What is an ISO 27001 certification body?
⌄
An ISO 27001 certification body is an independent organisation accredited to audit an Information Security Management System and issue the certificate. The body performs Stage 1 and Stage 2, makes the certification decision, returns for annual surveillance, and handles recertification in year three.
What is the difference between accreditation and certification?
⌄
Accreditation evaluates the certification body; certification evaluates your organisation. National accreditation bodies such as ANAB, UKAS, IAS, or SCC assess whether a certification body is competent and impartial. The accredited body then audits your ISMS and issues the ISO 27001 certificate.
Can my ISO 27001 consultant also certify my ISMS?
⌄
No. A consultant can design the ISMS, write policies, run a gap assessment, and prepare evidence, but the certification body must remain impartial. Keep implementation and certification in separate contracts and ask each provider to identify the legal entity performing its role.
What happens in Stage 1 and Stage 2?
⌄
Stage 1 reviews the ISMS scope, required documentation, internal audit, management review, and readiness for full assessment. Stage 2 tests whether the ISMS and selected controls operate in practice. Unresolved major nonconformities prevent certification until the body verifies corrective action.
How do I verify an ISO 27001 certification body?
⌄
Open the body’s current primary evidence or accreditor record, confirm ISO/IEC 27001 is inside the accredited scope, match the legal entity on the proposal, and verify the certificate through IAF CertSearch or the named national accreditation body. A logo or consultant partnership is not enough.