Guide · Updated July 2026

Choosing a certification body

Accreditation first. Everything else second.

The certification body decision mirrors the SOC 2 auditor decision with one sharper edge: accreditation is binary, checkable, and decisive.

The two-minute check that filters the market

Ask which accreditation the body holds and verify it in the accreditor’s public registry (ANAB, UKAS, DAkkS, and peers under the IAF umbrella). Unaccredited “certification mills” sell faster, cheaper certificates that fail the first procurement review that checks — which converts your entire program spend into wall art.

What separates the accredited ones

Sector experience. An auditor who has assessed SaaS ISMSs reads your cloud architecture natively; one from manufacturing audits your laptop fleet like a factory floor. Ask who would lead your engagement and what they’ve certified recently.

Scheduling reality. Good bodies book out months; your timeline inherits their calendar. Get Stage 1 and Stage 2 dates contracted together.

Three-year pricing. The certificate is a cycle: initial audit plus two surveillance years. Bodies discount year one and recover it in surveillance fees — quote the cycle, not the stage.

Recognition where you sell. Any IAF-accredited certificate is formally equivalent, but familiar names (BSI, TÜV, DNV, and peers) clear conservative procurement desks with fewer questions.

The independence line

Your implementation help — consultant, platform, or us — must be separate from the body that certifies. Structure it that way from day one and Stage 1 raises no eyebrows; blur it and you’ve built a finding into the foundation.

Frequently Asked
What does 'accredited' actually mean?

The certification body is itself audited by a national accreditation authority (ANAB in the US, UKAS in the UK, etc.) for competence and independence. Certificates from unaccredited bodies are legal to issue and commercially near-worthless — enterprise procurement checks.

Can our implementation consultant also certify us?

No — that's a structural independence violation. The body that certifies cannot have built your ISMS. Any vendor offering both in one package is offering a certificate that won't survive scrutiny.

How far ahead do we book?

Two to four months for reputable bodies, longer at year-end. Book Stage 1 and Stage 2 together, and get surveillance-audit pricing for years two and three in the same quote — that's where quiet price escalation lives.

Related Guides

What ISO 27001 costs — What ISO 27001 really costs — certification body fees, platform, internal audit, and the ISMS labor — with the surveillance-year costs quotes leave out.

The ISO 27001 timeline — How long ISO 27001 really takes — ISMS build, operating evidence, internal audit, Stage 1 and Stage 2 — and the clause that quietly sets your minimum.