You asked a vendor for evidence of ISO 27001 certification. They sent you a PDF with an official-looking seal, you added it to the vendor file, and you moved on. Job done, no?
That may be enough to satisfy a checklist, but the existence of a certificate doesn’t tell you whether it was issued by an accredited certification body, whether it remains valid, or whether its scope covers the service you’re buying.
A fact that often surprises people is that ISO itself doesn’t certify organizations. It develops standards, including ISO/IEC 27001, but independent certification bodies conduct the audits and issue certificates.
Accreditation provides oversight of those certification bodies and gives customers a way to assess the credibility of the certificates they issue.
The role of accreditation in ISO 27001 certification
An accreditation body assesses a certification body against ISO/IEC 17021-1, the international standard for organizations that audit and certify management systems. For information security management systems, ISO/IEC 27006-1:2024 adds requirements specific to ISO 27001 certification.
This assessment considers whether auditors have the appropriate information security competence, whether conflicts of interest are managed, how audit duration is calculated, and whether certification decisions are made independently from the audit itself. It can also include observing certification-body auditors as they conduct client audits.
The result is a chain of assurance. A certification body audits an organization, an accreditation body assesses the certification body, and international recognition arrangements provide oversight of the accreditation bodies.
A non-accredited certificate isn’t necessarily fraudulent, in fact it may have been issued in good faith by people with relevant experience. However, the competence, independence and methodology of the issuer haven’t been assessed through the same recognized accreditation process. The certificate may therefore provide less assurance and may not meet a customer’s procurement, contractual or regulatory requirements.
Four ways to assess an ISO 27001 certificate
1. Identify the certification and accreditation bodies
Start with the name of the certification body that issued the certificate. Many accredited certificates also display the accreditation body’s mark or identify the relevant accreditation number.
If the accreditation details aren’t shown, ask the vendor or certification body to provide them. You can then confirm the certification body’s status directly through the accreditation body’s directory.
2. Search IAF CertSearch
IAF CertSearch is the global database for accredited management system certifications. Search using the organization’s name or certificate number, then check that the company, certification body, standard and status match the document you received.
Finding the certificate provides useful independent validation. If it doesn’t appear, investigate further rather than assuming immediately that it’s invalid. Ask the vendor for a current verification link or confirm the certification directly with the issuing certification body.
3. Check the edition and validity
The certificate should identify ISO/IEC 27001:2022. The transition period for certificates issued against ISO/IEC 27001:2013 ended on October 31, 2025. After that date, remaining 2013 certificates were required to expire or be withdrawn under the international transition requirements.
Review the certificate’s issue and expiry dates as well. A certificate can refer to the current edition of the standard and still be out of date.
4. Read the certification scope
The words “ISO 27001 certified” don’t explain which parts of an organization have been assessed. That information appears in the scope statement.
Check the legal entity, locations, products, services and business processes covered by the certification. A certificate covering one office or product line provides limited assurance if the service your organization uses sits outside that boundary.
When a certificate can’t be verified
Ask the vendor for clarification before escalating the issue. There may be a reasonable explanation, such as a transfer between certification bodies, a recently renewed certificate or an outdated copy of the document.
The vendor should still be able to provide a current certificate, verification record and clear accreditation details. If it can’t, consider the gap in the context of the vendor’s access to your data, systems and critical operations. An unverifiable certificate shouldn’t be treated as equivalent to accredited ISO 27001 certification.
Selecting an ISO 27001 certification body
Organizations pursuing certification should apply the same checks before selecting a certification body. Ask for its accreditation number and confirm that its scope of accreditation specifically includes ISO/IEC 27001. Accreditation for another standard, such as ISO 9001, doesn’t automatically extend to information security certification.
An ISO 27001 certificate can be valuable evidence of how an organization manages information security. Its value depends on who issued it, the oversight behind that issuer, and the systems and services included within its scope.
Related Posts
Stay connected
Subscribe to receive new blog articles and updates from Thoropass in your inbox.
Want to join our team?
Help Thoropass ensure that compliance never gets in the way of innovation.









.png)