Who can certify
ISO doesn't certify organizations. Independent certification bodies do. A certificate carries most weight when the certification body is accredited for ISO/IEC 27001 by a recognized accreditation body, which checks that the auditor follows ISO/IEC 17021-1 and the ISMS-specific rules in ISO/IEC 27006-1.
In Canada, the Standards Council of Canada (SCC) is the accreditation body that offers an information security management systems accreditation program. Other accreditation bodies, such as ANAB in the United States and UKAS in the United Kingdom, accredit certification bodies that also audit Canadian organizations. Their certificates are treated as equivalent because these bodies take part in the multilateral recognition arrangement that the IAF ran until the Global Accreditation Cooperation Incorporated took it over on January 1, 2026. Unaccredited certificates also exist.
Before the audit
Organizations usually spend several months building the ISMS before the first audit. They define the scope, complete a risk assessment, write the Statement of Applicability, put controls in place, and run at least one internal audit and one management review. Auditors need operating evidence. A quote is normally based on headcount, sites, and scope complexity, using audit time rules set by the accreditation requirements.
Stage 1 and stage 2 audits
The initial certification audit has 2 parts. Stage 1 reviews the ISMS design, the documented scope, the risk assessment, and the Statement of Applicability, and checks whether the organization is ready. It often ends with a list of concerns to fix. Stage 2 follows, sometimes weeks later.
During stage 2, auditors interview staff, sample records, and test whether controls work as described across the scope. Findings are graded as major or minor nonconformities or as opportunities for improvement. Major nonconformities must be corrected and verified before a certificate is granted, while minor ones need an accepted corrective action plan. The audit team doesn't decide. An independent reviewer at the certification body makes the certification decision.
Surveillance and recertification
Accredited certificates last 3 years. Surveillance audits happen in the years between, with the first one due within 12 months of the initial certification decision, and they sample parts of the ISMS rather than the whole system. Before the certificate expires, a recertification audit reviews the full ISMS again and starts a new 3-year cycle. Missing a surveillance audit or failing to close a major nonconformity can lead to suspension or withdrawal. An organization can also move to a different accredited certification body partway through a cycle, and the new body reviews the existing certificate, recent audit reports, and open findings before it accepts the transfer.
Checking a certificate
Logos prove little. The certificate should name the certification body, the accreditation body, the standard and edition, the scope, the sites covered, and the issue and expiry dates. Scope matters most, because a certificate covering 1 data centre says little about a separate software service.
IAF CertSearch is the global database of accredited management system certificates, and it remains available after the move to the Global Accreditation Cooperation Incorporated. Searching by company name or certificate number confirms whether an accredited certificate is valid. Searches are free. The SCC also publishes a directory of the certification bodies it accredits.
Resources
- ISO/IEC 27001:2022 Information security management systems, ISO
- Information security management systems accreditation, Standards Council of Canada
- IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
- IAF CertSearch, International Accreditation Forum
- ISO Online Browsing Platform, ISO
References
- Information security management systems accreditation, Standards Council of Canada
- IAF CertSearch, International Accreditation Forum
- Global Accreditation Cooperation Incorporated, Global Accreditation Cooperation Incorporated
- ISO/IEC 27001:2022 Information security management systems, ISO
General information, reviewed 2026-10-11. Not legal advice.