Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What does accreditation mean for security assurance?

Last verified

What does accreditation mean for security assurance? It is the AB→CB chain for ISO schemes and CPA peer review for SOC 2. Verify on public registers. Not legal advice.

Security assurance guidance, last verified 10 September 2026 against ISO/IEC 17011, ISO/IEC 17021-1:2015, IAF MLA materials, and AICPA peer-review programme materials. Accreditation is scheme-dependent and not always legally mandated — YOUR contract may require it. Not legal advice.

Accreditation chain

For ISO management-system certificates: national accreditation body (AB) accredits certification body (CB) under ISO/IEC 17011 → CB audits YOU → certificate bears AB recognition via IAF MLA where applicable. For SOC 2: there is no ISO certificate — a licensed CPA firm performs attestation under AICPA standards; AICPA peer review is the analogous quality mechanism. Last verified 10 September 2026.

  • Legal requirement vs professional standard: some sectors legally require accredited certification; many customer contracts require it commercially — counsel reads YOUR obligations.
  • A marketing 'certified' badge without a register entry is not verification.
  • IAF MLA signatory status matters for international recognition of ISO certificates.

ISO/IEC 17000-series and IAF MLA

Key standards in the accreditation chain (not legal advice)
Standard / programmeRoleKind of text
ISO/IEC 17011Requirements for accreditation bodies accrediting CBsInternational standard
ISO/IEC 17021-1:2015Requirements for bodies certifying management systemsInternational standard
IAF MLAMultilateral recognition of AB signatoriesProfessional standard — recognition
AICPA peer reviewQuality control for CPA firms performing attestationProfessional standard — SOC 2 analogue

Step-by-step verify-accreditation checklist

  • Identify the deliverable YOU need (SOC 2 report vs ISO/IEC 27001 certificate vs other).
  • For ISO: open IAF CertSearch or national AB register (UKAS, ANAB, DAkkS, A2LA as applicable).
  • Match legal entity name, standard (e.g. ISO/IEC 27001:2022), and accredited scope to YOUR sites.
  • For SOC 2: verify CPA licence and AICPA peer-review status for the signing firm.
  • Save register screenshots with date — certificates can be suspended between your check and audit day.
  • If register entry is missing, treat as UNKNOWN — not verified on this page.

What to do now

  • Before signing, complete the verify-accreditation checklist above.
  • Use best ISO 27001 certification bodies or best SOC 2 audit firms pages for named shortlists — stated criteria, not rankings.
  • Ask prospects to show their current register entry — good answer includes scope statement and validity dates.

Checklist

  • Register entry found for signing legal entity?
  • Scope includes the standard and sites YOU need?
  • AB is IAF MLA signatory (for ISO international recognition)?
  • Peer review current (for SOC 2 CPA firm)?
  • Certificate sample shows AB logo (ISO) or CPA firm name (SOC 2)?

Where this shows up in ShipReady Metrics

The crosswalk-density honesty layer is the product analogue — transparent about what is mapped vs claimed. ShipReadyMetrics is not an accreditation body and does not issue certificates or SOC 2 reports.

Frequently asked questions