Useful advice when choosing your certification body and the certification process
Use only accredited certification bodies
It is vital to ensure that the certification body you use is properly accredited by a recognised national accreditation body that is a member of the IAF (International Accreditation Forum), such as UKAS (the United Kingdom Accreditation Service).
A full list of recognised national accreditation bodies by country can be found on the IAF website. Here you can see whether a particular certification body’s ISMS scheme has been officially accredited. If you can’t find an accreditation body on this list, you can safely assume that it is not officially recognised and that ‘certificates’ it issues are unlikely to be recognised as valid.
The certification process
The certification body will:
- Review your documentation (including the scope of the ISMS, risk assessment and treatment documents, and Statement of Applicability)
- Check that you have implemented appropriate controls from Annex A of ISO 27001,
- Carry out a site audit to see the procedures in practice.
If it is satisfied with your implementation, the certification body will issue your certificate.
The certification process typically takes days rather than weeks, depending on the size of your organisation.