Skip to main content

Who issues an ISO 27001 certificate, and what every other party produces

An ISO 27001 programme produces four kinds of document and no party produces more than two. Who holds the certificate, the accreditation, and the Statement of Applicability.

9 min read
On this page (9)

An ISO 27001 programme produces four kinds of document, and no party produces more than two of them. The Statement of Applicability belongs to the organisation. The certificate belongs to the certification body. The accreditation that makes it mean anything to a third party comes from somewhere else again. And the readiness work cannot be done by the body issuing the certificate: the standard certifiers are accredited against forbids it in six clauses.

Most arguments about who is responsible for what end once you can name the artefact and the party whose signature belongs on it.

Party Governed by What it produces
The organisation ISO/IEC 27001:2022 Scope, risk assessment and treatment, the Statement of Applicability, internal audit and management review records
Consultant or internal auditor Appointed by the organisation Gap assessment, control design, the clause 9.2 internal audit, the evidence base
Certification body ISO/IEC 17021-1:2015; ISO/IEC 27006-1:2024 Stage 1 and Stage 2 reports, nonconformity records, the certification decision, the certificate
Accreditation body ISO/IEC 17011:2017 The certifier's accreditation, scoped to named schemes
Global Accreditation Cooperation Formed by the IAF–ILAC merger, 1 January 2026 The Multilateral Recognition Arrangement recognising members' accreditations
CPA firm, the service auditor AICPA attestation standards and Code The SOC 2 report: an opinion on management's description and assertion

The organisation writes the document the auditor reads

Scope is set by the organisation, not proposed by an auditor. ISO/IEC 27001:2022 clause 4.3: "The organization shall determine the boundaries and applicability of the information security management system to establish its scope."

The Statement of Applicability is the same kind of artefact. Clause 6.1.3 c) asks the organisation to compare the controls it determined from its own risk treatment against Annex A and "verify that no necessary controls have been omitted". Clause 6.1.3 d) requires it to

"produce a Statement of Applicability that contains: — the necessary controls (see 6.1.3 b) and c)); — justification for their inclusion; — whether the necessary controls are implemented or not; and — the justification for excluding any of the Annex A controls."

Two of those four bullets are justifications. The Statement of Applicability is an argument the organisation makes and the certifier tests, and it is the first thing Stage 1 reads.

The certificate, and what has to be on it

Clause 8.2.1 of ISO/IEC 17021-1:2015 puts the certification documents in the client's hands. Clause 8.2.2 lists nine things they must identify. Four decide whether the certificate can be checked at all:

  • c) the expiry or recertification due date, consistent with the recertification cycle
  • d) a unique identification code
  • e) the standard used for the audit, including its issue status — revision date or number
  • f) the scope of certification with respect to the type of activities, products and services, as applicable at each site, without being misleading or ambiguous

The rest cover the client's name and sites, the effective dates, scheme requirements, and how to tell a revised certificate from the one it replaces. Item g) requires the certifier's own name, address and certification mark, and permits further marks — an accreditation symbol, the client's logo — provided they are not misleading or ambiguous.

Two of the four get skipped by almost everyone. Issue status is why a certificate names an edition rather than a family: the audit ran against a particular published text. Scope wording is the certificate's actual content, and the only way to know what was assessed. For an ISMS, ISO/IEC 27006-1:2024 adds its own 8.2.2, ISMS certification documents, on top.

Stage 1, Stage 2, and a decision made by neither

Clause 9.3.1.1 requires the initial certification audit to be conducted in two stages.

Stage 1 (9.3.1.2) audits the management system documentation, evaluates site-specific conditions and preparedness for Stage 2, and evaluates whether internal audits and management review are being planned and performed. So the internal audit has to have happened before the certifier's first visit concludes — see internal audit and management review.

Stage 2 (9.3.1.3) takes place at the client's sites and evaluates implementation and effectiveness: conformity to the standard, performance against objectives, legal compliance, operational control, internal audit and management review.

The audit team analyses both stages and agrees the conclusions (9.3.1.4). It does not grant the certificate. Clause 9.5.1.1 requires the persons making the certification decision to be different from those who carried out the audit, and competent to make it. Clause 9.5.2 sets what has to be true first: sufficient information against the certification requirements and the scope applied for; for every major nonconformity, the correction and corrective actions reviewed, accepted and verified; for the minor ones, an accepted plan. The auditor in the room does not hold the answer to when your certificate issues, and is not permitted to.

The decision starts a programme, not a document: clause 9.1.3.2 requires a two-stage initial audit, surveillance in the first and second years, and recertification in the third before expiry, with 9.6.5 covering suspension, withdrawal or reduction of scope. Costs are in what ISO 27001 certification costs and how long it takes.

Accreditation is the part of the chain nobody explains

A certification body is itself assessed. Accreditation bodies operate to ISO/IEC 17011:2017 and assess certifiers against ISO/IEC 17021-1:2015 plus the scheme standard — for an ISMS, ISO/IEC 27006-1:2024. In India that body is the National Accreditation Board for Certification Bodies, a constituent board of the Quality Council of India.

Accreditation is granted for a scope: the schemes a body has been assessed as competent to certify against. Which is why "accredited" is checkable only when the accreditation body and the scheme are both named.

Above it sits a multilateral arrangement, by which an accreditation granted in one economy is recognised in another. That layer changed at the start of this year.

The arrangement changed on 1 January 2026

The International Accreditation Forum ceased operations on 1 January 2026. Its site now carries one notice: "IAF ceased operations on 01 January 2026. This website is a legacy site maintained for archival/reference purposes only." IAF merged with the International Laboratory Accreditation Cooperation to form Global Accreditation Cooperation Incorporated, which commenced full operations the same day under a single Multilateral Recognition Arrangement covering the scopes previously recognised under the IAF MLA and the ILAC MRA.

Three things follow, and they travel together.

A certificate carrying an IAF mark is not stale. The launch announcement records that the older marks "will remain valid for as long as required until full adoption of the Global Accreditation Cooperation Incorporated new mark". One issued before 2026 under the IAF MLA was accurate when issued, and the recognition carried across.

The register did not close with the forum. IAF CertSearch continues to operate under its established name, and a certificate looked up in it today still shows IAF branding alongside the certifier and the accreditation body.

But the IAF MLA is not the arrangement in force. NABCB signed it for information security management systems on 5 November 2015, in Milan — a fact about 2015, and one that belongs in the past tense. Anything describing the IAF MLA as current was written before January 2026, which is worth noticing when the page is a supplier's.

Organisation, certification body, accreditation body, multilateral arrangement: every link in that chain has a name, and a link nobody will name is the finding.

Ours, since we are asking you to check other people's

Security Brigade holds certificate AMER24908, ISO/IEC 27001:2022, issued by Americo Quality Standards Registech Private Limited and accredited by the United Accreditation Foundation. Original issue 24 February 2025, current issue 17 March 2026, surveillance due 23 February 2027, recertification 23 February 2028. The scope covers the management of information security applied to our consulting services and to the development, management and delivery of ShadowMap.

The entry is public: AMER24908 in IAF CertSearch. It shows status Active, last updated 17 March 2026 — the same date as the reissue — with the certification body and the accreditation body named, and one site.

That is the whole chain in this article, walkable end to end in about thirty seconds by someone who has met none of us. It is also the only fair way to publish this article. A page that teaches you to ask a supplier for a certificate number, and does not put its own where you can check it, is asking for a standard of evidence it has not met.

One thing our certificate does not say, since the point of this article is reading them precisely: an ISMS certificate certifies the management system. It does not certify any assessment we deliver, and no ISO 27001 certificate — ours or anyone's — ever certifies a product or a service.

The party that prepares you is not the party that certifies you

ISO/IEC 17021-1:2015 defines the activity at clause 3.3. Management system consultancy is "participation in establishing, implementing or maintaining a management system", an example being "Giving specific advice, instructions or solutions towards the development and implementation of a management system". Six clauses apply to it, and two decide how a proposal reads.

5.2.5"The certification body and any part of the same legal entity and any entity under the organizational control of the certification body [see 9.5.1.2, bullet b)] shall not offer or provide management system consultancy."

The bracketed cross-reference is doing work. Clause 9.5.1.2 defines organisational control, and it reaches majority ownership, majority participation on another entity's board, and documented authority inside a network linked by ownership or board control. A separately incorporated sister company is inside the clause.

5.2.9"The certification body's activities shall not be marketed or offered as linked with the activities of an organization that provides management system consultancy."

Four more close the remaining routes: 5.2.6 on internal audits, 5.2.7 on a related body's consultancy, 5.2.8 on outsourcing audits, 5.2.10 on the individuals who consulted. All six are quoted in full in why the firm that prepares you cannot be the firm that certifies you.

So a proposal carrying you from gap analysis to certificate under one signature is one of two things. Either the seller is not the certification body, and the certificate comes from a body you have not been introduced to — ask which one, now rather than at Stage 2. Or the seller is a certifier, or linked to one, and 5.2.5, 5.2.7 and 5.2.9 are read against it in sequence.

Security Brigade works the readiness side: scoping, risk assessment and treatment, the Statement of Applicability, control implementation, and the clause 9.2 internal audit.

The SOC 2 side: two professions, one structure

A SOC 2 engagement changes the profession and keeps the shape. Under the AICPA's description criteria, DC section 200, "the CPA (known as a service auditor) expresses an opinion". Who writes the description is a stated premise: "service organization management is also responsible for developing and presenting in the SOC 2 report a description of the service organization's system."

So no party produces a certificate; the reason is in "SOC 2 certified" is a phrase that cannot be true. The report carries management's description, management's assertion and the service auditor's opinion — three artefacts, two signatories, held apart by ET section 1.295 of the AICPA Code on nonattest services. Security Brigade's own SOC 2 Type II is in progress, which describes work rather than an opinion.

What to ask, and who has to answer

Three questions are answerable before anyone is engaged: which accreditation body has accredited the certifier, and for which scheme; which party signs the certificate; and what the scope wording under 8.2.2 f) will say.

A fourth is answerable about somebody else's certificate. Clause 8.1.2 requires a certification body to provide, on request, the status of a given certification and the name, related normative document, scope and geographical location of a specific certified client. When a supplier sends you a PDF, the body named on it is obliged to confirm what it says.

Every clause number, quotation and date above was checked against published text on 27 August 2026.