Screenata

Beyond SOC 2

What are ISO 27001 certification companies?

August 18, 20263 min read

What are ISO 27001 certification companies?

ISO 27001 certificates are issued by accredited certification bodies, not by consultants, auditors of other kinds, or software vendors. The body must be accredited by a recognised national accreditation body such as UKAS in the UK or ANAB in the US, and it must be independent of whoever helped you implement the management system. That independence rule catches most first-time buyers out.

Three different suppliers, and people conflate them

SupplierDoesCannot do
Certification bodyRuns Stage 1 and Stage 2 audits, issues the certificateConsult on building your ISMS
ConsultantHelps build the ISMS, writes the Statement of Applicability, runs gap analysisIssue a certificate
Compliance platformManages controls, evidence, and the crosswalk to other frameworksIssue a certificate

The rule comes from ISO/IEC 17021, the impartiality standard for certification bodies. A body that designed your management system cannot then certify it. This differs from the US consulting norm, which is why teams coming from a SOC 2 background are frequently surprised.

Accredited versus unaccredited

Unaccredited certificates exist, cost less, and are worth correspondingly less. An enterprise buyer with a mature vendor-risk process will check the accreditation, and a certificate from a body with no recognised accreditation fails that check.

How to verify: look the body up on its accreditation body's public register (UKAS, ANAB, or your national equivalent) and confirm the scope covers ISO/IEC 27001. An accreditation logo on a marketing page is not evidence.

What the audit actually involves

  1. Stage 1. Documentation review. Is the ISMS defined, is the scope coherent, does the Statement of Applicability justify inclusions and exclusions across all 93 Annex A controls?
  2. Stage 2. Implementation audit. Is it actually operating, with evidence?
  3. Surveillance, years two and three, roughly a third of the initial fee each.
  4. Recertification in year three, restarting the cycle.

Choosing between them

Price varies more than quality at the accredited tier, and the variables that move it are headcount, number of sites, and scope. Ask each body for a quote against the same scope statement, and ask how many auditors they have with experience in your sector, because that determines how much explaining you do during Stage 2.

See how much does ISO 27001 cost for the full cost breakdown including the three-year cycle.

Where a platform fits

Screenata covers implementation and evidence: ISO 27001 at $499/month per framework for a company up to 50 employees, $1,000/month at 51 to 200, and 70% of that base rate if it is your second framework, because evidence crosswalks through a NIST 800-53 hub. The certification body fee is separate and paid to them, not to us. We do not sell audits or take referral fees from auditors, so the body you choose is entirely your decision.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.