Certification bodies

How to Choose an ISO 27001 Certification Body: 8 Questions to Ask

The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.

Start with the non-negotiable

ISO 27001 certificates can only be issued by accredited certification bodies — CBs accredited by a national accreditation body such as UKAS (UK), ANAB (US), DAkkS (Germany), or RvA (Netherlands). That is the entire credential that matters. A consultant, a penetration-testing shop, and a compliance platform can all prepare you — none can certify you. Verify accreditation before anything else, ideally in the accreditation body's directory or IAF CertSearch.

The 8 questions

  1. Are you accredited for ISO 27001, and by whom?
    Ask for the accreditation body and check the CB's name and ISO 27001 scope in that body's directory. Accreditation for ISO 9001 does not cover ISO 27001.
  2. How many audit days are you quoting — and how did you calculate them?
    Audit days come from ISO/IEC 27006 tables based on in-scope headcount and complexity. A CB that won't show its math is a CB that will change-order you later.
  3. Who is my actual audit team?
    Partner bios in the pitch deck mean nothing if junior auditors do the Stage 2 fieldwork. Ask for the lead auditor and their ISO 27001 audit count in your sector.
  4. Fixed fee or per-day — and what breaks the fixed fee?
    Get scope boundaries in writing: headcount band, sites, and what triggers a change order. Ask for year-2 and year-3 surveillance pricing now too.
  5. What's your experience with our stack and sector?
    AWS vs on-prem, SaaS vs manufacturing — a CB that knows your world audits faster and asks smarter questions.
  6. How do you handle multi-site sampling?
    Additional sites add audit days. Understand the sampling logic before you agree a fee, or the second site becomes a surprise invoice.
  7. What does your timeline look like from engagement to certificate?
    Then ask what they need from you to hit it. The bottleneck is almost always the client.
  8. Can you bundle other schemes?
    If ISO 27701 or SOC 2 is on your roadmap, one CB doing combined audits shares evidence and cuts total cost.

Red flags

Big brand vs specialist CB

The certificate's value comes from its accreditation, not the size of the logo. An accredited certificate from a specialist CB carries the same structural weight as one from a global TIC — what differs is procurement-brand recognition, bench depth, and price. Match the CB to your complexity and your customers' acceptance requirements, not your aspirations. Browse verified CB profiles or get matched.

Frequently asked

Should I use a big-name CB for ISO 27001?

Only if a customer, tender, or regulator requires it. Accreditation is what makes the certificate valid; big brands add procurement recognition at a premium. For most SMBs, a right-sized accredited CB is the better value.

How many quotes should I get?

Two to three scoped quotes is the sweet spot — enough to see the real price band, few enough to evaluate properly.

Related reading

Get quotes from accredited CBs

One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.

Get a free quote

More guides

Fundamentals

ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different

Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.

Comparisons

ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?

Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.

Costs

How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)

ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.