ISO27K

ISO 27001 for UK and EU customers

A European or British enterprise customer has asked a Canadian supplier for ISO 27001. The first question is always whether a Canadian certificate counts over there. It does, and the reason is worth understanding, because it is also the answer when the certificate arrives from the other direction.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Yes, an ISO 27001 certificate issued by a Standards Council of Canada accredited certification body is accepted by UK and EU buyers. The mechanism is the International Accreditation Forum Multilateral Recognition Arrangement, under which signatory accreditation bodies recognise each other's accredited certificates. SCC, UKAS in the United Kingdom and ANAB in the United States are all signatories, which is why nobody needs to re-certify to sell across the Atlantic. You do not need a European certification body and you do not need a second certificate.

What you do need is the six documents a European procurement team asks for after the certificate, because handing over a PDF of the certificate alone is what turns a two-week security review into a two-month one.

Why is a Canadian certificate accepted in Europe?

Because certification is a three-layer arrangement and only the middle layer is national. An accreditation body assesses certification bodies against ISO/IEC 17021-1 and, for information security specifically, the ISO/IEC 27006 series. Those are international documents, so a UKAS-accredited body and an SCC-accredited body are being held to the same requirements. The IAF arrangement is the formal recognition of that fact between accreditation bodies, and it is what a European buyer's own auditors rely on whether or not they can name it.

Who does what, and where the national boundary actually is
LayerExamplesNational or international
Accreditation bodySCC (Canada), UKAS (United Kingdom), ANAB (United States), and one national body per EU member stateNational, and mutually recognised through IAF
Certification bodyThe organization that audits you and issues the certificateOften multinational, accredited per country and per scope
The standardISO/IEC 27001:2022International, identical everywhere
Your consultantWhoever helped you get readyIrrelevant to the certificate, and forbidden from certifying you

The one thing to check is that your certification body holds accreditation for information security management systems specifically, not just for management system certification in general. A scope of accreditation is public and checkable, and how to read one is on the accreditation page. That check matters far more than which country the accreditation came from.

What does a European procurement team ask for beyond the certificate?

The standard European supplier security pack, and where each item comes from
What they ask forWhyWhere it comes from
The certificate with accreditation mark and validity datesTo confirm it is accredited and current rather than expired or unaccreditedYour certification body
The scope statementTo check the service they are buying is inside the certified scope. This is the item that most often failsPrinted on the certificate, expanded in your scope statement
The Statement of ApplicabilityTo see which of the 93 Annex A controls you excluded and whyYour Statement of Applicability
Date of the last surveillance auditTo confirm the certificate has not lapsed between issue and expiryYour certification body, or the public certificate directory
A data processing agreement with Article 28 termsBecause they are a controller and you are a processor under GDPRYour legal counsel, not your ISMS
Sub-processor list and transfer mechanismTo document the chain and the legal basis for data leaving the EEAYour supplier register plus the transfer analysis
Most recent penetration test summaryBecause Annex A control testing expectations are read strictly in EuropeYour tester, see what an ISO 27001 test should cover

The scope statement is where Canadian suppliers lose

A narrow scope is cheaper to certify and it is read by the buyer. If your certificate covers the development and operation of one product from one office and the customer is buying a different product, the certificate does not answer their question and they will find that in ten seconds. Scope is the decision that prices the entire project and it is also the one that decides whether the certificate does the commercial job you bought it for.

Which dates on the certificate do they check?

Three, and all three come out of the certification cycle rather than the audit itself. The cycle is fixed at three years, surveillance happens annually, and a certificate whose surveillance is overdue is a certificate a careful buyer will question.

The ISO 27001 three-year certification cycle in months Stage 1 sits around month minus two, stage 2 at month zero, the certificate is issued at month one, the first surveillance audit falls at month twelve, the second at month twenty four, recertification between months thirty and thirty five, and the certificate expires at month thirty six. Stage 1, about month minus 2 Stage 2, month 0, certificate issued month 1 Surveillance 1, month 12 Surveillance 2, month 24 Recertification window, months 30 to 35 0 12 24 36, expiry
Months from the last day of the stage 2 audit. The same dates are in the table below.
Certificate dates and what a buyer reads into each
Date on the certificateMonthWhat a buyer concludes
Original certification date1How long you have run a management system. A first-cycle certificate is not a problem, it is just information.
Issue or revision dateVariesReissued after a surveillance audit or a scope change. A recent revision date is a good sign.
Last surveillance audit12 and 24Overdue surveillance means the certificate may be suspended, and this is the check most buyers miss and careful ones do not.
Expiry date36If it is inside 90 days, they will ask whether recertification is booked.

What happens at each of those visits, in audit days and CAD, is on the surveillance audit page.

A European supplier sent us a certificate. How do we check it?

  1. Read the scope statement first, not the logo. Confirm the service you are buying and the site or entity delivering it are named inside it.
  2. Find the accreditation mark and the accreditation body. If there is no mark, the certificate may be unaccredited, which is not automatically worthless and is a different thing from what you asked for.
  3. Verify the certificate in the certification body's public directory rather than trusting the PDF. Most accredited bodies publish a searchable register.
  4. Check the standard named is ISO/IEC 27001:2022. The 2013 transition period closed on 31 October 2025, so a 2013 certificate is not current.
  5. Ask for the Statement of Applicability and read the exclusions. That document tells you far more about the supplier than the certificate does.
  6. Ask when the last surveillance audit happened and whether any nonconformities are open.

When will a European buyer still not accept it?

The certificate is a gate opener, not a gate remover, and pretending otherwise sets a Canadian sales team up for a bad month. Four situations where it does not end the conversation.

Regulated financial services buyers in the EU work under DORA and its requirements for contractual terms, exit plans and register entries for information and communication technology providers, none of which an ISO 27001 certificate supplies. Public-sector tenders frequently name a national scheme alongside ISO 27001, such as Cyber Essentials Plus in the UK or a member state cloud scheme. Any buyer processing personal information will run a privacy review regardless, because the certificate says nothing about lawful basis or data subject rights, which is the subject of the GDPR page. And large enterprises with a mature third-party risk function send their own questionnaire whatever you hold, because their process requires it. The certificate turns that questionnaire from a three-week research project into an afternoon of pointing at documents you already have.

And when they ask for SOC 2 instead

North American buyers usually ask for SOC 2 and European buyers usually ask for ISO 27001, but plenty of companies get both requests within a quarter. Doing the second framework costs far less than the first, and what carries over is set out on the comparison page and priced by the reuse estimator. If the request came from a US customer, SOC 2 for Canadian companies is the other side of the question.

Get certified for a European customer deadline

Tell us the scope your buyer named and when they need it, and we will match you with Canadian firms that do this work.

Get matched

Common questions

Is a Canadian ISO 27001 certificate valid in Europe?

Yes, provided it is accredited. Accreditation bodies including SCC in Canada, UKAS in the UK and the national bodies in EU member states are signatories to the IAF Multilateral Recognition Arrangement, under which each recognises certificates issued under the others' accreditation. There is no separate European ISO 27001 and no need for a second certificate.

Do we need a UKAS-accredited certification body to sell to UK customers?

No. Some UK buyers write UKAS into a tender out of habit, and that is worth pushing back on with the IAF arrangement in the reply. If a buyer insists contractually, several multinational certification bodies hold both UKAS and SCC accreditation and can issue under either, so the answer is a conversation with your body rather than a second project.

Why do European customers ask for ISO 27001 rather than SOC 2?

Because ISO is the international standards body and ISO 27001 is the recognised certification in most of the world outside North America. SOC 2 is an attestation performed by a CPA firm under American Institute of Certified Public Accountants standards, and a European procurement team frequently has no process for evaluating one. Neither is better; they answer to different professional systems.

Our certificate scope covers only one product. Is that a problem?

Only if the customer is buying something else. A narrow scope is a legitimate and cheaper choice, and it is transparent because the scope is printed on the certificate. The failure is scoping narrowly for cost and then presenting the certificate as if it covered the whole company, which a competent buyer will catch and which damages more than it saves.

Does ISO 27001 satisfy GDPR for our European customers?

It evidences the security of processing obligation in Article 32 and almost nothing else. Lawful basis, data subject rights, records of processing, breach notification within 72 hours, impact assessments and international transfers are all outside what the standard addresses. It is also not an approved certification mechanism under Article 42.

How long does it take to get certified if a European deal is waiting?

Six to twelve months for a first certification for most Canadian companies, and the part that cannot be compressed is the operating record. An auditor needs to see controls that have been running, not controls that were approved last week. If the deal cannot wait, the useful interim answers are a completed gap assessment, a signed management commitment and a booked stage 1 date, all of which a buyer can be shown.