ANAB Accreditation
ANAB accreditation is a formal, independent third-party declaration that an organization conforms to established standards and is competent to perform specific work. ANAB, the ANSI National Accreditation Board, is a wholly owned subsidiary of ANSI and one of the largest accreditation bodies in North America, providing accreditation services in over 75 countries. In practical terms, ANAB does not audit or certify individual companies against standards such as ISO 27001 directly; instead, it accredits the bodies that perform that work.
ANAB accreditation is the assessment and accreditation, by the ANSI National Accreditation Board, of conformity assessment bodies (CABs), including certification bodies, calibration and test laboratories, and inspection bodies, against international and domestic standards and requirements. It confirms that an accredited entity possesses the appropriate competence and management system to properly perform conformity assessment activities. In an ISO/IEC 27001 context, an ISMS certificate carries greater assurance when issued by a certification body accredited by a recognized accreditation body such as ANAB, since accreditation attests to the certification body's competence rather than to any individual organization's ISMS. ANAB accreditation is distinct from SOC 2 attestation work, which is performed by licensed CPA firms under the AICPA SSAE 18 standard and is not subject to this accreditation regime. The scope and applicable standards of any given ANAB accreditation vary by the type of conformity assessment activity accredited.
Why it matters
ANAB accreditation matters because it establishes a chain of trust behind certifications rather than the certifications themselves. When an organization holds an ISO/IEC 27001 certificate, the assurance value of that certificate depends heavily on whether the certification body that issued it is itself accredited by a recognized accreditation body such as ANAB. Accreditation attests to the certification body's competence and management system, not to any individual organization's ISMS, so it functions as the quality control layer that makes third-party certification credible to customers, regulators, and business partners.
For GRC professionals and compliance managers evaluating a vendor's ISO 27001 certificate, understanding ANAB accreditation helps distinguish certificates carrying meaningful independent oversight from those issued by unaccredited bodies. Because ANAB provides accreditation services in over 75 countries and is one of the largest accreditation bodies in North America, its accreditation is a widely recognized marker of certification body competence. This distinction is easy to overlook, since a certificate on its own does not indicate who stood behind the certifying body.
It is important to note the boundaries here: ANAB accreditation applies to conformity assessment bodies such as certification bodies, laboratories, and inspection bodies, not to the end organizations being certified. It also does not extend to SOC 2 attestation work, which is performed by licensed CPA firms under the AICPA SSAE 18 standard and sits outside this accreditation regime. Confusing these two governance models is a common source of error when comparing SOC 2 reports and ISO 27001 certificates.
Who it's relevant to
Inside ANAB
Common questions
Answers to the questions practitioners most commonly ask about ANAB.