iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 certificate: who issues it, what it states, how long it lasts and how to use it

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 1 October 2026
By the iso27001partners.co.uk editorial team · Published 1 October 2026 · Last reviewed 1 October 2026 · 8 min read
5 primary sources cited on this page. How we check what is on this site
iso.org “ISO does not perform certification.”

“Organizations looking to get certified to an ISO standard must contact an independent certification body.”

An ISO 27001 certificate is a document a certification body issues after auditing your information security management system. What it must say, how long it lasts and how you may use it are all fixed by the accreditation standard certification bodies work to, ISO/IEC 17021-1. This page is the holder's side; if you are checking someone else's certificate, see certificate verification.

Who issues it

Not ISO. The certificate comes from a certification body, and in the UK the ones worth having are accredited by UKAS for ISO/IEC 27001. ISO/IEC 17021-1 clause 8.2.1: the certification body “shall provide by any means it chooses certification documents to the certified client”. See UKAS-accredited certification bodies and UKAS vs non-UKAS.

How you get one

“The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” The certificate follows the certification decision after Stage 2. The steps are on the certification process and the audit days and cost on the cost calculator.

What it states

ISO/IEC 17021-1:2015 clause 8.2.2 lists what the certificate shall identify. In short:

What an ISO 27001 certificate must identify (ISO/IEC 17021-1:2015 8.2.2, summarised; full text on the verification page)
Item
aYour name and location, or headquarters and sites if multi-site
bWhen it was granted, expanded, reduced or renewed
cThe expiry or recertification due date
dA unique identification code
eThe standard and its edition: ISO/IEC 27001:2022
fThe scope: activities, products and services, at each site
gThe certification body's name, address and mark

The scope line matters most

Item (f) has to describe the scope “without being misleading or ambiguous”. Customers read it to see whether the service they buy is covered. If your scope is narrower than what you sell, expect the question.

How long it lasts

The cycle is 3 years. “Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.”

Renewal

“This shall be planned and conducted in due time to enable for timely renewal before the certificate expiry date.” “When recertification activities are successfully completed prior to the expiry date of the existing certification, the expiry date of the new certification can be based on the expiry date of the existing certification. The issue date on a new certificate shall be on or after the recertification decision.” See recertification.

Suspension and the 2013 edition

“Under suspension, the client’s management system certification is temporarily invalid.” And certificates to the old edition have ended: the transition deadline was 31 October 2025.

“A certification body shall have rules governing any management system certification mark that it authorizes certified clients to use. These rules shall ensure, among other things, traceability back to the certification body.” “There shall be no ambiguity, in the mark or accompanying text, as to what has been certified and which certification body has granted the certification.”

What a certified organisation may and may not do (ISO/IEC 17021-1:2015 clause 8.3, our summary with clause references)
UseAllowed?Clause
Website, proposals, email signaturesYes, within the certification body's rules8.3.4 a)
Saying a product or service is ‘ISO 27001 certified’No: the certificate is for the management system8.3.1, 8.3.4 f)
The certification mark on a product or its packagingNo8.3.1
A statement on packaging or accompanying informationOnly within the certification body's rules, naming you, the standard and the certification body8.3.3
The mark on test, calibration or inspection reportsNo8.3.2
Showing sites or activities outside the scope as certifiedNo8.3.4 g)
Using it after withdrawalNo: stop, as the certification body directs8.3.4 d)

Not a product mark

“This mark shall not be used on a product nor product packaging nor in any other way that may be interpreted as denoting product conformity.” “A certification body shall not permit its marks to be applied by certified clients to laboratory test, calibration or inspection reports or certificates.”

Statements on packaging

A certified client may make a statement on packaging or accompanying information under the certification body's rules. “The statement shall in no way imply that the product, process or service is certified by this means.” The statement shall include reference to:

A packaging statement must refer to (ISO/IEC 17021-1:2015 8.3.3, verbatim)
Reference
identification (e.g. brand or name) of the certified client
the type of management system (e.g. quality, environment) and the applicable standard
the certification body issuing the certificate

What you agree to

The certification body must bind you, through legally enforceable arrangements, to rules including that you “does not make or permit any misleading statement regarding its certification” and “does not imply that the certification applies to activities and sites that are outside the scope of certification”.

The ‘ISO 27001 logo’ and badges (our reading)

The mark you are entitled to use is the one your certification body gives you, on its terms. Generic “ISO 27001 certified” badges that do not identify the certification body sit uneasily with the requirement for traceability and no ambiguity. Ask your certification body for its mark rules before designing anything.

Before you publish

Check three things: the scope wording you quote matches the certificate, the mark is your certification body's and used under its rules, and nothing suggests a product or service is certified.

We do not certify, audit or consult, and are paid the same fixed fee per enquiry whichever firm you use. The rules are quoted from ISO/IEC 17021-1 and iso.org; the summaries are ours.

Where this fits

Common questions

Who issues an ISO 27001 certificate?

A certification body, not ISO. iso.org: “ISO does not perform certification.” “Organizations looking to get certified to an ISO standard must contact an independent certification body.” In the UK, look for a certification body accredited by UKAS for ISO/IEC 27001.

How long is an ISO 27001 certificate valid?

For a 3-year cycle, with surveillance audits in years one and two and a recertification audit in year three. The expiry or recertification due date is printed on it. It stays valid only while surveillance goes ahead; a suspended certificate is temporarily invalid.

What does an ISO 27001 certificate look like?

There is no single design: each certification body issues its own. ISO/IEC 17021-1 fixes what it must show — your name and location, dates, expiry, a unique code, the standard and edition, the scope, and the certification body's name, address and mark.

Can I use the ISO 27001 logo?

What you are given is the certification body's mark, under its rules. ISO does not certify, and we have not read ISO's own logo policy, so we do not say what it permits. ISO/IEC 17021-1 requires the certification body's rules to ensure traceability back to it and no ambiguity about what was certified.

Can we say our product is ISO 27001 certified?

No. The certification is of your management system. ISO/IEC 17021-1: “This mark shall not be used on a product nor product packaging nor in any other way that may be interpreted as denoting product conformity.”

Is an ISO/IEC 27001:2013 certificate still valid?

No. The transition deadline was 31 October 2025. Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.

Sources cited on this page

  1. ISO, The ISO Survey (iso.org)
  2. ISO/IEC 17021-1:2015 clause 8.3, reference to certification and use of marks
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
  5. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Need an ISO 27001 certificate?

Say your size, what the scope should cover, and who is asking for it.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now