Skip to main content
Category: Certification and Accreditation

Accredited Certification

Also known as: Accredited Certification Program
Simply put

Accredited certification is when an independent, recognized authority confirms that the organization issuing certifications operates according to specific standards and guidelines. In practice, certification is the third-party confirmation (through audit) that an organization's systems or products meet a standard, while accreditation is the higher-level recognition that the certification program or body itself is competent to issue those certifications. This layered oversight is intended to give the resulting certificate greater trust and credibility.

Formal definition

Accredited certification refers to a certification issued by a certification body whose competence to operate a given certification program has been independently recognized by an accreditation authority against defined standards and guidelines. Accreditation functions as third-party recognition of the certification program's conformance to those requirements, and certification bodies typically must meet ongoing renewal obligations to maintain accredited status. In the ISO/IEC 27001 context, an accredited certification is issued by an accredited certification body against the ISMS requirements (clauses 4 through 10), and the certificate covers only the defined scope of the ISMS; this differs from a SOC 2 engagement, which is an attestation examination performed by a licensed CPA firm and results in a report rather than an accredited certificate.

Why it matters

Accredited certification introduces a layer of oversight that distinguishes a certificate backed by an independently recognized authority from one issued by a body whose competence has not been verified. Certification is the third-party confirmation, through audit, that an organization's systems or products meet a standard; accreditation is the higher-level recognition that the certification body itself adheres to defined guidelines and standards. For compliance managers and GRC professionals, this distinction matters because the credibility a stakeholder places in a certificate depends in part on whether the issuing body is accredited and on what scope that certificate actually covers.

In the ISO/IEC 27001 context, this layering is what allows a certificate to carry weight with customers, partners, and regulators. An accredited certification is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, and the certificate covers only the defined scope of the ISMS. Recognizing that boundary is essential: an accredited ISO 27001 certificate confirms conformance for the systems, locations, and processes within the declared scope, and does not extend assurance beyond it or guarantee freedom from security incidents.

Understanding accredited certification also helps professionals avoid conflating the two major frameworks they work with. ISO 27001 produces an accredited certificate issued by a certification body, whereas a SOC 2 engagement is an attestation examination performed by a licensed CPA firm and results in a report rather than an accredited certificate. Treating these as interchangeable can lead to misrepresenting the assurance a given deliverable provides, so keeping the certification-versus-attestation boundary clear is important when responding to customer requests or building a compliance roadmap.

Who it's relevant to

Compliance and GRC Managers
Those responsible for pursuing or maintaining ISO 27001 certification need to understand that the value of a certificate depends on the accreditation status of the issuing body and on the scope defined for the ISMS. This informs how they select a certification body, define scope, and communicate the meaning of their certificate to internal and external stakeholders.
Auditors and Certification Body Personnel
Professionals working within or alongside certification bodies must recognize that accreditation is third-party recognition of the program's conformance to defined standards and typically carries ongoing renewal obligations. Maintaining accredited status affects how their certifications are trusted and how they conduct scoped audits against the ISMS requirements.
Vendor Risk and Procurement Teams
Teams evaluating third-party providers rely on the distinction between accredited certification and other forms of assurance. They should confirm whether an ISO 27001 certificate was issued by an accredited body and verify what scope it covers, while recognizing that a SOC 2 report is a separate attestation deliverable rather than an accredited certificate.

Inside Accredited Certification

Accreditation Body
A national or regional oversight organization that evaluates and authorizes certification bodies to issue ISO/IEC 27001 certificates. Accreditation bodies typically operate under recognized international arrangements, though the specific body varies by country.
Certification Body (Registrar)
The independent organization that conducts the ISO 27001 audit and, upon a successful outcome, issues the certificate against the ISMS requirements in clauses 4 through 10. When it holds accreditation, its certificates carry the accreditation body's mark.
Accredited Certificate
The certification outcome issued by an accredited certification body, distinguishing it from an unaccredited certificate. It signals that the certification process itself was overseen for competence and impartiality, though it covers only the defined scope of the certified ISMS.
Defined ISMS Scope
The boundaries of the information security management system to which the certificate applies. An accredited certificate attests only to the ISMS within this defined scope and does not extend to systems, locations, or processes outside it.
Distinction from SOC 2 Attestation
Accredited certification applies to ISO/IEC 27001 and results in a certificate. It differs from a SOC 2 examination, which is an attestation engagement performed by a licensed CPA firm under AICPA SSAE 18 and results in a report rather than a certificate.

Common questions

Answers to the questions practitioners most commonly ask about Accredited Certification.

Is a SOC 2 report a form of accredited certification?
No. A SOC 2 engagement results in an attestation report issued by a licensed CPA firm under the AICPA's SSAE 18 standard, not a certification. The concept of accredited certification applies to standards such as ISO/IEC 27001, where an accredited certification body issues a certificate. SOC 2 and accredited certification operate under different models, and the two should not be conflated.
Does any CPA firm or auditor count as an accredited certification body?
No. Accredited certification bodies are organizations that have been assessed and authorized by a recognized accreditation authority to issue certificates against a specific standard, such as ISO/IEC 27001. A CPA firm performing a SOC 2 examination is licensed to conduct attestation work but is not acting as an accredited certification body, and its SOC 2 report is not a certificate.
How do I confirm that a certification body is genuinely accredited?
Verification typically involves checking that the certification body holds accreditation from a recognized accreditation authority for the specific standard in question, and confirming that the scope of that accreditation covers the standard you need certified. Because accreditation arrangements and the authorities involved vary by region, the specific verification steps depend on your jurisdiction and the standard concerned.
Does accredited certification cover my entire organization automatically?
Not necessarily. An ISO/IEC 27001 certificate covers only the defined scope of the information security management system as documented and assessed. Systems, locations, or business units outside that defined scope are not covered by the certificate, so the scope statement should be reviewed to understand exactly what the certification addresses.
Does holding an accredited certification against one framework satisfy the requirements of another?
Not automatically. Mapping between frameworks such as ISO/IEC 27001 and SOC 2 is possible but partial, and satisfying the requirements of one does not automatically satisfy the other. Each framework has its own criteria, assessment model, and evidence expectations, so meeting the requirements of a second framework typically requires a separate evaluation.
What are the practical limits of what an accredited certification demonstrates?
An accredited certification attests that the defined scope was assessed against the applicable standard and found to conform at the time of assessment, subject to ongoing surveillance where the certification scheme requires it. It does not guarantee freedom from security incidents or breaches, and it does not extend beyond the documented scope. It reflects conformance with the standard's requirements rather than an absolute assurance of security outcomes.

Common misconceptions

Any organization issuing an ISO 27001 certificate provides equivalent assurance.
Certificates issued by an accredited certification body reflect oversight of the certifier's competence and impartiality by an accreditation body, whereas unaccredited certificates lack that independent oversight. Stakeholders often specifically request accredited certification.
An accredited ISO 27001 certificate is interchangeable with a SOC 2 report.
They are different frameworks with different mechanisms. ISO 27001 accredited certification results in a certificate against a management system standard, while SOC 2 is a CPA attestation resulting in a report. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
An accredited certificate guarantees the organization is free from security breaches.
The certificate attests only that the ISMS within the defined scope met the ISO 27001 requirements at the time of assessment. It does not guarantee freedom from incidents and does not cover activities outside the defined scope.

Best practices

Confirm that the certification body holds accreditation from a recognized accreditation body, and verify the accreditation mark appears on the issued certificate.
Review the defined ISMS scope on the certificate carefully to ensure it covers the systems, locations, and processes relevant to your assurance needs.
Do not treat an accredited ISO 27001 certificate as a substitute for a SOC 2 report; assess which framework, or both, your stakeholders require based on scope and applicable criteria.
When mapping controls between ISO 27001 and SOC 2, treat any crosswalk as partial and validate that gaps are addressed separately for each framework.
Specify the ISO 27001 version (for example, the 2013 or 2022 edition) when discussing Annex A controls, since control counts and structure differ between editions.
Request and retain evidence of the certification body's accreditation status during vendor due diligence rather than relying on the certificate alone.