ISO27K

Publishing your ISO 27001 certificate and Statement of Applicability safely

An ISO 27001 certificate is meant to be shown. The mistakes are in how: an unverifiable PDF, a scope that claims more than the certificate covers, and a Statement of Applicability handed to anyone who asks.

Last reviewed 2026-10-01Written by Jacob Masse, TrazTech Inc.

Publish the certificate openly, with its exact scope statement, the certification body's name, the issue and expiry dates and a way to verify it. Keep the Statement of Applicability behind an NDA, because it lists every Annex A control you apply or exclude and why. Reviewers check that the certificate is accredited and that its scope covers the service they are buying, so make both easy to confirm.

What should you publish about the certificate?

ISO 27001 material: public or gated
ItemPublic or gatedWhy
The certificate itselfPublicIt is designed to be shown, and buyers want to see it before asking for anything else
Scope statement, word for word from the certificatePublicReviewers compare it with the service they are buying
Certification body and accreditation bodyPublicLets a reviewer confirm the certificate is accredited
Issue date, expiry date and surveillance schedulePublicShows the certificate is current and maintained
Statement of ApplicabilityGated, NDALists every control and every exclusion with reasons
Audit reports and nonconformitiesUsually not sharedInternal to you and the certification body; summarise remediation if asked
Risk assessment and treatment planNot sharedToo detailed for buyers and useful to attackers

How do buyers verify an ISO 27001 certificate?

A careful reviewer checks three things. First, that the certification body is accredited for ISO 27001 by an accreditation body that is a member of the International Accreditation Forum. In Canada that is the Standards Council of Canada; certificates issued under other members, such as UKAS or ANAB, are also recognised. Second, that the certificate appears in the certification body's register or the IAF CertSearch database. Third, that the scope covers the product they are buying. Make all three easy: name both bodies, link the public register entry if one exists, and quote the scope exactly. The accreditation guide explains why an unaccredited certificate is worth little to an enterprise buyer.

Why does the scope wording matter so much?

Because a certificate only covers what its scope statement says. A scope of "the provision of the Acme platform, operated from Toronto" says something different from "Acme Inc.", and reviewers read the difference. Never paraphrase the scope into something broader on your website. If a buyer's service sits outside it, they will find out, and the rest of what you publish loses credibility with it. The scope statement page covers how scopes are written in the first place.

Why keep the Statement of Applicability gated?

The Statement of Applicability lists all 93 Annex A controls of ISO 27001:2022, whether each is applied, and the justification for any exclusion. That is exactly what a reviewer wants and exactly what an attacker would like. Share it with customers and serious prospects under an NDA, the same way a SOC 2 report is shared. When you share it, make sure it matches the current certificate: a Statement of Applicability from before the transition to the 2022 edition, which ended on 31 October 2025, is a flag in its own right. See the Statement of Applicability guide for what it contains.

Which dates keep it current?

An ISO 27001 certificate runs for three years, with surveillance audits in the years between. Publish the expiry date and keep the certificate shown current through each surveillance audit. Diary the recertification audit early enough that a new certificate exists before the old one expires. A lapsed certificate on a public page is worse than no certificate at all.

Where should all this live?

On a trust centre: certificate and scope open, Statement of Applicability behind an NDA request, a log of who received it. TrustCenter covers trust centres for ISO 27001 companies, including how to present ISO 27001 and SOC 2 together, and NDA-gated security documents for the gate.

Common questions

Can we put our ISO 27001 certificate on our website?

Yes. The certificate is meant to be shown. Publish it with the exact scope, the certification body, and the issue and expiry dates, and give reviewers a way to verify it in the certification body's register.

Should we share our Statement of Applicability with prospects?

With serious prospects and customers, under an NDA. It lists every control and every exclusion with reasons, which is valuable to a reviewer and too detailed to publish openly.

Can we use the ISO logo on our website?

Use the certification body's certification mark under its rules, which usually allow it on websites and letterhead but not on products. The ISO logo itself is ISO's trademark and is not for certified organizations to display.

How can a buyer tell if our certificate is accredited?

The certificate should name an accredited certification body and usually the accreditation body, such as the Standards Council of Canada. Buyers can confirm it in the body's register or the IAF CertSearch database.

Compare ISO 27001 certification bodies and consultants

Describe your scope once and Canadian firms reply with dates and prices.

Get matched