ISO 27001 for UK and EU customers
A European or British enterprise customer has asked a Canadian supplier for ISO 27001. The first question is always whether a Canadian certificate counts over there. It does, and the reason is worth understanding, because it is also the answer when the certificate arrives from the other direction.
Yes, an ISO 27001 certificate issued by a Standards Council of Canada accredited certification body is accepted by UK and EU buyers. The mechanism is the International Accreditation Forum Multilateral Recognition Arrangement, under which signatory accreditation bodies recognise each other's accredited certificates. SCC, UKAS in the United Kingdom and ANAB in the United States are all signatories, which is why nobody needs to re-certify to sell across the Atlantic. You do not need a European certification body and you do not need a second certificate.
What you do need is the six documents a European procurement team asks for after the certificate, because handing over a PDF of the certificate alone is what turns a two-week security review into a two-month one.
Why is a Canadian certificate accepted in Europe?
Because certification is a three-layer arrangement and only the middle layer is national. An accreditation body assesses certification bodies against ISO/IEC 17021-1 and, for information security specifically, the ISO/IEC 27006 series. Those are international documents, so a UKAS-accredited body and an SCC-accredited body are being held to the same requirements. The IAF arrangement is the formal recognition of that fact between accreditation bodies, and it is what a European buyer's own auditors rely on whether or not they can name it.
| Layer | Examples | National or international |
|---|---|---|
| Accreditation body | SCC (Canada), UKAS (United Kingdom), ANAB (United States), and one national body per EU member state | National, and mutually recognised through IAF |
| Certification body | The organization that audits you and issues the certificate | Often multinational, accredited per country and per scope |
| The standard | ISO/IEC 27001:2022 | International, identical everywhere |
| Your consultant | Whoever helped you get ready | Irrelevant to the certificate, and forbidden from certifying you |
The one thing to check is that your certification body holds accreditation for information security management systems specifically, not just for management system certification in general. A scope of accreditation is public and checkable, and how to read one is on the accreditation page. That check matters far more than which country the accreditation came from.
What does a European procurement team ask for beyond the certificate?
| What they ask for | Why | Where it comes from |
|---|---|---|
| The certificate with accreditation mark and validity dates | To confirm it is accredited and current rather than expired or unaccredited | Your certification body |
| The scope statement | To check the service they are buying is inside the certified scope. This is the item that most often fails | Printed on the certificate, expanded in your scope statement |
| The Statement of Applicability | To see which of the 93 Annex A controls you excluded and why | Your Statement of Applicability |
| Date of the last surveillance audit | To confirm the certificate has not lapsed between issue and expiry | Your certification body, or the public certificate directory |
| A data processing agreement with Article 28 terms | Because they are a controller and you are a processor under GDPR | Your legal counsel, not your ISMS |
| Sub-processor list and transfer mechanism | To document the chain and the legal basis for data leaving the EEA | Your supplier register plus the transfer analysis |
| Most recent penetration test summary | Because Annex A control testing expectations are read strictly in Europe | Your tester, see what an ISO 27001 test should cover |
The scope statement is where Canadian suppliers lose
A narrow scope is cheaper to certify and it is read by the buyer. If your certificate covers the development and operation of one product from one office and the customer is buying a different product, the certificate does not answer their question and they will find that in ten seconds. Scope is the decision that prices the entire project and it is also the one that decides whether the certificate does the commercial job you bought it for.
Which dates on the certificate do they check?
Three, and all three come out of the certification cycle rather than the audit itself. The cycle is fixed at three years, surveillance happens annually, and a certificate whose surveillance is overdue is a certificate a careful buyer will question.
| Date on the certificate | Month | What a buyer concludes |
|---|---|---|
| Original certification date | 1 | How long you have run a management system. A first-cycle certificate is not a problem, it is just information. |
| Issue or revision date | Varies | Reissued after a surveillance audit or a scope change. A recent revision date is a good sign. |
| Last surveillance audit | 12 and 24 | Overdue surveillance means the certificate may be suspended, and this is the check most buyers miss and careful ones do not. |
| Expiry date | 36 | If it is inside 90 days, they will ask whether recertification is booked. |
What happens at each of those visits, in audit days and CAD, is on the surveillance audit page.
A European supplier sent us a certificate. How do we check it?
- Read the scope statement first, not the logo. Confirm the service you are buying and the site or entity delivering it are named inside it.
- Find the accreditation mark and the accreditation body. If there is no mark, the certificate may be unaccredited, which is not automatically worthless and is a different thing from what you asked for.
- Verify the certificate in the certification body's public directory rather than trusting the PDF. Most accredited bodies publish a searchable register.
- Check the standard named is ISO/IEC 27001:2022. The 2013 transition period closed on 31 October 2025, so a 2013 certificate is not current.
- Ask for the Statement of Applicability and read the exclusions. That document tells you far more about the supplier than the certificate does.
- Ask when the last surveillance audit happened and whether any nonconformities are open.
When will a European buyer still not accept it?
The certificate is a gate opener, not a gate remover, and pretending otherwise sets a Canadian sales team up for a bad month. Four situations where it does not end the conversation.
Regulated financial services buyers in the EU work under DORA and its requirements for contractual terms, exit plans and register entries for information and communication technology providers, none of which an ISO 27001 certificate supplies. Public-sector tenders frequently name a national scheme alongside ISO 27001, such as Cyber Essentials Plus in the UK or a member state cloud scheme. Any buyer processing personal information will run a privacy review regardless, because the certificate says nothing about lawful basis or data subject rights, which is the subject of the GDPR page. And large enterprises with a mature third-party risk function send their own questionnaire whatever you hold, because their process requires it. The certificate turns that questionnaire from a three-week research project into an afternoon of pointing at documents you already have.
And when they ask for SOC 2 instead
North American buyers usually ask for SOC 2 and European buyers usually ask for ISO 27001, but plenty of companies get both requests within a quarter. Doing the second framework costs far less than the first, and what carries over is set out on the comparison page and priced by the reuse estimator. If the request came from a US customer, SOC 2 for Canadian companies is the other side of the question.
Get certified for a European customer deadline
Tell us the scope your buyer named and when they need it, and we will match you with Canadian firms that do this work.
Get matchedCommon questions
Is a Canadian ISO 27001 certificate valid in Europe?
Yes, provided it is accredited. Accreditation bodies including SCC in Canada, UKAS in the UK and the national bodies in EU member states are signatories to the IAF Multilateral Recognition Arrangement, under which each recognises certificates issued under the others' accreditation. There is no separate European ISO 27001 and no need for a second certificate.
Do we need a UKAS-accredited certification body to sell to UK customers?
No. Some UK buyers write UKAS into a tender out of habit, and that is worth pushing back on with the IAF arrangement in the reply. If a buyer insists contractually, several multinational certification bodies hold both UKAS and SCC accreditation and can issue under either, so the answer is a conversation with your body rather than a second project.
Why do European customers ask for ISO 27001 rather than SOC 2?
Because ISO is the international standards body and ISO 27001 is the recognised certification in most of the world outside North America. SOC 2 is an attestation performed by a CPA firm under American Institute of Certified Public Accountants standards, and a European procurement team frequently has no process for evaluating one. Neither is better; they answer to different professional systems.
Our certificate scope covers only one product. Is that a problem?
Only if the customer is buying something else. A narrow scope is a legitimate and cheaper choice, and it is transparent because the scope is printed on the certificate. The failure is scoping narrowly for cost and then presenting the certificate as if it covered the whole company, which a competent buyer will catch and which damages more than it saves.
Does ISO 27001 satisfy GDPR for our European customers?
It evidences the security of processing obligation in Article 32 and almost nothing else. Lawful basis, data subject rights, records of processing, breach notification within 72 hours, impact assessments and international transfers are all outside what the standard addresses. It is also not an approved certification mechanism under Article 42.
How long does it take to get certified if a European deal is waiting?
Six to twelve months for a first certification for most Canadian companies, and the part that cannot be compressed is the operating record. An auditor needs to see controls that have been running, not controls that were approved last week. If the deal cannot wait, the useful interim answers are a completed gap assessment, a signed management commitment and a booked stage 1 date, all of which a buyer can be shown.