Certificate Walkaround

Certificate Walkaround

An ISO/IEC 27001 certificate is a formal document issued by a certification body, confirming that an organization’s Information Security Management System (ISMS) complies with the requirements of the ISO 27001 standard.

In fact, any organization may certify ISO 27001 compliance, but only certificates issued by an accredited certification body are globally recognized and have real value. Accreditation is awarded by national accreditation bodies to testify that the certification body meets audit and certification standards criteria. The accreditation body logo may only be presented on the certificates issued by the certification bodies as long as they pass the audits of the accreditation body to maintain their accredited status.

The certificate will clearly display the legal name of the organization that has achieved certification, along with its registered or operational address(es). If the certification covers multiple sites, some certificates list each location or refer to an appendix or annex.

The scope section defines what parts of the organization, systems, and processes are covered by the ISMS. This is critical information, as no certification automatically applies to the entire organization or all of its business processes unless stated. The scope may refer to specific departments, business units, services, or geographical locations. On the other hand, several – affiliated – organizations may operate a single ISMS, so more than one legal entity may also be certified.

The certificate explicitly states the version of the standard to which the organization is certified. As the current edition of the ISO 27001 standard was issued in October 2022 and the transition period is 3 years, in 5 months from now all the valid certificates will be according to the new standard.

ISO management system standards allow exclusion of certain requirements (in the case of ISO 27001, it can be done from Annex A only). Certificates always list or refer to excluded requirements. In an ISMS, the compulsory Statement of Applicability (SoA) document contains exclusions; therefore, certificates always list excluded controls or refer to the SoA.

Certificates show the initial certification date, which may indicate the maturity of the ISMS. But the most important date on a certificate is the expiration date. Certificates are usually valid for 3 years with successful surveillance audits every 6 or 12 months. Certificates are owned by the certification body; in case of a major nonconformity not properly corrected, they can be withdrawn.  In such a case the certification body may not be able to recollect the physical certificate. This is where checking the validation link on the certificate or the list of certified organizations on the internet can prove useful.

An ISO/IEC 27001 certificate is not just a badge of honor — it contains critical information that stakeholders, clients, and auditors rely on to understand what is certified, by whom, and to what extent.

04/06/2025
DACHS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.