Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What are the best ISO 27001 certification bodies?
Last verifiedWhat are the best ISO 27001 certification bodies? This is an inclusion-criteria checklist, not a ranking. Verify accreditation on IAF and national AB registers. Inclusion is not endorsement. Not legal advice.
Security assurance guidance, last verified 10 September 2026 against ISO/IEC 27001:2022, ISO/IEC 17021-1:2015, ISO/IEC 17011, and IAF MLA materials. This page does not rank bodies, does not endorse anyone on it, does not determine that ISO/IEC 27001 applies to YOU, and is not legal advice or procurement advice.
Accreditation chain — AB → CB → your certificate
ISO/IEC 27001 certification is issued by a certification body (CB) accredited by a national accreditation body (AB) under ISO/IEC 17011, with IAF MLA recognition for the scheme. A consultant's letter is not a certificate. A SOC 2 CPA attestation is a different instrument. This page does not determine that ISO/IEC 27001 applies to YOU. Last verified 10 September 2026. Not legal advice.
- Legal requirement versus professional standard: customers may contractually require an accredited certificate — that is YOUR contract, not a universal law this page applies to YOU.
- IAF CertSearch and national AB registers (UKAS, ANAB, DAkkS, etc.) are the verification path — not a vendor marketing badge.
- Inclusion is not endorsement. Rows are alphabetical, not ranked.
Stated inclusion criteria
| Criterion | What to verify | Primary source | Kind of text |
|---|---|---|---|
| ISO/IEC 17021-1 accreditation | The CB is accredited for ISO/IEC 27001 (or ISO/IEC 27001:2022) management-system certification. | National AB register; IAF CertSearch. | Professional standard — accreditation is scheme-dependent. |
| IAF MLA signatory AB | The accrediting AB is an IAF MLA signatory for the relevant scheme. | IAF MLA signatories list. | Professional standard — supports international recognition. |
| Scope covering ISO/IEC 27001 | Accreditation scope explicitly includes ISO/IEC 27001 — not only other ISO management-system standards. | AB scope statement on the register entry. | Professional standard. |
| Sector and geography | The CB's accredited scope and offices cover YOUR sector and operating locations. | Register scope fields; engagement proposal. | Best practice — operational fit. |
| Impartiality / consultancy prohibition | The CB does not also sell consultancy that creates self-review threats under ISO/IEC 17021-1 §5. | CB structure disclosure; same-firm guide on this site. | Professional standard — ISO/IEC 17021-1 §5 impartiality. |
Named certification bodies (alphabetical — not a ranking)
Rows are alphabetical by current public brand. UNKNOWN accreditation cells mean check the current register — not a fail. Inclusion is not endorsement.
| Current brand | Public ISO 27001 offering | Accreditation (this page) | Notes | Last verified |
|---|---|---|---|---|
| BSI | Official page describes ISO/IEC 27001 certification. | Not verified on this page — check IAF CertSearch and the relevant national AB register. | Global CB; verify scope for YOUR sites. | 10 September 2026 |
| Bureau Veritas | Official page describes ISO/IEC 27001 certification. | Not verified on this page — check IAF CertSearch. | Verify accredited scope includes ISO/IEC 27001 for YOUR sector. | 10 September 2026 |
| DNV | Official page describes ISO/IEC 27001 certification. | Not verified on this page — check IAF CertSearch. | Verify which legal entity signs YOUR certificate. | 10 September 2026 |
| Intertek | Official page describes ISO/IEC 27001 certification. | Not verified on this page — check IAF CertSearch. | Check AB scope for ISO/IEC 27001:2022 if that is YOUR requirement. | 10 September 2026 |
| LRQA | Official page describes ISO/IEC 27001 certification. | Not verified on this page — check IAF CertSearch. | Verify geography coverage for YOUR offices. | 10 September 2026 |
| SGS | Official page describes ISO/IEC 27001 certification. | Not verified on this page — check IAF CertSearch. | Large global CB — match register entry to signing entity. | 10 September 2026 |
What to do now
- Confirm YOU need ISO/IEC 27001 certification (contract, regulator, market access) — not SOC 2 attestation alone.
- Open IAF CertSearch or your national AB register and verify the CB's ISO/IEC 27001 scope before shortlisting.
- Confirm the CB is not also YOUR primary readiness consultant — see same-firm-prepare-and-audit guide on this site.
- Use the accreditation-explained guide on this site for the AB → CB chain walkthrough.
- Print the questions-before-hiring-an-auditor guide before calls.
Checklist
- CB accredited for ISO/IEC 27001 on a current national AB register?
- Accrediting AB is an IAF MLA signatory for the scheme?
- Scope covers YOUR sites, sectors, and ISO/IEC 27001:2022 if required?
- Certificate sample shows AB logo and valid scope statement?
- Stage 1 / Stage 2 timeline and fees documented before signing?
- Independence clear — no same-firm consultancy creating self-review?
Where this shows up in ShipReady Metrics
ShipReadyMetrics collects control-mapped evidence for ISO 27001-style programmes, maintains an obligation map, and offers a 24-framework crosswalk. Signed-in ShipReady Passport and evidence-review surfaces help YOU prepare — they do not issue certificates. This product is NOT a certification body and NOT legal advice.