ISO27K

ISO 27001 accreditation, and what it means

Accreditation is the layer above certification. It is the reason a certificate issued in Calgary is accepted in Frankfurt, and the reason a cheaper certificate from an unaccredited body is worth very little to the buyer who asked for one.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

An accredited ISO 27001 certificate is one issued by a certification body that has itself been audited, by a national accreditation body such as the Standards Council of Canada, against ISO/IEC 17021-1 and the ISMS-specific rules in ISO/IEC 27006-1. That accreditation is what makes the certificate portable. Because SCC is a signatory to the International Accreditation Forum Multilateral Recognition Arrangement, an SCC accredited certificate is recognized by buyers in the United Kingdom, the European Union, Japan, Australia and every other IAF member economy, and the reverse is equally true in Canada. Certificates from bodies with no accreditation at all also exist, cost less, and answer a different question than the one your customer asked.

One arrangement The IAF MLA is why a Canadian certificate travels

What does accredited actually mean

There are three organizations in this picture and confusing any two of them is the most common error in published guidance. Each is bound by different rules and each sells something the others are forbidden to sell.

Who does what in an ISO 27001 certification, and who checks them
RoleExampleBound byAudited byCannot do
Accreditation bodySCC in Canada, UKAS in the UK, ANAB in the USISO/IEC 17011Peer evaluation by other IAF membersCertify your company. It never audits you
Certification bodyThe firm that issues your certificateISO/IEC 17021-1 and ISO/IEC 27006-1Its accreditation body, including witness audits of real client auditsBuild the management system it certifies, or supply your internal audit
ConsultantThe firm that gets you readyNothing, in law. No accreditation exists for this roleNobodyIssue any certificate at all

The middle row carries the consequence people care about. ISO/IEC 17021-1 prohibits a certification body from certifying a management system it advised on, and imposes a two-year cool-off after the advice ends. It also stops a body from supplying your internal audit and then certifying you, which catches several bundled offers sold to small Canadian companies. Anyone offering readiness work and an accredited certificate in one quote is either running two genuinely separate legal entities or is not describing the arrangement accurately. How to shortlist and question a body before signing is on certification bodies in Canada.

Will a Canadian certificate be accepted in the UK or the EU

Yes, and the mechanism is worth being able to name in an email, because it ends the conversation. The IAF Multilateral Recognition Arrangement is a standing agreement among national accreditation bodies to recognize each other's accreditations, on the strength of peer evaluations they run against one another. SCC is a signatory. So is UKAS, and so are the accreditation bodies of the EU member states through the European co-operation for Accreditation. A certificate issued by an SCC accredited body carries the same standing in that system as one issued by a UKAS accredited body.

What European procurement teams actually do with that fact varies. Some ask only for a certificate. Some have a policy naming their own national accreditation body and have to be told, once, that IAF recognition exists. A few genuinely require a certificate from a body with a legal presence in their jurisdiction, which is a contractual preference rather than a standards requirement, and it is negotiable if you raise it early. What a European buyer asks a Canadian supplier, and how to answer the rest of the questionnaire, is covered on ISO 27001 for UK and EU buyers.

Accreditation is granted per standard, not per body

A body accredited for ISO/IEC 27001 is not thereby accredited for ISO/IEC 42001, and in 2026 far fewer bodies hold the second than the first. If you expect to add an AI management system later, ask about it now, because moving certification body mid-cycle to get a second standard is a transfer with its own process and cost. The same rule applies to the scope of the accreditation: it names the standards and the sectors, and a body operating outside its scope is issuing an unaccredited certificate whatever the mark on it says.

What an accreditation body actually checks

Not your security. It never looks at you at all. What it examines is whether the certification body is capable of reaching a defensible conclusion about you, and four things dominate that assessment.

  • Auditor competence. Records showing that the person auditing your cloud platform has the technical background and the ISMS audit qualification for it, and that the audit team was assembled against your sector rather than against who was free.
  • Audit time. Certification bodies derive audit days from the tables in the ISO/IEC 27006 series, starting from effective headcount and adjusted for sites, technology and outsourcing. An accreditation body checks the arithmetic and challenges reductions, which is why a body cannot discount days very far even when it wants your business.
  • Impartiality. The consulting prohibition, the cool-off, the internal audit prohibition, and how the body manages an auditor who used to work for you.
  • Witness audits. An assessor from the accreditation body sits in on a real client audit and watches the certification body work. This is the check that catches shallow sampling, and it is the reason a thorough stage 2 is in the auditor's interest as well as yours.

How to check a certificate somebody sent you

This is a five-minute procedure and it is the same whether you are checking a supplier or checking that your own body is what it claims. Do not rely on the certificate document itself. A well-made PDF proves nothing.

  1. Read the scope statement on the certificate before anything else. It tells you which entity, which products and which locations are covered, and a certificate whose scope excludes the product you are buying is not the assurance you wanted.
  2. Confirm the standard and the edition. It should say ISO/IEC 27001:2022. The transition from the 2013 edition closed on 31 October 2025, so a certificate naming the older edition is not current.
  3. Find the accreditation mark and the accreditation body's name and number on the certificate. A certificate with no accreditation mark is unaccredited, regardless of how official it looks.
  4. Go to that accreditation body's own public directory, not the certification body's website, and confirm the certification body is listed and accredited for ISO/IEC 27001 specifically.
  5. Check the certification body's public register for the certificate number itself, and confirm the status is active rather than suspended or withdrawn. Accredited bodies are required to publish status.
  6. Check the expiry date and the certification date. A certificate in its third year is due for recertification, and one issued years ago with no visible surveillance history is worth a question.

What an unaccredited certificate is worth

It is a real document from a real company, and there is no law against issuing one. What it lacks is the second opinion. Nobody has checked the auditor's competence, nobody has checked that the audit ran for a defensible number of days, and nobody has checked that the body did not also build the system it audited. The price difference is substantial, frequently half or less, and the reason for the price difference is exactly the work that was not done.

The practical failure mode is not that the certificate is rejected on sight. It is that it is accepted by the first three customers, and then a security-review team at the fourth, larger customer asks which accreditation body stands behind it, at the point where a deal is already in the pipeline and a real certification takes nine months from a standing start.

When an unaccredited certificate is genuinely fine

Sometimes it is, and the sites that will not say so are the ones selling audits. There are two honest cases.

The first is that nobody has asked. If you are certifying because you want the discipline of an external audit against a real standard, and no customer contract or tender names a certificate, then what you are buying is the audit rather than the badge, and a competent unaccredited auditor delivers most of that at a lower price. Be clear with yourself that this is the purchase, and expect to redo it properly the first time a customer does ask.

The second is a staged plan with a date on it. Some companies use an unaccredited audit as a dress rehearsal ahead of the real thing. That is a defensible use of money, though a paid gap assessment normally buys more useful information for the same spend, because a gap assessment is allowed to tell you how to fix things and an auditor is not.

Where it is never fine: a tender or a customer contract that names ISO 27001 certification, any deal in the EU or UK where procurement checks accreditation as routine, and any situation where you intend to put the certification mark in front of buyers who will assume accreditation because almost every other certificate they see has it. In those cases the discount buys you a document that does not do the one job you bought it for. What the accredited version costs across the full three-year cycle is on the Canadian cost page.

Get quotes from accredited bodies only

Tell us your scope and headcount and we will put it in front of Canadian certification bodies whose accreditation you can verify.

Get matched

Common questions

Does our certification body have to be accredited by SCC?

No. The Standards Council of Canada is the national accreditation body here, but accreditation from any IAF Multilateral Recognition Arrangement signatory carries the same recognition, and plenty of Canadian companies hold certificates accredited by ANAB in the United States or UKAS in the United Kingdom. What matters is that the accreditation is real, current, and covers ISO/IEC 27001 specifically.

Is an ISO 27001 certificate from a Canadian body valid in Europe?

Yes. The IAF Multilateral Recognition Arrangement is a standing agreement among national accreditation bodies to recognize each other's accreditations, and SCC and the European accreditation bodies are all in it. If a European buyer pushes back, the useful reply names the IAF arrangement and the accreditation number on your certificate. A buyer who still insists on a body in their own jurisdiction is stating a contractual preference, not a requirement of the standard.

How can I tell if an ISO 27001 certificate is fake?

Check the certification body's public register for the certificate number, then check the accreditation body's directory for the certification body. Both are free and public. A certificate that cannot be found on the issuing body's own register is either withdrawn or was never issued, and a certificate with no accreditation mark is not fake but is also not what most buyers assume they are receiving.

Why is one certification body quoting double another?

Usually the day count differs, and usually that means one of them priced a smaller scope than you described. Ask both for days per visit across stage 1, stage 2, each surveillance and recertification. Where the day counts match and only the rate differs, you are looking at a genuine commercial difference and you can negotiate. Where the days differ by half, one quote is for a different audit. The itemised cost page shows how the days are derived.

Can a consultant issue an ISO 27001 certificate?

No. Certification is issued by a certification body, and an accredited body is prohibited from certifying a management system it consulted on, with a two-year cool-off after the advice ends. A consultant who offers a certificate is either reselling an unaccredited one or describing something else, such as a readiness attestation, which is a document with no standing in the certification system.

Does accreditation mean the auditor checked our security?

No, and this is the limit worth knowing. Accreditation means the process that produced your certificate was run properly. The audit itself samples your management system against the requirements you selected in your Statement of Applicability. It is not a penetration test and it is not a technical assessment, which is why buyers who want technical assurance ask for a test report as well as a certificate.