How to check an ISO 27001 certificate is genuine and valid
ISO/IEC 17021-1 clause 8.1.2: “The certification body shall provide upon request information about:” … “b) the status of a given certification”. Every accredited certification body has to answer that question.
A supplier sends a PDF with an ISO 27001 certificate on it. Whether it is genuine, current and relevant to what you are buying cannot be read off the document. UKAS's guidance gives three checks, and the accreditation standard for certification bodies obliges them to answer the last one. This page sets both out, then what to look for on the certificate itself.
Three checks, in order
| Step | What you check | UKAS says | For ISO 27001 (our reading) |
|---|---|---|---|
| 1 | Accreditation body | Check that the certificate has been provided by a certification body that is accredited by an internationally recognised accreditation body. | For a UK certificate this is usually UKAS. For another accreditation body, check it is a signatory for the management-system sub-scope that covers ISO/IEC 27001 |
| 2 | Certification body | Check that the claims by the certification body that they hold the appropriate accreditation from the accreditation body are valid. | Open the certification body's schedule of accreditation and confirm ISO/IEC 27001 is on it, not only ISO 9001 |
| 3 | The certificate | “This can be achieved through the certification body, either through a search function on their website or through direct contact” | Ask the certification body for the status of that certificate number. It has to answer |
Step 1: the accreditation body
“There is no restriction on who can become an accreditation body”, UKAS warns — which is why a certificate carrying an accreditation mark proves nothing until you know whose mark it is. UKAS's test is peer evaluation: an accreditation body that is a signatory to a recognised multilateral agreement, and, it adds, “you must ensure that the accreditation body is a signatory for the sub-scope that relates to the certificate in question.”
UKAS's guidance points to the International Accreditation Forum for that check. Note the change since it was written: “As of 01 January 2026, the International Accreditation Forum (IAF) is no longer operational.” The notice points instead to the Global Accreditation Cooperation Incorporated, which has replaced IAF and the International Laboratory Accreditation Cooperation (ILAC). If the accreditation body is UKAS itself, step 1 is settled: see UKAS vs non-UKAS certification.
Step 2: the certification body's accreditation
“Check that the claims by the certification body that they hold the appropriate accreditation from the accreditation body are valid.” And, in UKAS's words: “take care: the certification body may hold accreditation but it may not include the service or management system relevant to the product or service being provided”. A body can be properly accredited for ISO 9001 and not for ISO/IEC 27001. The schedule of accreditation shows which standards are covered. How to read one is on UKAS-accredited certification bodies.
Step 3: the certificate itself
Once the issuer checks out, UKAS says you need confirmation that the certificate itself is valid: “This can be achieved through the certification body, either through a search function on their website or through direct contact”. That route is not a courtesy. The certification body's own standard requires it to answer, as the next section shows.
What the certification body must tell you
“The certification body shall provide upon request information about:”
| Information the certification body shall provide upon request | |
|---|---|
| a | geographical areas in which it operates |
| b | the status of a given certification |
| c | the name, related normative document, scope and geographical location (city and country) for a specific certified client |
Status means more than valid or not
The standard's openness principle (clause 4.5.1) explains what “certification status” covers: “the granting, maintaining of certification, expanding or reducing the scope of certification, renewing, suspending or restoring, or withdrawing of certification”. So the answer to your question can be granted, suspended, withdrawn or reduced in scope — and each one changes what the certificate tells you.
Limits and publication
“In exceptional cases, access to certain information can be limited on the request of the client (e.g. for security reasons).” A body may also publish it: “The certification body can also make the information in 8.1.2 public by any means it chooses without request, e.g. on its internet website.” And whatever they tell you is bound by clause 8.1.3: “Information provided by the certification body to any client or to the marketplace, including advertising, shall be accurate and not misleading.”
What the certificate must show
ISO/IEC 17021-1:2015 clause 8.2.2 lists what a certification document shall identify. Each item gives you something to check against the supplier and the contract:
| The certificate shall identify | What to check | |
|---|---|---|
| a | the name and geographical location of each certified client (or the geographical location of the headquarters and any sites within the scope of a multi-site certification) | Is it the company you are contracting with, and the site that will handle your data? |
| b | the effective date of granting, expanding or reducing the scope of certification, or renewing certification | When was it granted or last renewed? |
| c | the expiry date or recertification due date consistent with the recertification cycle | Has the date passed? After it, the certificate is not a current certificate |
| d | a unique identification code | The number you give the certification body when you ask for the status |
| e | the management system standard and/or other normative document, including indication of issue status (e.g. revision date or number) used for audit of the certified client | ISO/IEC 27001:2022. A certificate naming the 2013 edition has expired |
| f | the scope of certification with respect to the type of activities, products and services as applicable at each site without being misleading or ambiguous | Does the scope cover the service you are buying? |
| g | the name, address and certification mark of the certification body; other marks (e.g. accreditation symbol, client’s logo) may be used provided they are not misleading or ambiguous | Which body issued it, and is the accreditation mark one you can check? |
Scope is the check most often skipped
A genuine, current certificate can still be irrelevant to you. The certified client must not imply “does not imply that the certification applies to activities and sites that are outside the scope of certification” (clause 8.3.4 g). Read the scope line against the service in your contract, and ask for the Statement of Applicability if you need to know which controls were in play.
CertCheck and IAF CertSearch
UKAS CertCheck
UKAS launched CertCheck in June 2022 as “a quick and easy mechanism to independently check the authenticity of claims regarding accredited management systems certifications”. It lets you “Verify UKAS accredited Management System certificates to ISO standards by entering either the “Company name” or “Certificate number””. The landing page names ISO 9001, ISO 14001 and ISO 45001, “Plus over 15 other international standards / schemes”; it does not name ISO/IEC 27001, so do not read an empty result as proof of anything — go to step 3.
IAF CertSearch
UKAS described it as a useful first port of call, but warned “it is not comprehensively populated, and therefore the information you seek may not be available”, because “Although it is mandatory for IAF accreditation bodies to populate IAF CertSearch with data on their accredited certification bodies it is not mandatory for certification bodies to upload data of their certificates.” With the IAF itself no longer operating, treat any database as a shortcut and the certification body as the answer.
Suspended, withdrawn, reduced or expired
Suspended
“Under suspension, the client’s management system certification is temporarily invalid.” “In most cases, the suspension would not exceed six months.” A certificate PDF does not change when it is suspended, which is why the status question matters. See recertification, expiry and lapse.
Withdrawn or reduced
On withdrawal the client must stop using advertising that refers to certification, and when scope is reduced it must amend its advertising (clause 8.3.4 d and e). A supplier still showing the old certificate is not doing what clause 8.3.4 requires of it.
Expired, including the 2013 edition
Item c) on the certificate is the expiry or recertification due date. Separately, the transition deadline for the 2013 edition was 31 October 2025: Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.
Counterfeits and false claims
“Independently checking the authenticity of an organisation’s management systems certification is an integral part of the business procurement process.” UKAS also says: “Since launching CertCheck, UKAS has become aware of several counterfeit certificates in circulation and/or organisations falsely claiming accreditation or affiliation with UKAS.” In response, “UKAS has taken the decision to publish details of those organisations known to be falsely claiming UKAS accreditation for management systems certification” — the list is on its counterfeit certificates page.
The certified client's side of the bargain
Certification bodies must bind their clients, through legally enforceable arrangements, to rules that include:
| The certified client | |
|---|---|
| b | does not make or permit any misleading statement regarding its certification |
| c | does not use or permit the use of a certification document or any part thereof in a misleading manner |
| d | upon withdrawal of its certification, discontinues its use of all advertising matter that contains a reference to certification, as directed by the certification body (see 9.6.5) |
| e | amends all advertising matter when the scope of certification has been reduced |
And the certification body must act on misuse. The standard's note: “Such action could include requests for correction and corrective action, suspension, withdrawal of certification, publication of the transgression and, if necessary, legal action.”
The one-email version
Send the certificate number to the certification body named on it and ask for its current status and scope. Clause 8.1.2 obliges an accredited body to answer. If the body is not accredited for ISO/IEC 27001, you already have your answer.
We do not certify, audit or consult, and are paid the same fixed fee per enquiry whichever firm you use. The rules are quoted from ISO/IEC 17021-1 and from UKAS; the right-hand columns are marked as our reading.
Where this fits
- UKAS-accredited certification bodies
- UKAS vs non-UKAS
- Recertification and expiry
- Statement of Applicability
Common questions
How do I check an ISO 27001 certificate is genuine?
Check three things in order, as UKAS sets out: that the certification body is accredited by a recognised accreditation body, that its accreditation covers the standard on the certificate, and that the certificate itself is valid — which you confirm with the certification body, through a search function on its website or by contacting it.
Does the certification body have to tell me whether a certificate is valid?
Yes. Under ISO/IEC 17021-1 clause 8.1.2, “The certification body shall provide upon request information about:” the status of a given certification, and the name, normative document, scope and city and country of a specific certified client. The standard notes one exception: “In exceptional cases, access to certain information can be limited on the request of the client (e.g. for security reasons).”
Can I check ISO 27001 certificates on UKAS CertCheck?
CertCheck lets you “Verify UKAS accredited Management System certificates to ISO standards by entering either the “Company name” or “Certificate number””. Its landing page names ISO 9001, ISO 14001 and ISO 45001, “Plus over 15 other international standards / schemes”, and does not name ISO/IEC 27001 — so search it, and if nothing comes back, go to the certification body.
Is IAF CertSearch still the place to check?
UKAS's own guidance notes that “Although it is mandatory for IAF accreditation bodies to populate IAF CertSearch with data on their accredited certification bodies it is not mandatory for certification bodies to upload data of their certificates.” And iaf.nu now says: “As of 01 January 2026, the International Accreditation Forum (IAF) is no longer operational.” A missing entry proves nothing either way; the certification body is the authoritative answer.
Is a suspended ISO 27001 certificate still valid?
No. “Under suspension, the client’s management system certification is temporarily invalid.” ISO/IEC 17021-1 adds: “In most cases, the suspension would not exceed six months.”
Is a certificate to ISO/IEC 27001:2013 still valid?
No. The transition deadline was 31 October 2025. Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.
What does a fake ISO certificate look like?
It may look complete. UKAS's point is that appearance proves nothing: “There is no restriction on who can become an accreditation body”, so the checks are about who accredited whom, not about what the document looks like. UKAS publishes a list of organisations known to be falsely claiming UKAS accreditation for management systems certification.
Sources cited on this page
- ISO/IEC 17021-1:2015 clauses 4.5.1, 8.1.2, 8.1.3, 8.3.4, 8.3.5
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- UKAS, Validating Management System Certificates — How to differentiate the fake from the valid
- UKAS, Counterfeit certificates and false claims of UKAS accreditation
- UKAS CertCheck (certcheck.ukas.com), landing page
- IAF, IAF CertSearch page (archival notice)
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A customer asked you to prove your certificate?
Say who issued it, the scope, and what the customer asked for.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.