File 04
Who can certify your ISMS, and why it cannot be your consultant
The rule that separates the people who help you from the people who certify you is the reason a certificate is worth anything. It is also the rule most vendor pages quietly avoid.
Two different transactions
There are two things you can buy on the road to an ISO/IEC 27001 certificate, and they are legally and commercially distinct.
The first is help. Gap assessment, risk assessment, the Statement of Applicability, policy work, control implementation, awareness training, penetration testing, internal audit, a rehearsal of the certification audit. All of it is a normal professional service and you can buy it from anyone competent.
The second is certification. An audit conducted by a certification body, resulting in a certificate that says an accredited third party examined your information security management system and found it conforming. That is not a professional service in the same sense. It is a conformity assessment activity performed under ISO/IEC 17021-1, by a body that has itself been accredited to perform it by a national accreditation body.
The distinction matters commercially because the same organization is not allowed to do both for you. ISO/IEC 17021-1 requires certification bodies to be impartial, and bars a certification body, or a body under its organizational control, from providing management-system consultancy to a client it certifies. A certifier who also built your ISMS would be auditing their own work, and everyone downstream of your certificate knows it.
Why the rule exists, from your customer’s point of view
Look at the certificate from the far end. A prospect asks for it because they want an independent statement that your information security is managed to a defined standard. The whole value is in the word independent. If your consultant could also certify you, the certificate would be a receipt for consultancy, and every buyer would learn to discount it within about a year.
So the impartiality rule is not administrative friction. It is the mechanism that keeps the certificate worth the money you spend obtaining it. Treat any supplier who offers to “handle certification end to end” with the scepticism that phrasing deserves, and ask them a direct question: which accredited body issues the certificate, and how is the separation maintained.
What an accredited certification body actually does
The framework is public. The International Accreditation Forum publishes the mandatory documents that accredited certification bodies work to, and those documents describe the process in enough detail to plan around.
The initial audit has two stages. Stage 1 is a readiness and documentation review: scope, Statement of Applicability, risk assessment and treatment plan, policies, the internal audit programme and the management review. Stage 2 examines implementation and effectiveness against your Statement of Applicability. Together they form the initial certification audit, and they open a three-year certification cycle.
Inside that cycle there is an audit every year. IAF MD 5:2023 sets out how the time is calculated: the total time spent annually on surveillance should be “about 1/3 of the audit time spent on the initial certification audit”, and it notes that a surveillance audit is unlikely to be less than one audit day. Recertification, at the end of the cycle, is “normally approximately 2/3 of the audit time that would be required for an initial certification audit” carried out at that point, rather than two thirds of what your original audit happened to cost.
The practical reading: certification is not a project with an end date. It is an annual obligation with a known rhythm, and the evidence you produce for it has to be produced again each year. That is exactly why the testing calendar in the scoping guide is built around the cycle rather than around the first audit.
Roles, and what each may do
| Role | May do | May not do |
|---|---|---|
| Accredited certification body | Stage 1 and Stage 2 audits, surveillance, recertification, grant, suspend or withdraw the certificate, apply the accreditation mark | Provide management-system consultancy to a client it certifies |
| Consultant or implementation partner | Gap assessment, risk assessment, Statement of Applicability, policy and control work, mock Stage 2 | Issue a certificate, or describe itself as accredited to certify |
| Outsourced internal auditor | Run the clause 9.2 internal audit programme as an external, independent auditor and report nonconformities | Be your certification body, or audit work they themselves implemented |
| Penetration testing supplier | Test, evidence A.8.8 and A.8.29, retest, and produce a customer-shareable summary | Assess your ISMS or state in a report that you are compliant with the standard |
| National accreditation body | Accredit certification bodies and maintain the register of who is accredited for what | Certify your organization directly |
Outsourced internal audit is not a loophole
Clause 9.2 requires an internal audit programme that checks the ISMS against your own requirements and against the standard, conducted so that the process is objective and impartial. Nothing in it says the auditor must be your employee. In organizations without a separate audit function, an external independent auditor is often the only way to satisfy the impartiality requirement at all, since an internal candidate would end up auditing their own work.
Two boundaries keep this legitimate. The outsourced internal auditor cannot be your certification body, and they should not audit controls they personally designed or implemented. Both are easy to arrange, and both should be written into the engagement. What you get in return is genuinely useful: an audit run to the same clause structure the certification body will use, delivered by someone who has seen how those audits go, several months before it matters.
An internal audit is also the cheapest place to discover that your Statement of Applicability no longer matches your systems. That mismatch is the most common substantive finding in a Stage 2, and it costs almost nothing to fix in advance.
Choosing a certification body
Certification bodies are not interchangeable, and the differences show up years later.
- Accreditation, and for this scheme. A body may be accredited for some management-system standards and not for ISO/IEC 27001. Ask which national accreditation body accredits them and for which scheme, then verify it rather than accepting a logo.
- Sector experience. An auditor who has audited your kind of estate asks better questions and wastes less of your time on translation. Ask what proportion of their ISO 27001 work is in your sector.
- Audit-day estimate, and how it was derived. Audit time is calculated from effective number of personnel and complexity under published rules. A quote well below others usually means a smaller day count, which your customers can compare.
- Continuity of auditor. The same lead auditor across a cycle saves a great deal of re-explanation. Ask whether they can commit to it.
- How they handle remote auditing. Preferences differ, and the answer affects both cost and how much of your team’s week disappears.
- What they expect as evidence for A.8.8 and A.8.29. Ask before you buy testing. Their answer is the most efficient scoping input you will get.
Do not choose on price alone. A certificate from a body your customers have not heard of, or one whose accreditation you cannot verify, will be questioned in exactly the procurement conversations the certificate was bought to win.
What a mock Stage 2 buys you
A rehearsal audit run by someone who is not your certification body, to the same clause structure, four to eight weeks before the real one. It is the highest-value item in most readiness budgets and the one most often skipped.
What it typically surfaces: a Statement of Applicability that has drifted from the systems, a risk treatment plan with actions past their due date and no revised date, an internal audit programme that covered the easy clauses, a management review with no documented decisions, evidence held in personal drives rather than as controlled documented information, and a penetration test report that does not cover the certified scope.
None of those is difficult to fix with a month of notice. All of them are expensive to fix during a Stage 2, where the outcome is a nonconformity, a corrective action plan, and in the worse cases a follow-up visit you pay for.
Reading a certificate, yours or a supplier’s
Once you understand who issues certificates, the document itself becomes readable, and so do the certificates your own suppliers send you. Five things are worth checking every time, and most of them take seconds.
- The scope statement. The most important sentence on the page and the one nobody reads. A certificate whose scope covers “the operation of the corporate IT function” tells you nothing about the product you are buying. If the scope does not name the service, the certificate is not about the service.
- The standard and its edition. ISO/IEC 27001:2022 rather than the withdrawn 2013 edition. Both editions appear in circulation and in statistics, so the year matters.
- The accreditation mark and the accreditation body. A certificate issued without accreditation carries the certification body’s word alone. Verifying which national accreditation body stands behind it is the whole point of the mark.
- Validity dates and the position in the cycle. A certificate issued two years ago sits just before recertification, which is useful context when you ask what has changed.
- Any multi-site or exclusion annex. Larger certificates carry a site list. Check that the site running the service you buy is on it.
Certificates are also verifiable independently of the paper you were sent. Accredited certification bodies report their issued certificates into IAF CertSearch, the joint ISO and International Accreditation Forum database of accredited certifications; the ISO Survey 2024 was itself compiled from that database, with 76 accreditation bodies and more than 2,400 certification bodies contributing. When a supplier’s certificate cannot be located anywhere except in the PDF they emailed you, that is worth a question.
This matters in both directions. It is how you assess a supplier under A.5.19, and it is how your own customers will assess you. A certificate with a narrow, honest scope that actually names your service is more useful commercially than a broad one that does not.
Where OffSeq sits, stated plainly
This site is published by OffSeq (SEQ SIA, Riga), which sells penetration testing and security services. That is a commercial interest and it should colour how you read every recommendation here.
OffSeq is not an accredited certification body and does not issue ISO/IEC 27001 certificates. It cannot certify you, it cannot grant an accreditation mark, and nobody at OffSeq will suggest otherwise. What it does sell in this area is the preparation and the testing: gap assessment, risk assessment and Statement of Applicability support, outsourced internal audit under clause 9.2, penetration testing that evidences A.8.8 and A.8.29 with retest, awareness training for A.6.3, supplier assurance work for A.5.19 to A.5.22, and a mock Stage 2.
The certificate is issued by an independent accredited body of your choosing. That separation is not a limitation to work around. It is the reason the certificate is worth buying, and any supplier who blurs it is telling you something useful about their other advice.
Sources
- IAF MD 5:2023, Determination of Audit Time of Quality, Environmental, and Occupational Health and Safety Management Systems The three-year certification cycle, the Stage 1 plus Stage 2 initial audit, annual surveillance at about one third and recertification at approximately two thirds, all quoted above.
- IAF mandatory documents The published documents accredited certification bodies operate to, including multi-site and transfer rules.
- Technical Implementation Guidance on cybersecurity risk-management measures, mapping table v1.2 Maps independent review under the implementing regulation to ISO/IEC 27001:2022 clause 9.2, clause 10.1, A.5.35 and A.8.34.
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 Annex point 2.3 on independent review, including the requirement that reviewers not be in the line of authority of the area under review.
Questions
Related questions
Can our ISO 27001 consultant also be our certification body?
Is a certificate from a non-accredited body valid?
Can we use an external firm for our internal audit?
How long does certification take?
Keep reading
Other files in this dossier
- File 01 Does ISO 27001 require a penetration test? No, and the pages telling you otherwise are wrong. Here is the exact chain from your risk assessment to the test report your auditor expects, and what to do if you genuinely do not need one. Open file
- File 02 How to scope an ISO 27001 penetration test Scope written from your Statement of Applicability, not from a vendor package. The five inputs, the exclusions you can defend, the wording of the scope statement, and when in the three-year cycle to run it. Open file
- File 03 What an ISO 27001 penetration test report must contain The ten sections that let an auditor trace a finding from discovery to closure, why CVSS alone is not enough for clause 6.1.2, and how to produce a customer-shareable summary without circulating exploit detail. Open file