iso27001partnersUK certification, costed Get a cost estimate

UKAS vs non-UKAS: what accreditation actually buys you

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
5 primary sources cited on this page. How we check what is on this site
The distinction in one line Who checked the checker

An accredited certificate comes from a body UKAS has itself assessed and publishes a schedule for. A non-accredited certificate comes from a body nobody has assessed. Both are pieces of paper; only one of them has anyone standing behind it.

This is the question the large international compliance platforms cannot answer for you, because UKAS is a UK institution created by a UK statutory instrument and has no equivalent in the markets those products were built for. It is also the question that decides whether the certificate you are about to buy will survive contact with a procurement team.

Key points

  • UKAS is the UK’s sole national accreditation body by law. Regulation 3 of The Accreditation Regulations 2009 (SI 2009/3155), regulation 3: “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”.
  • UKAS does not certify you. It assesses the bodies that do, against ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 and the ISMS-specific requirements, and publishes what each one is competent to certify.
  • The price gap is usually a day-count gap. An accredited body works to the published audit-day table and cannot cut it by more than 30%. A body nobody assesses can audit for as long as it likes.
  • The asymmetry decides it. If your customer does not check, an accredited certificate still satisfies them. If they do check, only one of the two survives.

What accreditation is, in UK law

The word gets used loosely, so it is worth being exact. United Kingdom Accreditation Service is appointed under The Accreditation Regulations 2009 (SI 2009/3155), regulation 3. Regulation 3 provides that “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”. There is one, it is named in secondary legislation, and no other organisation in the United Kingdom holds that position however it describes itself.

UKAS sits one level up from you. It never audits your management system and never issues you a certificate. What it does is assess certification bodies: whether they are competent, whether their auditors are, and whether they follow the rules they are supposed to follow — including the impartiality requirements and the audit-time rule that sets how long your audit has to be.

The three roles in ISO 27001 certification and the rule separating them Three boxes: UKAS accredits certification bodies; certification bodies audit and certify you; consultancies help you prepare. A crossed line between certification body and consultancy marks the bar in ISO/IEC 17021-1 clause 5.2.5. A footer notes that this site is none of the three. Accreditation body UKAS Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 Issues no certificates to you Certification body Audits you Runs Stage 1 and Stage 2 Issues your certificate Surveillance every year Cannot consult for you Consultancy Helps you get ready Gap analysis, risk assessment Statement of Applicability Internal audit support Cannot certify you accredits barred by 17021-1 cl. 5.2.5 iso27001partners.co.uk is none of these three. We publish the rules and the arithmetic, and sell advertising to consultancies at a fixed fee per enquiry. We cannot audit, certify or accredit anything.
The body that audits you is barred from selling you the help to get ready. That is a requirement of the standard its accreditation is granted against, not a market convention.
The same diagram as a table
Who does what, and what each one is barred from doing
RoleDoesCannot do
Accreditation body (UKAS)Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1Issue you a certificate
Certification bodyStage 1, Stage 2, annual surveillance, issues the certificateProvide management system consultancy to you (clause 5.2.5)
ConsultancyGap analysis, risk assessment, Statement of Applicability, internal audit supportIssue or influence a certificate
This sitePublishes the rules and the cost arithmetic; sells advertisingAudit, certify, accredit or advise

What the accredited body is being held to

This is the concrete part, and it is why accreditation is worth something rather than being a badge. A body accredited to certify ISO 27001 has been assessed against ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1, which contains clauses like these — quoted rather than paraphrased, so you can see how little room they leave:

Clause 5.2.5. “The certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy.”

Clause 5.2.9. “The certification body’s activities shall not be marketed or offered as linked with the activities of an organisation that provides management system consultancy. … A certification body shall not state or imply that certification would be simpler, easier, faster or less expensive if a specified consultancy organisation were used.”

And against the ISMS-specific requirements, which is where the audit-day table lives. An accredited body's audit length is not a commercial decision it makes freely. It starts from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), is adjustable by up to 30% for genuine complexity, and is never reduced by more than 30%.

A body without accreditation may follow all of that voluntarily. Several do. The point is that nobody is checking, and you have no way to find out that they stopped.

Side by side

Accredited against non-accredited ISO 27001 certification
UKAS-accredited certification bodyNon-accredited body
Who assessed the body that issued itUKAS, against ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 and ISO/IEC 27006-1:2024Nobody, or a body that is not a recognised national accreditation body
Published evidence you can checkA schedule of accreditation naming the scopes the body may certify, on the UKAS registerWhatever the body says about itself on its own website
The impartiality rules applyYes, and are audited. The body cannot consult for you, cannot do your internal audits, and cannot imply that using a particular consultancy makes certification easierThe body may assert the same things. Nobody is checking
Audit daysSet by the published table and assessed by UKASSet by the body. This is usually where the price difference comes from
What happens when a customer checksThe certificate number resolves on the accreditation registerThere is nothing independent to resolve it against
Accepted by public-sector frameworks and large enterprise procurementNormally, and often named explicitlyFrequently not. This is the risk you are buying

Where the cheaper price comes from

When two quotes for the same scope differ by a factor of two or three, the explanation is almost never efficiency. It is days.

Take a 25-person scope. The published table puts the initial certification audit at 7 days, which at UK day rates is roughly £7,700 to £10,500. A body that audits the same scope in two days can charge a fraction of that and still make a margin, because it has sold you a fraction of the work. The certificate looks the same. What is behind it is not.

The arithmetic on getting this wrong is simple, and you can do it yourself from the figures on this site. If a customer rejects the certificate, you have paid for it and you then buy the accredited certification you needed in the first place — from £7,700 for a scope that size, plus the delay, which in a tender is frequently the more expensive half. The saving on the first certificate has to be weighed against losing all of it plus the contract that prompted the exercise.

The question to ask your customer first

“Does your requirement specify certification by a body accredited by a national accreditation body?” Ask it in writing, before you buy anything. It costs an email and it is the only thing on this page that settles the question for your situation rather than in general.

How to check a certification body before you engage it

  1. Look the body up on the UKAS register rather than trusting a logo. A symbol on a website is a claim; the register is the record.
  2. Read the schedule of accreditation, not just the listing. A body can be accredited for ISO 9001 and not ISO/IEC 27001, or accredited for ISO/IEC 27001 within a scope that does not cover your sector. The schedule says which.
  3. Ask for the day count before the price. Any accredited body will give you one, because it is derived from a published rule. A reluctance to state it is informative.
  4. Ask what the relationship is with any consultancy you are also talking to. This is the one that catches people. If your consultancy is related to your certification body, the two-year clock can apply to you — so the relationship between the two firms is a question worth asking before you engage either.
  5. Ask for the three-year schedule of charges, including surveillance, recertification, application and certificate fees, and travel.

Choosing a certification body goes through this in more detail, including the questions that cost nothing to ask and the answers that should give you pause.

We do not sell certification, cannot arrange it, and are paid the same fixed fee per enquiry whatever you decide. If the honest answer for your situation is that the certificate can wait and Cyber Essentials cannot, this site is as happy to tell you that.

The other certificate that expires quietly

While you are checking accreditation, check the edition. Certificates issued against ISO/IEC 27001:2013 ceased to be valid on 31 October 2025 under IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022. Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.

It is worth a look at your suppliers' certificates as well as your own. A supplier assurance pack assembled a few years ago and not revisited may contain certificates that expired against a withdrawn edition, and that is the sort of thing an auditor examining your own supplier-relationship controls will find.

Common questions

Is a non-UKAS ISO 27001 certificate fake?

No, and it is important to be precise here. A non-accredited certificate is not forged and the body issuing it may run a perfectly honest audit. The difference is that nobody has assessed that body. Accreditation is a second layer: UKAS assesses the certification body against ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 and the ISMS-specific requirements, including the impartiality rules and the audit-day rule, and publishes a schedule saying what it is competent to certify. Without that layer you have a certificate whose only backing is the assertion of the firm that sold it to you.

What is UKAS, exactly?

The United Kingdom Accreditation Service. It is the United Kingdom's sole national accreditation body, and that is not a marketing claim: regulation 3 of The Accreditation Regulations 2009 (SI 2009/3155), regulation 3 provides that “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”. It does not certify organisations. It assesses the bodies that do.

How do I check whether a certification body is accredited?

Look it up on the UKAS register rather than taking the logo on the website as evidence, and check two things: that the body is listed, and that its schedule of accreditation covers ISO/IEC 27001 for the kind of work you do. A body can be accredited for one management system standard and not another, and a UKAS symbol used outside the accredited scope is a misuse of it. If you are checking somebody else's certificate, the certificate itself should carry the accreditation symbol and a number you can resolve.

Does my customer actually care?

Ask them, in writing, before you buy anything. Public-sector frameworks and large enterprise vendor-security teams generally specify accredited certification and increasingly say so explicitly, because they have been shown unaccredited certificates before. A smaller customer may genuinely not distinguish. The asymmetry is what matters: if they do not care, an accredited certificate still satisfies them, so accredited is the only option that cannot be wrong.

How much cheaper is a non-accredited certificate?

Materially, and the saving comes from a shorter audit. An accredited body works to the published day table — 5 days for a company of ten, rising with headcount — and cannot cut it by more than 30%. A body nobody assesses can audit for as long as it likes. When you compare two quotes and one is a fraction of the other, compare the day counts, because that is usually the entire explanation.

We already bought a non-accredited certificate. What now?

Find out whether it is actually being rejected before doing anything. If a specific customer has refused it, ask them precisely what they require, because it may be accredited certification or it may be something narrower. If you do need to recertify with an accredited body, you start the cycle again: Stage 1 and Stage 2 against the full day count. Work already done on the management system is not wasted — the risk assessment, the Statement of Applicability and the internal audit all still count. The audit fee is what you pay twice.

Can a certification body be accredited by somebody other than UKAS?

Yes. Accreditation bodies in other countries operate under the same international arrangements and their accreditation is recognised across them, so a certificate from a body accredited by another national accreditation body is a properly accredited certificate. What does not follow is that any organisation calling itself an accreditation body qualifies. If the body issuing your certificate names its accreditor, check that the accreditor is itself a recognised national body and not simply another private company.

Sources cited on this page

  1. The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
  2. United Kingdom Accreditation Service
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
  5. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Not sure what your customer will accept?

Five click-only questions. Say what triggered this and a consultancy can tell you what that customer normally requires.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now