ISO 27001, “certified”, “compliant” and “UKAS accredited”: what each one actually means
These phrases are used interchangeably in tenders, security questionnaires and supplier assurance packs. They are not interchangeable, and the gaps between them decide whether a certificate you are shown answers the question you asked. This page is the translation table.
The same thing, called five different ways
Start here if you are holding a document and are not sure what it is asking for. The left column is what gets written. The middle column is what the standard, or the rules the certification bodies are accredited under, actually define. The right column is what the difference does.
| What the document says | What the standard or the accreditation rules actually define | What the difference does |
|---|---|---|
| “ISO 27001”, no edition given | ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements is the current edition, published 25 October 2022. The standard is a joint ISO and IEC publication, which is why its formal name carries both. | On its own the phrase does not say which edition. That mattered a great deal until 31 October 2025 and still decides whether an older certificate you are shown is live or expired. |
| “ISO 27001:2013” | The previous edition, ISO/IEC 27001:2013. Withdrawn. | Certificates issued against it ceased to be valid on 31 October 2025 under IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022. A certificate naming this edition today is expired whatever the date printed on it says. |
| “ISO 27001 compliant” | Not a status that ISO/IEC 27001, ISO/IEC 17021-1 or ISO/IEC 27006-1 defines. Those three between them define what an ISMS must contain, who may audit it, and how long the audit must take. None of them defines “compliant” as something anybody checks. | It is a self-assessment. There is no auditor, no certificate, no scope statement and no expiry date, and nothing to verify against a register. It may be perfectly truthful. It is not the same product as the next row. |
| “ISO 27001 certified” | A defined term. ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 clause 3.1 defines a certified client as an “organization whose management system has been certified”. A certification body audited the management system in two stages and issued a certificate. | There is a document, and BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text says what it must identify — including the standard with its issue status and a scope stated “without being misleading or ambiguous”. All four of the checks further down this page come off the certificate itself. |
| “we are UKAS accredited” | UKAS accredits certification bodies. An organisation that holds a certificate is certified, not accredited. United Kingdom Accreditation Service is appointed under The Accreditation Regulations 2009 (SI 2009/3155), regulation 3. | The sentence describes the wrong party. What the speaker usually means is that their certificate was issued by a UKAS-accredited body — which is a real and valuable thing, and is the next row. |
| “accredited certification” | A certificate issued by a body UKAS has itself assessed against ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 and ISO/IEC 27006-1:2024. | The only version with an independent assessor standing behind the assessor. It carries an accreditation symbol and a number, and the body appears on a public register with a schedule saying what it may certify. |
| “accredited by” a body you have not heard of | Accreditation is done by a national accreditation body. In the United Kingdom regulation 3 of The Accreditation Regulations 2009 (SI 2009/3155), regulation 3 provides that “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”. | Other countries have their own national accreditation bodies and those are real. A private company that has appointed itself is not the same thing, and the check is whether the accreditor is a national accreditation body at all. |
| “ISO 27001 aligned”, “working towards ISO 27001” | Neither phrase has any status in the standard or in the accreditation rules. | It means there is no certificate today. That can be an honest description of a project in progress; it is not an answer to a contract clause that asks for certification. |
| “we have implemented all 93 controls” | Annex A of ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements is a reference set of 93 controls. You are certified against clauses 4 to 10, which are the management system itself. | Implementing all of them is not the requirement and can be a finding in its own right. Clause 6.1.3 d) asks for a Statement of Applicability justifying inclusions and exclusions — the reasoning is the deliverable, not the count. |
| “ISO 27002 certified” | Certification is issued against ISO/IEC 27001:2022, whose clauses 4 to 10 are the requirements an ISMS is audited against. ISO/IEC 27002:2022, Information security controls is the companion standard that explains the same controls at length; the requirements you are certified against are in ISO/IEC 27001. | Organisations are not certified against the guidance standard. If a supplier offers this, ask which standard the certificate names. |
| “our certificate covers the company” | Scope is set under clause 4.3 and is printed on the certificate. | A certificate scoped to one product line, one site or one business unit evidences nothing about a different service you are buying. Reading the scope is the single most useful thing a procurement reviewer can do with a certificate. |
| “certified for three years” | Valid for three years, with a surveillance audit in each of years one and two at one third of the initial audit time, and recertification at two thirds in year three. | It is not three years of nothing. A missed surveillance audit can lead to suspension or withdrawal, so “valid until 2028” on a certificate is a maximum, not a guarantee. |
| “our consultant will get us certified” | BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5: a certification body “shall not offer or provide management system consultancy”. Clause 5.2.7 bars certification for 2 years where the consultancy came from a related body. | A consultant prepares you; only an accredited certification body certifies you. One firm offering both is either describing something other than accredited certification, or creating a two-year problem for you. |
| “ISO 27001 will satisfy the Cyber Essentials requirement” | PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note) requires Cyber Essentials or Cyber Essentials Plus, or equivalent, before contract award for in-scope contracts. | Whether ISO 27001 counts as equivalent is the contracting authority’s decision, not the supplier’s, and some buying organisations state that it does not. Read the tender and ask a clarification question rather than assuming. |
| “ISO 27001 certified” software, or a certified product | A management system certificate is not a product certificate. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text governs the certification mark, and clause 8.3.1 provides that it “This mark shall not be used on a product nor product packaging nor in any other way that may be interpreted as denoting product conformity.” Clause 8.3.3 adds that a statement about certification “The statement shall in no way imply that the product, process or service is certified by this means.” | A vendor whose certificate is real can still be describing it wrongly. The certificate says the organisation runs a management system; it says nothing about whether the product you are buying is secure. Product certification is a different scheme entirely. |
| “our people are ISO 27001 certified” | Certification of persons runs under a different standard from certification of management systems — ISO/IEC 17024, against ISO/IEC 17021-1 for the organisation. Source: ISO/CASCO, Conformity assessment bodies and the standards that govern each type. | An individual holding a qualification is not the organisation holding a certificate. Both can be true and they are answers to different questions, so it is worth asking which one is being offered. |
| “ISMS” | Information security management system — the thing described by clauses 4 to 10 and the thing that is audited. | Not a synonym for the controls, and not a product you can buy. Software that manages an ISMS is not an ISMS, which is why a platform subscription does not by itself move you towards a certificate. |
Three distinctions in that table do most of the damage, so each one gets a section below: certified against compliant, accredited against certified, and the edition.
Certified, or compliant?
What certification actually produces
A certification body audits the management system in two stages, and if it is satisfied it issues a certificate. That certificate names an edition of the standard, a scope, an issuing body and an expiry date. Every one of those four is checkable by somebody who has never met you.
The audit behind it is not a matter of opinion either. Its length comes from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21), which sets audit days by the number of people doing work under the organisation’s control inside the scope, and which caps any adjustment at 30% either way. The full audit-day table is published on this site in all 22 bands.
What “compliant” produces
Nothing that can be checked. The word is not defined as a status in ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, in ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 or in ISO/IEC 27006-1:2024. Those three between them define what a management system must contain, who is allowed to audit it, and how long that audit has to take. None of them defines a category called “compliant”.
That does not make the claim dishonest. An organisation that has genuinely built an ISMS and has not yet paid for an audit is accurately described as compliant and not certified. The problem is only that the two words look like degrees of the same thing and are not: one has an independent party attached and the other does not.
How to tell which one you have been sent
Ask for the certificate. Not a statement, not a page on a website, not a badge in an email signature — the document. If it exists, the four checkable facts above are on it. If the answer is a paragraph rather than a PDF, you have the row above.
The one-sentence version
“Compliant” is an organisation’s opinion of itself. “Certified” is somebody else’s opinion, written down, with a scope and a date on it.
Accredited, or certified? They describe different parties
Who accredits whom
This is the distinction most often got backwards, including by people who hold the certificate. Accreditation and certification sit at different levels:
- UKAS accredits certification bodies. It assesses them against ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 and the ISMS-specific requirements, and publishes what each one is competent to certify.
- Certification bodies certify organisations. That is where your certificate comes from.
- UKAS never certifies you, and no organisation holds ISO 27001 by being accredited.
United Kingdom Accreditation Service holds that position by law, not by reputation: regulation 3 of The Accreditation Regulations 2009 (SI 2009/3155), regulation 3 provides that “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”.
The same diagram as a table
| Role | Does | Cannot do |
|---|---|---|
| Accreditation body (UKAS) | Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 | Issue you a certificate |
| Certification body | Stage 1, Stage 2, annual surveillance, issues the certificate | Provide management system consultancy to you (clause 5.2.5) |
| Consultancy | Gap analysis, risk assessment, Statement of Applicability, internal audit support | Issue or influence a certificate |
| This site | Publishes the rules and the cost arithmetic; sells advertising | Audit, certify, accredit or advise |
So what does a supplier mean by “we are UKAS accredited”?
Almost always that their certificate was issued by a UKAS-accredited body. That is a real and useful thing to know — it is the difference between a certificate somebody assessed and a certificate nobody assessed. It is just a different sentence, and worth confirming rather than assuming, because the same words are also what you would hear from somebody who has not understood the structure at all.
What accreditation actually buys you works through the difference, and how to check a certification body covers verifying it against the register.
Why the wording is not merely pedantic
Claims about certification are claims about your own qualifications, made to other businesses, and there is a regulation that addresses exactly that. The Business Protection from Misleading Marketing Regulations 2008 (SI 2008/1276), regulation 3 provides at regulation 3(1):
“Advertising which is misleading is prohibited.”
“Advertising is misleading which— in any way, including its presentation, deceives or is likely to deceive the traders to whom it is addressed or whom it reaches; and by reason of its deceptive nature, is likely to affect their economic behaviour” — regulation 3(2)(a).
And at regulation 3(5), the “nature, attributes and rights” of the advertiser include the advertiser’s— identity; assets; qualifications; ownership of industrial, commercial or intellectual property rights; or awards and distinctions.
Regulation 6: “A trader is guilty of an offence if he engages in advertising which is misleading under regulation 3.”
We are not a law firm and this is not advice about any particular claim or any particular supplier. It is the text of the regulation, linked at the foot of this page so you can read the whole of it. The practical reading is narrow and useful: in a business-to-business context, what you say about your own certifications is advertising, and the regulation names “qualifications” and “awards and distinctions” among the things that can make advertising misleading.
Which edition, and why a contract should say
The transition that has already happened
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements was published on 25 October 2022. Certificates issued against the previous edition, ISO/IEC 27001:2013, ceased to be valid on 31 October 2025 under IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022. Certificates issued against the 2013 edition ceased to be valid after that date. Any certificate you are shown today that still names ISO/IEC 27001:2013 is expired, whoever issued it.
What that means for a document drafted before 2023
A clause that says only “ISO 27001” gives you no basis to reject a certificate naming the withdrawn edition, because on its face the certificate matches what you asked for. Naming the edition costs four characters and closes it.
It is also worth a pass through certificates you have already collected. A supplier assurance folder assembled before late 2025 and not revisited contains certificates that are now expired by definition rather than by date — and if you are certified yourself, that folder is evidence for your own supplier controls. The hour of work that fixes it is a short walkthrough.
The count that dates a document
The same tell appears in prose. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements has 93 Annex A controls in four themes; the withdrawn edition had 114 in 14 clauses. A policy, questionnaire or supplier statement that says 114 was written before October 2022 and has not been revisited since. The controls, theme by theme sets out what moved.
The same diagram as a table
| Theme | Reference | Controls | Covers |
|---|---|---|---|
| Organisational | A.5 | 37 | Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed. |
| People | A.6 | 8 | Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working. |
| Physical | A.7 | 14 | Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring. |
| Technological | A.8 | 34 | Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about. |
| ISO/IEC 27001:2022 total | 93 | Four themes | |
| ISO/IEC 27001:2013 total | 114 | 14 clauses, A.5 to A.18. Withdrawn. | |
What a certificate has to say, and what to read off it
The list is not the certification body’s to choose
Most of the checks on this page can be done from the certificate itself, because BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text sets out what a certification document must identify. It is worth knowing the list, because it turns “can I trust this?” into seven specific questions with answers printed on the page in front of you.
| The certificate must identify | What to do with it | |
|---|---|---|
| a | the name and geographical location of each certified client (or the geographical location of the headquarters and any sites within the scope of a multi-site certification) | Confirm the legal entity is the one you are contracting with, and that the site matters to you. |
| b | the effective date of granting, expanding or reducing the scope of certification, or renewing certification | Tells you how long the management system has actually been certified. |
| c | the expiry date or recertification due date consistent with the recertification cycle | The expiry. Check it against the term of the contract you are about to sign. |
| d | a unique identification code | The number you quote when asking the issuing body to confirm it. |
| e | the management system standard and/or other normative document, including indication of issue status (e.g. revision date or number) used for audit of the certified client | The edition. “Issue status” is the clause’s own wording, and it is why a certificate naming the withdrawn edition is visible as such. |
| f | the scope of certification with respect to the type of activities, products and services as applicable at each site without being misleading or ambiguous | The scope. The clause requires it to be stated without being misleading or ambiguous — so if you cannot tell whether it covers your service, that is itself a finding. |
| g | the name, address and certification mark of the certification body; other marks (e.g. accreditation symbol, client’s logo) may be used provided they are not misleading or ambiguous | The issuing body, and any accreditation symbol. This is what you check against the register. |
Certified organisations, certified people, certified products
Three different things, three different standards, and they get conflated constantly. A supplier saying “we are certified” and a supplier saying “our engineers are certified” have said entirely different sentences.
| What is being certified | Standard for the body doing it | Full title |
|---|---|---|
| Management system certification | ISO/IEC 17021-1 | Requirements for bodies providing audit and certification of management systems |
| Certification of persons | ISO/IEC 17024 | General requirements for bodies operating certification of persons |
| Product, process and service certification | ISO/IEC 17065 | Requirements for bodies certifying products, processes and services |
| Testing and calibration laboratories | ISO/IEC 17025 | General requirements for the competence of testing and calibration laboratories |
| Inspection bodies | ISO/IEC 17020 | Requirements for the operation of various types of bodies performing inspection |
| Validation and verification bodies | ISO/IEC 17029 | General principles and requirements for validation and verification bodies |
The one that catches procurement teams is the middle row. An individual qualification is a real thing and evidences competence; it is not an organisational certificate and it does not come with a scope, an expiry or an accreditation.
A management system certificate is not a product certificate
The same clause set governs the mark. Clause 8.3.1 provides that the certification mark “This mark shall not be used on a product nor product packaging nor in any other way that may be interpreted as denoting product conformity.” Clause 8.3.3 adds that a statement about certification “The statement shall in no way imply that the product, process or service is certified by this means.”
So a certificate tells you the supplier runs a management system that was audited. It does not tell you that the software you are buying is secure, and a vendor presenting it as though it does has overstated it — whether or not the certificate itself is genuine.
If you are the one writing the requirement
The table at the top read from the other side. Each row is what to write when you mean a particular thing, so that the ambiguity never reaches an evaluation.
| If you mean | Write | Why this wording |
|---|---|---|
| You want a certificate that somebody independent stands behind | “Certification to ISO/IEC 27001:2022 by a certification body accredited for that standard by a national accreditation body.” | Names the edition, the act of certification and the accreditation. Closes all three of the common gaps at once. |
| You want the certificate to cover the service you are buying | “… with a scope covering [the service], as stated on the certificate.” | Scope is printed on the certificate, so this is checkable rather than aspirational. |
| You want it to still be valid during the contract | “… maintained for the term, including surveillance audits, with notification of any suspension or withdrawal.” | Certification is a three-year cycle with annual audits. Without this clause you have evidence about the day it was issued and nothing after. |
| You are willing to accept an alternative | “… or [named alternative], at the authority’s discretion.” | “Or equivalent” with nothing named puts the decision back on you later, in the middle of an evaluation, with a supplier arguing. |
| You only need basic technical hygiene | “Cyber Essentials, or Cyber Essentials Plus where [condition].” | Naming the smaller scheme when the smaller scheme is what you need is cheaper for your suppliers and gets you more bidders. |
The sentence that closes the most gaps at once
“Certification to ISO/IEC 27001:2022 by a certification body accredited for that standard by a national accreditation body, with a scope covering [the service], maintained for the term.” Edition, certification, accreditation, scope and currency — five checks in one sentence.
We are not a certification body, not an accreditation body and not a consultancy, and we cannot issue, arrange or influence any certificate. Consultancies pay us a fixed fee per enquiry agreed in advance. That is why this page can tell you that a smaller scheme may be the right answer, and why it has no list of firms on it.
If you are the one being asked
Answer the question that was asked
If a questionnaire asks whether you are certified and you are not, say so and say what you do have. A supplier who answers “we are ISO 27001 compliant” to a question asking about certification has not answered it, and a vendor-risk reviewer reads that as evasion whether or not it was meant as one.
Know what your own certificate says
Three facts about your own certificate are worth knowing without looking: the edition, the scope wording, and the expiry. The scope is the one that catches people, because it was decided early, often by somebody who has since left, and it is what a reviewer reads first.
If you do not have one yet
The two questions that decide the cost are how many people are inside the scope and how many sites, because those are the inputs the audit-day rule actually takes. The calculator runs them, and the process page sets out what has to happen before a certification body can audit you at all.
Common questions
Is “ISO 27001 compliant” the same as “ISO 27001 certified”?
No, and the gap between them is the single most common misunderstanding in this subject. Certification means a certification body audited the management system in two stages and issued a certificate naming a scope and an expiry date. “Compliant” is not a status defined by ISO/IEC 27001, by ISO/IEC 17021-1 or by ISO/IEC 27006-1 — it is an organisation's own assessment of itself, with no auditor, no certificate and nothing to check. A supplier saying it may be telling the complete truth. It is still not what a contract clause asking for certification is asking for.
Can a company be “UKAS accredited”?
Not for holding ISO 27001. UKAS accredits certification bodies; the organisations those bodies certify are certified, not accredited. United Kingdom Accreditation Service is appointed under The Accreditation Regulations 2009 (SI 2009/3155), regulation 3. When a supplier says “we are UKAS accredited” they almost always mean their certificate came from a UKAS-accredited body, which is a good thing and a different sentence. Accreditation of a laboratory or an inspection body is a separate matter and does exist — but that is not what an ISO 27001 certificate is.
Which edition should a contract name?
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, published 25 October 2022. Naming the edition matters because certificates issued against the withdrawn ISO/IEC 27001:2013 ceased to be valid on 31 October 2025, and a clause that says only “ISO 27001” gives you no way to reject one. If your contracts were drafted before late 2022 this is worth a pass through the template.
What is the difference between ISO 27001 and ISO 27002?
Certification is issued against ISO/IEC 27001:2022, whose clauses 4 to 10 are the requirements an ISMS is audited against. ISO/IEC 27002:2022, Information security controls is the companion standard that explains the same controls at length; the requirements you are certified against are in ISO/IEC 27001. In practice: ISO 27001 is what the auditor holds you to, and ISO 27002 is what your own team reads when working out what a control means in your organisation. A certificate always names ISO/IEC 27001.
How do I check that a certificate is real?
Most of it comes off the certificate, because BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text sets out what a certification document must identify. Read the standard and its issue status, and reject anything still naming ISO/IEC 27001:2013. Read the scope, which that clause requires to be stated “without being misleading or ambiguous”, and confirm it covers the service you are buying rather than some other part of the supplier. Check the expiry date and the unique identification code. Then check the issuing body against the accreditation body's public register: a logo on a supplier's website is a claim, and the register is the record.
Does a false certification claim have any legal consequence?
There is a regulation that speaks directly to business-to-business claims of this kind. The Business Protection from Misleading Marketing Regulations 2008 (SI 2008/1276), regulation 3 provides at regulation 3(1) that “Advertising which is misleading is prohibited.”, and regulation 3(3) and 3(5) list the advertiser's own “qualifications” and “awards and distinctions” among the things that can make advertising misleading. Regulation 6 provides that “A trader is guilty of an offence if he engages in advertising which is misleading under regulation 3.” We are not a law firm and this is not advice on any particular claim; it is the text of the regulation, linked so you can read it yourself.
We wrote “ISO 27001 or equivalent”. Is that a problem?
It is not wrong, and it does move a decision to the worst possible moment. “Or equivalent” with nothing named means that when a bid arrives holding something else, you have to decide equivalence during evaluation, under time pressure, with a supplier arguing their case. Naming the alternatives you would actually accept costs one sentence at drafting time and removes the argument entirely.
Our supplier says certification is “in progress”. What does that tell us?
That there is no certificate today, and little else on its own. The useful follow-up is to ask which certification body has been engaged and what stage has been booked, because Stage 1 and Stage 2 are separate scheduled visits and a supplier who has genuinely started can name both. A supplier who cannot name a certification body has not started the part that produces a certificate.
Sources cited on this page
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO/IEC 27002:2022, Information security controls
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
- PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
- The Business Protection from Misleading Marketing Regulations 2008 (SI 2008/1276), regulation 3
- The Business Protection from Misleading Marketing Regulations 2008 (SI 2008/1276), regulation 6
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Work out what you actually need
Five click-only questions. If the honest answer is that a smaller scheme covers it, a consultancy will tell you that too.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.