iso27001partnersUK certification, costed Get a cost estimate

Choosing a certification body, and how to check one

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
5 primary sources cited on this page. How we check what is on this site

This page does not list certification bodies and does not rank them. A list would be stale the moment a schedule of accreditation changed, and we hold no data that would justify ranking anybody. What follows is how to check any body yourself, which stays correct.

We have no commercial relationship with any certification body and could not arrange certification if we wanted to. Consultancies pay us a fixed fee per enquiry; certification bodies pay us nothing at all. That is why this page has no list on it.

Key points

  • Check the schedule, not the logo. The schedule of accreditation names which standards and scopes a body may certify. A body accredited for ISO 9001 is not thereby accredited for ISO/IEC 27001.
  • Ask for the day count before the price. It comes from a published rule and there is no reason for it to be confidential.
  • Ask for three years of charges, not one. Surveillance, recertification, application and certificate fees together exceed the initial audit.
  • A body that recommends a consultancy has a problem. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.9 forbids implying that certification would be easier with a specified consultancy.

What accreditation means here

United Kingdom Accreditation Service is appointed under The Accreditation Regulations 2009 (SI 2009/3155), regulation 3, regulation 3 of which provides that “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”. It assesses certification bodies. It never certifies you.

An accredited certificate is one issued by a body that UKAS has itself assessed against ISO/IEC 17021-1 and ISO/IEC 27006-1, and it carries the UKAS symbol with a schedule of accreditation naming the scope. A non-accredited certificate is issued by a body nobody has assessed. Both are pieces of paper. Only one of them has anybody standing behind it. The full comparison sets out what the difference costs when a customer checks.

The three roles in ISO 27001 certification and the rule separating them Three boxes: UKAS accredits certification bodies; certification bodies audit and certify you; consultancies help you prepare. A crossed line between certification body and consultancy marks the bar in ISO/IEC 17021-1 clause 5.2.5. A footer notes that this site is none of the three. Accreditation body UKAS Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 Issues no certificates to you Certification body Audits you Runs Stage 1 and Stage 2 Issues your certificate Surveillance every year Cannot consult for you Consultancy Helps you get ready Gap analysis, risk assessment Statement of Applicability Internal audit support Cannot certify you accredits barred by 17021-1 cl. 5.2.5 iso27001partners.co.uk is none of these three. We publish the rules and the arithmetic, and sell advertising to consultancies at a fixed fee per enquiry. We cannot audit, certify or accredit anything.
The body that audits you is barred from selling you the help to get ready. That is a requirement of the standard its accreditation is granted against, not a market convention.
The same diagram as a table
Who does what, and what each one is barred from doing
RoleDoesCannot do
Accreditation body (UKAS)Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1Issue you a certificate
Certification bodyStage 1, Stage 2, annual surveillance, issues the certificateProvide management system consultancy to you (clause 5.2.5)
ConsultancyGap analysis, risk assessment, Statement of Applicability, internal audit supportIssue or influence a certificate
This sitePublishes the rules and the cost arithmetic; sells advertisingAudit, certify, accredit or advise

How to check a body against the register

  1. Find the body on the UKAS register. Not the logo on its website — the register itself, at ukas.com.
  2. Open the schedule of accreditation. This is the document that matters. It lists the standards the body is accredited to certify against and the scopes it may work in.
  3. Confirm ISO/IEC 27001 is on it. Accreditation is granted per standard.
  4. Confirm the scope covers your sector. Accreditation can be limited, and a UKAS symbol used outside the accredited scope is a misuse of the symbol.
  5. If you are checking somebody else's certificate, also check that it is current, that it names ISO/IEC 27001:2022 rather than the withdrawn ISO/IEC 27001:2013, and that the scope on it covers the service you actually buy.

Seven questions before you commit

What to ask, why it matters, and the answer that should worry you
QuestionWhy it mattersWarning sign
What is your accreditation, and can I see the schedule?A body should answer this without hesitation and point you at the register. The schedule matters more than the listing: it names which standards and which scopes the body may certify, and a body accredited for ISO 9001 is not thereby accredited for ISO/IEC 27001.Hesitation, or a logo offered in place of a register entry.
How many audit days, and which band?The answer comes from the published table and there is no reason for it to be confidential. It should reconcile to your headcount band within the 30% the rule permits.A price with no day count behind it, or a day count materially below your band.
What is the full schedule of charges for three years?Certification audit, both surveillance years, recertification, application fee, certificate fee, any annual registration charge, and travel. Together these exceed the initial audit.A single headline figure, with the rest 'discussed later'.
What is your relationship with any consultancy you are recommending?BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.7: where a client has had consultancy from a body related to the certification body, that body must not certify the management system for at least 2 years. You want to know before you engage either.A recommendation of a specific consultancy, or any suggestion that using one would make certification easier — clause 5.2.9 forbids a certification body from implying it.
What is your current lead time to Stage 1 and to Stage 2?Certification body availability decides more contractual dates than preparation speed does, and the gap between the two stages is scheduled around theirs, not yours.An unwillingness to commit to a window when you have a contractual date.
Who will audit us, and what is their sector experience?Auditor competence for your sector is part of what accreditation assesses. It is reasonable to ask, and a good body will tell you.No answer until after contract signature.
What happens if Stage 2 raises a major nonconformity?A major nonconformity must be closed before a certificate is issued, and closing it often needs a further visit. Find out now whether that visit is chargeable and how it is priced.Vagueness. This is a known, priced event for any experienced body.

Five claims that should end the conversation

Language worth reacting to
The claimWhat is wrong with it
“We are an ISO-certified certification body”ISO writes standards. It does not certify anyone, accredit anyone, or operate any certification scheme. A body describing itself this way is either careless with language or relying on you not knowing the difference.
“Accredited certification” with no accreditor namedAsk which accreditation body, then check that the accreditor is a recognised national accreditation body rather than another private company. In the UK there is exactly one, named in secondary legislation.
“We can get you certified quickly”The audit length is set by the published table and the timeline floor is set by clauses 9.2 and 9.3. Neither is within a certification body's gift, and a body suggesting otherwise is describing something other than accredited certification.
“Our consultants will prepare you and our auditors will certify you”This is the one that should end the conversation. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5 bars a certification body from offering management system consultancy at all.
A UKAS symbol on a certificate for a scope outside the scheduleA body can be accredited for some scopes and not others. Using the symbol outside the accredited scope is a misuse of it, and reading the schedule is how you would know.

The clause worth knowing by heart

“The certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy.” — BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text, clause 5.2.5. One sentence, and it settles most of the questions on this page.

What the certification body can and cannot tell you

The boundary confuses people, and the standard is more precise about it than most summaries are. A certification body may exchange information with you — explaining a finding, clarifying what a requirement means. That is explicitly preserved. What it may not do is consultancy: telling you how to design your management system, writing anything for you, or recommending a firm that will.

In practice an experienced auditor will tell you exactly what they observed and why it does not meet the requirement, and will then stop. That is not unhelpfulness. An auditor who goes further is putting their own body's accreditation at risk, and the two-year bars in clauses 5.2.6 and 5.2.7 exist because the rule takes this seriously.

Transferring between bodies

If lead times or costs are not what you were led to expect, you are not locked in. There are established rules for transferring certification between accredited bodies so that the new body can rely on the audits already done rather than restarting at Stage 1. Ask a prospective body how it handles a transfer before assuming the answer is difficult, and ask your current one what it will provide.

Where to go next

Common questions

Which certification body should we use?

We do not answer that, and we would be the wrong people to. We do not rank, score or vet certification bodies, we hold no data that would justify doing so, and any list we published would go stale the moment a schedule of accreditation changed. What this page does instead is show you how to check any body yourself against the register, which is a check that stays correct.

How do I verify a certification body is UKAS-accredited?

Search the UKAS register for the body, and then read its schedule of accreditation rather than stopping at the listing. The schedule names the standards and the scopes the body may certify. Two failure modes to look for: the body is not there at all, or it is there but ISO/IEC 27001 is not on its schedule. A logo on a website is a claim; the register is the record.

Can I check somebody else's certificate?

Yes, and for supplier assurance you should. An accredited certificate carries the accreditation symbol and a number, and the issuing body maintains a register of the certificates it has issued. Check three things: that the certificate is current, that the edition is ISO/IEC 27001:2022 — certificates against the withdrawn ISO/IEC 27001:2013 expired on 31 October 2025 — and that the scope on the certificate actually covers the service you buy from them. The third is where most supplier assurance quietly fails.

Is a bigger certification body better?

Not inherently, and size is a poor proxy for anything you care about. What matters is that the body is accredited for ISO/IEC 27001, that its auditors are competent in your sector, that its lead time fits your date, and that its three-year cost is what you were told. A large body may have longer lead times; a smaller one may have deeper sector knowledge. The accreditation check is binary and the rest is fit.

Can our certification body help us fix a nonconformity?

It can explain the finding — the standard explicitly preserves exchange of information such as explaining findings or clarifying requirements. What it cannot do is tell you how to fix it, because that would be consultancy, and BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5 bars it. Auditors are practised at walking that line, and an auditor who offers to design your solution is creating a problem for their own body's accreditation as well as for you.

Do we have to stay with the same certification body?

No. You can transfer certification between accredited bodies, and there are established rules for how a transfer is handled so that the new body can rely on the previous audits rather than starting from Stage 1. If you are unhappy with lead times or cost, it is a real option. Ask the prospective body how it handles transfers before assuming it is difficult.

What does UKAS do if a certification body gets it wrong?

UKAS assesses accredited bodies on a cycle and can raise findings, suspend or withdraw accreditation for a scope. That mechanism is the whole difference between an accredited and a non-accredited certificate: not that mistakes never happen, but that there is somebody independent who will find them and act.

Sources cited on this page

  1. The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
  2. United Kingdom Accreditation Service
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  5. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Working out what you need before you approach a body

Scope and headcount decide the audit. A consultancy can help you settle both before you ask anyone for a quote.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now