Buying advice
How to choose an ISO 27001 certification body: nine questions to ask
What to check before signing with an ISO 27001 certification body: accreditation, auditor competence, scheduling, cycle pricing, impartiality, and what buyers forget.
Choosing a certification body is a three-year commitment, and switching mid-cycle is possible but tedious. Most buyers compare price and pick the cheapest. Here are the questions that matter more.
1. Are you accredited, and does your accreditation cover ISO/IEC 27001?
This is the only question that can disqualify a provider outright. Accreditation means a national accreditation body, such as ANAB, UKAS, DAkkS, JAS-ANZ, or IAS, has assessed the certification body against ISO/IEC 17021-1 and ISO/IEC 27006-1 and checks it regularly. Certificates from unaccredited providers are cheaper and are routinely rejected in tenders and vendor due diligence.
Check the accreditation body’s public register yourself rather than relying on a logo on a website. Confirm that the scope of accreditation includes ISO/IEC 27001 and, if relevant, your industry sector.
2. Who will actually audit us, and what have they done before?
Ask for the lead auditor’s background before you sign. An auditor who has run or secured systems like yours will ask better questions and produce findings you can act on. An auditor whose experience is in manufacturing quality systems will audit a cloud-native company through the wrong lens, and both sides will find it frustrating.
Ask whether the same auditor will be with you across the cycle. Continuity is valuable; a different auditor each year means re-explaining your business.
3. How soon can you give us dates?
Lead times vary from two weeks to several months. If a customer contract is waiting on your certificate, a cheap quote with a long wait is expensive. Ask for specific dates for Stage 1 and Stage 2 before signing, and ask how surveillance dates are set.
4. What is the total cost over three years?
Get the audit days and rates for Stage 1, Stage 2, both surveillance audits, and recertification, plus travel, certificate fees, and the cost of any follow-up visits. Ask whether rates are fixed for the cycle. Our article on what drives ISO 27001 certification cost explains how the audit time is calculated and what to look for in a quote.
5. Do you also offer consultancy?
The answer should be no, at least for organizations they certify. Accreditation rules prohibit a certification body from auditing an ISMS it helped design, and any body that blurs the line is creating a conflict that undermines the value of its certificate. Ask for the impartiality statement and read it.
6. How do you make the certification decision?
The decision must be made by someone other than the auditor, following a review of the audit file. Ask how long the decision takes after Stage 2 and how findings are closed. A body that issues certificates on the day of the closing meeting is skipping a step.
7. What does your report look like?
Ask for a redacted sample. A good report explains findings with the clause or control reference, the evidence examined, and why it is a finding. A report that is a list of ticks and a single paragraph gives your board nothing to work with and gives you little to improve.
8. How do you handle remote audits, multiple sites, and scope changes?
Remote auditing is normal for cloud-first organizations but should be justified in the audit plan, and physical sites in scope still need visiting during the cycle. Multi-site organizations can be certified with sampling. Ask how each is handled and priced, and how adding a site or product mid-cycle works.
9. Is your certificate publicly verifiable?
Accredited bodies must make certification status available. The best maintain a searchable public registry showing scope, status, and expiry, so your customers can verify your certificate without asking you. It also means suspended or withdrawn certificates are visible, which is what makes valid ones trustworthy.
Questions to ask yourself
- Do our customers or tenders specify a particular accreditation body? Some public sector buyers do.
- Do we want one body for several standards? Integrated audits save time if you plan ISO 27701 or ISO 22301 later.
- How important is auditor continuity to us?
- Is the body responsive now, during the sales process? It rarely gets better after signing.
A note on price
Because audit time is regulated, accredited bodies quoting the same scope should land in a similar range. Large differences usually mean a different reading of your scope, missing items in the quote, or a body that is not applying the rules. The lowest quote is worth investigating rather than accepting.
- certification body
- procurement
- accreditation