Guides
Switching ISO 27001 certification bodies
You are not locked in. Certificates transfer between accredited CBs — here's when and how to do it without breaking your certification cycle.
When switching makes sense
- Surveillance pricing crept up. Years 2–3 fees that no longer match the market.
- Service degraded. Slow scheduling, rotating audit teams, unresponsive account management.
- Scope changed. New countries, new sites, or new schemes your current CB covers poorly.
- Procurement requires it. A customer or tender names a CB tier yours doesn't meet.
How transfers work
- Time it to the cycle. Transfers usually happen at a surveillance audit or at recertification — the cleanest handoff points.
- The new CB reviews your file. Expect them to examine prior audit reports, nonconformity closures, and your current certificate before accepting the transfer.
- No re-certification from scratch. A proper transfer keeps your three-year cycle intact; the new CB picks up surveillance where the old one left off.
- Notify stakeholders. Customers who hold your certificate on file should get the updated one — and check contract clauses that name your CB.
Check your agreement. Some certification agreements have notice periods or transfer fees. Read yours before you start the conversation — and get the new CB's transfer terms in writing too.
Compare your alternatives
Get scoped quotes from CBs that fit your new scope — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.