Publishing your ISO 27001 certificate and Statement of Applicability safely
An ISO 27001 certificate is meant to be shown. The mistakes are in how: an unverifiable PDF, a scope that claims more than the certificate covers, and a Statement of Applicability handed to anyone who asks.
Publish the certificate openly, with its exact scope statement, the certification body's name, the issue and expiry dates and a way to verify it. Keep the Statement of Applicability behind an NDA, because it lists every Annex A control you apply or exclude and why. Reviewers check that the certificate is accredited and that its scope covers the service they are buying, so make both easy to confirm.
What should you publish about the certificate?
| Item | Public or gated | Why |
|---|---|---|
| The certificate itself | Public | It is designed to be shown, and buyers want to see it before asking for anything else |
| Scope statement, word for word from the certificate | Public | Reviewers compare it with the service they are buying |
| Certification body and accreditation body | Public | Lets a reviewer confirm the certificate is accredited |
| Issue date, expiry date and surveillance schedule | Public | Shows the certificate is current and maintained |
| Statement of Applicability | Gated, NDA | Lists every control and every exclusion with reasons |
| Audit reports and nonconformities | Usually not shared | Internal to you and the certification body; summarise remediation if asked |
| Risk assessment and treatment plan | Not shared | Too detailed for buyers and useful to attackers |
How do buyers verify an ISO 27001 certificate?
A careful reviewer checks three things. First, that the certification body is accredited for ISO 27001 by an accreditation body that is a member of the International Accreditation Forum. In Canada that is the Standards Council of Canada; certificates issued under other members, such as UKAS or ANAB, are also recognised. Second, that the certificate appears in the certification body's register or the IAF CertSearch database. Third, that the scope covers the product they are buying. Make all three easy: name both bodies, link the public register entry if one exists, and quote the scope exactly. The accreditation guide explains why an unaccredited certificate is worth little to an enterprise buyer.
Why does the scope wording matter so much?
Because a certificate only covers what its scope statement says. A scope of "the provision of the Acme platform, operated from Toronto" says something different from "Acme Inc.", and reviewers read the difference. Never paraphrase the scope into something broader on your website. If a buyer's service sits outside it, they will find out, and the rest of what you publish loses credibility with it. The scope statement page covers how scopes are written in the first place.
Why keep the Statement of Applicability gated?
The Statement of Applicability lists all 93 Annex A controls of ISO 27001:2022, whether each is applied, and the justification for any exclusion. That is exactly what a reviewer wants and exactly what an attacker would like. Share it with customers and serious prospects under an NDA, the same way a SOC 2 report is shared. When you share it, make sure it matches the current certificate: a Statement of Applicability from before the transition to the 2022 edition, which ended on 31 October 2025, is a flag in its own right. See the Statement of Applicability guide for what it contains.
Which dates keep it current?
An ISO 27001 certificate runs for three years, with surveillance audits in the years between. Publish the expiry date and keep the certificate shown current through each surveillance audit. Diary the recertification audit early enough that a new certificate exists before the old one expires. A lapsed certificate on a public page is worse than no certificate at all.
Where should all this live?
On a trust centre: certificate and scope open, Statement of Applicability behind an NDA request, a log of who received it. TrustCenter covers trust centres for ISO 27001 companies, including how to present ISO 27001 and SOC 2 together, and NDA-gated security documents for the gate.
Common questions
Can we put our ISO 27001 certificate on our website?
Yes. The certificate is meant to be shown. Publish it with the exact scope, the certification body, and the issue and expiry dates, and give reviewers a way to verify it in the certification body's register.
Should we share our Statement of Applicability with prospects?
With serious prospects and customers, under an NDA. It lists every control and every exclusion with reasons, which is valuable to a reviewer and too detailed to publish openly.
Can we use the ISO logo on our website?
Use the certification body's certification mark under its rules, which usually allow it on websites and letterhead but not on products. The ISO logo itself is ISO's trademark and is not for certified organizations to display.
How can a buyer tell if our certificate is accredited?
The certificate should name an accredited certification body and usually the accreditation body, such as the Standards Council of Canada. Buyers can confirm it in the body's register or the IAF CertSearch database.
Compare ISO 27001 certification bodies and consultants
Describe your scope once and Canadian firms reply with dates and prices.
Get matched