iso27001pentest.com

ISO/IEC 27001 · testing and audit evidence

Scope a test

File 04

Who can certify your ISMS, and why it cannot be your consultant

Updated 10 min read iso27001pentest.com

The rule that separates the people who help you from the people who certify you is the reason a certificate is worth anything. It is also the rule most vendor pages quietly avoid.

Two different transactions

There are two things you can buy on the road to an ISO/IEC 27001 certificate, and they are legally and commercially distinct.

The first is help. Gap assessment, risk assessment, the Statement of Applicability, policy work, control implementation, awareness training, penetration testing, internal audit, a rehearsal of the certification audit. All of it is a normal professional service and you can buy it from anyone competent.

The second is certification. An audit conducted by a certification body, resulting in a certificate that says an accredited third party examined your information security management system and found it conforming. That is not a professional service in the same sense. It is a conformity assessment activity performed under ISO/IEC 17021-1, by a body that has itself been accredited to perform it by a national accreditation body.

The distinction matters commercially because the same organization is not allowed to do both for you. ISO/IEC 17021-1 requires certification bodies to be impartial, and bars a certification body, or a body under its organizational control, from providing management-system consultancy to a client it certifies. A certifier who also built your ISMS would be auditing their own work, and everyone downstream of your certificate knows it.

Why the rule exists, from your customer’s point of view

Look at the certificate from the far end. A prospect asks for it because they want an independent statement that your information security is managed to a defined standard. The whole value is in the word independent. If your consultant could also certify you, the certificate would be a receipt for consultancy, and every buyer would learn to discount it within about a year.

So the impartiality rule is not administrative friction. It is the mechanism that keeps the certificate worth the money you spend obtaining it. Treat any supplier who offers to “handle certification end to end” with the scepticism that phrasing deserves, and ask them a direct question: which accredited body issues the certificate, and how is the separation maintained.

What an accredited certification body actually does

The framework is public. The International Accreditation Forum publishes the mandatory documents that accredited certification bodies work to, and those documents describe the process in enough detail to plan around.

The initial audit has two stages. Stage 1 is a readiness and documentation review: scope, Statement of Applicability, risk assessment and treatment plan, policies, the internal audit programme and the management review. Stage 2 examines implementation and effectiveness against your Statement of Applicability. Together they form the initial certification audit, and they open a three-year certification cycle.

Inside that cycle there is an audit every year. IAF MD 5:2023 sets out how the time is calculated: the total time spent annually on surveillance should be “about 1/3 of the audit time spent on the initial certification audit”, and it notes that a surveillance audit is unlikely to be less than one audit day. Recertification, at the end of the cycle, is “normally approximately 2/3 of the audit time that would be required for an initial certification audit” carried out at that point, rather than two thirds of what your original audit happened to cost.

The practical reading: certification is not a project with an end date. It is an annual obligation with a known rhythm, and the evidence you produce for it has to be produced again each year. That is exactly why the testing calendar in the scoping guide is built around the cycle rather than around the first audit.

Roles, and what each may do

Who may do what in an ISO 27001 engagement
RoleMay doMay not do
Accredited certification bodyStage 1 and Stage 2 audits, surveillance, recertification, grant, suspend or withdraw the certificate, apply the accreditation markProvide management-system consultancy to a client it certifies
Consultant or implementation partnerGap assessment, risk assessment, Statement of Applicability, policy and control work, mock Stage 2Issue a certificate, or describe itself as accredited to certify
Outsourced internal auditorRun the clause 9.2 internal audit programme as an external, independent auditor and report nonconformitiesBe your certification body, or audit work they themselves implemented
Penetration testing supplierTest, evidence A.8.8 and A.8.29, retest, and produce a customer-shareable summaryAssess your ISMS or state in a report that you are compliant with the standard
National accreditation bodyAccredit certification bodies and maintain the register of who is accredited for whatCertify your organization directly

Outsourced internal audit is not a loophole

Clause 9.2 requires an internal audit programme that checks the ISMS against your own requirements and against the standard, conducted so that the process is objective and impartial. Nothing in it says the auditor must be your employee. In organizations without a separate audit function, an external independent auditor is often the only way to satisfy the impartiality requirement at all, since an internal candidate would end up auditing their own work.

Two boundaries keep this legitimate. The outsourced internal auditor cannot be your certification body, and they should not audit controls they personally designed or implemented. Both are easy to arrange, and both should be written into the engagement. What you get in return is genuinely useful: an audit run to the same clause structure the certification body will use, delivered by someone who has seen how those audits go, several months before it matters.

An internal audit is also the cheapest place to discover that your Statement of Applicability no longer matches your systems. That mismatch is the most common substantive finding in a Stage 2, and it costs almost nothing to fix in advance.

Choosing a certification body

Certification bodies are not interchangeable, and the differences show up years later.

  • Accreditation, and for this scheme. A body may be accredited for some management-system standards and not for ISO/IEC 27001. Ask which national accreditation body accredits them and for which scheme, then verify it rather than accepting a logo.
  • Sector experience. An auditor who has audited your kind of estate asks better questions and wastes less of your time on translation. Ask what proportion of their ISO 27001 work is in your sector.
  • Audit-day estimate, and how it was derived. Audit time is calculated from effective number of personnel and complexity under published rules. A quote well below others usually means a smaller day count, which your customers can compare.
  • Continuity of auditor. The same lead auditor across a cycle saves a great deal of re-explanation. Ask whether they can commit to it.
  • How they handle remote auditing. Preferences differ, and the answer affects both cost and how much of your team’s week disappears.
  • What they expect as evidence for A.8.8 and A.8.29. Ask before you buy testing. Their answer is the most efficient scoping input you will get.

Do not choose on price alone. A certificate from a body your customers have not heard of, or one whose accreditation you cannot verify, will be questioned in exactly the procurement conversations the certificate was bought to win.

What a mock Stage 2 buys you

A rehearsal audit run by someone who is not your certification body, to the same clause structure, four to eight weeks before the real one. It is the highest-value item in most readiness budgets and the one most often skipped.

What it typically surfaces: a Statement of Applicability that has drifted from the systems, a risk treatment plan with actions past their due date and no revised date, an internal audit programme that covered the easy clauses, a management review with no documented decisions, evidence held in personal drives rather than as controlled documented information, and a penetration test report that does not cover the certified scope.

None of those is difficult to fix with a month of notice. All of them are expensive to fix during a Stage 2, where the outcome is a nonconformity, a corrective action plan, and in the worse cases a follow-up visit you pay for.

Reading a certificate, yours or a supplier’s

Once you understand who issues certificates, the document itself becomes readable, and so do the certificates your own suppliers send you. Five things are worth checking every time, and most of them take seconds.

  • The scope statement. The most important sentence on the page and the one nobody reads. A certificate whose scope covers “the operation of the corporate IT function” tells you nothing about the product you are buying. If the scope does not name the service, the certificate is not about the service.
  • The standard and its edition. ISO/IEC 27001:2022 rather than the withdrawn 2013 edition. Both editions appear in circulation and in statistics, so the year matters.
  • The accreditation mark and the accreditation body. A certificate issued without accreditation carries the certification body’s word alone. Verifying which national accreditation body stands behind it is the whole point of the mark.
  • Validity dates and the position in the cycle. A certificate issued two years ago sits just before recertification, which is useful context when you ask what has changed.
  • Any multi-site or exclusion annex. Larger certificates carry a site list. Check that the site running the service you buy is on it.

Certificates are also verifiable independently of the paper you were sent. Accredited certification bodies report their issued certificates into IAF CertSearch, the joint ISO and International Accreditation Forum database of accredited certifications; the ISO Survey 2024 was itself compiled from that database, with 76 accreditation bodies and more than 2,400 certification bodies contributing. When a supplier’s certificate cannot be located anywhere except in the PDF they emailed you, that is worth a question.

This matters in both directions. It is how you assess a supplier under A.5.19, and it is how your own customers will assess you. A certificate with a narrow, honest scope that actually names your service is more useful commercially than a broad one that does not.

Where OffSeq sits, stated plainly

This site is published by OffSeq (SEQ SIA, Riga), which sells penetration testing and security services. That is a commercial interest and it should colour how you read every recommendation here.

OffSeq is not an accredited certification body and does not issue ISO/IEC 27001 certificates. It cannot certify you, it cannot grant an accreditation mark, and nobody at OffSeq will suggest otherwise. What it does sell in this area is the preparation and the testing: gap assessment, risk assessment and Statement of Applicability support, outsourced internal audit under clause 9.2, penetration testing that evidences A.8.8 and A.8.29 with retest, awareness training for A.6.3, supplier assurance work for A.5.19 to A.5.22, and a mock Stage 2.

The certificate is issued by an independent accredited body of your choosing. That separation is not a limitation to work around. It is the reason the certificate is worth buying, and any supplier who blurs it is telling you something useful about their other advice.

Sources

  1. IAF MD 5:2023, Determination of Audit Time of Quality, Environmental, and Occupational Health and Safety Management Systems International Accreditation Forum · 2023 The three-year certification cycle, the Stage 1 plus Stage 2 initial audit, annual surveillance at about one third and recertification at approximately two thirds, all quoted above.
  2. IAF mandatory documents International Accreditation Forum · 2026 The published documents accredited certification bodies operate to, including multi-site and transfer rules.
  3. Technical Implementation Guidance on cybersecurity risk-management measures, mapping table v1.2 ENISA · 2025 Maps independent review under the implementing regulation to ISO/IEC 27001:2022 clause 9.2, clause 10.1, A.5.35 and A.8.34.
  4. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 EUR-Lex · 2024 Annex point 2.3 on independent review, including the requirement that reviewers not be in the line of authority of the area under review.

Questions

Related questions

Can our ISO 27001 consultant also be our certification body?
No. ISO/IEC 17021-1 bars a certification body, or a body under its organizational control, from providing management-system consultancy to a client it certifies. If a single supplier offers both, ask which accredited body signs the certificate and how the separation is maintained.
Is a certificate from a non-accredited body valid?
It is a document, but it carries far less weight. Accreditation is the mechanism that makes a certificate comparable and verifiable, and enterprise and public buyers increasingly check. If you are buying certification to win deals, buy accredited certification.
Can we use an external firm for our internal audit?
Yes. Clause 9.2 requires the internal audit process to be objective and impartial, and does not require the auditor to be an employee. The two constraints are that they cannot be your certification body and should not audit controls they implemented themselves.
How long does certification take?
It depends on the maturity of the ISMS rather than on the audit, and the audit itself is scheduled around the certification body’s availability. What is fixed is what comes after: an audit every year, surveillance at roughly a third of the initial audit time, and recertification at roughly two thirds in year three.