Beyond SOC 2
What are ISO 27001 certification companies?
What are ISO 27001 certification companies?
ISO 27001 certificates are issued by accredited certification bodies, not by consultants, auditors of other kinds, or software vendors. The body must be accredited by a recognised national accreditation body such as UKAS in the UK or ANAB in the US, and it must be independent of whoever helped you implement the management system. That independence rule catches most first-time buyers out.
Three different suppliers, and people conflate them
| Supplier | Does | Cannot do |
|---|---|---|
| Certification body | Runs Stage 1 and Stage 2 audits, issues the certificate | Consult on building your ISMS |
| Consultant | Helps build the ISMS, writes the Statement of Applicability, runs gap analysis | Issue a certificate |
| Compliance platform | Manages controls, evidence, and the crosswalk to other frameworks | Issue a certificate |
The rule comes from ISO/IEC 17021, the impartiality standard for certification bodies. A body that designed your management system cannot then certify it. This differs from the US consulting norm, which is why teams coming from a SOC 2 background are frequently surprised.
Accredited versus unaccredited
Unaccredited certificates exist, cost less, and are worth correspondingly less. An enterprise buyer with a mature vendor-risk process will check the accreditation, and a certificate from a body with no recognised accreditation fails that check.
How to verify: look the body up on its accreditation body's public register (UKAS, ANAB, or your national equivalent) and confirm the scope covers ISO/IEC 27001. An accreditation logo on a marketing page is not evidence.
What the audit actually involves
- Stage 1. Documentation review. Is the ISMS defined, is the scope coherent, does the Statement of Applicability justify inclusions and exclusions across all 93 Annex A controls?
- Stage 2. Implementation audit. Is it actually operating, with evidence?
- Surveillance, years two and three, roughly a third of the initial fee each.
- Recertification in year three, restarting the cycle.
Choosing between them
Price varies more than quality at the accredited tier, and the variables that move it are headcount, number of sites, and scope. Ask each body for a quote against the same scope statement, and ask how many auditors they have with experience in your sector, because that determines how much explaining you do during Stage 2.
See how much does ISO 27001 cost for the full cost breakdown including the three-year cycle.
Where a platform fits
Screenata covers implementation and evidence: ISO 27001 at $499/month per framework for a company up to 50 employees, $1,000/month at 51 to 200, and 70% of that base rate if it is your second framework, because evidence crosswalks through a NIST 800-53 hub. The certification body fee is separate and paid to them, not to us. We do not sell audits or take referral fees from auditors, so the body you choose is entirely your decision.