Attestio
ISO 27001 · 2026 CB Directory

The ISO 27001 certification body directory

80 accredited certification bodies (CBs) across 7 countries, sourced from IAF CertSearch, UKAS, ANAB, and direct AB accreditation records. Whether you’re a SaaS company preparing for your first ISO 27001 statement of applicability, a multinational pursuing global certification, or a renewer comparing CBs, this is the research base.

✓ Independently verified Last updated June 14, 2026
80
Indexed CBs
7
Countries
5
Accreditation bodies
12
Avg years accredited
Editorial illustration of an ISO certification process
The buyer's guide

How to choose a firm — and what to expect

ISO 27001 is the international standard for information security management systems (ISMS). Unlike PCI QSA or SOC 2, ISO 27001 certification is performed by accredited certification bodies (CBs) — independent third parties licensed by an Accreditation Body (AB) like UKAS, ANAB, or IAF. This guide explains the CB landscape, what an ISO 27001 audit costs and how long it takes, and the differences between accredited and unaccredited certification.

01

What is an ISO 27001 certification body?

An ISO 27001 certification body (CB) is a third-party organization accredited by an Accreditation Body (AB) to issue ISO 27001 certificates. The CB conducts the audit, the AB accredits the CB, and your certificate is only as credible as the AB behind the CB. The major ABs are UKAS (UK), ANAB (US), IAF CertSearch (international), and national bodies in each country. An unaccredited certificate (one issued by a CB without AB backing) is essentially worthless in enterprise procurement — always check that the CB is accredited by a recognized AB.

02

How to choose an ISO 27001 CB: 6 criteria

1. Accreditation Body. UKAS and ANAB are the most widely recognized. If your customers are in Europe, UKAS is the default; in the US, ANAB. 2. Industry experience. ISO 27001 is generic, but auditors with your industry background (SaaS, fintech, healthcare) write a sharper risk assessment and produce fewer irrelevant findings. 3. Geographic scope. If you operate in multiple countries, you need a CB accredited to issue certificates recognized in each market. 4. Audit days. ISO 27001 audit duration is prescribed by the standard based on employee count and risk. A CB that quotes fewer audit days than the standard prescribes is cutting corners. 5. Certificate format. The CB should issue a certificate with the AB logo, the CB logo, your scope statement, and a statement of applicability. 6. Surveillance cadence. ISO 27001 has annual surveillance audits and a full re-cert every 3 years. The CB should be clear about this schedule and pricing.

03

How much does ISO 27001 certification cost?

Initial certification for a small-to-mid SaaS company: $20K–$60K. Surveillance audits in years 2 and 3: $8K–$20K each. Re-certification (every 3 years): $15K–$40K. Cost drivers: number of employees in scope, complexity of the ISMS, number of sites to visit, and the number of Annex A controls you implement. Hourly rates: $150–$300 for senior auditors, less for junior. Red flag: any CB that quotes a flat fee before doing a scoping assessment is not accredited — accredited CBs follow ISO/IEC 17021-1 audit-time requirements.

04

How long does ISO 27001 certification take?

From project kickoff to certificate: typically 6–12 months. Stage 1 audit (documentation review): 1–2 months after your ISMS is documented. Stage 2 audit (certification audit): 2–4 weeks on-site or remote. Certificate issued: 2–4 weeks after Stage 2 close. The certificate is valid for 3 years, with annual surveillance audits.

05

ISO 27001 vs. SOC 2: which do you need?

For US enterprise SaaS buyers: SOC 2 is the default. For European and APAC enterprise buyers: ISO 27001 is increasingly the default. For multinationals: you need both, ideally with shared evidence collection. The Statement of Applicability (SoA) for ISO 27001 maps closely to SOC 2 control descriptions; a CB that also does SOC 2 can run both audits in parallel with one evidence pull.

The CB is the auditor; the AB is the auditor of the auditor. A UKAS-accredited CB issuing a UKAS-logo ISO 27001 certificate is the gold standard in the EU; an ANAB-accredited CB issuing an ANAB-logo certificate is the U.S. equivalent. Check both the CB’s accreditation and the AB’s recognition in your customer’s jurisdiction. The directory below is filtered by AB and country.
Editor's picks

Six firms worth shortlisting

For each use case below, we picked one CB from the 80 we index. These are the firms we’d shortlist first, based on volume of ISO 27001 certifications, depth of industry experience, and geographic coverage.

Best for US SaaS

A-LIGN

ISO 27001 + SOC 2 in one engagement

A-LIGN delivers ISO 27001 alongside SOC 2 with shared control mapping, so a SaaS company that needs both can do them in a single audit window. They use the major GRC platforms (Vanta, Drata, Secureframe) as their evidence collection layer, which keeps the engagement price 20-30% below traditional CBs.

300+ ISO 27001 certificates issued in 2024
View profile →
Best for global enterprises

British Assessment Bureau

UKAS-accredited, global delivery

British Assessment Bureau is a UKAS-accredited CB that delivers ISO 27001 globally. For multinationals, they coordinate with local ABs in each market to ensure the certificate is recognized everywhere. Their methodology is built for multi-site ISMS assessments.

UKAS-accredited; 1,000+ ISO 27001 certificates
View profile →
Best for European SaaS

TÜV Rheinland

The European default for ISO 27001

TÜV is the brand European enterprise buyers recognize. A TÜV-issued ISO 27001 certificate carries weight in DACH, France, and the UK. They are particularly strong in industrial / manufacturing ISMSs but have a growing SaaS practice.

TÜV brand recognized at 95%+ of EU enterprise procurement
View profile →
Best for fast-track SaaS

Schellman Compliance

ANAB-accredited, fast turnaround

Schellman is one of the few ANAB-accredited CBs with a SaaS-native ISO 27001 practice. They will issue a Stage 1 + Stage 2 in 4–6 months for a typical mid-market SaaS company. They also do SOC 2 in parallel.

ANAB-accredited; 500+ ISO 27001 certificates
View profile →
Best for fintech

Prescient Security

ISO 27001 + SOC 2 + PCI for fintech

Prescient runs ISO 27001 alongside SOC 2 and PCI in a single engagement for fintechs. They have a methodology specifically for payment platforms and crypto exchanges, and their certificates carry ANAB accreditation in the US and UKAS recognition in the EU.

Joint ISO 27001 + SOC 2 + PCI standard
View profile →
Best for healthcare

Coalfire

ISO 27001 + HITRUST + HIPAA, one audit

For healthcare tech, Coalfire runs ISO 27001 alongside HITRUST CSF and HIPAA Security Risk Analysis. The evidence collection is shared, so you do one audit and get three reports. ANAB-accredited, recognized in both US and EU markets.

Joint ISO 27001 + HITRUST engagements standard
View profile →
How we pick: Picks are based on the CB’s track record (volume of ISO 27001 certificates issued), accreditation body recognition, depth of industry experience, and geographic coverage. We do not accept payment for inclusion. CBs: <a href="/operators/claim">claim your firm’s profile</a> to update your listing.
How we verify

We aggregate ISO 27001 certification bodies from 5 independent sources. The CB and the AB behind them are both verified.

Verified quarterly Last verified June 14, 2026 Last crawled June 14, 2026
The International Accreditation Forum registry. The primary source for accredited CBs globally.
UK Accreditation Service — the dominant AB for European-issued ISO 27001 certificates.
ANSI National Accreditation Board — the dominant AB for US-issued ISO 27001 certificates.
Direct from each AB’s public registry (ACCREDIA, JASANZ, SCC, etc.).
Direct verification
CBs with a claimed profile can update their scope, accreditation, and certificate template directly.
📋

Get the free checklist

We'll email you the PDF. Plus weekly compliance insights. No spam, unsubscribe with one click.

We use this only to send your checklist. One-click unsubscribe in every email.

The full directory

All 80 ISO 27001 firms

Filter by name or search.

Showing 77 firms

A Good Certification Group (formerly Certification Oceania) Australia

ACCORP PARTNERS CERT Inc

ADOK CERTIFICACIÓN, S.L. Spain

AENOR CONFÍA, S.A. (Unipersonal) Spain

APROVA BELGELENDİRME VE GÖZETİM HİZMETLERİ LİMİTED ŞİRKETİ

Accredify Global LLC

Amtivo Ltd Ireland

Atlas Certification Limited

BSI Group Italia S.r.l.

Bulletproof Solutions ULC Canada

Bureau Veritas Certification Holding SAS Italy Branch

Bureau de normalisation du Québec Canada

C&amp;M S.r.l.

C&amp;M S.r.l. Italy

CAS SERTİFİKASYON ANONİM ŞİRKETİ

CERTIFICACIONES CERTHIA, S.L. (Unipersonal) Spain

CERTIFICACIÓN Y CONFIANZA CÁMARA, S.L. (Unipersonal) (CÁMARA CERTIFICA) Spain

CERTivation GmbH Germany

CFE BELGELENDİRME GÖZETİM VE EĞİTİM HİZMETLERİ LİMİTED ŞİRKETİ

CFE BELGELENDİRME GÖZETİM VE EĞİTİM HİZMETLERİ LİMİTED ŞİRKETİ Türkiye

CPSI CERTIFICATIONS (CANADA) INC. Canada

CTR BELGELENDİRME VE DENETİM ANONİM ŞİRKETİ

CTR BELGELENDİRME VE DENETİM ANONİM ŞİRKETİ Türkiye

CYBERCERT UYGUNLUK DEĞERLENDİRME ANONİM ŞİRKETİ

Complade Canada Inc. Canada

Cybertryzub Infosec Private Limite

DCERT BELGELENDİRME VE EĞİTİM HİZMETLERİ TİCARET ...

DMSZ Deutsche Managementsystem Zertifizierungsgesellschaft mbH Germany

DNV Business Assurance Australia P/L Australia

Eurolab Laboratuvar A.Ş.

First Wave International Certification Private Limited

Fortreum International

GAMACERT ULUSLARARASI BELGELENDİRME ANONİM ŞİRKETİ

GCAI CERTIFICATION SERVICES LLP

GLI Europe B.V. Spain

GLOBAL INTER CERTIFICATION (GIC)

GLOBAL REGISTRAR OF SYSTEMS PTY. LTD Australia

ICS INTERNATIONAL CERTIFICATION

IGC CERTIFICACIÓN GLOBAL, S.L. (Unipersonal) Spain

IGNYTE ASSURANCE LLC.

IQR International Certification Services LLC

IS Partners, LLC

KPMG Cert GmbH Umweltgutachterorganisation Germany

MAYA INTERNATIONAL CERTIFICATION TEKNİK KONTROL VE GÖZETİM HİZMETLERİ L...

MHM Advisory Ltd. Canada

MSECB Canada

NQA Certification Limited t/a BM TRADA

OBJEKTİF ULUSLARARASI BELGELENDİRME TEKNİK KON...

OBJEKTİF ULUSLARARASI BELGELENDİRME TEKNİK KONTROL VE GÖZETİM HİZMETLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ Türkiye

OCA Instituto de Certificación, S.L. (Unipersonal) (OCA GLOBAL) Spain

ORION ASSESSMENT SERVICES INTERNATIONAL INC. Canada

PDCA Certification Private Limited

PIAQ DEUTSCHLAND GMBH Germany

PricewaterhouseCoopers LLP Canada

Proks Certification GmbH Germany

PÜG Prüf- und Überwachungsgesellschaft mbH Germany

Pİ BELGELENDİRME VE EĞİTİM HİZMETLERİ LİMİTED ŞİRKETİ

Pİ BELGELENDİRME VE EĞİTİM HİZMETLERİ LİMİTED ŞİRKETİ Türkiye

QSERC Pty Ltd Australia

RECTO SOLUTIONS PVT LTD

RISK3SIXTY ISO CERTIFICATIONS, LLC

SAV Advisory Inc. Canada

SC&amp;H Group, Inc.

SC&amp;H Group, Inc. United States of America (the)

SGS Australia Pty Ltd Australia

SGS INTERNATIONAL CERTIFICATION SERVICES IBÉRICA, S.A. (Unipersonal) Spain

SI CERT ITALY S.r.l.

SI CERT ITALY S.r.l. Italy

Sancert LTD

Sensiba Australia Pty Ltd Australia

Toris Managment PVT. LTD.

TÜV Saarland Certification GmbH Germany

VATSIN WORLD SERVICES PRIVATE LIMITED

Veritas Management System UK Ltd.

West Assured Solutions Ltd Ireland

Zertia USA Corp.

“M.G BUGATTI CERTIFICATION” sh.p.k

FAQ

Common questions

Is an ISO 27001 certificate from an unaccredited CB worth anything?

No. ISO 27001 certificates are only credible when issued by a CB accredited by a recognized AB. Unaccredited certificates are often marketed as "ISO 27001 ready" or "ISO 27001 compliant" — there is no such thing. A certificate without an AB logo is essentially a self-attestation.

How do I verify a CB is accredited?

Check the AB’s public registry. UKAS: ukas.com. ANAB: anab.org. IAF CertSearch: iafcertsearch.org (cross-references all member ABs). If the CB is not listed in the AB’s registry, the certificate is not valid.

How long is an ISO 27001 certificate valid?

3 years, with annual surveillance audits in years 1 and 2. The re-certification audit in year 3 issues a new 3-year certificate. If the CB misses a surveillance audit or finds a major nonconformity, the certificate can be suspended or withdrawn.

Can I get ISO 27001 and SOC 2 at the same time?

Yes, and you should. The control mapping between ISO 27001 Annex A and SOC 2 Trust Service Criteria is 70-80% overlap. A CB that also issues SOC 2 reports can run both audits in parallel with shared evidence, saving 30-40% of the total cost.