iso27001partnersUK certification, costed Get a cost estimate

How to check an ISO 27001 certificate is genuine and valid

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
8 primary sources cited on this page. How we check what is on this site
Ask the issuer The status of a given certification

ISO/IEC 17021-1 clause 8.1.2: “The certification body shall provide upon request information about:” … “b) the status of a given certification”. Every accredited certification body has to answer that question.

A supplier sends a PDF with an ISO 27001 certificate on it. Whether it is genuine, current and relevant to what you are buying cannot be read off the document. UKAS's guidance gives three checks, and the accreditation standard for certification bodies obliges them to answer the last one. This page sets both out, then what to look for on the certificate itself.

Three checks, in order

UKAS's three checks (quoted from its guidance) and how they apply to an ISO 27001 certificate (our reading)
StepWhat you checkUKAS saysFor ISO 27001 (our reading)
1Accreditation bodyCheck that the certificate has been provided by a certification body that is accredited by an internationally recognised accreditation body.For a UK certificate this is usually UKAS. For another accreditation body, check it is a signatory for the management-system sub-scope that covers ISO/IEC 27001
2Certification bodyCheck that the claims by the certification body that they hold the appropriate accreditation from the accreditation body are valid.Open the certification body's schedule of accreditation and confirm ISO/IEC 27001 is on it, not only ISO 9001
3The certificate“This can be achieved through the certification body, either through a search function on their website or through direct contact”Ask the certification body for the status of that certificate number. It has to answer

Step 1: the accreditation body

“There is no restriction on who can become an accreditation body”, UKAS warns — which is why a certificate carrying an accreditation mark proves nothing until you know whose mark it is. UKAS's test is peer evaluation: an accreditation body that is a signatory to a recognised multilateral agreement, and, it adds, “you must ensure that the accreditation body is a signatory for the sub-scope that relates to the certificate in question.”

UKAS's guidance points to the International Accreditation Forum for that check. Note the change since it was written: “As of 01 January 2026, the International Accreditation Forum (IAF) is no longer operational.” The notice points instead to the Global Accreditation Cooperation Incorporated, which has replaced IAF and the International Laboratory Accreditation Cooperation (ILAC). If the accreditation body is UKAS itself, step 1 is settled: see UKAS vs non-UKAS certification.

Step 2: the certification body's accreditation

“Check that the claims by the certification body that they hold the appropriate accreditation from the accreditation body are valid.” And, in UKAS's words: “take care: the certification body may hold accreditation but it may not include the service or management system relevant to the product or service being provided”. A body can be properly accredited for ISO 9001 and not for ISO/IEC 27001. The schedule of accreditation shows which standards are covered. How to read one is on UKAS-accredited certification bodies.

Step 3: the certificate itself

Once the issuer checks out, UKAS says you need confirmation that the certificate itself is valid: “This can be achieved through the certification body, either through a search function on their website or through direct contact”. That route is not a courtesy. The certification body's own standard requires it to answer, as the next section shows.

What the certification body must tell you

“The certification body shall provide upon request information about:”

ISO/IEC 17021-1:2015 clause 8.1.2 (verbatim)
Information the certification body shall provide upon request
ageographical areas in which it operates
bthe status of a given certification
cthe name, related normative document, scope and geographical location (city and country) for a specific certified client

Status means more than valid or not

The standard's openness principle (clause 4.5.1) explains what “certification status” covers: “the granting, maintaining of certification, expanding or reducing the scope of certification, renewing, suspending or restoring, or withdrawing of certification”. So the answer to your question can be granted, suspended, withdrawn or reduced in scope — and each one changes what the certificate tells you.

Limits and publication

“In exceptional cases, access to certain information can be limited on the request of the client (e.g. for security reasons).” A body may also publish it: “The certification body can also make the information in 8.1.2 public by any means it chooses without request, e.g. on its internet website.” And whatever they tell you is bound by clause 8.1.3: “Information provided by the certification body to any client or to the marketplace, including advertising, shall be accurate and not misleading.”

What the certificate must show

ISO/IEC 17021-1:2015 clause 8.2.2 lists what a certification document shall identify. Each item gives you something to check against the supplier and the contract:

What the certificate shall identify (ISO/IEC 17021-1:2015 clause 8.2.2, verbatim) and what to check (our reading)
The certificate shall identifyWhat to check
athe name and geographical location of each certified client (or the geographical location of the headquarters and any sites within the scope of a multi-site certification)Is it the company you are contracting with, and the site that will handle your data?
bthe effective date of granting, expanding or reducing the scope of certification, or renewing certificationWhen was it granted or last renewed?
cthe expiry date or recertification due date consistent with the recertification cycleHas the date passed? After it, the certificate is not a current certificate
da unique identification codeThe number you give the certification body when you ask for the status
ethe management system standard and/or other normative document, including indication of issue status (e.g. revision date or number) used for audit of the certified clientISO/IEC 27001:2022. A certificate naming the 2013 edition has expired
fthe scope of certification with respect to the type of activities, products and services as applicable at each site without being misleading or ambiguousDoes the scope cover the service you are buying?
gthe name, address and certification mark of the certification body; other marks (e.g. accreditation symbol, client’s logo) may be used provided they are not misleading or ambiguousWhich body issued it, and is the accreditation mark one you can check?

Scope is the check most often skipped

A genuine, current certificate can still be irrelevant to you. The certified client must not imply “does not imply that the certification applies to activities and sites that are outside the scope of certification” (clause 8.3.4 g). Read the scope line against the service in your contract, and ask for the Statement of Applicability if you need to know which controls were in play.

CertCheck and IAF CertSearch

UKAS CertCheck

UKAS launched CertCheck in June 2022 as “a quick and easy mechanism to independently check the authenticity of claims regarding accredited management systems certifications”. It lets you “Verify UKAS accredited Management System certificates to ISO standards by entering either the “Company name” or “Certificate number””. The landing page names ISO 9001, ISO 14001 and ISO 45001, “Plus over 15 other international standards / schemes”; it does not name ISO/IEC 27001, so do not read an empty result as proof of anything — go to step 3.

IAF CertSearch

UKAS described it as a useful first port of call, but warned “it is not comprehensively populated, and therefore the information you seek may not be available”, because “Although it is mandatory for IAF accreditation bodies to populate IAF CertSearch with data on their accredited certification bodies it is not mandatory for certification bodies to upload data of their certificates.” With the IAF itself no longer operating, treat any database as a shortcut and the certification body as the answer.

Suspended, withdrawn, reduced or expired

Suspended

“Under suspension, the client’s management system certification is temporarily invalid.” “In most cases, the suspension would not exceed six months.” A certificate PDF does not change when it is suspended, which is why the status question matters. See recertification, expiry and lapse.

Withdrawn or reduced

On withdrawal the client must stop using advertising that refers to certification, and when scope is reduced it must amend its advertising (clause 8.3.4 d and e). A supplier still showing the old certificate is not doing what clause 8.3.4 requires of it.

Expired, including the 2013 edition

Item c) on the certificate is the expiry or recertification due date. Separately, the transition deadline for the 2013 edition was 31 October 2025: Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.

Counterfeits and false claims

“Independently checking the authenticity of an organisation’s management systems certification is an integral part of the business procurement process.” UKAS also says: “Since launching CertCheck, UKAS has become aware of several counterfeit certificates in circulation and/or organisations falsely claiming accreditation or affiliation with UKAS.” In response, “UKAS has taken the decision to publish details of those organisations known to be falsely claiming UKAS accreditation for management systems certification” — the list is on its counterfeit certificates page.

The certified client's side of the bargain

Certification bodies must bind their clients, through legally enforceable arrangements, to rules that include:

What the certified client must do (ISO/IEC 17021-1:2015 clause 8.3.4, selected items, verbatim)
The certified client
bdoes not make or permit any misleading statement regarding its certification
cdoes not use or permit the use of a certification document or any part thereof in a misleading manner
dupon withdrawal of its certification, discontinues its use of all advertising matter that contains a reference to certification, as directed by the certification body (see 9.6.5)
eamends all advertising matter when the scope of certification has been reduced

And the certification body must act on misuse. The standard's note: “Such action could include requests for correction and corrective action, suspension, withdrawal of certification, publication of the transgression and, if necessary, legal action.”

The one-email version

Send the certificate number to the certification body named on it and ask for its current status and scope. Clause 8.1.2 obliges an accredited body to answer. If the body is not accredited for ISO/IEC 27001, you already have your answer.

We do not certify, audit or consult, and are paid the same fixed fee per enquiry whichever firm you use. The rules are quoted from ISO/IEC 17021-1 and from UKAS; the right-hand columns are marked as our reading.

Where this fits

Common questions

How do I check an ISO 27001 certificate is genuine?

Check three things in order, as UKAS sets out: that the certification body is accredited by a recognised accreditation body, that its accreditation covers the standard on the certificate, and that the certificate itself is valid — which you confirm with the certification body, through a search function on its website or by contacting it.

Does the certification body have to tell me whether a certificate is valid?

Yes. Under ISO/IEC 17021-1 clause 8.1.2, “The certification body shall provide upon request information about:” the status of a given certification, and the name, normative document, scope and city and country of a specific certified client. The standard notes one exception: “In exceptional cases, access to certain information can be limited on the request of the client (e.g. for security reasons).”

Can I check ISO 27001 certificates on UKAS CertCheck?

CertCheck lets you “Verify UKAS accredited Management System certificates to ISO standards by entering either the “Company name” or “Certificate number””. Its landing page names ISO 9001, ISO 14001 and ISO 45001, “Plus over 15 other international standards / schemes”, and does not name ISO/IEC 27001 — so search it, and if nothing comes back, go to the certification body.

Is IAF CertSearch still the place to check?

UKAS's own guidance notes that “Although it is mandatory for IAF accreditation bodies to populate IAF CertSearch with data on their accredited certification bodies it is not mandatory for certification bodies to upload data of their certificates.” And iaf.nu now says: “As of 01 January 2026, the International Accreditation Forum (IAF) is no longer operational.” A missing entry proves nothing either way; the certification body is the authoritative answer.

Is a suspended ISO 27001 certificate still valid?

No. “Under suspension, the client’s management system certification is temporarily invalid.” ISO/IEC 17021-1 adds: “In most cases, the suspension would not exceed six months.”

Is a certificate to ISO/IEC 27001:2013 still valid?

No. The transition deadline was 31 October 2025. Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.

What does a fake ISO certificate look like?

It may look complete. UKAS's point is that appearance proves nothing: “There is no restriction on who can become an accreditation body”, so the checks are about who accredited whom, not about what the document looks like. UKAS publishes a list of organisations known to be falsely claiming UKAS accreditation for management systems certification.

Sources cited on this page

  1. ISO/IEC 17021-1:2015 clauses 4.5.1, 8.1.2, 8.1.3, 8.3.4, 8.3.5
  2. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  3. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
  4. UKAS, Validating Management System Certificates — How to differentiate the fake from the valid
  5. UKAS, Counterfeit certificates and false claims of UKAS accreditation
  6. UKAS CertCheck (certcheck.ukas.com), landing page
  7. IAF, IAF CertSearch page (archival notice)
  8. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

A customer asked you to prove your certificate?

Say who issued it, the scope, and what the customer asked for.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now