vendors against, what the three-year cycle costs, and what to ask before you sign.
What an ISO 27001 Certification Body Actually Does
An ISO 27001 certification body is an independent organization that audits your information security management system (ISMS) against ISO/IEC 27001:2022 and issues a certificate if you pass. That is the whole job. It does not write your policies, run your risk assessment, close your findings or tell you which Annex A controls to apply — and as you will see below, it is prohibited from doing so.
Two standards govern how it must behave:
- ISO/IEC 17021-1:2015 — the general requirements for any body auditing and certifying management systems. This is where impartiality, competence and the appeals process come from.
- ISO/IEC 27006-1:2024 — the ISMS-specific layer on top, published in March 2024. It sets auditor competence, how audit time is calculated, how remote auditing is handled, and what the audit report and certificate must say.
ISO itself is explicit that a certificate from an accredited conformity assessment body carries an extra layer of confidence, because an accreditation body has independently confirmed the certification body’s competence. That distinction — accredited versus not — is the single biggest variable in this decision. You can read the scope of the standard on the official ISO/IEC 27001:2022 page, where the standard sells for CHF 155 and the Amendment 1:2024 climate change addition is free.
The Accreditation Rules Changed on 1 January 2026
Most advice online still tells you to check that your certification body sits under the “IAF MLA”. That wording is now out of date, and it matters when you are reading certificates.
On 1 January 2026, the International Accreditation Forum (IAF) and the International Laboratory Accreditation Cooperation (ILAC) stopped operating as separate organizations and were replaced by Global Accreditation Cooperation Incorporated, which now runs a single Multilateral Recognition Arrangement covering both certification and laboratory accreditation. Regional groups such as APAC in Asia-Pacific and EA in Europe continue as recognized regional cooperations.
The substance has not changed. National accreditation bodies — UKAS in the United Kingdom, ANAB in the United States, DAkkS in Germany, and their equivalents elsewhere — still assess certification bodies, and an accredited certificate is still recognised across borders. What has changed is the vocabulary on newer certificates, and the fact that the accreditation body’s own directory is now the most reliable place to confirm that a given ISO 27001 certification body is genuinely accredited.
A second date is worth knowing. ANAB-accredited certification bodies had until 31 March 2026 to transition to ISO/IEC 27006-1:2024. That deadline has passed, so any ANAB-accredited body you talk to now should be auditing under the 2024 edition. Ask them to confirm it, because the 2024 edition changed how audit days are counted and how much of your audit can be run remotely.
Accredited vs Non-Accredited: A Side-by-Side Comparison
Cheap “ISO 27001 certificates” are widely advertised. They are not fraudulent in a legal sense — anyone can write a document — but they are not the same product.
The same word carries a different meaning for laboratories. A laboratory is not certified at all — it is accredited to ISO 17025 for a defined schedule of methods and measurement ranges, assessed by a national accreditation body rather than a certification body.
| Factor | Accredited certification body | Non-accredited certificate issuer |
|---|---|---|
| Independent oversight | Assessed on a cycle by a national accreditation body | None; self-declared |
| Rules it must follow | ISO/IEC 17021-1 and ISO/IEC 27006-1:2024 | Whatever the issuer decides |
| Audit time | Calculated using the Annex C method, driven by headcount in scope | Often a single day, or a document review only |
| Two-stage audit | Mandatory Stage 1 and Stage 2 | Frequently skipped |
| Customer acceptance | Routinely accepted in enterprise and public-sector procurement | Commonly rejected on review |
| Certificate life | Three years, with mandatory annual surveillance | Varies; sometimes indefinite |
| Typical cost | Higher | Lower, and often has to be repeated properly later |
If your reason for certifying is a customer contract, a tender requirement or a security questionnaire, accredited is the only option that reliably survives the buyer’s review, and the only kind of ISO 27001 certification body worth shortlisting.
How to Choose an ISO 27001 Certification Body: Seven Criteria
Score every shortlisted ISO 27001 certification body against these seven points before you compare prices.
1. Accreditation, verified at the source
Do not accept a logo on a proposal. Go to the accreditation body’s own website — ukas.com, anab.ansi.org, dakks.de or your national equivalent — and confirm the certification body appears in its directory for ISO/IEC 27001 specifically. Many bodies are accredited for ISO 9001 but not for ISMS work.
2. Scope competence for your sector
Accreditation is granted per economic sector code. A body accredited for information technology may not be accredited for financial services, healthcare or manufacturing. Ask which codes their ISO 27001 accreditation covers and check that yours is on the list.
3. Auditor competence, since the numbers were removed
ISO/IEC 27006-1:2024 deleted the old prescriptive requirement for a fixed number of years of practical workplace experience for ISMS auditors. Competence is still required, but it is no longer a number you can check. So ask: who specifically will audit us, what is their background in our technology stack, and how many ISMS audits have they led in our sector?
4. Remote audit policy
The 2024 edition removed the requirement to obtain accreditation body approval when remote activity exceeds 30% of planned on-site time, and added a requirement that the extent and effectiveness of remote auditing be recorded in the audit report. For a distributed or fully remote company this is good news, but the split should be agreed in writing before Stage 1, not negotiated on the day.
5. How the audit days were calculated
Audit duration is not a negotiation, it is a calculation. Under the Annex C method in ISO/IEC 27006-1:2024, the driver is the number of people doing work within the ISMS scope — including contractors and freelancers, regardless of whether they are employees. For multi-site organizations, total headcount now drives the calculation rather than the number of sites. Ask for the headcount figure they used. If a quote looks unusually cheap, this is usually where the corner was cut.
6. Scheduling and auditor continuity
Ask how far out their calendar is booked and whether you will keep the same lead auditor across the cycle. Continuity saves real days of re-explaining your architecture at every surveillance visit.
7. Three-year commercial terms, priced up front
You are not buying one audit. Get Stage 1, Stage 2, both surveillance audits and the recertification audit priced in the same proposal, along with the day rate for handling nonconformities and any scope changes.
Your ISO 27001 Certification Body Cannot Also Be Your Consultant
This is the rule most first-time applicants trip over. Under ISO/IEC 17021-1, the certification body — along with any part of the same legal entity and any entity under its organizational control — must not offer or provide management system consultancy. Where a related body has provided consultancy to a client, the recognized mitigation is that the certification body must not certify that management system for a minimum of two years after the consultancy ends. The same logic applies if they ran your internal audit.
In practice this means you buy your documentation, tooling and implementation help from one supplier and your audit from a different one. It is also why an ISO 27001 certification body will happily explain what a nonconformity is but will refuse to tell you how to fix it.
The cheapest way to keep that separation clean is to build the ISMS from a documentation set you own outright. Our ISO 27001 Toolkit gives you 162 editable templates — ISMS policies, the risk assessment, the Statement of Applicability, the Annex A control assessment and the internal audit pack — for $99, so the auditor arrives to review documents you have already tailored rather than a blank page.
What an ISO 27001 Certification Body Costs
Certification body fees are only part of the total, and they are the part driven by that audit-day calculation. As a typical market range in North America and Western Europe, accredited bodies quote roughly $1,200 to $2,500 per auditor day, and a small organization with fewer than 50 people in scope commonly sees 4 to 8 auditor days across Stage 1 and Stage 2 combined. Each surveillance audit is usually about a third of the initial assessment effort, and recertification lands somewhere between a surveillance and a full Stage 2.
Treat those as planning ranges, not quotes — headcount, number of sites, sector risk and how much is delivered remotely all move the number. For the full picture including internal effort, tooling and training, see our detailed ISO 27001 certification cost breakdown.
One saving worth knowing: getting at least three accredited proposals is standard practice, and the spread between them is often 30% or more for identical scope, because day rates differ far more than day counts do.
The Three-Year Cycle You Are Signing Up For
An accredited certificate is valid for three years, and your ISO 27001 certification body will be back every year of it.
- Stage 1 — a readiness review of your documented ISMS, scope, Statement of Applicability and internal audit records. Findings here are normal and are meant to be fixed before Stage 2.
- Stage 2 — the full audit of implementation and effectiveness. Pass, and the certificate is issued.
- Surveillance audit 1 — around 12 months after certification. Shorter and narrower, sampling a subset of controls and focusing on previous findings.
- Surveillance audit 2 — around 24 months, usually sampling different controls to build coverage across the cycle.
- Recertification — before the certificate expires. Closer in rigour to Stage 2, and it resets the three-year clock.
Surveillance audits are mandatory, not optional. Miss one and the certificate can be suspended. If you want the detail on the first two steps, our guide to Stage 1 vs Stage 2 walks through what each auditor actually asks for, and the wider ISO 27001 certification guide covers the project from scoping to certificate.
Questions to Ask Before You Sign
Send these to every ISO 27001 certification body on your shortlist and compare the answers side by side.
- Which accreditation body accredits you for ISO/IEC 27001, and under which sector codes?
- Have you completed your transition to ISO/IEC 27006-1:2024?
- How many auditor days are you quoting, and what headcount figure produced that number?
- Who is the named lead auditor, and will they stay with us for the full cycle?
- What percentage of the audit will be remote, and will that be stated in the report?
- What is your written policy on nonconformities — how long do we have, and is a re-visit chargeable?
- What are the fees for Stage 1, Stage 2, both surveillance audits and recertification?
- What does your appeals and complaints process look like if we disagree with a finding?
- Has any part of your organization provided consultancy or internal audit services to us in the last two years?
Frequently Asked Questions
Do I have to use an accredited ISO 27001 certification body?
No law requires it. But if your reason for certifying is customer or tender pressure, an unaccredited certificate frequently fails the buyer’s review and you end up paying twice. Check your customer contract — many now specify accredited certification explicitly.
Can I change certification body in the middle of a cycle?
Yes. A transfer of certification between accredited bodies is a recognised process; the incoming body reviews your existing certificate, audit reports and open nonconformities before accepting the transfer. It is most straightforward shortly after a successful surveillance audit and hardest when there are unresolved major findings.
Does the auditor check all 93 Annex A controls?
Not every control at every visit. ISO/IEC 27001:2022 has 93 Annex A controls in four themes — 37 organizational, 8 people, 14 physical and 34 technological — and your Statement of Applicability, mandatory under clause 6.1.3, records which apply and why. Stage 2 covers the applicable set; surveillance audits sample from it so that coverage builds across the three-year cycle.
How far in advance should I book?
Accredited bodies commonly schedule several months out, and demand is seasonal around calendar and financial year ends. Start conversations while you are still implementing, not once you are ready — the quote and the calendar slot are separate commitments.
Is a certificate from one country valid in another?
If the accreditation body signs the Global Accreditation Cooperation Multilateral Recognition Arrangement — as UKAS, ANAB and DAkkS do — the certificate is designed to be recognised internationally. Some regulated sectors and government buyers still prefer a domestic accreditation body, so check tender wording before assuming.
The Short Version
Verify accreditation in the accreditation body’s own directory, confirm the sector codes, ask how the audit days were calculated and who the lead auditor will be, price all four audits in the cycle up front, and keep your implementation supplier and your ISO 27001 certification body strictly separate. Do that and you will end up with a certificate that survives your customer’s due diligence — which is the only test that matters.