Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What are the best ISO 27001 certification bodies?

Last verified

What are the best ISO 27001 certification bodies? This is an inclusion-criteria checklist, not a ranking. Verify accreditation on IAF and national AB registers. Inclusion is not endorsement. Not legal advice.

Security assurance guidance, last verified 10 September 2026 against ISO/IEC 27001:2022, ISO/IEC 17021-1:2015, ISO/IEC 17011, and IAF MLA materials. This page does not rank bodies, does not endorse anyone on it, does not determine that ISO/IEC 27001 applies to YOU, and is not legal advice or procurement advice.

Accreditation chain — AB → CB → your certificate

ISO/IEC 27001 certification is issued by a certification body (CB) accredited by a national accreditation body (AB) under ISO/IEC 17011, with IAF MLA recognition for the scheme. A consultant's letter is not a certificate. A SOC 2 CPA attestation is a different instrument. This page does not determine that ISO/IEC 27001 applies to YOU. Last verified 10 September 2026. Not legal advice.

  • Legal requirement versus professional standard: customers may contractually require an accredited certificate — that is YOUR contract, not a universal law this page applies to YOU.
  • IAF CertSearch and national AB registers (UKAS, ANAB, DAkkS, etc.) are the verification path — not a vendor marketing badge.
  • Inclusion is not endorsement. Rows are alphabetical, not ranked.

Stated inclusion criteria

Inclusion criteria for an ISO/IEC 27001 certification body (not a ranking, not legal advice)
CriterionWhat to verifyPrimary sourceKind of text
ISO/IEC 17021-1 accreditationThe CB is accredited for ISO/IEC 27001 (or ISO/IEC 27001:2022) management-system certification.National AB register; IAF CertSearch.Professional standard — accreditation is scheme-dependent.
IAF MLA signatory ABThe accrediting AB is an IAF MLA signatory for the relevant scheme.IAF MLA signatories list.Professional standard — supports international recognition.
Scope covering ISO/IEC 27001Accreditation scope explicitly includes ISO/IEC 27001 — not only other ISO management-system standards.AB scope statement on the register entry.Professional standard.
Sector and geographyThe CB's accredited scope and offices cover YOUR sector and operating locations.Register scope fields; engagement proposal.Best practice — operational fit.
Impartiality / consultancy prohibitionThe CB does not also sell consultancy that creates self-review threats under ISO/IEC 17021-1 §5.CB structure disclosure; same-firm guide on this site.Professional standard — ISO/IEC 17021-1 §5 impartiality.

Named certification bodies (alphabetical — not a ranking)

Rows are alphabetical by current public brand. UNKNOWN accreditation cells mean check the current register — not a fail. Inclusion is not endorsement.

Major ISO/IEC 27001 certification bodies by stated criteria (alphabetical — not a ranking, not an endorsement). Last verified 10 September 2026.
Current brandPublic ISO 27001 offeringAccreditation (this page)NotesLast verified
BSIOfficial page describes ISO/IEC 27001 certification.Not verified on this page — check IAF CertSearch and the relevant national AB register.Global CB; verify scope for YOUR sites.10 September 2026
Bureau VeritasOfficial page describes ISO/IEC 27001 certification.Not verified on this page — check IAF CertSearch.Verify accredited scope includes ISO/IEC 27001 for YOUR sector.10 September 2026
DNVOfficial page describes ISO/IEC 27001 certification.Not verified on this page — check IAF CertSearch.Verify which legal entity signs YOUR certificate.10 September 2026
IntertekOfficial page describes ISO/IEC 27001 certification.Not verified on this page — check IAF CertSearch.Check AB scope for ISO/IEC 27001:2022 if that is YOUR requirement.10 September 2026
LRQAOfficial page describes ISO/IEC 27001 certification.Not verified on this page — check IAF CertSearch.Verify geography coverage for YOUR offices.10 September 2026
SGSOfficial page describes ISO/IEC 27001 certification.Not verified on this page — check IAF CertSearch.Large global CB — match register entry to signing entity.10 September 2026

What to do now

  • Confirm YOU need ISO/IEC 27001 certification (contract, regulator, market access) — not SOC 2 attestation alone.
  • Open IAF CertSearch or your national AB register and verify the CB's ISO/IEC 27001 scope before shortlisting.
  • Confirm the CB is not also YOUR primary readiness consultant — see same-firm-prepare-and-audit guide on this site.
  • Use the accreditation-explained guide on this site for the AB → CB chain walkthrough.
  • Print the questions-before-hiring-an-auditor guide before calls.

Checklist

  • CB accredited for ISO/IEC 27001 on a current national AB register?
  • Accrediting AB is an IAF MLA signatory for the scheme?
  • Scope covers YOUR sites, sectors, and ISO/IEC 27001:2022 if required?
  • Certificate sample shows AB logo and valid scope statement?
  • Stage 1 / Stage 2 timeline and fees documented before signing?
  • Independence clear — no same-firm consultancy creating self-review?

Where this shows up in ShipReady Metrics

ShipReadyMetrics collects control-mapped evidence for ISO 27001-style programmes, maintains an obligation map, and offers a 24-framework crosswalk. Signed-in ShipReady Passport and evidence-review surfaces help YOU prepare — they do not issue certificates. This product is NOT a certification body and NOT legal advice.

Frequently asked questions