An accredited ISO 27001 certification is the only version of the certificate that a serious procurement team will accept without asking follow-up questions, and in 2026 the machinery behind it changed in a way almost no guide has caught up with. On 1 January 2026 the International Accreditation Forum stopped operating. The peer-review system that makes a certificate mean something is now run by a different organisation, under a different arrangement, with a different mark. If your supplier questionnaire still says “IAF MLA signatory,” it is describing a body that no longer exists.
This guide explains what accredited ISO 27001 certification actually buys you, how to tell a real certificate from a printed one, what the Global ACI transition means for certificates issued in 2026, and when an unaccredited certificate is genuinely defensible. Everything here is read off primary sources, including ISO’s own conformity assessment page.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What accredited ISO 27001 certification actually means
There are three parties in the chain, and most buyers collapse them into one. ISO writes the standard. A certification body audits you against it. An accreditation body checks the certification body. ISO defines the two terms plainly on its own site: certification is “the provision by an independent body of written assurance (a certificate) that the product, service or system in question meets specific requirements,” while accreditation is “the formal recognition by an independent body, generally known as an accreditation body, that a certification body operates according to international standards.”
ISO itself is not in the certification business at all. Its page is blunt about it: “ISO does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification.” Any vendor showing you a certificate with an ISO logo on it is showing you something ISO says should not exist. That single check costs you ten seconds and screens out a meaningful share of fakes.
So an accredited ISO 27001 certification is a certificate issued by a certification body that has itself been assessed, by a national accreditation body, against international competence requirements — and whose accreditation body is in turn peer-evaluated internationally. Three layers, each checking the one below. Remove the accreditation layer and the certificate rests entirely on the reputation of whoever printed it.
Accredited vs non-accredited ISO 27001 certification
The honest comparison is narrower than most marketing pages admit. ISO’s guidance explicitly notes that “accreditation is not compulsory, and non-accreditation does not necessarily mean the certification body is not reputable.” That nuance matters, and I will come back to it. But the practical differences are real:
| Dimension | Accredited | Non-accredited |
|---|---|---|
| Who checks the auditor | A national accreditation body, on a recurring assessment cycle, including witnessed audits | Nobody outside the certification body |
| Standards the auditor must meet | ISO/IEC 17021-1:2015 plus ISO/IEC 27006-1:2024 for ISMS specifically | Whatever the body chooses to adopt |
| Audit duration | Calculated from published tables keyed to effective personnel; reductions are capped | Unconstrained — one-day “audits” are common |
| Independent verification by a customer | Searchable via the accreditation body and the global certificate database | Only by asking the issuer |
| Typical acceptance in enterprise procurement | Accepted as evidence | Frequently rejected or treated as self-attestation |
| Typical cost of the audit itself | Higher — you are paying for mandated audit days | Lower, sometimes dramatically |
| Mark on the certificate | Accreditation body mark, used only within the granted scope | House logo only |
The cost gap is the whole sales pitch for unaccredited certification, and it is also the tell. The price is lower because the audit is shorter, and the audit is shorter because nothing forces it to be long enough to find anything.
What changed on 1 January 2026
This is the part that dates every competing article. On 1 January 2026 the Global Accreditation Cooperation Incorporated — Global ACI — began operations as the single international body responsible for multilateral recognition arrangements across all of conformity assessment. It absorbed the roles previously split between the International Accreditation Forum, which covered management system certification, and the International Laboratory Accreditation Cooperation, which covered testing and calibration. IAF has discontinued all membership and operational activities; a caretaker board remains only to complete the wind-up. ILAC is being formally dissolved.
For anyone holding or buying an accredited ISO 27001 certification, the headline is continuity rather than disruption. ANAB, the main United States accreditation body for management systems, states that during the planned transition period there is no immediate effect on accredited bodies and that operations continue under current requirements. Specifically:
- The IAF MLA and ILAC MRA marks remain in effect and are recognised as equivalent during the transition.
- Bodies that held signatory status as of 31 December 2025 may keep using the legacy marks until the Global ACI MRA Mark becomes available in their economy.
- A new rulebook, Global ACI MRA-006, governs use of the new mark and claims of accreditation status — including the requirement that the combined mark be used only within the granted scope of accreditation.
- Continued use of the legacy marks is expected to conclude within a few years, not immediately.
Two practical consequences. First, a certificate issued in 2026 carrying an IAF MLA mark is not stale or suspect — it is correct. Second, your vendor security questionnaire almost certainly needs rewording, because asking a supplier to confirm “IAF MLA signatory status” will soon be asking about an arrangement that has been superseded. Phrase it as “accredited by a Global ACI MRA signatory (formerly IAF MLA)” and it survives the transition.
How to verify accredited ISO 27001 certification
Never accept a PDF as proof. A PDF is a picture. Verifying accredited ISO 27001 certification takes three checks, and all three are free.
- Read the certificate for the four facts that matter. The issuing certification body’s name, the accreditation body’s mark, the certificate number, and the scope statement. The scope is the one people skip and the one that decides whether the certificate covers the service you are actually buying. A certificate scoped to a holding company’s head office does not cover the subsidiary running your data.
- Check the certification body against its accreditation body’s directory. Every accreditation body publishes a searchable list of the bodies it accredits and, critically, the standards each is accredited for. A body accredited for ISO 9001 but not for ISO 27001 cannot issue an accredited ISO 27001 certificate, and this mismatch is far more common than outright forgery.
- Look the certificate up in the global database. IAF CertSearch aggregates data from accreditation bodies and certification bodies and cross-checks three sources: that the certificate is valid, that the certification body was accredited to issue it, and that the accreditation body is a recognised member and signatory for that standard. As of October 2026 it carries 3,711,989 certifications from 2,566 certification bodies across 81 accreditation bodies, and supports individual, bulk and API lookups.
If the certificate does not appear, that is not automatic proof of fraud — database coverage is not universal — but it moves the burden back to the supplier. ISO’s own fallback advice is to contact the certification body, the accreditation body, or Global ACI directly to confirm the respective statuses. If you conclude a claim of accredited certification is false, including misuse of the Global ACI logo, you can report it to the Global ACI secretariat; ISO undertakes to respond to complaints routed through it within 14 days. For a deeper walkthrough of selection criteria, see our guide to choosing an ISO 27001 certification body.
What the certification body must prove to stay accredited
Two standards sit behind the mark. ISO/IEC 17021-1:2015 sets the generic requirements for any body auditing management systems: impartiality, competence, the two-stage initial audit, the three-year cycle, and the rules for suspending or withdrawing a certificate. ISO/IEC 27006-1:2024 layers the information-security-specific requirements on top — independence and impartiality, the competence of each role involved in delivering the certification, certification documents, and the audit process itself.
ISO/IEC 27006-1:2024 was published in March 2024 and replaced ISO/IEC 27006:2015. The transition is now complete rather than pending: ANAB required all of its accredited and applicant ISMS certification bodies to be using the 2024 edition for all clients no later than 31 March 2026. That date has passed. Any page telling you to “check whether your body has transitioned to 27006-1” is describing a question that is no longer open for accredited bodies — and any body still working to the 2015 edition is, by definition, no longer accredited.
The practical reading for a buyer: ask which accreditation body accredits your certification body, and ask for the scope of that accreditation in writing. A reputable body answers in one email.
When unaccredited certification is defensible
ISO’s position — that non-accreditation does not necessarily mean a body is disreputable — is worth taking seriously rather than dismissing. There are narrow cases where unaccredited certification is a rational purchase:
- Internal assurance only. You want a competent external opinion on your ISMS before committing to the real thing, and nobody outside the company will ever see the result. This is a gap assessment wearing a certificate costume, and it is fine as long as you call it that internally.
- A scheme with no accreditation available. Some sector or national schemes genuinely have no accredited route. ISO 27001 is not one of them.
- A deadline you have already lost. Occasionally a customer will accept an unaccredited certificate as an interim step with a contractual commitment to accredited certification by a fixed date. Get that in writing, because the clock will be enforced.
Outside those cases, assume anything short of accredited ISO 27001 certification will be rejected. The failure mode is expensive: you pay for an unaccredited audit, a customer refuses it, and you then pay again for a full two-stage accredited audit with no credit for the first. If any part of your plan involves showing the certificate to someone else, buy the accredited one first.
What accredited ISO 27001 certification costs and delivers
Costs vary enormously by headcount, scope and region, so treat these as typical ranges rather than quotes. For a company of 20 to 50 people with a single site and a software scope, certification body fees across the three-year cycle commonly land somewhere in the region of 15,000 to 30,000 US dollars, split across the initial two-stage audit and two surveillance visits. Internal effort — writing the documentation, running the risk assessment, closing gaps — usually costs more than the auditor does. Below roughly 20 people the audit fees fall but do not disappear, because accredited audit duration is calculated from published tables and reductions are capped.
Free ISO 27001 risk assessment
Which of your risks sit above your appetite line?
Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free risk assessment → or View premium report sample
What the money buys is the thing the standard was designed around: 93 Annex A controls organised into four themes — 37 organizational, 8 people, 14 physical and 34 technological — a mandatory Statement of Applicability under clause 6.1.3 justifying every inclusion and exclusion, and a certificate a customer can verify without taking your word for it. The 2013 to 2022 transition closed on 31 October 2025, so every current certificate is against the 2022 edition; the climate-change amendment published in 2024 is a free addendum, not a new edition.
Scale is worth knowing for context. The ISO Survey 2024 recorded 96,709 valid ISO/IEC 27001 certificates across 179,877 sites. That looks like explosive growth against prior years, but the 2024 edition was the first compiled from the IAF CertSearch database rather than voluntary reporting by certification bodies, so most of the jump is better counting rather than new certificates. Do not quote it as a growth rate.
If you are at the stage of working out what documentation an accredited audit will actually ask for, our ISO 27001 implementation guide covers the sequence, and ISO 27001 certificate validity explains what keeps the certificate alive once you have it.
Frequently asked questions
Is accredited ISO 27001 certification legally required?
No. There is no general law requiring ISO 27001 certification, accredited or otherwise. It becomes effectively mandatory through contracts — enterprise procurement, supplier codes and tender requirements — rather than through statute. Where a contract specifies certification, it almost always specifies accredited certification.
Can I certify my own organisation to ISO 27001?
No. Certification is by definition the written assurance of an independent third party. You can self-assess against the standard, and you must run internal audits under clause 9.2, but neither produces a certificate. A document you issue to yourself is a self-declaration of conformity, and calling it a certification is the kind of false claim ISO invites complaints about.
Does the accreditation body matter, or are they interchangeable?
Signatories to the international arrangement are treated as equivalent by design — that is the entire point of mutual recognition. In practice, check that the accreditation body is a Global ACI member and that its accreditation of your certification body explicitly covers ISO/IEC 27001. The scope of the accreditation matters far more than which country issued it.
My certificate shows an IAF mark in 2026. Is it out of date?
No. Bodies that held IAF MLA signatory status on 31 December 2025 may continue using the legacy marks until the Global ACI MRA Mark becomes available in their economy, and the legacy and new marks are recognised as equivalent during the transition. Expect the changeover to complete over the next few years.
How long does an accredited ISO 27001 certification last?
An accredited ISO 27001 certification runs on a three-year cycle: an initial two-stage audit, surveillance audits in years one and two, and a recertification audit before the third anniversary. The certificate is not a static document — it can be suspended or withdrawn between audits if the certification body finds the management system has failed.
Getting the documentation right before the auditor arrives
The part of accredited ISO 27001 certification you control is the evidence. An accredited auditor works to a fixed number of days and will spend them sampling your documented information: the scope, the risk assessment and treatment plan, the Statement of Applicability, the policies behind each applicable control, and the records proving the controls actually run. Turning up with that set already built is the difference between a stage 1 that confirms readiness and a stage 1 that sends you away.
Our ISO 27001 Toolkit is 165 editable templates mapped to the 2022 edition — scope, risk methodology, Statement of Applicability, and a policy set covering all four Annex A themes — for 99 US dollars. It will not pass the audit for you, but it removes the blank-page problem that consumes most of the first three months.
For the authoritative definitions of certification and accreditation, and ISO’s own guidance on choosing and verifying a certification body, see ISO’s conformity assessment and certification page.