iso27001partnersUK certification, costed Get a cost estimate

Lists of ISO 27001 certified companies: where they come from and what they miss

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 1 October 2026
By the iso27001partners.co.uk editorial team · Published 1 October 2026 · Last reviewed 1 October 2026 · 8 min read
6 primary sources cited on this page. How we check what is on this site
What the ISO Survey counts Accredited, and uploaded

“The ISO Survey counts the number of certificates issued by certification bodies that have been accredited by members of the Global Accreditation Cooperation Incorporated (Global ACI), uploaded to IAF CertSearch” — iso.org.

People look for a list of ISO 27001 certified companies for two reasons: to find suppliers who hold the certificate, or to check that one does. No single public list answers either. Certificate data sits with certification bodies, in two search services and in an annual survey, and each holds a different part of it. This page sets out where lists come from, what each one counts, and what all of them leave out.

Where lists of certified organisations come from

Sources of data on ISO 27001 certified organisations (our summary of the sources cited)
SourceWhat it gives youWhat it leaves out
The certification bodyMust answer on request; may publish a directoryOnly its own clients; access can be limited for security reasons
UKAS CertCheckSearch by company name or certificate numberUKAS-accredited certificates only; its landing page names ISO 9001, 14001 and 45001 plus others
IAF CertSearchThe database the ISO Survey is now compiled fromAccredited certificates that have been uploaded; country data behind a login
The ISO SurveyAnnual counts by country, standard and sectorNumbers, not names
Company websites and tendersWhat organisations say about themselvesSelf-description; check it against the certification body

The certification body

The only complete record of a certificate is the certification body's. ISO/IEC 17021-1 clause 8.1.2: “The certification body shall provide upon request information about:”

ISO/IEC 17021-1:2015 clause 8.1.2 (verbatim)
Information the certification body shall provide upon request
ageographical areas in which it operates
bthe status of a given certification
cthe name, related normative document, scope and geographical location (city and country) for a specific certified client

Directories are optional

“The certification body can also make the information in 8.1.2 public by any means it chooses without request, e.g. on its internet website.” So some certification bodies publish searchable directories and some do not. And: “In exceptional cases, access to certain information can be limited on the request of the client (e.g. for security reasons).”

Status, not just presence

A name in a directory is not a status. ISO/IEC 17021-1's openness principle describes certification status as “the granting, maintaining of certification, expanding or reducing the scope of certification, renewing, suspending or restoring, or withdrawing of certification”. A list that does not show status cannot tell suspended from current.

The search services and the ISO Survey

UKAS CertCheck

UKAS launched CertCheck in June 2022. It lets you “Verify UKAS accredited Management System certificates to ISO standards by entering either the “Company name” or “Certificate number””. It is a search, not a list to download, and it covers UKAS-accredited certification. Its landing page names ISO 9001, ISO 14001 and ISO 45001, “Plus over 15 other international standards / schemes”; ISO/IEC 27001 is not named there.

IAF CertSearch and the ISO Survey

“Since 1993, the ISO Survey has provided an annual snapshot of valid certificates to some ISO management system standards worldwide.” “From 2025 onwards, the Survey will be compiled directly from anonymised, aggregated data in IAF CertSearch, the global database of accredited management system certifications.” “IAF CertSearch is developed and operated by Quality Trade, a joint partner of both ISO and Global ACI.”

What it counts

“The ISO Survey counts the number of certificates issued by certification bodies that have been accredited by members of the Global Accreditation Cooperation Incorporated (Global ACI), uploaded to IAF CertSearch”. A certificate from a body outside that system — or one whose data has not been uploaded — is not counted.

Upload is the gap

UKAS, writing in 2022, noted: “Although it is mandatory for IAF accreditation bodies to populate IAF CertSearch with data on their accredited certification bodies it is not mandatory for certification bodies to upload data of their certificates.” Whether that has changed since the ISO Survey moved onto CertSearch, the pages we read do not say.

The numbers

The ISO Survey 2024 reported 96,709 valid ISO/IEC 27001 certificates worldwide, covering 179,877 sites (taken from a document reproducing the survey). Country figures are available to logged-in CertSearch users; IAF CertSearch lists among what you can do once logged in: “View the number of valid certificates and certified sites by country, standard, and sector”. We have not downloaded them, so we do not state a UK figure.

What every list leaves out

Scope

A certificate covers a scope, not a company. A list entry that shows a name but not the scope cannot tell you whether the service you buy is covered.

Status

“Under suspension, the client’s management system certification is temporarily invalid.” A list compiled from past data can still show a certificate that is suspended or withdrawn.

Certificates outside accreditation

Certificates from bodies that are not accredited are not in the accredited databases at all. Whether that matters is set out on UKAS vs non-UKAS certification.

Using a list (our reading)

To find suppliers

A list is a starting point. Before relying on any supplier's certificate, confirm status and scope with the certification body, as set out on certificate verification.

To be found

If you hold a certificate, ask your certification body whether it publishes a directory and whether it uploads your data to IAF CertSearch. Your own statements about it are bound by the rules you agreed to, including that you “does not make or permit any misleading statement regarding its certification”. See ISO 27001 certificate.

The authoritative answer

For any one organisation, ask the certification body named on its certificate for the status and scope. Every list is a copy of that answer, at some date.

We do not certify, audit or consult, and are paid the same fixed fee per enquiry whichever firm you use. We do not publish a list of certified companies. Sources are quoted from iso.org, IAF CertSearch, UKAS and ISO/IEC 17021-1.

Where this fits

Common questions

Is there a list of ISO 27001 certified companies?

There is no single public list. Certification bodies hold their own clients' data and must give the status of a given certification on request; UKAS CertCheck searches UKAS-accredited certificates; IAF CertSearch is the database of accredited certifications the ISO Survey is now compiled from. Each covers part of the picture.

How many companies are ISO 27001 certified?

The ISO Survey 2024 reported 96,709 valid ISO/IEC 27001 certificates worldwide, covering 179,877 sites. Those figures are taken from a document that reproduces the survey, not from the dataset itself. We have not been able to read the UK figure: the country data is behind a login.

Does the ISO Survey count every certificate?

No. iso.org: “The ISO Survey counts the number of certificates issued by certification bodies that have been accredited by members of the Global Accreditation Cooperation Incorporated (Global ACI), uploaded to IAF CertSearch”. Certificates from bodies outside that system, or not uploaded, are not in it.

Can I get a list of a certification body's clients?

You can ask about a specific organisation. ISO/IEC 17021-1 requires the certification body to provide on request the status of a given certification and the name, standard, scope and location of a specific certified client. Whether it publishes a full directory is its choice.

Why is a company I know is certified missing from a list?

Several possible reasons: its certification body has not uploaded the data, it is accredited outside the list's scope, or access is restricted: “In exceptional cases, access to certain information can be limited on the request of the client (e.g. for security reasons).”

Does ISO publish a list of certified companies?

No. “ISO does not perform certification.” ISO's survey publishes counts, compiled from IAF CertSearch.

Sources cited on this page

  1. ISO, The ISO Survey (iso.org)
  2. IAF CertSearch, ISO Survey — now powered by IAF CertSearch
  3. ISO/IEC 17021-1:2015 clauses 4.5.1, 8.1.2, 8.1.3, 8.3.4, 8.3.5
  4. UKAS CertCheck (certcheck.ukas.com), landing page
  5. UKAS, Validating Management System Certificates — How to differentiate the fake from the valid
  6. The ISO Survey of management system standard certifications 2024

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Looking for a certified supplier, or to get certified?

Say which, and what the certificate needs to cover.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now