A certification body is the independent organisation that audits your management system and issues the ISO 27001 certificate. It cannot also be the consultant that built it.
The short answer
A certification body, sometimes called a registrar, performs the Stage 1 and Stage 2 audits and issues your certificate. The credible ones are accredited by a national accreditation body such as UKAS, ANAB or NABCB, which audits the auditor. An unaccredited certificate is legally a piece of paper, and enterprise procurement teams increasingly check.
The distinction that catches people out: accreditation and certification are different things at different levels. You are certified. Your certification body is accredited.
On this page
Accreditation, certification and you
What a certification body does
| Activity | Detail |
|---|---|
| Determines audit duration | Set by accreditation rules based on headcount and scope complexity, not negotiable |
| Runs Stage 1 and Stage 2 | Documentation review followed by the certification audit |
| Raises nonconformities | Graded major or minor, with corrective action tracked to closure |
| Independent certification decision | A reviewer who did not audit you signs off the report before the certificate is issued |
| Conducts surveillance audits | Years one and two, then full recertification in year three |
| Suspends or withdraws | When a major nonconformity is unresolved or audits are missed |
What it cannot do
Consulting and certifying are separated by rule
ISO 17021 prohibits a certification body from providing consultancy to an organisation it certifies. It cannot write your policies, build your ISMS or perform your internal audit and then also certify you. Anyone offering both is either unaccredited or operating outside the rules.
Your auditor can tell you a control is inadequate. They cannot tell you what to build instead. That gap is deliberate, and it is why implementation happens separately from audit. The same separation exists in SOC 2, where the CPA firm audits but does not build.
Choosing one
Verify accreditation
Check the national register directly. Do not rely on a logo on a proposal.
Check the scope sector
Accreditation is granted per sector. Confirm the body is accredited for software and IT services.
Compare on total cycle
Quote all three years including surveillance, not just the initial audit fee.
Where Osto fits
Osto sits on the implementation side of that line. The platform deploys and runs the controls, access management, vulnerability testing, cloud posture, endpoint control and monitoring, generates policies and collects evidence mapped to ISO 27001 and Annex A. The audit and the certificate come from an accredited certification body, independently, which is exactly how it should work.
Free security assessment
Implementation from Osto, certification from your auditor
Osto builds and runs the controls and collects the evidence. The certificate comes from an accredited body, independently.
Get a free security assessment Book a platform walkthroughSecurity first · Compliance as byproduct · One platform, everything
Frequently asked questions
What is a certification body?
An independent organisation, sometimes called a registrar, that audits your information security management system against ISO 27001 and issues the certificate. It also conducts the annual surveillance audits that keep it valid.
What is the difference between accreditation and certification?
Accreditation is the oversight of the auditor: a national body confirms the certification body is competent and impartial. Certification is what the certification body issues to you. You are certified, your auditor is accredited.
Does the certification body need to be accredited?
Not legally, but an unaccredited certificate carries little weight. Enterprise procurement and security questionnaires increasingly ask which body issued the certificate and whether it is accredited, and unaccredited ones get rejected.
Can a certification body help implement ISO 27001?
No. ISO 17021 prohibits consultancy to an organisation the body certifies, to protect impartiality. Implementation support has to come from a separate provider, tool or internal team.
Can you change certification body mid-cycle?
Yes. This is a transfer, and the new body reviews your existing certificate, audit reports and open nonconformities before taking it on. The three-year cycle usually carries over rather than restarting.

