Choosing an ISO 27001 certification body

The body that certifies you is the one decision in ISO 27001 a buyer can check from the outside. Here is how to check it first.

What is an ISO 27001 certification body? The company that audits your information security management system and issues the certificate. It is never ISO:

  • ISO states that it does not perform certification or issue certificates, and that certification is performed by external certification bodies. Source, read 2026-09-28.
  • ISO states that companies implementing ISO/IEC 27001 can decide whether they want to go through a certification process, and that a certificate from an accredited body may add confidence because an accreditation body has independently confirmed the certification body’s competence. Source, read 2026-09-28.

So choosing one is two checks. Is the body accredited to certify ISO/IEC 27001, and will its certificate be accepted by the buyer who asked for it?

Everything else is ordinary vendor selection: price, calendar, and whether the auditors understand a software company. This page covers the two checks first, because they are the ones that cannot be fixed after the certificate is issued.

What ISO itself advises

ISO publishes a short list for exactly this decision. It is worth reading in full, including the caveat at the end.

  • ISO advises evaluating several certification bodies, checking whether a body uses the relevant CASCO standard, and checking whether it is accredited. It adds that accreditation is not compulsory and that non-accreditation does not necessarily mean a body is not reputable. Source, read 2026-09-28.

That caveat is honest, and it cuts both ways. An unaccredited body can be competent. But its certificate will not appear in the accredited registers, and a buyer who checks there will not find you.

What accreditation means

There are three layers, each checking the one below it. ISO writes the standards, accreditation bodies assess certification bodies, and certification bodies audit companies like yours.

  • ISO describes ISO/IEC 17021-1:2015 as containing principles and requirements for the competence, consistency and impartiality of bodies providing audit and certification of all types of management systems. Source, read 2026-09-28.
  • ANAB accredits management systems certification bodies for ISO/IEC 27001, lists ISO/IEC 27006 among its accreditation requirements, and publishes a searchable directory of accredited management systems certification bodies. Source, read 2026-09-28.

Two standards govern the certification body rather than you. ISO/IEC 17021-1 covers any body certifying any management system. ISO/IEC 27006 adds the requirements specific to information security, including how audit time is worked out.

Accreditation has a scope. A body accredited for quality management is not thereby accredited for ISO/IEC 27001. Check that the standard you need is named on the accreditation itself.

How to check a body, and a certificate

You can do all of this before you sign, and your buyer can do the same after the certificate is issued. It takes minutes.

  • ISO states that a certification issued by an accredited certification body can be verified in IAF CertSearch, or by contacting the certification body, the accreditation body or Global ACI directly. Source, read 2026-09-28.
  • IAF CertSearch describes itself as the official global database for accredited certificates, searchable by company name or certificate details, and states that it cross-checks data from the IAF, accreditation bodies and certification bodies. Source, read 2026-09-28.
  • UKAS describes CertCheck as a free online service for independently verifying UKAS accredited management system certifications, searchable by company name or certificate number. Source, read 2026-09-28.
  1. Find the accreditation body. Ask the certification body which accreditation body accredits it for ISO/IEC 27001, then look the body up in that accreditation body’s own directory.
  2. Check the scope. The accreditation should name ISO/IEC 27001 and the country or region you operate in.
  3. Look up a live certificate. Search IAF CertSearch for one of the body’s existing clients. If its certificates appear, the body is reporting to the register.
  4. Ask where your certificate will be listed. A buyer will look for it, and it should be findable by your company name.

What to compare in a quote

Once two or three bodies pass the checks above, compare them on the same basis. The basis is audit days, because that is how the fee is built.

  • Schellman states that the number of employees in scope plays a part in the total number of audit days needed for Stage 1 and Stage 2, and names it among the factors ISO 27006 considers when calculating audit time. Source, read 2026-09-28.
Audit days
Stage 1 and Stage 2 separately. Two quotes with different day counts are not comparable.
All three years
The first audit, both surveillance audits and the recertification. Year one alone can make a quote look lower than it is.
Scheduling
When Stage 1 can start, and how long the body usually leaves between the two stages.
Remote audit
Whether a fully remote company can be audited remotely, and on what conditions.

What ISO 27001 certification costs quotes the published Stage 1 and Stage 2 figures, so you can see where a quote sits.

Keep preparation and certification apart

The body that certifies you cannot be the one that prepared you. That rule is the whole reason a certificate means anything to a buyer.

Watch for offers that blur it. A certification body offering to write your policies, or a readiness vendor offering to issue the certificate, is offering to audit its own work, and either way the certificate is worth less to the buyer who asked for it.

Where we stand

Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.

Where we fit

Polara G.R.C. prepares you for the certification body. Readiness is $5,000 one time. It covers the risk assessment, the Statement of Applicability, the policies, the evidence, the internal audit and the management review.

The certification audit is a separate engagement. The body you choose quotes and bills it, and we publish no figure for it. When the certificate arrives, we record it and show it as verified only after a named person has checked it against the register.

The ISO 27001 product page lists what the readiness work includes, and how long ISO 27001 takes shows when to start talking to bodies. For the controls a body will test, Annex A for a small team goes theme by theme.

Questions

What is an ISO 27001 certification body?
The company that audits your information security management system and issues the certificate. ISO writes the standard and does not certify anyone. Certification bodies perform the Stage 1 and Stage 2 audits, the surveillance audits and recertification.
Does a certification body have to be accredited?
ISO says accreditation is not compulsory. It is the independent confirmation that a body is competent, and a certificate from an accredited body can be verified in IAF CertSearch. Check what your buyer asked for before choosing a body that is not accredited.
How do I check whether a certification body is accredited?
Look it up with the accreditation body that accredited it. In the United States that includes the ANAB directory of accredited management systems certification bodies, and in the United Kingdom UKAS. IAF CertSearch cross-checks certificates, certification bodies and accreditation bodies in one place.
Can the company that helped me prepare also certify me?
No. ISO/IEC 17021-1 sets impartiality requirements for certification bodies, and a body certifying a client it consulted for would be auditing its own work. Keep the two separate.
What should I compare between certification body quotes?
Audit days for Stage 1 and Stage 2, the price across all three years including surveillance and recertification, the accreditation and its scope, and when the body can schedule you. The day count is what makes two quotes comparable.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.