Choosing a certification body, and how to check one
This page does not list certification bodies and does not rank them. A list would be stale the moment a schedule of accreditation changed, and we hold no data that would justify ranking anybody. What follows is how to check any body yourself, which stays correct.
We have no commercial relationship with any certification body and could not arrange certification if we wanted to. Consultancies pay us a fixed fee per enquiry; certification bodies pay us nothing at all. That is why this page has no list on it.
Key points
- Check the schedule, not the logo. The schedule of accreditation names which standards and scopes a body may certify. A body accredited for ISO 9001 is not thereby accredited for ISO/IEC 27001.
- Ask for the day count before the price. It comes from a published rule and there is no reason for it to be confidential.
- Ask for three years of charges, not one. Surveillance, recertification, application and certificate fees together exceed the initial audit.
- A body that recommends a consultancy has a problem. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.9 forbids implying that certification would be easier with a specified consultancy.
What accreditation means here
United Kingdom Accreditation Service is appointed under The Accreditation Regulations 2009 (SI 2009/3155), regulation 3, regulation 3 of which provides that “UKAS is appointed for the purposes of Article 4(1) of the EC Regulation as the national accreditation body”. It assesses certification bodies. It never certifies you.
An accredited certificate is one issued by a body that UKAS has itself assessed against ISO/IEC 17021-1 and ISO/IEC 27006-1, and it carries the UKAS symbol with a schedule of accreditation naming the scope. A non-accredited certificate is issued by a body nobody has assessed. Both are pieces of paper. Only one of them has anybody standing behind it. The full comparison sets out what the difference costs when a customer checks.
The same diagram as a table
| Role | Does | Cannot do |
|---|---|---|
| Accreditation body (UKAS) | Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 | Issue you a certificate |
| Certification body | Stage 1, Stage 2, annual surveillance, issues the certificate | Provide management system consultancy to you (clause 5.2.5) |
| Consultancy | Gap analysis, risk assessment, Statement of Applicability, internal audit support | Issue or influence a certificate |
| This site | Publishes the rules and the cost arithmetic; sells advertising | Audit, certify, accredit or advise |
How to check a body against the register
- Find the body on the UKAS register. Not the logo on its website — the register itself, at ukas.com.
- Open the schedule of accreditation. This is the document that matters. It lists the standards the body is accredited to certify against and the scopes it may work in.
- Confirm ISO/IEC 27001 is on it. Accreditation is granted per standard.
- Confirm the scope covers your sector. Accreditation can be limited, and a UKAS symbol used outside the accredited scope is a misuse of the symbol.
- If you are checking somebody else's certificate, also check that it is current, that it names ISO/IEC 27001:2022 rather than the withdrawn ISO/IEC 27001:2013, and that the scope on it covers the service you actually buy.
Seven questions before you commit
| Question | Why it matters | Warning sign |
|---|---|---|
| What is your accreditation, and can I see the schedule? | A body should answer this without hesitation and point you at the register. The schedule matters more than the listing: it names which standards and which scopes the body may certify, and a body accredited for ISO 9001 is not thereby accredited for ISO/IEC 27001. | Hesitation, or a logo offered in place of a register entry. |
| How many audit days, and which band? | The answer comes from the published table and there is no reason for it to be confidential. It should reconcile to your headcount band within the 30% the rule permits. | A price with no day count behind it, or a day count materially below your band. |
| What is the full schedule of charges for three years? | Certification audit, both surveillance years, recertification, application fee, certificate fee, any annual registration charge, and travel. Together these exceed the initial audit. | A single headline figure, with the rest 'discussed later'. |
| What is your relationship with any consultancy you are recommending? | BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.7: where a client has had consultancy from a body related to the certification body, that body must not certify the management system for at least 2 years. You want to know before you engage either. | A recommendation of a specific consultancy, or any suggestion that using one would make certification easier — clause 5.2.9 forbids a certification body from implying it. |
| What is your current lead time to Stage 1 and to Stage 2? | Certification body availability decides more contractual dates than preparation speed does, and the gap between the two stages is scheduled around theirs, not yours. | An unwillingness to commit to a window when you have a contractual date. |
| Who will audit us, and what is their sector experience? | Auditor competence for your sector is part of what accreditation assesses. It is reasonable to ask, and a good body will tell you. | No answer until after contract signature. |
| What happens if Stage 2 raises a major nonconformity? | A major nonconformity must be closed before a certificate is issued, and closing it often needs a further visit. Find out now whether that visit is chargeable and how it is priced. | Vagueness. This is a known, priced event for any experienced body. |
Five claims that should end the conversation
| The claim | What is wrong with it |
|---|---|
| “We are an ISO-certified certification body” | ISO writes standards. It does not certify anyone, accredit anyone, or operate any certification scheme. A body describing itself this way is either careless with language or relying on you not knowing the difference. |
| “Accredited certification” with no accreditor named | Ask which accreditation body, then check that the accreditor is a recognised national accreditation body rather than another private company. In the UK there is exactly one, named in secondary legislation. |
| “We can get you certified quickly” | The audit length is set by the published table and the timeline floor is set by clauses 9.2 and 9.3. Neither is within a certification body's gift, and a body suggesting otherwise is describing something other than accredited certification. |
| “Our consultants will prepare you and our auditors will certify you” | This is the one that should end the conversation. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5 bars a certification body from offering management system consultancy at all. |
| A UKAS symbol on a certificate for a scope outside the schedule | A body can be accredited for some scopes and not others. Using the symbol outside the accredited scope is a misuse of it, and reading the schedule is how you would know. |
The clause worth knowing by heart
“The certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy.” — BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text, clause 5.2.5. One sentence, and it settles most of the questions on this page.
What the certification body can and cannot tell you
The boundary confuses people, and the standard is more precise about it than most summaries are. A certification body may exchange information with you — explaining a finding, clarifying what a requirement means. That is explicitly preserved. What it may not do is consultancy: telling you how to design your management system, writing anything for you, or recommending a firm that will.
In practice an experienced auditor will tell you exactly what they observed and why it does not meet the requirement, and will then stop. That is not unhelpfulness. An auditor who goes further is putting their own body's accreditation at risk, and the two-year bars in clauses 5.2.6 and 5.2.7 exist because the rule takes this seriously.
Transferring between bodies
If lead times or costs are not what you were led to expect, you are not locked in. There are established rules for transferring certification between accredited bodies so that the new body can rely on the audits already done rather than restarting at Stage 1. Ask a prospective body how it handles a transfer before assuming the answer is difficult, and ask your current one what it will provide.
Where to go next
Common questions
Which certification body should we use?
We do not answer that, and we would be the wrong people to. We do not rank, score or vet certification bodies, we hold no data that would justify doing so, and any list we published would go stale the moment a schedule of accreditation changed. What this page does instead is show you how to check any body yourself against the register, which is a check that stays correct.
How do I verify a certification body is UKAS-accredited?
Search the UKAS register for the body, and then read its schedule of accreditation rather than stopping at the listing. The schedule names the standards and the scopes the body may certify. Two failure modes to look for: the body is not there at all, or it is there but ISO/IEC 27001 is not on its schedule. A logo on a website is a claim; the register is the record.
Can I check somebody else's certificate?
Yes, and for supplier assurance you should. An accredited certificate carries the accreditation symbol and a number, and the issuing body maintains a register of the certificates it has issued. Check three things: that the certificate is current, that the edition is ISO/IEC 27001:2022 — certificates against the withdrawn ISO/IEC 27001:2013 expired on 31 October 2025 — and that the scope on the certificate actually covers the service you buy from them. The third is where most supplier assurance quietly fails.
Is a bigger certification body better?
Not inherently, and size is a poor proxy for anything you care about. What matters is that the body is accredited for ISO/IEC 27001, that its auditors are competent in your sector, that its lead time fits your date, and that its three-year cost is what you were told. A large body may have longer lead times; a smaller one may have deeper sector knowledge. The accreditation check is binary and the rest is fit.
Can our certification body help us fix a nonconformity?
It can explain the finding — the standard explicitly preserves exchange of information such as explaining findings or clarifying requirements. What it cannot do is tell you how to fix it, because that would be consultancy, and BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text clause 5.2.5 bars it. Auditors are practised at walking that line, and an auditor who offers to design your solution is creating a problem for their own body's accreditation as well as for you.
Do we have to stay with the same certification body?
No. You can transfer certification between accredited bodies, and there are established rules for how a transfer is handled so that the new body can rely on the previous audits rather than starting from Stage 1. If you are unhappy with lead times or cost, it is a real option. Ask the prospective body how it handles transfers before assuming it is difficult.
What does UKAS do if a certification body gets it wrong?
UKAS assesses accredited bodies on a cycle and can raise findings, suspend or withdraw accreditation for a scope. That mechanism is the whole difference between an accredited and a non-accredited certificate: not that mistakes never happen, but that there is somebody independent who will find them and act.
Sources cited on this page
- The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
- United Kingdom Accreditation Service
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Working out what you need before you approach a body
Scope and headcount decide the audit. A consultancy can help you settle both before you ask anyone for a quote.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.