<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are ISO 27001 certification companies?"
title: "ISO 27001 Certification Companies"
seoTitle: "ISO 27001 Certification Companies: How to Choose"
summary: "ISO 27001 certificates are issued by accredited certification bodies, not by consultants or software vendors. The certification body must be accredited by a national accreditation body such as UKAS or ANAB, and must be independent of whoever helped you implement. That independence rule is the single most common surprise: the consultant who built your ISMS cannot certify it."
publishedAt: "2026-08-18"
keywords:
  - "ISO 27001 certification companies"
  - "iso certification companies"
  - "ISO 27001 certified company"
  - "ISO 27001 certification body"
  - "ISO 27001 certification consultants"
pillar: "Beyond SOC 2"
faqs:
  - question: "Who can issue an ISO 27001 certificate?"
    answer: "Only a certification body accredited by a recognised national accreditation body, such as UKAS in the UK or ANAB in the US. Certificates from unaccredited bodies exist and are cheaper, and enterprise buyers who check accreditation will reject them."
  - question: "Can my consultant also certify me?"
    answer: "No. Impartiality rules under ISO/IEC 17021 prevent a body from certifying a management system it helped design or implement. This catches people out, because the US consulting market has no equivalent restriction. Plan for two separate suppliers from the start."
  - question: "How do I check a certification body is accredited?"
    answer: "Look up the body on its accreditation body's public directory, for example the UKAS or ANAB register, and confirm the accreditation covers ISO/IEC 27001 specifically. An accreditation mark on a website is not evidence; the register is."
---

## What are ISO 27001 certification companies?

ISO 27001 certificates are issued by **accredited certification bodies**, not by consultants, auditors of other kinds, or software vendors. The body must be accredited by a recognised national accreditation body such as **UKAS** in the UK or **ANAB** in the US, and it must be **independent of whoever helped you implement** the management system. That independence rule catches most first-time buyers out.

### Three different suppliers, and people conflate them

| Supplier | Does | Cannot do |
|---|---|---|
| **Certification body** | Runs Stage 1 and Stage 2 audits, issues the certificate | Consult on building your ISMS |
| **Consultant** | Helps build the ISMS, writes the Statement of Applicability, runs gap analysis | Issue a certificate |
| **Compliance platform** | Manages controls, evidence, and the crosswalk to other frameworks | Issue a certificate |

The rule comes from **ISO/IEC 17021**, the impartiality standard for certification bodies. A body that designed your management system cannot then certify it. This differs from the US consulting norm, which is why teams coming from a SOC 2 background are frequently surprised.

## Accredited versus unaccredited

Unaccredited certificates exist, cost less, and are worth correspondingly less. An enterprise buyer with a mature vendor-risk process will check the accreditation, and a certificate from a body with no recognised accreditation fails that check.

**How to verify:** look the body up on its accreditation body's public register (UKAS, ANAB, or your national equivalent) and confirm the scope covers ISO/IEC 27001. An accreditation logo on a marketing page is not evidence.

## What the audit actually involves

1. **Stage 1.** Documentation review. Is the ISMS defined, is the scope coherent, does the Statement of Applicability justify inclusions and exclusions across all 93 Annex A controls?
2. **Stage 2.** Implementation audit. Is it actually operating, with evidence?
3. **Surveillance,** years two and three, roughly a third of the initial fee each.
4. **Recertification** in year three, restarting the cycle.

## Choosing between them

Price varies more than quality at the accredited tier, and the variables that move it are headcount, number of sites, and scope. Ask each body for a quote against the same scope statement, and ask how many auditors they have with experience in your sector, because that determines how much explaining you do during Stage 2.

See [how much does ISO 27001 cost](/resources/answers/how-much-does-iso-27001-cost) for the full cost breakdown including the three-year cycle.

## Where a platform fits

Screenata covers implementation and evidence: ISO 27001 at **$499/month per framework for a company up to 50 employees**, $1,000/month at 51 to 200, and 70% of that base rate if it is your second framework, because evidence crosswalks through a NIST 800-53 hub. **The certification body fee is separate and paid to them, not to us.** We do not sell audits or take referral fees from auditors, so the body you choose is entirely your decision.
