Certification Body

Certification body and accreditation chain for ISO 27001

A certification body is the independent organisation that audits your management system and issues the ISO 27001 certificate. It cannot also be the consultant that built it.

  • Glossary
  • ISO 27001

The short answer

A certification body, sometimes called a registrar, performs the Stage 1 and Stage 2 audits and issues your certificate. The credible ones are accredited by a national accreditation body such as UKAS, ANAB or NABCB, which audits the auditor. An unaccredited certificate is legally a piece of paper, and enterprise procurement teams increasingly check.

The distinction that catches people out: accreditation and certification are different things at different levels. You are certified. Your certification body is accredited.

Accreditation, certification and you

Accreditation body UKAS, ANAB, NABCB and other national bodies accredits, against ISO 17021 Certification body Runs Stage 1, Stage 2 and surveillance audits certifies, against ISO 27001 Your organisation
Swipe to see the full diagram. Check the accreditation body’s public register for your certification body before signing anything.

What a certification body does

ActivityDetail
Determines audit durationSet by accreditation rules based on headcount and scope complexity, not negotiable
Runs Stage 1 and Stage 2Documentation review followed by the certification audit
Raises nonconformitiesGraded major or minor, with corrective action tracked to closure
Independent certification decisionA reviewer who did not audit you signs off the report before the certificate is issued
Conducts surveillance auditsYears one and two, then full recertification in year three
Suspends or withdrawsWhen a major nonconformity is unresolved or audits are missed

What it cannot do

Consulting and certifying are separated by rule

ISO 17021 prohibits a certification body from providing consultancy to an organisation it certifies. It cannot write your policies, build your ISMS or perform your internal audit and then also certify you. Anyone offering both is either unaccredited or operating outside the rules.

Your auditor can tell you a control is inadequate. They cannot tell you what to build instead. That gap is deliberate, and it is why implementation happens separately from audit. The same separation exists in SOC 2, where the CPA firm audits but does not build.

Choosing one

Verify accreditation

Check the national register directly. Do not rely on a logo on a proposal.

Check the scope sector

Accreditation is granted per sector. Confirm the body is accredited for software and IT services.

Compare on total cycle

Quote all three years including surveillance, not just the initial audit fee.

Where Osto fits

Osto sits on the implementation side of that line. The platform deploys and runs the controls, access management, vulnerability testing, cloud posture, endpoint control and monitoring, generates policies and collects evidence mapped to ISO 27001 and Annex A. The audit and the certificate come from an accredited certification body, independently, which is exactly how it should work.

Free security assessment

Implementation from Osto, certification from your auditor

Osto builds and runs the controls and collects the evidence. The certificate comes from an accredited body, independently.

Get a free security assessment Book a platform walkthrough

Security first · Compliance as byproduct · One platform, everything

Frequently asked questions

What is a certification body?

An independent organisation, sometimes called a registrar, that audits your information security management system against ISO 27001 and issues the certificate. It also conducts the annual surveillance audits that keep it valid.

What is the difference between accreditation and certification?

Accreditation is the oversight of the auditor: a national body confirms the certification body is competent and impartial. Certification is what the certification body issues to you. You are certified, your auditor is accredited.

Does the certification body need to be accredited?

Not legally, but an unaccredited certificate carries little weight. Enterprise procurement and security questionnaires increasingly ask which body issued the certificate and whether it is accredited, and unaccredited ones get rejected.

Can a certification body help implement ISO 27001?

No. ISO 17021 prohibits consultancy to an organisation the body certifies, to protect impartiality. Implementation support has to come from a separate provider, tool or internal team.

Can you change certification body mid-cycle?

Yes. This is a transfer, and the new body reviews your existing certificate, audit reports and open nonconformities before taking it on. The three-year cycle usually carries over rather than restarting.