Choosing Your ISO 27001 Certification Body: What to Ask
The certification body you pick shapes cost, timeline, and how much your certificate is worth to customers. Here is how to choose well and what to ask before signing.
By Kellwick Team · July 24, 2026 · 5 min read
The certification body is the organization that audits you and issues your ISO 27001 certificate. Kellwick is not one; we help companies get ready and choose well. That independence is why we can say plainly what a certification body will not: the choice matters more than most founders realize, and the cheapest quote is often the most expensive decision. Here is how to pick.
Accreditation is the first filter
Not all certificates are equal, and the difference comes down to accreditation. An accredited certification body has itself been assessed by a national accreditation authority against international rules for how audits must be conducted. An unaccredited body can still issue an official-looking certificate, but it carries far less weight.
This matters because your certificate exists to reassure customers. A sophisticated enterprise buyer's security team knows to check accreditation. When they see a certificate from an unaccredited body, they discount it, and sometimes reject it outright. You will have paid for an audit and still be answering the same security questionnaires as before.
Before anything else, confirm two things:
- The certification body is accredited by a recognized national accreditation body
- That accreditation specifically covers ISO 27001, not just other standards they also certify
You can usually verify accreditation directly on the accreditation body's public register rather than taking the certification body's word for it. Do that. It takes minutes and it is the single most important check. A cheaper quote from an unaccredited body is not a saving; it is buying a certificate that fewer customers will accept.
Understand the two-stage audit and what drives cost
ISO 27001 certification follows a defined rhythm, and understanding it lets you read quotes intelligently. Certification is not a single event. It is a cycle.
The initial certification has two stages. Stage 1 is a review of your documentation and readiness, where the auditor checks that your management system exists and identifies anything likely to fail Stage 2. Stage 2 is the main audit, where the auditor tests whether your controls actually operate. Pass Stage 2 and you receive a certificate valid for three years, subject to lighter surveillance audits, usually annual, that confirm you are maintaining the system. At three years you recertify.
Cost is driven largely by audit duration, which in turn is driven by your headcount, the complexity of your scope, and the number of sites. When you gather quotes:
- Ask for the total three-year cost, not just year one. Surveillance audits are part of the commitment.
- Confirm how many auditor-days each stage and each surveillance audit involves.
- Check what is included: travel, reporting, and any fees for follow-up on findings.
- Ask how findings are handled and whether re-review of corrected findings costs extra.
A quote that looks cheap in year one can carry heavier surveillance costs later. Compare the full cycle, and compare like for like on auditor-days, because a suspiciously low day count can mean a shallow audit that customers will not respect, or a scramble when the auditor runs out of time.
Auditor fit is not a soft factor
The individual auditor assigned to you shapes the entire experience. Two accredited bodies can deliver very different audits depending on who shows up. An auditor who understands modern SaaS will look at your CI/CD pipeline and recognize change control. An auditor whose frame of reference is traditional IT may expect a change advisory board and struggle to accept that your pipeline is the control.
This is worth probing before you commit:
- Ask whether their auditors have experience with cloud-native SaaS, fintech, or payments companies, depending on what you are.
- Ask how they approach controls implemented through tooling and automation rather than manual process.
- Ask whether you will have consistency of auditor across the three-year cycle, or a different person each visit.
You are not looking for an easy auditor. An auditor who waves things through does you no favors, because the certificate's value comes from the audit being credible. You are looking for one who is rigorous and fluent in how your kind of company operates, so the audit tests real security rather than the absence of controls you have deliberately replaced with better ones. Where you have a choice, an auditor who speaks your technical language turns the audit into something useful rather than a translation exercise.
Questions to ask before you sign
By the time you are choosing between bodies, a focused set of questions separates them. Ask each shortlisted body:
- Accreditation. Who accredits you, and can I verify it on their register?
- Full-cycle cost. What is the total cost across three years including all surveillance audits, and what could change it?
- Auditor-days. How many days for Stage 1, Stage 2, and each surveillance audit, and what determines that?
- Sector experience. What experience do your auditors have with companies like ours?
- Auditor continuity. Will we have the same auditor across the cycle?
- Scheduling. What is your lead time to book Stage 1, and how far ahead must surveillance audits be scheduled?
- Findings process. How are nonconformities classified and resolved, and what are the timelines and any costs?
- Scope handling. How do you handle scope changes if we grow or add products mid-cycle?
The answers tell you more than the price. A body that answers clearly, verifies its own accreditation without hesitation, and asks intelligent questions about your business is one that will run a professional audit. Vagueness on cost or accreditation is a signal to walk.
Where an advisor fits, and where it does not
A certification body must remain independent of you to issue a valid certificate. That independence is a rule, not a preference. It means the body that audits you cannot also have built your management system, and it means they will not coach you toward passing. Their job is to assess, not to prepare you.
That separation is exactly why readiness work sits with someone else. An independent advisor helps you build the management system, close gaps, and walk into Stage 2 confident, then steps back. The certification body audits. Keeping these roles distinct protects the integrity of your certificate, because a buyer can trust that the auditor had no stake in the outcome.
Practically, this means you are managing two relationships: the advisor who gets you ready, and the certification body who certifies you. Choosing the certification body well, on accreditation, cost, and fit, is a decision you make once and live with for three years. Getting it wrong is expensive to unwind. It is worth the diligence.
Bottom line
The certification body you choose determines what your certificate is worth. Insist on verified accreditation, compare the full three-year cost rather than the headline quote, and treat auditor fit as a real factor, not a nicety. Ask the direct questions and weigh the clarity of the answers as much as the numbers. Choose deliberately, because you are committing to a three-year relationship.
If you are approaching certification and want to be genuinely ready before you engage a certification body, a Kellwick readiness review can assess where you stand and help you walk into the audit with the gaps already closed.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.